Semji
SEO

Updated 7 min read

Google Analytics: What to do after the CNIL's decision? - Semji

Google Analytics: What to do after the CNIL’s decision?

Will we still be able to use Google Analytics? That’s the question many site managers are asking themselves today, following the CNIL’s decision on February 10, 2022. Indeed, France’s data protection authority (the Commission nationale de l’informatique et des libertés) ruled that Google Analytics, as configured by default, did not meet the requirements of the General Data Protection Regulation (GDPR).

The result: a great many site owners are now looking for an alternative to Google’s tool.

Like them, you may have installed Google Analytics to get data about your traffic, and you’re probably wondering how to bring yourself into compliance with the GDPR.

Here are a few leads and solutions we can suggest to help you track your content’s traffic data.

Understanding the CNIL’s decision on Google Analytics

Let’s recap the facts. On February 10, 2022, the CNIL formally ordered a site manager to bring itself into compliance with the GDPR. The issue at hand was the use of Google Analytics and, in particular, the transfer of data to the United States.

“The CNIL finds that internet users’ data is thus transferred to the United States in violation of Articles 44 et seq. of the GDPR. It therefore formally orders the site manager to bring these processing operations into compliance with the GDPR, if necessary by ceasing to use the Google Analytics functionality (under the current conditions) or by using a tool that does not entail a transfer outside the EU. The site manager concerned has one month to bring itself into compliance…”

Indeed, even with users’ consent through Analytics cookies, the CNIL considers that the tool does not make it possible to fully anonymize the data.

From a GDPR standpoint, this poses a problem because:

  • Google would be able to identify visitors by cross-referencing this data with other information it holds.
  • The CNIL considers that Google does not provide sufficient guarantees regarding data security once the data is transferred to the United States.

The origin of this CNIL decision lies in an action by the Austrian NGO NOYB, led by activist Max Schrems. In 2020, it filed complaints against 101 European companies that, in its view, did not comply with the GDPR and the “Schrems II” ruling.

In January, the Austrian data protection authority ruled that Google Analytics did indeed violate the European regulation, closely followed by the CNIL. These decisions could be followed by other European supervisory authorities.

As a result, the sites affected by these decisions have one month to bring themselves into compliance and abandon Google Analytics. Nevertheless, for now, no financial penalty has been imposed on the sites concerned.

Google also responded in a statement, announcing that the company would make new tools available.

Data collection and the GDPR: how does it work?

The General Data Protection Regulation, or GDPR, came into force in May 2018 and aims to protect the personal and sensitive data of internet users.

With Google Analytics, for example, sites must ask their visitors for consent to collect their data. There are two main scenarios.

➔ The user does not give consent for Analytics cookies to be placed.

Google’s Analytics and advertising solutions continue to work, but in a more limited way and without placing cookies.

➔ The user gives consent

This leads to the placement of a Google Analytics cookie that makes it possible to:

  • measure the site’s audience,
  • personalize advertising campaigns (e.g., Google Ads).

The data collected by Google to measure the audience is as follows:

  • the IP address: a unique address specific to the connected device.
  • the client ID (an identifier used to track an individual browsing journey on your site, UA-XXXXX-X).

Note that some information-collection solutions do not require users’ consent if the data collected is perfectly anonymized.

A cookie is a small text file saved by a user’s web browser when they visit a website.

There are two types of cookies:

First-party or internal cookies. Hosted by the server of the website being visited, they help, among other things, to improve the user experience by retaining a certain amount of information about the visitor: language preference, login ID, pages viewed, cart contents, etc.

They can also be used for advertising purposes.

Third-party cookies. They are hosted by a domain different from the one being visited. They allow third-party applications to see which pages have been viewed and to collect a certain amount of data about the user. They are widely used for ad targeting. In fact, Google announced it would phase out this type of cookie by 2023.

Google Analytics and the GDPR: how should you respond?

Faced with this situation, several solutions are available to you to improve Google Analytics’ GDPR compliance.

Solution 1: wait…

Many companies are indeed waiting for Google to bring itself into compliance with the GDPR at the European level, but also for the United States and Europe to agree on relaxing the law. This could happen, for example, through the hosting of Google Analytics data in Europe, via a European company.

Solution 2: adapt Google Analytics

If you’re comfortable with Google Analytics, you can also configure it to make it more respectful of GDPR requirements.

There is not yet a confirmed solution to guarantee Google Analytics’ compliance with GDPR requirements.

However, based on our research, there are several leads and hypotheses for making Google Analytics more respectful of GDPR requirements.

This can include:

  • Anonymizing IP addresses before storage,
  • Reducing the lifespan of Google Analytics cookies,
  • Signing a Data Protection Agreement with Google,
  • Securing Google Analytics cookies through visitor consent,
  • Reducing the data collected by GA cookies,
  • etc.

For now, these recommendations aren’t very easy to implement and require a great deal of effort. That’s why it might be wiser to turn to a complementary solution.

Solution 3: opt for alternative solutions

Don’t panic — there are also many alternatives to complement Google Analytics.

The CNIL provides, for example, a list of GDPR-compliant solutions. Here are a few of them:

Names Key features
Analytics Suite Delta developed by AT Internet Recommended by the CNIL.
Pricing on request, based on your web page volume.
A Semji connector has been developed to pull in all of your site’s data.
Abla Analytics Free below 5,000 page views per month ( see the pricing grid).
This solution is on the CNIL’s official list.
Matomo self-hosting Free and open source.
The tool is available for self-hosting, which lets you own your data.
This solution is on the CNIL’s official list.
Etracker Analytics Free below 25,000 page views per month.
Fathom A Canadian company that complies with the GDPR and stores and processes European data in Germany.
Plausible No cookies.
Hosting in Europe.

Semji’s stance

For our part, we’ve chosen to wait and see whether the negotiations between Google and the CNIL will lead to an agreement.

Whichever alternative you choose, we can ensure the continuity of your tracking data. Today we have a connector with AT Internet. But it’s entirely possible to develop connections for other analytics solutions.

Feel free to contact us to discuss the analytics solution you’ve adopted. In the meantime, you can try Semji for free to maximize the ROI of your content!

Try Semji AI WRITING

See it on your own brand

Find out where AI engines mention you

Semji tracks which prompts surface your brand across ChatGPT, Google AI Overviews, Perplexity, Gemini, Claude and DeepSeek — then shows you the content to write to close the gaps.

ChatGPTGoogle AI OverviewsPerplexityGeminiClaudeDeepSeek

By

  • Semji

Listen to this article

0:00 / ~8:53

Share this article