What GDPR requires for web analytics
GDPR (General Data Protection Regulation) requires that any collection of personal data has a legal basis, is transparent, is minimized, and can be deleted on request. For web analytics, this means: (1) you need a legal basis to collect data — typically consent or legitimate interest, (2) you must tell visitors what you collect and why, (3) you must collect the minimum data needed, and (4) you must delete data on request. The ePrivacy Directive (the "cookie law") adds a specific requirement: you need consent before storing or accessing information on a user's device, which includes cookies and similar technologies.
Why GA4 is not GDPR compliant by default
GA4 uses cookies to track users across sessions. Under the ePrivacy Directive, this requires consent — meaning a cookie banner. But even with a consent banner, GA4 has problems. Regulators in Austria (DSB, January 2022), France (CNIL, February 2022), and Italy (Garante, June 2022) all ruled that Google Analytics' data transfers to the US do not comply with GDPR because US surveillance laws allow access to EU citizens' data without adequate safeguards. Google added EU data residency and consent mode, but the configuration is complex and the legal status remains uncertain. Using GA4 in the EU carries legal risk.
How to make analytics GDPR compliant
There are two paths to GDPR compliance. Path 1: Use a cookie-based tool with a consent banner. Install GA4 or Hotjar, add a GDPR-compliant consent banner (Cookiebot, OneTrust, Klaro), and configure your tool to not load until consent is given. This is compliant but you lose 30-60% of your data to banner rejections. Path 2: Use a cookieless tool without a consent banner. Tools like Dashly, Plausible, and Fathom do not use cookies or persistent identifiers, so they do not trigger ePrivacy consent requirements. They are GDPR compliant by design, without a banner, and you do not lose data to rejections. Path 2 is simpler and captures more data.
The cookieless compliance advantage
Cookieless analytics tools are GDPR compliant because they do not collect personal data. GDPR defines personal data as information that can identify a natural person. A daily-changing hash of an IP address cannot identify a person — it cannot be reversed, and it changes every 24 hours. No cookies means no ePrivacy consent requirement. No personal data means no GDPR processing restrictions. The result: you get accurate analytics (30-60% more data than cookie-based tools) without legal risk. This is why Plausible, Fathom, and Dashly are popular in the EU — they are compliant by design, not by configuration.
GDPR fines for analytics non-compliance
GDPR fines can reach €20 million or 4% of global revenue, whichever is higher. Real fines for analytics violations have been smaller but significant. The CNIL fined Google €150 million in 2021 for cookie consent issues. The Austrian DSB ruled that using Google Analytics violated GDPR (no fine, but the website had to stop using it). The Italian Garante fined two companies for analytics non-compliance in 2023. The risk is not just fines — it is the cost of compliance work, legal review, and the reputational damage of a data breach notification. Cookieless tools eliminate this risk entirely.
Checklist: Is your analytics GDPR compliant?
Check these items: (1) Do you use cookies? If yes, do you have a GDPR-compliant consent banner that blocks analytics until consent is given? (2) Is your data stored in the EU if you have EU visitors? (3) Can you delete a user's data on request? (4) Do you disclose analytics tracking in your privacy policy? (5) Do you have a data processing agreement (DPA) with your analytics provider? (6) Is your analytics provider GDPR compliant? If you use a cookieless tool (Dashly, Plausible, Fathom), items 1 and 6 are handled automatically. If you use GA4, you need to verify all six.
Country-specific GDPR enforcement
GDPR enforcement varies by country. Germany is the strictest — some state regulators argue that even hashed IPs are personal data. France (CNIL) is active and has fined Google. Austria (DSB) ruled Google Analytics non-compliant. Italy (Garante) has fined companies for analytics non-compliance. Spain and Ireland are less active. If you have EU visitors, assume the strictest interpretation (Germany) applies. Cookieless tools are compliant even under German standards because they do not store IPs, even hashed ones — the hash is computed and the IP is discarded immediately.
FAQ
Is Google Analytics GDPR compliant?
GA4 is not GDPR compliant by default. It uses cookies (requiring a consent banner), and regulators in Austria, France, and Italy have ruled that its data transfers to the US do not comply with GDPR. Google added EU hosting and consent mode, but the configuration is complex and the legal status remains uncertain.
Do I need a consent banner for analytics?
If you use cookies (GA4, Hotjar, Mixpanel), yes — the ePrivacy Directive requires consent before setting cookies. If you use a cookieless tool (Dashly, Plausible, Fathom), no — cookieless tools do not trigger consent requirements because they do not store or access information on the user's device.
Are cookieless analytics tools GDPR compliant?
Yes. Cookieless tools like Dashly, Plausible, and Fathom do not use cookies, do not store IPs, and do not use persistent identifiers. They do not collect personal data under GDPR, so they do not require a legal basis, consent, or a data processing agreement in most interpretations.
What are the GDPR fines for analytics non-compliance?
GDPR fines can reach €20 million or 4% of global revenue. Real fines for analytics violations have been smaller: the CNIL fined Google €150 million for cookie consent issues. The risk includes fines, compliance costs, legal review, and reputational damage from breach notifications.
Which EU countries enforce GDPR most strictly for analytics?
Germany is the strictest — some regulators argue even hashed IPs are personal data. France (CNIL), Austria (DSB), and Italy (Garante) have all taken action against analytics non-compliance. Cookieless tools are compliant even under German standards because they discard IPs immediately after hashing.