惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
Vercel News
Vercel News
T
Tailwind CSS Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 聂微东
Hugging Face - Blog
Hugging Face - Blog
WordPress大学
WordPress大学
S
SegmentFault 最新的问题
小众软件
小众软件
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
人人都是产品经理
人人都是产品经理
Google DeepMind News
Google DeepMind News
Engineering at Meta
Engineering at Meta
B
Blog RSS Feed
U
Unit 42
Y
Y Combinator Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
The Register - Security
The Register - Security
量子位
C
CXSECURITY Database RSS Feed - CXSecurity.com
P
Privacy & Cybersecurity Law Blog
Scott Helme
Scott Helme
GbyAI
GbyAI
Know Your Adversary
Know Your Adversary
月光博客
月光博客
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Stack Overflow Blog
Stack Overflow Blog
S
Secure Thoughts
L
Lohrmann on Cybersecurity
腾讯CDC
P
Palo Alto Networks Blog
MongoDB | Blog
MongoDB | Blog
T
Tor Project blog
博客园_首页
W
WeLiveSecurity
G
Google Developers Blog
K
Kaspersky official blog
爱范儿
爱范儿
V
Visual Studio Blog
T
Threat Research - Cisco Blogs
Simon Willison's Weblog
Simon Willison's Weblog
F
Fortinet All Blogs
T
The Exploit Database - CXSecurity.com
N
News and Events Feed by Topic
Last Week in AI
Last Week in AI
aimingoo的专栏
aimingoo的专栏
A
About on SuperTechFans

Blog of Simple Analytics

The EU wants to kill cookie banners Google is tracking you (even when you use DuckDuckGo) German court rules Meta’s tracking tech violates GDPR Closing the data gap - Simple Analytics x Usercentrics The EU-US data deal may be dead in the water You are missing 20% of your website data with GA4 How a reverse trial will push Simple Analytics to the next level Google will start tracking all your devices (WTF?) Big Tech Fails EU’s Digital Services Act: Only Wikipedia Passes the Test Meta fined $102 million by the Irish Data Protection Commission Europeans spend 575 Million hours per year clicking cookie banners The most interesting GDPR fines GDPR and fines: all there is to know Google loses key antitrust case Web Analytics for Crypto Companies Web analytics for publishers Google pulls Uno Reverse card: Rolls back decision to kill third-party cookies Privacy Monthly July 2024 Privacy Perspectives June 2024 Privacy Monthly June APRA fumbles targeted advertising Privacy Monthly May Meta loses key privacy battle Google delays cookie phase-out once again Privacy Monthly April 2024 Web Analytics and Consent Cookies 101 Privacy Monthly March 2024 German authority cracks down on cookie banners Google Tag Manager vs Google Analytics Google search alternative Data retention in Google Analytics Guide to Google Analytics and Cookie consent What are Google Analytics' identifiers? How to export data from Google Analytics Privacy Monthly February 2024 The Criteo case: a big deal for Big Tech Privacy Monthy January 2024 What the Digital Markets Act means for privacy Google Settles in $5B Incognito Mode Lawsuit Legal troubles for Adobe Analytics Web analytics for nonprofits HIPAA and mental health Why Meta subscriptions are under attack, and why it matters for privacy Privacy Monthly: December Simple Analytics AI Host analytics on Cloudflare Zaraz Add Google Analytics to Convertkit Google Analytics Pricing - Paid vs Free Road to 1 Million ARR - October update CCPA and Data Protection: all there is to know Analytics without a cookie banner Enterprise Analytics Privacy Monthly: November 2023 Delete Act: all you need to know Mobile App Tracking Under Fire The road to 1 Million ARR - September Update Privacy Monthly: October 2023 HIPAA violations First challenge to the EU-US data transfer framework Direct Marketing under GDPR Road to 1 million ARR - August Update CCPA vs CPRA: what is new? Privacy Monthly: September 2023 A/B Testing with Simple Analytics Dobbs v. Jackson ruling is a privacy mess Privacy Monthly: August 2023 What are your rights under the CCPA? When does the CCPA apply? How does the HIPAA compare to the CCPA and GDPR? Why Meta is in a world of trouble CJEU: cookie-based analytics collects sensitive data Road to 1 million ARR - July update All about the new Data Transfer Framework Road to 1 Million ARR - June update What is PHI under HIPAA? Sweden declares Google Analytics illegal Searching for GA4 Alternatives? Top 10 Reliable Options for Google Analyticss Ultimate HIPAA Compliance Checklist: Essential Steps for Healthcare Providers Privacy Monthly: June 2023 The path to 1M ARR - May Update Data Processing Agreements Minimal Product Analytics Facebook data transfers declared illegal Is Google Analytics CCPA-compliant? Help us with your input Cookie banners: How to stay GDPR compliant? GDPR Compliance Checklist Privacy Monthly: May 2023 Simple Analytics: Privacy-first website analytics Improve your e-commerce performance with analytics European Facebook blackout is closer than we think Know your website’s Carbon Emissions - and how to reduce it The path to 1M ARR - April 2023 How to add video tracking using Google Tag Manager? How to track form submissions using Google Tag Manager? Why is my Simple Analytics data different from Google Analytics? Debug Simple Analytics script How to Import Google Analytics Data to Simple Analytics
More troubles for Google Analytics
Iron Brands · 2023-06-08 · via Blog of Simple Analytics

