惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
博客园 - 三生石上(FineUI控件)
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MongoDB | Blog
MongoDB | Blog
小众软件
小众软件
Y
Y Combinator Blog
博客园 - 聂微东
Google DeepMind News
Google DeepMind News
D
Docker
罗磊的独立博客
Microsoft Security Blog
Microsoft Security Blog
D
DataBreaches.Net
B
Blog
Vercel News
Vercel News
Recent Announcements
Recent Announcements
GbyAI
GbyAI
阮一峰的网络日志
阮一峰的网络日志
T
The Blog of Author Tim Ferriss
H
Hackread – Cybersecurity News, Data Breaches, AI and More
P
Proofpoint News Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Microsoft Azure Blog
Microsoft Azure Blog
宝玉的分享
宝玉的分享

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
CNIL's latest on Google Analytics | iubenda
2022-07-28 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

According to the French DPA (CNIL), interrupting the connection between the user’s terminal and the analytics tool server is required to comply with GDPR lawson data transfer when using Google Analytics. This was noted in the opinion issued on July 20, 2022.

CNIL Google Analytics

Background

On February 10, 2022, the CNIL issued a compliance order to many organizations utilizing Google Analytics due to unauthorized data transfers to the US as provided for by the Austrian and Italian DPA rulings.

In these decisions, the CNIL and other EU data protection authorities concluded that the usage of Google Analytics resulted in transfers to the United States that were not appropriately regulated.

As was mentioned in the CNIL Q&A, using Google Analytics under the GDPR requires more than just the straightforward adoption of standard contractual clauses.

According to the latest release from the French DPA,

Using a properly configured proxy can be an operational solution to limit the risks to individuals.

About processing IP addresses on US servers

While CNIL has said that “simply changing the processing settings of the IP address is not sufficient to meet the Court of Justice of the European Union (CJEU) requirements, especially as these continue to be transferred to the US.” 

With reference to the possibility of using encryption techniques, the CNIL stated that “encrypting” the identifier produced by Google Analytics or swapping it out for one produced by the site operator. However, due primarily to Google’s ongoing processing of IP addresses, this offers little to no further protection against the potential re-identification of data subjects.

According to CNIL, simply making changes to how you process IP addresses – a form of personal data under the GDPR – is not enough to meet their standards. 

This problem can only be solved by methods that allow disconnecting the connection between the terminal and the server. 

How do I set up a valid Proxy Server? 

The CNIL has said that using a proxy server to prevent any direct communication between an Internet user’s terminal and the analytics tool is one potential approach. 

According to the CNIL, this is what you must do in order for the proxy to be considered valid:

  • the IP address is not transferred to the analytics tool’s servers. If a location is sent to the measuring tool’s servers, it must be carried out by the proxy server;
  • the replacement of the user identifier by the proxy server. To ensure effective pseudonymization, the algorithm performing the replacement should ensure a sufficient level of collision (i.e., a sufficient probability that two different identifiers will give an identical result after a hash) and include a time-varying component;
  • the site’s removal of external referrer information;
  • the removal of any parameters present in the gathered URLs (including URL parameters permitting internal site routing and UTMs);
  • the reprocessing of data that can be used to create a fingerprint, like user agents, to remove the most uncommon configurations that can result in re-identification;
  • the absence of collecting lasting or cross-site identifiers (such as CRM IDs or unique IDs);
  • the removal of any additional information that might permit re-identification.

The proxy server must also be hosted in a country that offers protections equal to those of the GDPR in order to prevent the data it processes from being sent outside the European Economic Area.

As with anything privacy-related, it is recommended that you conduct an analysis on this issue, put the necessary safeguards in place in the event that you choose to use this kind of solution, and ensure that these safeguards are maintained over time in light of changes.

This piece is part of an ongoing series about the latest decisions on Google Analytics. Want to know more? See our other related guides here: