Google Analytics 4 GDPR Compliance After Austrian DSB Ruling

Austria's ruling reshaped Google Analytics compliance across Europe, but not how most assume.

Senior Writer · · 10 min read
Privacy Compliance · September 23, 2026 · 10 min read · 2,184 words

The Austrian data protection authority (DSB) never fined Google or NetDoktor a single euro, yet its December 2021 decision became the founding legal text for how Europe treats Google Analytics under the GDPR. Four years and one adequacy decision later, the ruling's core finding, that operators, not Google, bear liability, still holds. What changed is narrower than most website owners assume, and what didn't change is what actually costs money.

What the DSB decided in December 2021

The respondent was NetDoktor, an Austrian medical information site. The DSB signed the decision on December 22, 2021, though it wasn't publicly announced until January 13, 2022. It was the first ruling to come out of a batch of 101 near-identical complaints that the Vienna-based privacy group noyb, run by Max Schrems, had filed across EU and EEA member states in the wake of Schrems II. NetDoktor happened to be first through the pipeline, not first by design.

The technical finding keeps getting cited. The DSB held that a unique identification number, combined with a visitor's IP address and assorted browser parameters, builds what the decision called a digital footprint, and that footprint counts as personal data under Article 4(1) GDPR even without a name attached. The threshold is being able to single a person out from everyone else hitting the same site, not identifying someone by name. It's being able to single a person out from everyone else hitting the same site. On that basis, the DSB named the _ga cookie and the Client ID it generates as personal data.

The violation itself wasn't about consent banners or cookie disclosures. It was Article 44: NetDoktor had transferred that personal data to servers in a non-EU country without an adequate legal basis for doing so.

The legal backdrop: Schrems II and US surveillance law as the decisive factor

None of this makes sense without going back to July 2020, when a top European court struck down a transatlantic data-transfer agreement in the case known as Schrems II. The court's reasoning was blunt: US providers operating under a US surveillance statute and a companion presidential directive can be compelled to hand over data to US intelligence agencies, and no contract a company signs can override that. A data processing agreement is worthless against a national security subpoena.

A widely used EU data transfer mechanism survived the ruling, but only on paper. The court said operators relying on SCCs now had to run a transfer impact assessment and, where the assessment turned up a gap between EU protection and US law, apply supplemental technical measures to close it. The DSB, applying that standard to NetDoktor's Google Analytics setup, found no technical measure available at the time that could actually close the gap. Encryption in transit doesn't help when the recipient holds the decryption key and can be legally compelled to use it.

Schrems II framed adequacy as binary. A transfer mechanism either meets the bar or it doesn't, and there's no room for a company to argue that the risk of US government access is probably low enough to proceed anyway. The DSB's rejection of that risk-based defense wasn't invention. It was a direct application of what the CJEU had already ruled.

How the ruling cascaded through Europe, 2022 to 2025

The Austrian decision landed in the middle of a wave, not at the start of one. Days before it was made public, the EU's data protection authority for its own institutions sanctioned the European Parliament itself for running Google Analytics on its COVID testing sites, one of the earliest post-Schrems II enforcement actions in the EU institutional space.

France's CNIL followed on February 10, 2022, confirming that GA transfers violated Article 44 and giving an unnamed website operator one month to fix its setup. Italy's Garante went further in June 2022, finding that even shortened or anonymized IP addresses counted as personal data given the re-identification risk, and rejecting Google's technical protections as insufficient against US surveillance access.

Sweden's IMY delivered the first real financial consequences in 2023. Four companies, Tele2, CDON, Coop Sweden, and Dagens Industri, were named in enforcement actions. Tele2 was fined 12 million SEK (roughly €1 million), CDON drew a 300,000 SEK fine, and CDON, Coop Sweden, and Dagens Industri were all ordered to stop using Google Analytics outright, though Coop and Dagens Industri escaped fines. The Stockholm Court of Appeal later upheld the Tele2 penalty. What makes the Swedish decision matter beyond the fine amounts is IMY's specific finding: hashing cookie identifiers and routing IP addresses through server-side tagging weren't enough. The underlying transfer was still unlawful, no matter how the data got dressed up along the way.

What the EU-US Data Privacy Framework changed and left untouched

The European Commission adopted an adequacy decision for the EU-US Data Privacy Framework on July 10, 2023, using its Article 45 powers. Google LLC is on the DPF list and has relied on it for EEA transfers since September 1, 2023; its certification is active, with re-certification due September 13, 2026.

What the DPF actually fixes is narrow but real: the specific defect that Austria, France, and Italy all found, namely that there was no valid legal mechanism for the transfer at all, now has an answer. Sending personal data to a US company certified under the relevant transfer framework, like Google, is no longer, in itself, unlawful. That's a meaningful shift from where things stood in 2021 and 2022, and it means the earlier rulings can't be read as a blanket statement that GA remains illegal today. On the transfer issue specifically, they've been overtaken.

But the DSB's other finding, that the _ga cookie and Client ID are personal data, and that operators (not Google) carry liability for how that data gets collected and handled, was never about the transfer mechanism. That part of the reasoning is untouched. The DPF answers one question and leaves the rest of the compliance picture exactly where it was.

Why operators should not treat the DPF's stability as a solved problem

Treating the DPF as a permanent fix ignores what's happened to its oversight structure since adoption. In January 2025, three of the five sitting members of the Privacy and Civil Liberties Oversight Board, the US body responsible for reviewing DPF safeguards, were removed. Without a quorum, PCLOB's annual review function is effectively stalled, which is the kind of institutional fragility the EU worried about when it wrote conditions into the adequacy decision.