Legal troubles for Google Analytics keep coming. The Cologne District Court ruled against the use of Google Analytics on May 10. Two days later, the Austrian Federal Administrative Court reached the same conclusion and confirmed a decision against a decision against Google Analytics from the Austrian data protection authority.

  1. The German decision
  2. The Austrian decision
  3. The takeaway
  4. The core legal issues
  5. Supplementary safeguards: a general problem
  6. What about the new data transfer framework?
  7. Conclusions

Michelin chose Simple AnalyticsJoin them

Let’s dive in!

The German decision

The case was brought by the consumer center of Nordrhein-Westphalen against Deutsche Telekom, the largest telecom provider on the German market.

Deutsche Telekom’s website used Google Analytics and forwarded personal information to Google’s servers in the U.S. for processing. The consumer center argued for the obvious here: in light of the Schrems II ruling, this data transfer was not compliant with the GDPR.

Unsurprisingly, the Court agreed and ordered Deutsche Telekom to stop forwarding personal information to the US for the purposes of marketing and web analytics. In practice, this amounts to an order to dismiss the use of Google Analytics.

The action also involved other privacy issues, including the confusing design of the website’s cookie banner, and the transmission of personal data to credit agencies. Only the claims related to Google Analytics were successful.

Given Deutsche Telkom’s resources and the amounts of personal data involved, we expect the company to appeal the decision.

The Austrian decision

The Austrian decision stems from one of NGO noyb’s 101 complaints which we already discussed in depth. It is an appeal against a previous decision taken by the Austrian privacy authority (DSB)- in fact, the very first decision against Google Analytics’ data transfers from a European privacy authority.

As for the facts, an individual represented by noyb complained that an unnamed website violated the GDPR’s rules on data transfer by transferring their personal data to the US through Google Analytics without sufficient safeguards. The complaint was upheld by the Austrian DPA and the decision was then appealed by the owner of the website.

The Austrian Federal Administrative Court confirmed the DSB’s decision and rejected the defenses of the website owner, including the controversial** risk-based approach** to data transfers.

According to the gdprhub, the website owner intends to challenge the decision again before the Austrian Supreme Administrative Court.

The takeaway

The two decisions add nothing new on the legal side, but they do show that the enforcement of Schrems II is not limited to privacy authorities: courts are jumping in as well.

Something similar already happened a while ago when a German administrative court ruled against the use of Google Analytics. But the decision came with a sloppy motivation and was overturned on appeal.

These two rulings are different. They come with a clear and well reasoned motivation and, in our opinion, stand good chances to be confirmed if challenged.

And of course the Austrian decision, being an appeal, suggests that the DSB’s approach to the issue with data transfers is a sound one. Then again, this was already evident. The Italian, French, Finnish, and Norwegian authorities adopted virtually identical decisions, and the Irish authority and the European Protection Board used the exact same criteria when evaluating Meta’s data transfers.

The decisions are in now way new and merely apply the criteria already laid out in the notorious Schrems II ruling of the EU Court of Justice. Data transfers are a long story and one we already covered in detail, so we will keep things short here.

The GDPR requires extra-EU data transfers to be safe. However, European data (as well as all foreign data) transferred to the US are subject to extensive State surveillance, as shown by the confidential files leaked by Edward Snowden. This surveillance system makes it hard for European organizations to transfer data to the US in a lawful and safe way.

