Technical compliance
Google Analytics and GDPR
What EU and German operators should verify for GA4: consent before load, contracts, configuration, and when a different analytics stack fits better.

TL;DR
- GA4 on a Germany/EU site usually needs prior consent before the library loads or sets identifiers. A banner that decorates while GA fires on page load fails the technical test.
- IP anonymization (or similar toggles) reduces risk signals. Alone, they do not replace consent, a data processing agreement, and transfer documentation where personal data leaves the EEA.
- Google Analytics is widely used under GDPR when consent, contracts, and configuration line up. Some supervisory decisions have criticised specific setups historically. There is no single sentence that every GA install is unlawful everywhere.
- For the wider website stack, use the GDPR website checklist. For a technical pass, see the GDPR audit.
Who this is for
Operators who already run GA4, or are deciding whether to keep it.
Marketing and product teams in Germany and the wider EU still ask one blunt question: “Is Google Analytics illegal?” The honest answer is operational: consent, contract, and configuration decide whether your install is defensible, and counsel should confirm for your entity.
This page supports the commercial GDPR audit service. It pairs with cookie banner requirements in Germany. It does not invent case citations or claim a blanket ban.
GA4 that loads before accept is a measurement tool running without a choice. Consent means the script waits.
Consent before load
Block the GA library until the visitor opts in.
For most marketing and behavioural analytics uses, GDPR expects a freely given, specific, informed, unambiguous opt-in. On a website that means: do not load gtag/GTM tags that send hits to Google Analytics until analytics consent is granted.
Test in a private window with reject-all. You should see no GA network calls and no Client ID cookies from Analytics. If hits appear before any click, fix blocking first (CMP auto-block, Consent Mode wired correctly, or remove hard-coded snippets).
Silence on first visit is the default. Closing the banner without accepting must keep GA off. Details on equal reject and no pre-ticks sit in the cookie banner article.
Operator checklist
Seven GA4 checks for GDPR-minded EU sites.
01
Consent gate before any GA request
Fresh browser, reject all: zero analytics.google.com / googletagmanager hits tied to your measurement ID. Accept analytics: hits appear. Withdraw: next load stays quiet.
02
One injection path
Pick GTM or a single site plugin or a theme snippet. Duplicate injectors bypass the CMP and create “ghost” hits. WordPress sites often stack Site Kit, a theme snippet, and GTM at once.
03
Data processing agreement with Google
Accept Google’s data processing terms for Analytics in the Admin / account settings path that applies to your property. Keep evidence (screenshot or export date) with your processor file.
04
Privacy policy matches reality
Name Google Analytics / GA4, purposes, categories of data, retention settings you use, and that Google acts as processor (or joint roles where your counsel says so). Update when you enable ads features or BigQuery export.
05
Transfers and configuration hygiene
Document international transfer tools your counsel relies on (for example adequacy / SCCs as applicable). Review Google signals, ads personalization, data retention, and any features that expand sharing. IP anonymization-style settings help; they do not replace consent or contracts.
06
Access control and retention
Limit who can see raw reports. Set retention to what you actually need. Delete or archive old properties you no longer use so orphaned measurement IDs do not linger in themes.
07
Retest after marketing stack changes
New GTM container version, new WordPress plugin, new consent tool: re-run the private-window test. Compliance decays when growth tools ship without a blocking check.
IP anonymization
Useful hardening. Incomplete as a solo control.
Truncating or anonymising IP addresses reduces one identifier. GA4 still typically uses client identifiers and event data that can qualify as personal data in an EU context. Treat anonymisation as hygiene inside a consented, contracted setup, with counsel confirming your bases and notices.
If someone claims “we turned on anonymize IP, so we are done,” ask for the network test with reject-all and for the signed processing terms. Those two artefacts decide more than a single toggle.
Alternatives (brief)
When teams keep measurement and change the stack.
| Option | What it often buys you | Trade-off to plan for |
|---|---|---|
| Matomo (self-hosted or carefully configured cloud) | More control over hosting location and processors | Ops cost; consent may still apply depending on setup |
| Plausible / similar privacy-focused tools | Smaller cookie footprint; simpler notices in many setups | Fewer product analytics features than GA4 |
| Server-side tagging / first-party collection | Tighter control over what leaves the browser | Engineering cost; still needs lawful basis and notices |
| Keep GA4 with strict consent + contracts | Familiar reports and marketing integrations | Ongoing CMP discipline and transfer documentation |
Audit vs self-check
Run the smoke test every release. Audit when the stakes rise.
After every GTM or plugin change, re-check consent blocking. Before an enterprise security questionnaire, funding diligence, or a year of unmanaged tags, commission a technical GDPR audit. Widen to cookies, forms, and DPAs with the website checklist. Cost context: GDPR audit cost.
Common questions
What people ask about Google Analytics and GDPR.
Is Google Analytics illegal in Germany?
There is no blanket rule that every Google Analytics install is unlawful in Germany. Supervisory authorities have, in various periods, criticised or acted against specific configurations (for example weak consent, missing contracts, or unresolved transfer issues). Whether your GA4 setup is acceptable depends on consent before load, processing terms, transfer documentation, configuration, and your counsel’s assessment for your entity. Treat “illegal everywhere” headlines as incomplete.
Does GA4 need cookie consent in the EU?
For typical behavioural analytics on marketing sites, yes: obtain prior consent before loading GA and setting analytics identifiers. Necessary site functions are a different category. See cookie banner GDPR requirements for Germany.
Is IP anonymization enough for GDPR?
No as a solo measure. It can reduce risk. You still need a lawful basis (usually consent for this use case), transparent notices, a data processing agreement, and documented transfers where applicable.
Do we need a DPA with Google for Analytics?
Yes in the usual controller–processor model: accept and retain Google’s data processing terms for the Analytics services you use, and list Google in your processor inventory and privacy policy.
Can we use Google Analytics without cookies?
Cookieless or reduced-storage modes change the technical footprint. They do not automatically remove GDPR duties if you still process personal data. Assess the actual identifiers and events you send, then decide consent and notices with counsel.
What are practical alternatives to GA4 in the EU?
Teams often evaluate Matomo, privacy-focused tools such as Plausible, or server-side / first-party collection. Each option still needs a lawful basis, accurate notices, and an owner who maintains the stack. Match the tool to the decisions you actually make from the data.
Start here
Ready to talk.Send us the brief.
or book a 15-minute call →or email us directly →
Not sure where to start? Send the page, workflow, or backlog causing the problem. We will tell you whether it needs a scope call, a short diagnostic, or a different first step.