Blog Updated

Is Google Analytics GDPR Compliant? (2026): The Rules, and What 2,208 Scanned Sites Actually Do

No, Google Analytics is not GDPR compliant by default. GA4 collects data the GDPR treats as personal, including IP addresses and the client IDs that follow a device around, so you cannot just drop the tag on an EU-facing site and be done. The more useful answer is what it takes to fix that: a properly configured GA4 can be run under the GDPR, and "properly configured" comes down to five things. One of them is where most sites quietly fail, even ones that already show a cookie banner. We know how many, because our compliance scanner has loaded 2,208 websites from inside the EU since May 2026 and recorded what each one sent to Google before anyone clicked.

Key Takeaways

  • 01No. Google Analytics 4 is not GDPR compliant out of the box. It can be used lawfully in the EU, but only after you add consent, a contract with Google, and the right configuration.
  • 02Five things have to be true: consent before GA loads, Google Consent Mode v2 wired up, Google's Data Processing Terms accepted, the EU-US Data Privacy Framework covering transfers, and GA4's retention and data-sharing settings tightened.
  • 03Most sites fail the first one. We scanned 2,208 websites from an EU vantage point between May and September 2026. 902 run Google Analytics, and on 76% of the GA sites that show a consent banner, GA sent data to Google before the visitor touched the banner.
  • 04A banner is not the fix. Cookiebot, OneTrust and CookieYes sites in the sample fired GA before consent 65% to 81% of the time. What decides it is whether the tag is held until consent, and that is configured per site.
  • 05ConsentStack holds Google tags until consent by default and runs Consent Mode v2 in Google's basic mode, so nothing reaches Google before a visitor agrees. The free scanner shows which side of that line your site is on.

Is Google Analytics GDPR compliant by default?

No, but it is not banned either. On its own, GA4 is just a tool that processes personal data, and the GDPR puts the responsibility on you. In the law's language you are the data controller and Google is your data processor, which means getting consent, signing Google's terms, and configuring the tool are your job, not something Google does for you. GA4 does help at the margins: it masks IP addresses by default and gives you privacy controls to switch on. But those defaults do not add up to consent, and consent is the part regulators actually enforce.

This is not theoretical. In 2022 several EU data protection authorities, in Austria, France, and Italy among them, ruled that sending Google Analytics data to US servers broke the GDPR. That specific problem eased in July 2023, when the EU-US Data Privacy Framework gave Google a valid way to handle those transfers again. Consent and configuration, though, were always the site owner's job, and they still are.

What a GDPR-compliant GA4 setup actually requires

Five requirements have to be met before GA4 is lawful on EU visitors. Miss any one and the whole setup is exposed.

The five requirements for a GDPR-compliant GA4 setup.
RequirementWhat it means
Consent before GA firesGet explicit, opt-in consent first. Analytics is not strictly necessary, so you cannot fall back on legitimate interest for EU visitors.
Google Consent Mode v2Connect your banner to Consent Mode v2 so Google's tags receive each visitor's choice as a signal, and Google Ads can model the conversions it is no longer allowed to observe.
Google's data terms (DPA)Accept Google's Data Processing Terms in your GA admin settings. This puts the controller-processor relationship in writing.
Lawful transfers (DPF)Google self-certifies under the EU-US Data Privacy Framework, the current legal basis for moving EU data to US servers.
GA4 privacy settingsShorten data retention, turn off the Google products and benchmarking data-sharing options, and keep IP masking and data redaction on.

What 2,208 scanned websites actually do with Google Analytics

Every guide on this topic says "get consent before Google Analytics fires." Almost none says how often that actually happens. Our compliance scanner does, because it loads each site from an EU vantage point, records every network request before anyone touches the banner, then clicks Reject and records again. Between May 5 and September 12, 2026 it scanned 2,208 unique websites. Here is what the first half of that test found.

Google Analytics before consent, EU vantage point, 2,208 sites scanned May to September 2026.
GroupSitesGoogle Analytics sent data before consent
All sites running Google Analytics902 of 2,208 (41%)744 (82%)
GA sites that show a consent banner669511 (76%)
GA sites with no banner at all233233 (100%)

Read the middle row twice. These are sites that have done the visible part of the job. A banner is on the page, the visitor has not clicked anything, and Google Analytics has already sent the visitor's IP address and the page they are reading to Google. Three in four of them. Only 26 of the 669 banner-equipped GA sites passed the scanner's EU check overall.

It is tempting to blame the consent platform. The data says it is the configuration, not the vendor. Every platform below can hold Google Analytics until consent when it is set up to. The rate shows how often its customers' sites actually do.

