Technical compliance

Google Analytics and GDPR

What EU and German operators should verify for GA4: consent before load, contracts, configuration, and when a different analytics stack fits better.

Project review with stakeholders
On this page
  1. TL;DR
  2. Who this is for
  3. Consent before load
  4. Operator checklist
  5. IP anonymization
  6. Alternatives (brief)
  7. Audit vs self-check
  8. Common questions
Analytics dashboard gated behind a consent choice on a website
TL;DR
  • GA4 on a Germany/EU site usually needs prior consent before the library loads or sets identifiers. A banner that decorates while GA fires on page load fails the technical test.
  • IP anonymization (or similar toggles) reduces risk signals. Alone, they do not replace consent, a data processing agreement, and transfer documentation where personal data leaves the EEA.
  • Google Analytics is widely used under GDPR when consent, contracts, and configuration line up. Some supervisory decisions have criticised specific setups historically. There is no single sentence that every GA install is unlawful everywhere.
  • For the wider website stack, use the GDPR website checklist. For a technical pass, see the GDPR audit.
Who this is for

Operators who already run GA4, or are deciding whether to keep it.

Marketing and product teams in Germany and the wider EU still ask one blunt question: “Is Google Analytics illegal?” The honest answer is operational: consent, contract, and configuration decide whether your install is defensible, and counsel should confirm for your entity.

This page supports the commercial GDPR audit service. It pairs with cookie banner requirements in Germany. It does not invent case citations or claim a blanket ban.

GA4 that loads before accept is a measurement tool running without a choice. Consent means the script waits.
Operator checklist

Seven GA4 checks for GDPR-minded EU sites.

Network panel showing no GA requests before consent
01

Consent gate before any GA request

Fresh browser, reject all: zero analytics.google.com / googletagmanager hits tied to your measurement ID. Accept analytics: hits appear. Withdraw: next load stays quiet.

Single analytics injection path diagram
02

One injection path

Pick GTM or a single site plugin or a theme snippet. Duplicate injectors bypass the CMP and create “ghost” hits. WordPress sites often stack Site Kit, a theme snippet, and GTM at once.

Signed data processing terms on file
03

Data processing agreement with Google

Accept Google’s data processing terms for Analytics in the Admin / account settings path that applies to your property. Keep evidence (screenshot or export date) with your processor file.

Privacy policy section describing Google Analytics
04

Privacy policy matches reality

Name Google Analytics / GA4, purposes, categories of data, retention settings you use, and that Google acts as processor (or joint roles where your counsel says so). Update when you enable ads features or BigQuery export.

GA4 admin settings for retention and data sharing
05

Transfers and configuration hygiene

Document international transfer tools your counsel relies on (for example adequacy / SCCs as applicable). Review Google signals, ads personalization, data retention, and any features that expand sharing. IP anonymization-style settings help; they do not replace consent or contracts.

Analytics access roles and retention controls
06

Access control and retention

Limit who can see raw reports. Set retention to what you actually need. Delete or archive old properties you no longer use so orphaned measurement IDs do not linger in themes.

Release checklist including analytics consent retest
07

Retest after marketing stack changes

New GTM container version, new WordPress plugin, new consent tool: re-run the private-window test. Compliance decays when growth tools ship without a blocking check.

IP anonymization

Useful hardening. Incomplete as a solo control.

Truncating or anonymising IP addresses reduces one identifier. GA4 still typically uses client identifiers and event data that can qualify as personal data in an EU context. Treat anonymisation as hygiene inside a consented, contracted setup, with counsel confirming your bases and notices.

If someone claims “we turned on anonymize IP, so we are done,” ask for the network test with reject-all and for the signed processing terms. Those two artefacts decide more than a single toggle.

Alternatives (brief)

When teams keep measurement and change the stack.

Pick the stack your team can operate weekly. A quiet Matomo with weak access control is still a risk.
OptionWhat it often buys youTrade-off to plan for
Matomo (self-hosted or carefully configured cloud)More control over hosting location and processorsOps cost; consent may still apply depending on setup
Plausible / similar privacy-focused toolsSmaller cookie footprint; simpler notices in many setupsFewer product analytics features than GA4
Server-side tagging / first-party collectionTighter control over what leaves the browserEngineering cost; still needs lawful basis and notices
Keep GA4 with strict consent + contractsFamiliar reports and marketing integrationsOngoing CMP discipline and transfer documentation
Audit vs self-check

Run the smoke test every release. Audit when the stakes rise.

After every GTM or plugin change, re-check consent blocking. Before an enterprise security questionnaire, funding diligence, or a year of unmanaged tags, commission a technical GDPR audit. Widen to cookies, forms, and DPAs with the website checklist. Cost context: GDPR audit cost.

Common questions

What people ask about Google Analytics and GDPR.

Is Google Analytics illegal in Germany?

There is no blanket rule that every Google Analytics install is unlawful in Germany. Supervisory authorities have, in various periods, criticised or acted against specific configurations (for example weak consent, missing contracts, or unresolved transfer issues). Whether your GA4 setup is acceptable depends on consent before load, processing terms, transfer documentation, configuration, and your counsel’s assessment for your entity. Treat “illegal everywhere” headlines as incomplete.

Does GA4 need cookie consent in the EU?

For typical behavioural analytics on marketing sites, yes: obtain prior consent before loading GA and setting analytics identifiers. Necessary site functions are a different category. See cookie banner GDPR requirements for Germany.

Is IP anonymization enough for GDPR?

No as a solo measure. It can reduce risk. You still need a lawful basis (usually consent for this use case), transparent notices, a data processing agreement, and documented transfers where applicable.

Do we need a DPA with Google for Analytics?

Yes in the usual controller–processor model: accept and retain Google’s data processing terms for the Analytics services you use, and list Google in your processor inventory and privacy policy.

Can we use Google Analytics without cookies?

Cookieless or reduced-storage modes change the technical footprint. They do not automatically remove GDPR duties if you still process personal data. Assess the actual identifiers and events you send, then decide consent and notices with counsel.

What are practical alternatives to GA4 in the EU?

Teams often evaluate Matomo, privacy-focused tools such as Plausible, or server-side / first-party collection. Each option still needs a lawful basis, accurate notices, and an owner who maintains the stack. Match the tool to the decisions you actually make from the data.

Start here

Ready to talk.Send us the brief.

or book a 15-minute call or email us directly

Not sure where to start? Send the page, workflow, or backlog causing the problem. We will tell you whether it needs a scope call, a short diagnostic, or a different first step.