In both cases at hand the data transfers took place between Google Ireland and its US-based mother company Google LLC. In order to make this data transfer secure and lawful, Google used a specific safeguard called standard contractual clauses (SCCs).

SCCs are a data transfer mechanism set up by the GDPR. In a nutshell, they are clauses that tell companies what they can and cannot do with the personal data they receive. SCCs are incorporated in a contract and are binding on the company that receives the data. Because of their binding nature SCCs they can make up for a lack of privacy legislation for the private sector.

But the Schrems II ruling highlighted a key problem with SCCs: they are not binding for the US or any other foreign State. On their own, SCCs cannot protect personal data from State surveillance.

This is why Schrems II requires organizations to adopt supplementary measures when transferring data to the US, and other countries with extensive electronic surveillance. But this is difficult for many services and entirely impossible for Google Analytics, because Google LLC needs to access and analyze data in the clear in order to provide the service.

This lack of supplementary measures is at the core of every decision against Google Analytics’s data transfer. Whenever the issue of data transfers is brought up, privacy authorities stick to the Schrems II rules and look into supplementary measures. And they always found them to be lacking- because there are simply no measures that can keep data transfers for Google Analytics confidential.

Supplementary safeguards: a general problem

Data transfers and supplementary measures are broad problems. Implementing proper safeguards is tricky for some services and entirely impossible for others.

This is the case for Google Analytics too. Under US legislation, surveillance agencies can require US communications providers (including Google) to provide any foreign data they control.

Encryption can help, but not for Google Analytics. In order for the service to work, Google needs access to the data in the clear in order to analyze them. And under US legislation, Google can be required to provide an encryption key to the government as well. So any data Google can access in the clear, the government can access in the clear as well- it’s as simple as that.

There are supplementary measures other than encryption, but when it comes to Google, none of them really fit- as we explained here.

In a nutshell, no solution works for Google Analytics. We have seen this again and again with the decisions against Google Analytics. The rulings from the Austrian, French, Italian, Norwegian, and Finnish data protection authorities all say the same thing: Google Analytics cannot transfer data safely.

Furthermore, all these decisions result from a coordinated approach to the problem at a European level. And the very same approach recently led to a landmark decision and a record fine against Meta, for the same exact legal issues that plague Google Analytics.

The order issued against Meta is proof that for some services, there is simply no solution to make data transfer safe until the legal situation changes. Meta is one of the biggest and richest multinational companies in the world, with access to all the legal and technical expertisew it could possibly want. The company had 1.2 billion good reasons to secure its data transfers, and yet failed to do so and is now facing the risk of an EU-wide Facebook blackout as a result

Of course, you are free to try and do better than Meta. But how many millions is your compliance budget?

What about the new data transfer framework?

In July 2023 the European Commission adopted an adequacy decision for the US. An adequacy decision is a unilateral act that enables the free flow of personal data to a non-EU Country.

Is the whole data transfer drama over? Not really. Schrems (yup, the guy from Schrems I and II) will certainly challenge the new framework in the Court of Justice, and will likely win.

Adequacy decisions are not merely political decisions. The Commission cannot sanction data flows towards a Country solely because they like it, or because it is a strategic ally. They need to make sure that the data are kept safe outside the EU, and this is not the case with the new data transfer framework in place between the EU and the US.

This is not the first attempt at a trans-atlantic data transfer framework, either. Two older frameworks (Safety Harbor and Privacy Shield) were both invalidated by the Court of Justice over surveillance concerns. This will probably happen again, as the new framework does not really offer the safeguards required to keep EU data safe against US surveillance

Long story short, Schrems III will come at some point, and the EU will be back to square one.

In the meantime, European companies must live with the uncertainty or invest in localization. And by the way, Microsoft is pouring billions into its EU Data Boundary Boundary program- they expect thousands of companies to rush to their EU-based cloud after Schrems III comes around.

Conclusions

Between Google Analytics’ never-ending legal issues with data transfers, and the upcoming sunsetting of Universal Analytics, this is a good time to ditch Google Analytics in favor of another provider. And we have just the one for you!

We at Simple Analytics believe that web analytics can be both privacy-friendly and ethical. This is why we build our service to provide great insights to our customers without collecting one bit of personal data from their visitors! If this sounds good to you, feel free to give us a try.