Is Google Analytics compliant with GDPR? – CNIL decision

27 czerwca 2022

Google Analytics is a popular online tool for analyzing website statistics. Its use, since the ruling of the Court of Justice of the European Union in the so-called Schrems II case, raises many doubts regarding compliance with the provisions of the GDPR. One of the first supervisory authorities to address this issue was the French CNIL. The article prepared for you discusses the decision issued by the French supervisory authority and answers the following questions: Is a company using Google Analytics a data controller and why? Does Google Analytics contain personal data, and if so, what kind? Why are standard contractual clauses not an effective tool for data transfer outside the EEA? Can data transfers rely on the exceptions described in Article 49 of the GDPR?

On Data Processing and Responsibility

The factual state described in the CNIL decision indicates that Google Analytics is used to measure the viewership and results of the company's media campaigns. The company stated that Google Analytics particularly enables the tracking of individuals if users have not refused consent for such actions. By linking a unique user identifier with their data from one or more sessions initiated from one or more devices, Google Analytics is able to obtain more accurate information about users (identifying them as a specific user, even in a different session).

The operation of Google Analytics involves placing a snippet of JavaScript code on the website pages. When a user visits a webpage, this code triggers the loading of a JavaScript file, which then performs the tracking operation for Google Analytics. The tracking operation consists of retrieving data related to the query through various means and sending this information to the Google Analytics servers.

Website administrators who have integrated the Google Analytics service can send instructions to Google regarding the processing of data collected through Google Analytics. These instructions are conveyed through the tag manager, which manages the tracking code integrated on their website, as well as through the settings of the tag manager. The website administrator can apply various settings, for example, regarding the data retention period. The Google Analytics feature also allows website administrators to monitor and maintain the stability of their site, for instance, by notifying them of certain events, such as an increase in visits or a lack of traffic. Google Analytics also enables website administrators to measure and optimize the effectiveness of advertising campaigns conducted using other Google tools.

In this context, Google Analytics collects, among other things, the user's HTTP request as well as information about their browser and operating system. The HTTP request concerning any page contains information about the browser and the device making the request, such as the domain name and browser information (including its type, referrer, and language). Google Analytics stores and reads cookies in the user's browser to assess the user's session and other information related to the request.

After collecting this information, it is transmitted to the Google Analytics servers. All data collected by Google Analytics is stored in the United States.

Regarding data transfer, the findings of CNIL indicate that the agreement concerning the Google Analytics functionality refers to an annex titled “Google Ads Data Processing Terms.” This annex contains standard contractual clauses governing the transfer of personal data to the United States of America within the framework of the Google Analytics service. The company has stated that it has no evidence to suggest that these clauses were not adhered to.

All these elements indicate that by deciding to implement the Google Analytics functionality on this website for assessment and optimization purposes, the entity managing the website has defined the objectives and methods of collecting and processing data obtained as a result of integrating Google Analytics on its website and should be regarded as a data controller within the meaning of Article 4(7) of the GDPR.

Does Google Analytics process personal data?

It can be stated that the data collected through the Google Analytics functionality and transmitted to the United States of America constitutes personal data.

Article 4(1) of the GDPR defines personal data as

information about an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more specific factors characteristic of the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

It should be noted that online identifiers, such as IP addresses or information stored in cookies, can commonly be used to identify a user, especially when combined with other similar types of information. This is illustrated by Recital 30 of the GDPR, which states that the assignment of online identifiers, such as IP addresses and cookie identifiers, to natural persons or their devices may result in leaving traces that, particularly when combined with unique identifiers and other information obtained by servers, can be used to create profiles and to identify those individuals. In particular, when a data controller claims that it is unable to identify a user through the use of such identifiers (alone or in combination with other data), it is expected to disclose specific measures taken to ensure the anonymity of the collected identifiers. Without such details, they cannot be considered anonymous.

In this regard, it is necessary to examine the extent to which the implementation of Google Analytics on the website allows the website administrator and Google to identify the data subject (the person visiting the specific website).

In its response to the CNIL, the data controller stated that the following categories of personal data are processed as part of the Google Analytics functions:

  • the identifier of the website visitor (the Google Analytics cookie identifier, i.e., the Google Analytics client ID);
  • for individuals who have logged into the website using a user account - an internal identifier;
  • any order identifiers;
  • IP addresses.

GDPR. Support is useful!

The company assures that IP addresses are anonymized, without specifying what process is used to make these addresses anonymous. However, the company classifies this data as personal data.

Regarding visitor identifiers, it should be noted that these are unique identifiers intended to distinguish individual persons. In the case discussed, these identifiers may be combined with other information, such as the address of the visited website, metadata regarding the browser and operating system, the time and data related to the website visit, and the IP address. Such a combination of information allows for further differentiation of individual persons.

