Google Analytics 4 and privacy in the EU: are you really compliant?

22 JUL 2026

Google Analytics 4 and privacy in the EU: are you really compliant?

Google Analytics 4 and GDPR: is your site really privacy-compliant in the EU

In July 2023 Google Analytics 4 took the place of the old Universal Analytics, and many migrated in a hurry thinking they had solved a problem. In reality the most uncomfortable question stayed exactly the same: can you use Google Analytics 4 in the EU in compliance with the GDPR? Installing GA4 does not, on its own, amount to being compliant — and those who take it for granted risk discovering the opposite at the worst moment. Let’s look at what really changed with GA4, where the privacy knot lies, and the concrete checklist for using it without exposing yourself.

From Universal Analytics to GA4: what changed (and what didn’t).

GA4 was redesigned with a little more attention to privacy than its predecessor: it doesn’t store IP addresses the way Universal Analytics did, it offers data-retention controls and settings to limit sharing. On this, a step forward genuinely happened, and it should be acknowledged without playing it down.

What didn’t change is the substance: GA4 remains a Google tool that collects data about your visitors and processes it on its infrastructure. The best settings in the world don’t remove the fact that you’re entrusting personal data to a provider, and that behind it there’s a flow crossing the Atlantic. The technical migration solved a product problem, not the legal one.

The real knot: data transfer.

The sensitive point has always been the transfer of data to the United States. In 2022 the Italian Garante, in line with other European authorities, declared unlawful the use of Google Analytics as one site had it configured, precisely because of that transfer to a country without adequate safeguards after the “Schrems II” ruling. It was a strong signal: the convenience of a tool isn’t enough to justify a data flow that breaks the rules.

In 2023 the picture changed again: the European Union and the United States adopted the “Data Privacy Framework,” a new legal basis for transfers to American companies that join it, Google included. It isn’t a definitive free-for-all — the Framework is already being challenged and could be called into question — but today it offers a legal foothold that was missing in 2022. On these developments it pays to be honest: they’re evolving, and they should be verified, not taken as settled.

Google Analytics 4 and GDPR: the checklist to be compliant.

Making GA4 compliant is possible, but it has to be done for real, point by point. You need a banner that blocks GA4 before consent and activates it only after acceptance, ideally through Consent Mode; data retention and sharing with other Google products have to be configured, switching off what you don’t use; the data processing agreement with Google has to be accepted and kept; and GA4 has to be declared in the cookie policy and the privacy notice, with the user’s rights made exercisable.

None of these steps is complicated taken on its own. The problem is that almost always one or two are missing — usually the first, consent — and that’s enough to make all the rest pointless. A systematic check, not one from memory, is the quickest way to know where you stand.

Google Analytics 4 and GDPR: the checklist to be privacy-compliant
GA4 compliant in five moves: consent collected before GA4 fires (1), data retention configured (2), sharing with Google switched off where not needed (3), the processing agreement signed (4), GA4 declared in the cookie and privacy policy (5). The first is often missing — and on its own it cancels the others.

Consent and configuration: the two most common mistakes.

The first mistake, the most widespread, is letting GA4 fire before consent: the banner is there, but it’s decorative, and the data is collected anyway from the first instant. It’s exactly what the authorities object to, and it’s also the easiest thing to detect with a scan. The second mistake is leaving data sharing with Google’s advertising products active out of inertia, without declaring it and without a valid basis: an extra layer of tracking the user knows nothing about.

Both mistakes come from the same misconception: thinking that installing the tool is the end of the job, when it’s the start. GA4’s default configuration is designed to collect the maximum, not for compliance: it’s up to you to narrow it. It’s the same technical clean-up work we do on every site, not a touch-up to postpone.

Compliant is possible, but you have to do it.

The answer to the title’s question, then, is: yes, you can use Google Analytics 4 compliantly in the EU — but not by the mere fact of having installed it. You need consent collected first, a narrowed configuration, the agreements in order and transparency in the notices. Do this and GA4 is a legitimate tool; skip even the first step and it’s a risk you carry with every visit.

And if all this effort to stay compliant seems out of proportion to what you actually need to know about the site, that’s a fair question: there are lighter, privacy-first alternatives that ask for less consent and less configuration. We cover them in the dedicated article. The right tool is the one you can keep compliant without forgetting a piece along the way.

Sources.

The figures and claims in this article come from here. These are primary sources, not summaries: open them and check for yourself.

Let’s talk about your website.

Free analysis of your current website; a fixed quote within 24 hours of the call.

100% freeNo obligation
Response within 24 hoursDetailed quote
Your data, protectedFull confidentiality

Lascia un commento

Il tuo indirizzo email non sarà pubblicato. I campi obbligatori sono contrassegnati *