GA sites with a detected consent banner, by the platform the scanner identified. Platforms with fewer than 25 GA sites in the sample are left out.
Consent platform detectedGA sites in the sampleGA sent data before consent
Cookiebot24475%
OneTrust14465%
CookieYes8881%
Ketch87100%
Custom or in-house banner5670%
How we measured this

The scanner loads each site's homepage in a real browser from an EU vantage point (Frankfurt), records every network request before it interacts with the banner, then clicks the banner's Reject control and records again. "Sent data before consent" means at least one request reached Google Analytics' collection endpoints (google-analytics.com or analytics.google.com) before anyone interacted with the banner. Cookieless Consent Mode pings count, because the request still carries the IP address and the page URL. The 2,208 sites are not a random sample of the web: they combine sites people scanned on our public scanner, lists of sites that use four different consent platforms, a Y Combinator company list, a slice of the Tranco top sites, and our own team's scans. That skews the sample toward sites that already bought a consent tool, which is the point. Each site is counted once, using its most recent scan. The random slice is small but points the same way: of the 23 Tranco sites running GA, 15 sent data before consent.

Notice that four of the five requirements are one-time settings. You accept the terms once, shorten retention once, confirm the transfer basis once. The first requirement is different, because it has to be true on every single page load, and it is the one most sites break. The scan numbers above are that failure, counted. GA has to stay off until the visitor agrees. This is the exact question developers keep asking in public: does firing Google Analytics before consent count as a GDPR breach? The short answer is yes, and it is worth understanding why.

Why firing GA early is the violation

The moment GA loads, it sends a request to Google carrying the visitor's IP address and the page they are on. That happens before the person has agreed to anything, and the request itself is what the GDPR objects to. Setting Consent Mode to "denied" does not undo it, because the connection has already gone out. Holding the tag until consent is the only thing that actually prevents it.

No, and this is the most common misunderstanding behind the scan numbers. Consent Mode is a signal layer: it tells Google's tags what the visitor agreed to. It comes in two modes. In basic mode the tag is held until consent, so nothing reaches Google first. In advanced mode the tag loads before consent and sends cookieless "pings" while the signals say denied, and Google uses those pings for its modeling. Those pings are still requests to Google that carry the visitor's IP address and the page URL, which the GDPR treats as personal data processing that needs a legal basis. A site in advanced mode shows up in our scanner as sending data before consent, because it does. If you want the consent requirement met rather than argued, hold the tag (basic mode) and send the consent signals when the visitor decides. Our Consent Mode v2 setup guide walks through both modes and the code.

Two ways banners get Google Analytics wrong

Having a cookie banner is not the same as consent working. Once you look at what the banner does to GA specifically, most fall into one of two failure modes, on opposite ends.

The three ways a consent banner can treat Google Analytics.
Banner behaviorWhat happensResult
Fires GA before consentThe GA request goes out as the page loadsThe visitor's IP and page reach Google before they agree. This is the leak, and in our scans the majority case: 76% of banner-equipped GA sites.
Blocks GA completelyThe tag is stripped out and never re-enabled, even after AcceptYou lose analytics from every EU visitor, including the ones who would have said yes. Compliant, but blind.
Holds GA until consentGA loads only after Accept; the Consent Mode signals carry the choice either wayCompliant, and you keep measurement for everyone who accepts. This is the target behavior.

The third row is the whole game, and it is harder than it sounds, which is why so few banners actually do it. It is the difference between a banner that decorates the page and one that actually holds the tag until consent.

How to make Google Analytics GDPR compliant

Putting it together, here is the order that works:

  1. Add a consent banner that blocks Google Analytics until the visitor opts in, and make sure it genuinely holds the tag rather than just hiding a message. Our free Google Analytics consent checker shows whether yours does.
  2. Connect the banner to Google Consent Mode v2 so Google's tags receive the visitor's choice as a signal, and hold the tag in basic mode rather than letting it ping before consent.
  3. Accept Google's Data Processing Terms in your GA4 admin, under Account Settings.
  4. Set data retention to the shortest window that works, and turn off the Google data-sharing options you do not need.
  5. Name Google Analytics in your privacy policy: what it collects, why, and how visitors can opt out.

Do those five and GA4 sits on the compliant side of the line for EU visitors. The first one is the only step that is ongoing, and the only one worth testing rather than trusting. For the full rulebook behind all of this, see our GDPR cookie consent requirements guide, and if Google Tag Assistant is warning you that a CMP may be blocking tags, here is what that means.

How ConsentStack handles Google Analytics

ConsentStack is a consent platform, so it does not replace Google Analytics, it governs it. It holds analytics and advertising tags until a visitor consents to their category and keeps them off when someone clicks Reject. Its Google integration runs Consent Mode v2 in basic mode by default: the denied defaults for all four v2 signals are set before any Google tag can load, the tag itself stays blocked until consent, and the update call fires the moment the visitor decides. A held tag cannot send anything, which is what the scan numbers above are really measuring. Accepting Google's data terms and writing your privacy policy stay yours, since no consent tool can do those for you. There is a free plan for small sites, Pro is $29 a month, and if you would rather not touch the setup, we install and configure the banner for you.

Before you change anything, see what your site does right now. Run it through our free compliance scanner and it will show you exactly which trackers, Google Analytics included, fire before and after someone clicks Reject. It takes about a minute and does not ask for an email. If you only care about the one tag, the Google Analytics consent checker answers that single question. Either report is the fastest way to find out whether your banner is holding GA back or just sitting on top of it.

Google Analytics and GDPR FAQ

See what fires before anyone clicks Accept

Run a free compliance scan and see exactly which trackers, including Google Analytics, load before and after Reject. No signup.

Related Posts