For this reason, the combination of several elements may enable the individual identification of visitors to a website where Google Analytics has been implemented. Knowledge of the visitor's name or physical address is not required, as according to Recital 26 of the GDPR, such distinction of individuals is sufficient to identify the visitor.

If a different conclusion were reached, the scope of the right to data protection guaranteed by Article 8 of the Charter of Fundamental Rights of the European Union would be undermined, as it would allow companies to specifically distinguish individuals along with their personal data (e.g., when they visit a particular website), while simultaneously denying them the right to protection against such distinction. Such a restrictive view, which would undermine the level of protection for natural persons, is also inconsistent with the case law of the Court of Justice of the European Union, which has repeatedly ruled that the scope of the GDPR should be understood very broadly (see, for example, C-439/19, para. 61).

Furthermore, the CNIL notes that in the case of website users who have identified themselves using a user account, or those who have placed an order, the data can be directly linked to identifying data.

Additionally, in the context of using Google Analytics and within certain Google account settings, Google receives information that the user associated with the Google account has visited a particular website. Consequently, personal data related to that account is collected.

All of this leads to the conclusion that the data in question should be treated as personal data within the meaning of Article 4 of the GDPR.

Regulation of Data Transfers to Third Countries

Article 44 of the GDPR states:

The transfer of personal data that are processed or are to be processed after transfer to a third country or an international organization occurs only if - subject to other provisions of this regulation - the data controller and the data processor fulfill the conditions set out in this chapter, including the conditions for further transfer of data from the third country or by the international organization to another third country or another international organization. All provisions of this chapter shall be applied with a view to ensuring that the level of protection of natural persons guaranteed in this regulation is not undermined.

Chapter V of the regulation provides various tools to ensure a level of protection essentially equivalent to that guaranteed in the European Union, in accordance with Article 44 of the regulation:

  • adequacy decisions (Article 45);
  • appropriate safeguards (Article 46).

In the absence of an equivalent level of protection, exceptions are established in specific situations (Article 49).

In this case, the CNIL examined whether the export of personal data to the United States of America is compliant with Article 44 of the GDPR, and in particular, whether this export was based on one of the listed grounds, and if so, whether appropriate measures were taken.

  1. Decisions on adequacy

In the judgment of July 16, 2020 (C-311/18), the Court of Justice of the European Union annulled the implementing decision of the Commission (EU) 2016/1250 of July 12, 2016, regarding the adequacy of protection provided by the EU-U.S. Privacy Shield, without maintaining its effects.

In the absence of another appropriate decision establishing an adequate level of protection, the data transfers in question cannot be based on Article 45 of the GDPR.

  1. Appropriate safeguards

Article 46(1) of the Regulation states that

in the absence of a decision under Article 45(3), the data controller or data processor may transfer personal data to a third country or international organization only if they provide appropriate safeguards, and provided that enforceable rights of data subjects and effective legal remedies are available.

Article 46 paragraph 2 of the Regulation states that

appropriate safeguards referred to in paragraph 1 may be provided – without the need to obtain special authorization from the supervisory authority – by means of […] (c) standard contractual clauses for data protection adopted by the Commission in accordance with the examination procedure referred to in Article 93(2) of the GDPR.

Practical DPO Course
Practical DPO Course
will confirm your high competencies
Prepare to serve as a Data Protection Officer. We invite you!
CHOOSE A DATE
In this case, the data controller and Google entered into standard contractual clauses regarding the transfer of personal data to the United States (Google Ads Data Processing Terms: Model Contract Clauses, Standard Contractual Clauses for Processors). These clauses are in accordance with the clauses published by the European Commission in Decision 2010/87/EU.

In this context, it should be emphasized that standard contractual clauses serve as a transfer tool within the meaning of Chapter V of the regulation and, as such, have not been challenged by the Court of Justice in its judgment of July 16, 2020 (C-311/18). However, the Court acknowledged that the contractual nature of these clauses implies that they cannot be binding on authorities of third countries.

In particular, the Court stated that:

Therefore, although there are situations in which - depending on the laws and practices in a given third country - the recipient of such a transfer is able to guarantee the necessary data protection solely based on the standard data protection clauses, there are also other situations in which the content of these standard clauses may not constitute a sufficient means to ensure effective protection of personal data transferred to that third country. This is particularly the case when the law of that third country allows its public authorities to interfere with the rights of the individuals to whom the data relates" (C-311/18, para. 126, emphasis added).

