Owners of websites can use a variety of analytics tools to calculate the performance of their websites on the web. And among the many, Google Analytics is one of the most popular.
Google Analytics is a web analytics service that is offered for free by the tech giant, so website owners can track and report website traffic. It was launched back in 2005, and in 2019, was considered the most widely-used web analytics service on the web, ever.
But Austria is not liking it.
The Austrian Data Protection Authority (“Datenschutzbehörde” or “DSB” or “DPA”) ruled that an Austrian website provider’s continuous use of Google Analytics and the resultant transfer of personal data to Google is a violation to the European Union’s (EU) privacy law, the General Data Protection Rules (GDPR) (PDF).
This ruling came from a decision made in 2020 by the Court of Justice of the European Union (CJEU) Schrems II decision, which stated that cloud services hosted in the U.S. are incapable of complying with the GDPR and EU privacy laws.

The decision was made because of the U.S. surveillance laws require U.S. providers (like Google) to provide personal data to U.S. authorities, whenever they are asked.
The ruling responded to a series of representations filed by the Austrian privacy advocacy group, before the DPA finally took its stance (PDF).
It is the Schrems II ruling that marked the end of the so-called "Privacy Shield," the framework that allowed EU data to be transferred to U.S. companies.
Tech industry in the U.S. was sent into a frenzy following this decision, but many U.S. and EU companies tend to ignore the Schrems II decision and commence working as if nothing happened.
Thanks to the U.S.' privacy laws which appear to be some way off and that there is appetite for reforming surveillance laws, tech companies were not literally bothered by EU's move.
But in this case, it is alleged that the transfer of personal data to U.S. companies falls under 50 USC § 1881a and Executive Order 12333, which violates international data transfer standards prescribed in Chapter V of the GDPR.
It is said that both Google as the data importer, and website providers that are the data exporters, violate Article 44 of the GDPR by transferring personal data to Google, which qualified as an “electronic communication service provider.”
The DPA decision however, said that no data importer obligation existed under Chapter V of the GDPR, but affirmed that Google is a data importer and is liable for breaching GDPR obligations.
In reaching its conclusion, the regulator mentioned a number of measures Google said it had implemented to protect EU users' data in the U.S.. which include encryption in its data centers, and claims that the data “must be considered as pseudonymous.”
The regulator however, did not find sufficient safeguards Google had been put in place to effectively block U.S. intelligence services from accessing the data, as required to meet the GDPR’s standard.
"U.S. intelligence services use certain online identifiers (such as the IP address or unique identification numbers) as a starting point for the surveillance of individuals,” the regulator notes in the decision [via a machine translation], adding that: “In particular, it cannot be excluded that these intelligence services have already collected information with the help of which the data transmitted here can be traced back to the person of the complainant."
"As long as the second respondent himself [i.e. Google] has the possibility to access data in plain text, the technical measures invoked cannot be considered effective in the sense of the above considerations," it noted at one point.
The case was filed when an Austrian business experienced a damaged brand reputation, and possibly resulting in a hefty fine.
The website in question, which is a health-focused website called netdoktor.at, had been exporting visitors’ data to the U.S. as a result of implementing Google Analytics.
It was the NOYB ("None of your business") privacy-advocacy group (the European Center for Digital Rights) which found that IP addresses (which are classified as personal data by the GDPR) and other identifiers were sent to the U.S. in cookie data as a result of the organization using Google Analytics.
The ruling found that the data transferred to Google, including personal user identifiers, IP address and browser parameters, is personal data under Article 4(1), and consequently dismissed Google’s claims of transfer of non-personal data.
Because of this, the DPA made a decision to rule that Austrian website providers using Google Analytics are in violation of GDPR.
"We expect similar decisions to now drop gradually in most EU member states. We have filed 101 complaints in almost all Member States and the authorities coordinated the response. A similar decision was also issued by the European Data Protection Supervisor last week."
While the Austrian decision is the first to address one of those 101 complaints, it follows a similar decision released earlier this week by the European Data Protection Supervisor (EDPS), which specifically has jurisdiction over top EU institutions.
At the time, the regulator sanctioned the European Parliament for using Google Analytics and the U.S. payments service Stripe on an internal website for arranging COVID-19 PCR tests.

The legal clash between the U.S. and the EU in terms of user privacy and surveillance can be dated back to almost a decade.
At that time, former NSA contractor Edward Snowden disclosed the extent of projects by the U.S. government, which conducted mass surveillance across the web and beyond.
In 2015, the EU’s Court of Justice to invalidate the Safe Harbor arrangement between the bloc and the U.S. on the grounds so EU data could no longer be considered safe when it is sent to the U.S..
The EU and U.S. have been discussing what should replace Privacy Shield since it was struck down in July 2020. This particular case, while it only involved a complaint from one website publisher, may open up Privacy Shield’s replacement to more legal scrutiny
In other words, if the agreement takes too long, then similar cases across Europe could make cloud services from Amazon, Facebook, Google, and Microsoft all potentially being ruled incompatible.
The ruling did not go entirely in NOYB's favor, because while the Austrian regulator decided to go against the website, but dismissed the part of the complaint to target Google.
















































































































































































































































































































































































