
🔒 €1 Million fine for Google Analytics: what changed by 2026
Imagine: you open your email in the morning and there's a message from a European regulator. A €1 million fine. The reason: Google Analytics, which you installed three years ago and forgot about. Not a fantasy. In October 2025, the Stockholm Court of Appeal upheld the penalty against Tele2. The appeal was rejected, the fine went into effect.
Seven European countries have issued decisions against Google Analytics in the form that 90% of website owners configure it. The problem is not the tool itself, but where and how European users' data leaks.
Google responded: GA4 with forced IP anonymization, Consent Mode v2, European processing servers. The European Commission adopted the Data Privacy Framework. But is that enough in 2026? And most importantly, what should a website owner do right now to avoid repeating Tele2's fate? Let's break it down based on facts, relying on real court and regulator decisions.
💡 Quick overview:
- Learn why the 2020 Schrems II decision brought down Privacy Shield and undermined the legal basis for Google Analytics in Europe
- Look at real fines: Tele2 paid €1 million, CDON €27,700, and Tele2's appeal failed in October 2025
- Explore the ban map: seven EU countries with official decisions against specific GA implementations
- Evaluate Google's response: forced IP anonymization, European servers, Consent Mode v2
- Understand the status of the Data Privacy Framework: it's alive, but NOYB is already preparing Schrems III
- Go through an eight-point checklist for bringing GA4 into GDPR compliance
- Compare GA4 with cookieless alternatives: Plausible, Fathom, Umami, and honestly weigh what you lose
Schrems II: the decision that undermined the legal basis for Google Analytics
On July 16, 2020, the Court of Justice of the European Union issued its ruling in the Schrems II case (Case C-311/18). The Court invalidated the Privacy Shield. This mechanism was the sole legal basis that allowed US companies to lawfully receive personal data from the EU.
The root cause: FISA Section 702 and Executive Order 12333. These two acts give US intelligence agencies access to data held by American providers. Google, with its California headquarters, falls entirely under their scope.
After Schrems II, companies were left with a single route for legal data transfers to the US: Standard Contractual Clauses (SCC) plus "supplementary measures." But the CJEU stated plainly: contractual promises do not override national security laws. No contract obligates US intelligence agencies to ignore FISA. This legal dead end became the foundation for decisions against Google Analytics.
More details: GDPR audit.
The first fines: Tele2, CDON, and the Swedish precedent
In June 2023, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) fined two major players:
- Tele2 (telecom operator): €1 million (12 million Swedish kronor) for using Google Analytics without sufficient data protection measures.
- CDON (online retailer): €27,700 (300,000 kronor) for the same violations.
Both companies transferred data to the US via SCC. But the regulator determined that the additional technical protection measures were insufficient. The contract existed, but there was no real protection against access by US intelligence agencies.
Tele2 appealed the fine. In October 2025, the Stockholm Court of Appeal rejected the appeal and upheld the penalty. This is a key moment: the court confirmed that using Google Analytics without adequate supplementary measures is not a technical shortcoming, but a full-fledged GDPR violation.
In parallel, IMY reviewed the cases of Coop and Dagens Industri. These companies also used Google Analytics. They did not receive fines. The difference: they conducted a technical audit, implemented encryption at a level the regulator deemed adequate, and documented every step.
The takeaway from the Swedish precedent: Google Analytics itself is not banned. What is banned is transferring data without proven, working protection measures. The difference between a €1 million fine and no claims is the volume of technical work, not the choice of tool.
The ban map: which EU countries have issued decisions against GA
Since 2022, seven European countries have published official decisions declaring the use of Google Analytics unlawful in the specific implementations reviewed:
Country | Regulator | Date | Essence of the decision |
|---|---|---|---|
Austria | DSB | January 2022 | First EU decision: GA transfers data to the US without adequate protection |
France | CNIL | February 2022 | Similar conclusion; CNIL issued guidance requiring remediation or cessation of use |
Italy | Garante | June 2022 | Caffeina Media was given 90 days to remedy the violations |
Denmark | Datatilsynet | September 2022 | Guidance published: GA "cannot be used in compliance with GDPR" without supplementary measures |
Norway | Datatilsynet | March 2023 | Preliminary decision against a Norwegian publisher |
Finland | Tietosuojavaltuutettu | 2024 | Joined the coordinated position of European regulators |
Sweden | IMY | June 2023 | First monetary fine (Tele2, CDON); appeal rejected in October 2025 |
Each decision concerned a specific GA implementation on a specific website. This is not an EU-wide ban. But the coordinated position through the European Data Protection Board (EDPB) means that a decision in one country serves as a precedent for the others.
NOYB's campaign (Max Schrems' organization) filed 101 complaints in 30 EU and EEA countries back in August 2020. The process stretched over years, but it has not stopped. Regulators continue to open proceedings.