However, further analysis of the legal situation in the USA is not necessary, as the CJEU has already provided such an analysis in its aforementioned judgment. The Court stated that the discussed surveillance programs are not aligned with the minimum guarantees arising from the principle of proportionality in EU law, such that surveillance programs based on these provisions cannot be considered limited to what is strictly necessary (para. 184). Furthermore, the Court noted that the discussed legal framework does not grant individuals whose data is concerned rights that can be challenged in court against U.S. authorities, which means that these individuals do not have the right to an effective remedy (para. 192).

The CJEU's analysis is significant in this case, as Google LLC (as the data importer to the USA) should be classified as a provider of electronic communications services within the meaning of 50 US. Code § 1881(b)(4) and is therefore subject to oversight by U.S. intelligence agencies in accordance with 50 US. Code § 1881a ("FISA 702"). Consequently, Google LLC is obliged to provide personal data to the U.S. government upon request under FISA 702.

As indicated in Google's Transparency Report, Google LLC regularly receives such access requests from U.S. intelligence agencies.

The Court of Justice stated on the one hand that the decision on adequate data protection issued in the United States of America is invalid due to the access capabilities of American intelligence services, and on the other hand, that the conclusion of SCCs cannot in itself ensure the level of protection required under Article 44 of the GDPR, as the guarantees they provide remain inapplicable in the case of such access requests. The CJEU reached the following conclusion:

This means that the standard contractual clauses for data protection adopted by the Commission under Article 46(2)(c) of the GDPR are intended solely to provide contractual guarantees that have uniform application across all third countries to data controllers and data processors based in the European Union, and consequently regardless of the level of protection guaranteed in each third country. To the extent that these standard contractual clauses for data protection cannot, by their nature, provide guarantees that go beyond the contractual obligation to ensure compliance with the level of protection required under EU law, they may require, depending on the situation prevailing in the relevant third country, the data controller to adopt additional measures to ensure compliance with that level of protection (para. 133).

Implementation of Additional Safeguards

In its recommendations 01/2020 dated June 18, 2021, the European Data Protection Board (EDPB) explained that if the assessment of the law and/or practices in the third country may affect the effectiveness of the relevant safeguards of the transfer tools relied upon by the exporter, in the context of its specific transfer, as is the case here following the assessment made by the CJEU, the exporter must either suspend the transfer or implement appropriate supplementary measures.

In this regard, the EDPB notes that:

Any supplementary measure may only be considered effective in the sense of the CJEU ruling "Schrems II" if and to the extent that - alone or in combination with others - it eliminates the specific deficiencies identified in the assessment of the situation in the third country regarding its laws and practices applicable to the transfer (para. 75).

Supplementary measures to standard contractual clauses for data protection can be divided into three categories: contractual, organizational, and technical.

Regarding contractual measures, the EDPB noted that such measures:

[...] may complement and strengthen the safeguards provided by the transfer tool and the relevant legislation of the third country [...]. Given the nature of contractual measures, which generally cannot bind the authorities of the third country unless they are a party to the agreement, these measures often need to be combined with other technical and organizational measures to ensure the required level of data protection [...] (para. 99).

With regard to organizational measures, the EDPB emphasized that

[...] the selection and implementation of one or more of these measures does not necessarily and systematically guarantee that the transferred data meets the essential equivalence standard required by EU law. Depending on the specific circumstances of the data transfer and the assessment of the legislation of the third country, additional organizational measures are necessary to complement contractual or technical measures to ensure a level of protection for personal data essentially equivalent to the level guaranteed in the EEA (para. 128).

DPO Function - it transfers well

With regard to technical measures, the EDPB indicated that

[...] these measures will be particularly necessary when the law of a given country imposes obligations on the data recipient that are inconsistent with the safeguards specified in Article 46 of the GDPR concerning data transfer tools, and in particular are capable of violating the contractual guarantee of a fundamentally equivalent level of protection against access by public authorities of that third country to such data (point 77). It was also added that the measures listed [in the guidelines] aim to ensure that access by public authorities in third countries to the transferred data does not affect the effectiveness of the relevant safeguards contained in the transfer tools specified in Article 46 of the GDPR. These measures would be necessary to guarantee a fundamentally equivalent level of protection to that which is guaranteed in the EEA, even if access by public authorities is lawful under the law of the importer country, when in practice such access goes beyond what is necessary and proportionate in a democratic society. These measures aim to prevent potentially unlawful access by making it impossible for authorities to identify individuals whose data is concerned, to infer about them, to extract them in another context, or to associate the transferred data with other datasets that may contain, among other things, online identifiers provided by devices, applications, tools, and protocols used by the individuals whose data is concerned,
in other contexts
(point 79).

Google LLC, as the data recipient, has taken contractual, organizational, and technical supplementary measures to the standard data protection clauses.