The framework has already faced its first courtroom test. French MP Philippe Latombe filed to annul the adequacy decision in a case (T-553/23) before the EU's General Court, challenging whether the US oversight mechanisms were sufficient. The General Court dismissed his challenge on September 3, 2025, finding the Data Protection Review Court sufficiently independent and the US bulk-collection limits adequate. That sounds like a resolution, but the General Court is the junior chamber of the EU court system, and its rulings can be appealed upward. The challenger did exactly that on October 31, 2025; the case is now pending before the Court of Justice as C-703/25 P, the same court that killed Privacy Shield in 2020 and the earlier transfer framework some years before that.

Schrems and noyb have signaled they intend to challenge the DPF as well, and the structural resemblance to Privacy Shield, a self-certification system resting on US executive assurances rather than binding legislation, is what makes European regulators uneasy. The European Data Protection Board published its first review of the DPF in 2025 and urged the Commission to reassess the adequacy decision, pointing to the mounting court challenges as reason for caution. Operators building compliance programs around the DPF as a settled fact are building on a foundation the EU's own privacy board has flagged as provisional.

What GA4 compliance requires in configuration and consent today

GA4 does not arrive compliant out of the box. It generates pseudonymous client IDs, logs behavioral events, and sends that data to US servers by default, the exact chain of facts the DSB scrutinized in 2021. Getting it into a defensible state today means working through five separate areas, and skipping any one of them leaves a gap a regulator or an NGO complaint can walk through.

Consent has to come before the tag fires, not after. A GA4 tag that loads and starts logging events before a visitor makes an active choice is invalid regardless of what the banner says, and pre-ticked consent boxes don't satisfy this either. Google's Consent Mode v2 sits next to this requirement: it tells Google's tags what they're allowed to do based on the visitor's actual choice, and without it configured correctly, GA4 and ads storage simply can't write cookies for new EEA visitors, a restriction that took effect in March 2024. Operators also need to have accepted Google's Data Processing Terms, a formal contractual step, not a checkbox buried in account settings. Retention settings need attention too: GA4's data retention controls should be set to the shortest period that still serves the operator's actual analytics needs, and event parameters should be audited for personal data fields that don't need to be there. Finally, the transfer mechanism itself needs paperwork behind it: reliance on the DPF should be documented, SCCs kept as a fallback, and a transfer impact assessment kept on file, not just filed away in memory.

Austria layers its own cookie banner rules on top of the GDPR baseline. Both "Accept" and "Reject" have to appear on the banner's first layer, with no burying the reject option behind extra clicks, and the accept button can't be styled to visually dominate the reject one. Withdrawing consent has to be just as easy as giving it. Enforcement here runs on two tracks: Austria's telecoms regulator handles violations of the TKG 2021 telecoms law separately, while the DSB handles the underlying GDPR violation. A single badly designed banner can trigger both agencies at once.

Server-side tagging has a role here, mainly around stripping personally identifiable information before it leaves the operator's own infrastructure and centralizing consent logic in one place. But Sweden's IMY already answered the question of whether it substitutes for consent: it doesn't. Proxying IP addresses through a server-side container doesn't make the underlying transfer lawful on its own, and consent still has to be collected properly regardless of where the tagging infrastructure sits.

Austria is the clearest illustration of what all this compliance work actually costs in visibility. Roughly a third of Austrian websites (34%) dropped Google Analytics entirely after the DSB ruling. The other 66% kept it, but now have to ask for consent that most visitors decline.

The result: on a typical Austrian site, 75% or more of visitors reject analytics cookies, meaning cookie-based GA4 tracking is only picking up somewhere around 20 to 30% of actual traffic, far more than a rounding error. That's not a rounding error. A dashboard that reflects reality looks very different from one that reflects whichever quarter of visitors happened to click accept.

This isn't uniquely an Austrian problem, either. Ad blockers and browser-native blocking tools target a widely used tag management platform, GA4's script, and every major analytics domain by name, and a significant share of audiences across Europe and North America run some form of blocking regardless of what any consent banner says. Consent Mode v2 tries to paper over the resulting gap with behavioral modeling, using observed patterns from consenting users to estimate what non-consenting users probably did. That's useful for spotting a trend line moving up or down, but modeled data is a statistical guess standing in for missing observation, not a substitute for it, and any analytics team relying on GA4 numbers should document that distinction rather than treating modeled and observed traffic as interchangeable.

Austria's enforcement realities: who is watching, and how

The DSB itself is a small operation for the scope of its mandate. It runs on 53 employees and a 2026 budget of €5.9 million to oversee data protection for roughly 9 million people, a fraction of the resources Ireland's DPC has for a comparable population, roughly five times the budget.

That hasn't stopped the complaint volume from climbing. Individual complaints hit 3,813 in 2024, a 769% increase since 2017. Of the cases the DSB actually closed out in 2024, 62 ended in fines totaling around €1.7 million, most of them modest amounts rather than headline-grabbing penalties, putting the overall fine rate at roughly 1.36% of proceedings. Starting in July 2025, the DSB announced changes to how it handles this caseload, though the specifics of that shift go beyond what's settled at time of writing.

None of this suggests Austrian regulators are chasing every website with a misconfigured cookie banner. It suggests the opposite: enforcement is thin, complaint-driven, and slow. That is why noyb's model-complaint strategy, filing the same complaint across dozens of jurisdictions at once, has done more to shape GA4 compliance behavior across Europe than the DSB's own enforcement capacity ever could on its own.

Sources

  1. Is Google Analytics Legal in Austria (2026)? The Ban, DSB Rules, and What Changed
  2. Austrian DSB: EU-US data transfers to Google Analytics illegal
  3. Google Analytics GDPR Compliance: Is GA4 Legal in the EU in 2026?

More in Privacy Compliance