What Google changed: GA4, European servers, and Consent Mode v2
Following the wave of decisions, Google introduced three changes significant from a GDPR perspective.
IP anonymization by default. In Universal Analytics, anonymization was an option. It was often forgotten, and this very fact appeared in the Austrian and French decisions. In GA4, anonymization is forced and cannot be disabled: European users' IP addresses are scrubbed before the data enters processing.
Processing on EU servers. Since 2023, European traffic can be processed on Google servers within the EU before being sent outside the region. The parent company in the US still falls under American surveillance laws, but the surface area for claims has become noticeably smaller.
Consent Mode v2, mandatory since March 2024. This is a JavaScript layer between the consent banner and Google tags. When a user rejects cookies, Consent Mode v2 does not simply block tracker installation; it sends anonymized "cookieless pings." Without Consent Mode v2, GA4 cannot lawfully operate with European traffic.
An important nuance: Consent Mode v2 has two modes. Basic blocks tags until explicit consent is obtained, a legally sound option. Advanced sends cookieless signals in any case, even without consent. Google gets more data for modeling, but legally this is a more contentious path. The choice of mode is one of the first decisions you will need to make during setup.
Data Privacy Framework: salvation or a temporary patch
On July 10, 2023, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework (DPF). This is the successor to Privacy Shield, which was struck down by Schrems II. Google LLC has certified under the DPF, which formally resolves the main legal compliance issue: data transfers to certified companies in the US once again have a legal basis.
But it is too early to relax. Three risk factors.
First: the DPF rests on US presidential executive orders. A change of administration could weaken or revoke these orders. Max Schrems has publicly stated that he cannot imagine how "an order imposed on the US by Europeans, regulating American surveillance abroad, would survive the America First logic."
Second: NOYB is already challenging the DPF in court. The first legal attack on the DPF was repelled, but NOYB is preparing a new, broader case, Schrems III. Lawyers call it a question of time, not probability.
Third: the DPF only resolves the cross-border transfer issue. All other GDPR requirements, consent, data minimization, purpose limitation, remain in force. A banner that does not comply with Article 7 GDPR makes the entire chain illegal regardless of the DPF.
Norway's Datatilsynet put it precisely: "What has so far been the main problem with Google Analytics appears to be resolved. However, we do not rule out that the tool may have other privacy issues."
So is GA4 legal in Europe in 2026
The short answer: it is legal when configured correctly. With caveats.
If you have GA4 with Consent Mode v2, a valid consent banner (equal "Accept" and "Reject" buttons, no pre-ticked checkboxes), processing on EU servers, signed SCCs, and minimized data collection, you are in a defensible position. Claims are possible. But you have documented compliance, and that is exactly what the regulator looks at.
The problem is that most websites do not reach that state. A 2025 analysis of 254,000 websites showed that only 15% of cookie banners in Europe meet the minimum GDPR requirements. Another study covering 35,000 websites found violations on 49% of the resources checked. If the banner is invalid, the GA4 implementation inherits that invalidity automatically.
A separate headache: data loss. The same research records a 40-70% loss of tracked data when a genuine banner with an equal "Reject" button is deployed. When up to two-thirds of European visitors refuse cookies, the numbers in GA4 become modeled rather than measured. Regulators are already asking questions: whether modeling itself creates new GDPR problems.
The practical takeaway: GA4 in Europe in 2026 is a managed risk, not a closed matter.
What to do right now: a practical checklist
Here are eight items that European regulators look at when auditing a GA implementation. Go through each one.
Switch to GA4 if you are still on Universal Analytics. Universal Analytics was shut down by Google in July 2024. Data is no longer being collected, but the GDPR risks have not gone away.
Implement Consent Mode v2. Without it, GA4 cannot lawfully process European traffic. Integration is done through a CMP platform: CookieYes, Cookiebot, Complianz, or iubenda. Choose Basic mode for maximum legal protection.
Check your consent banner. Two equal buttons: "Accept all" and "Reject all". No pre-ticked checkboxes, no "legitimate interest" as a pretext for collection. Verify through the Network tab in DevTools: when you reject cookies, there should be no requests to
google-analytics.com.Enable processing on EU servers. GA4, Admin, Data Settings, Data Collection, Regional Data Collection. Two minutes.
Set data retention to 14 months. GA4, Admin, Data Settings, Data Retention. This is the shortest period Google allows. GDPR requires that data not be kept longer than necessary.
Disable data sharing with Google products. GA4, Admin, Data Settings, Data Sharing: uncheck all boxes. By default, Google receives your data to improve its services. For GDPR compliance this must be turned off.
Sign a Data Processing Agreement with Google. The DPA is available in your GA4 account settings. Verify that your site's privacy policy explicitly mentions the use of Google Analytics and the purposes of processing.