Considering the considerations of the CJEU and EDPB, it is now necessary to verify whether the supplementary measures adopted by Google LLC are effective, that is, whether they address the specific issue of access by U.S. intelligence services.

Regarding the legal and organizational measures adopted, it should be noted that neither user notification - if such notification is permissible at all - nor the publication of a transparency report or the publicly available "Government Requests Policy" actually prevent or limit the possibilities of access by U.S. intelligence services. Furthermore, it is unclear how "careful analysis of each request" by Google LLC regarding its admissibility is effective as a supplementary measure, considering that, according to the CJEU, admissible (lawful) requests from U.S. intelligence services do not comply with the requirements of European data protection law.

Regarding the technical measures implemented, it should be noted that neither Google LLC nor the company has explained how the described measures - such as the protection of communication between Google services, data protection during transport between data centers, protection of communication between users and websites, or "on-site security" - actually prevent access by U.S. intelligence agencies to data under U.S. legal frameworks or limit the possibility of such access.

With respect to encryption technologies - such as in the case of "data at rest" in data centers, which Google LLC explicitly mentions as a technical measure - it should be noted that Google LLC, as the data recipient, has an obligation to provide or transfer imported personal data in its possession, including any cryptographic keys necessary to ensure the intelligibility of the data (see Recommendations 01/2020, para. 81). In other words: as long as Google LLC has the ability to access personal data in plain text form, such a technical measure cannot be considered effective in this case.

Google LLC claims that to the extent that Google Analytics data for measurement transmitted by website owners constitutes personal data, it should be treated as "pseudonymous." It should be noted that universally unique identifiers (UUIDs) do not fall within the definition contained in Article 4(5) of the GDPR. While pseudonymization may be a technique that enhances privacy, unique identifiers, as mentioned earlier, are intended to distinguish users rather than serve a protective function. Furthermore, it has been explained above why the combination of unique identifiers with other elements (such as browser or device metadata and IP addresses) and the ability to link such information to a Google account in any case enables the identification of a natural person.

If Google LLC refers to an "optional technical measure" in the form of IP address anonymization, it should first be noted that this measure - as the name suggests - is optional and does not apply to all transfers. Moreover, it is not clear from Google's response whether anonymization occurs before the transfer or whether the entire IP address is transferred to the United States and only shortened after the transfer to the United States. Thus, from a technical perspective, there is potential access to the entire IP address before it is shortened.

In this regard, the supplementary measures adopted by Google are ineffective, as none of them address the specific issues in the case at hand, which means that none of them prevent access by U.S. intelligence agencies or render such access ineffective.

Derogations provided for in Chapter V of the Regulation

Article 49 of the Regulation states:

GDPR Tools
Working with good GDPR tools is not work!
Applications, calculators, GDPR snapshots - everything that can help you manage your personal data protection system.
SEE MORE
In the absence of a decision determining an adequate level of protection as specified in Article 45(3) or in the absence of appropriate safeguards as specified in Article 46, including binding corporate rules, a one-time or repeated transfer of personal data to a third country or an international organization may only take place on the condition that:

  1. the data subject, informed of the potential risks associated with the proposed transfer due to the absence of a decision determining an adequate level of protection and the absence of appropriate safeguards, has explicitly consented to it;
  2. the transfer is necessary for the performance of a contract between the data subject and the data controller or for the implementation of pre-contractual measures taken at the request of the data subject.

The data controller argued that the data transfer could be based on Article 49(1)(a) of the GDPR, indicating that the data subjects may not consent to Google tracking their visits to the website.

However, the user's consent to the storage of cookies during their visit to the website cannot be considered equivalent to their explicit consent to the proposed data transfer, after being informed of the possible risks of such transfer for the data subject due to the absence of a decision determining an adequate level of protection and appropriate safeguards within the meaning of Article 49(1)(a) of the GDPR.

The company also invokes Article 49(1)(b) of the regulation, as these functions are necessary for the proper functioning of the website and for detecting anomalies.

However, this argument is not supported by any concrete evidence, and above all, the company has not demonstrated that there is a contractual relationship between it and all users of its website.

<pIn this regard, the enterprise cannot invoke Article 49 of the GDPR to justify the data transfer in question.

Conclusions

According to the findings of CNIL, it should be stated that the company cannot rely on any tools provided in Chapter V of the regulation to justify the transfer of personal data of individuals visiting its website, particularly unique identifiers, IP addresses, browser data, and metadata, to Google LLC in the United States. Consequently, it is agreed with the French supervisory authority that there are no effective tools ensuring the security of the data transferred to the USA.

quiz

Check what you remember - for the correct answer reward!

Which personal data is not processed under Google Analytics?

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.