Audit your data collection and storage processes. For companies with large traffic volumes this is not an option, it is a requirement. An auditor will compare actual data flows against documented processes. A discrepancy between what is stated in the policy and what GA4 actually collects is a direct path to a fine.
A separate track for those who do not want to manage this risk at all: cookieless tools. Plausible, Fathom, Umami, and Swetrix do not collect personal data by definition. No cookies, no consent banner requirement. No data transfers to the US, no Schrems II problem. The price: you lose user funnels, Google Ads attribution, and the usual depth of segmentation. For content projects, blogs, and small businesses this is often an honest compromise.
⁉️🤔 Frequent questions
Is Google Analytics completely banned in Europe?
No. Individual EU countries have found specific GA implementations on specific websites to be unlawful. There is no EU-wide ban. GA4 with Consent Mode v2, European servers, and a valid consent banner is in a defensible position in 2026.
It is important to understand the scale: the decisions concerned cases where data was transferred to the US without additional technical safeguards. The mere fact of using GA4 with a full compliance stack has not been fined even once so far. But this is not a guarantee: regulators work with a two- to three-year lag, and proceedings from 2023-2024 have not yet reached the decision stage.
How does GA4 differ from Universal Analytics from a GDPR standpoint?
In GA4, IP anonymization is enforced and cannot be disabled. Universal Analytics made it optional, and that was precisely the basis for the first decisions in Austria and France. GA4 uses an event-based rather than a session-based model, which reduces the volume of personal data collected. Plus mandatory Consent Mode v2.
GA4 was architecturally designed for the post-Schrems reality. IP addresses are scrubbed before processing, Consent Mode v2 became mandatory as of March 2024, and data processing on EU servers narrows the surface for claims. But compliance depends on your configuration: GA4 by itself does not make a website GDPR-compliant.
What does a GDPR violation fine through Google Analytics actually cost?
The upper limit under GDPR Article 83: up to €20 million or 4% of global annual turnover. Recorded fines for GA: Tele2, €1 million, CDON, €27,700. The amount depends on the scale of violations, the volume of data processed, and the safeguards demonstrated to the regulator.
The Swedish precedent showed: the difference between no claims and a €1 million fine is the volume of technical work and documentation, not the choice of tool. Coop and Dagens Industri used the same Google Analytics, but with adequate additional measures, and were not fined.
Do I need Consent Mode v2 if I do not use Google Ads?
Yes. Consent Mode v2 is mandatory for any website with European traffic that uses GA4. Whether you have Google Ads is irrelevant. As of March 2024, without Consent Mode v2, GA4 cannot lawfully collect data about European visitors.
Consent Mode v2 manages the
analytics_storageandad_storagesignals. Without properly configured consent, GA4 either does not collect data at all, or collects it in violation of GDPR. From the regulator's perspective, there is no difference between "just analytics" and "analytics for advertising": processing personal data requires consent in both cases.
What happens if the Data Privacy Framework is struck down?
The situation would revert to post-Schrems II: companies transferring data to the US must rely on SCCs plus additional safeguards. The difference is that GA4 with Consent Mode v2 and European servers is better prepared for such a scenario than Universal Analytics was in 2020.
A DPF invalidation would not be instantaneous: judicial procedures in the EU take years, and businesses would get a transition period. Practical advice: test a cookieless alternative in parallel with GA4 for a month. If DPF collapses, you will switch in a day, rather than a month of emergency migration.
Can I use GA4 on a website in Ukraine and other non-EU countries?
Technically yes. Legally: GDPR applies to the processing of EU residents' data regardless of the website's geographic location. If your website is visited by users from Germany, France, or Poland, you are processing their personal data and must comply with GDPR. Server geolocation is irrelevant.
GDPR is extraterritorial by design. A Ukrainian website with a European audience is in exactly the same legal situation as a German one. The practical difference is only in the likelihood of enforcement: the Swedish IMY will not go and fine a Ukrainian company directly, but European users can file a complaint through NOYB, and the local regulator will get involved via EDPB coordination.
The bottom line: weighing risk and action
GA4 in 2026 is neither "banned" nor "completely safe". It is a tool that requires deliberate configuration. Seven EU countries have issued decisions against it, a €1 million fine has already been issued and upheld by an appellate court, and NOYB continues to pressure regulators. At the same time, Google has built a compliance stack that did not exist in 2020: enforced IP anonymization, Consent Mode v2, European servers, DPF certification.
For a website owner, the choice comes down to two options. If you need the full depth of GA4 (funnels, attribution, remarketing, Google Ads integration), go through the eight-point checklist above, configure every item, and sleep soundly with documented compliance. If depth is not critical and legal certainty matters more, switch to a cookieless tool and close the GDPR question entirely.
The third option, "install GA4 as-is and hope for the best", no longer exists in 2026. Regulators in Europe have proven they will fine for that. With real money, not warnings. The decision is yours, but it should be made on an informed basis.



