Go to main contentGo to footer
GDPR
|
12 July 22

Is Google Analytics illegal in Italy? Let’s clear things up

A ruling by the Italian Data Protection Authority has effectively declared Google Analytics unfit for tracking traffic on Italian websites. But what really happened?

Massimiliano PalloniDigital Marketing Specialist

A quick refresher on the GDPR

Let’s take a step back: the GDPR (General Data Protection Regulation) is the European regulation on data protection that gives EU citizens greater control over the personal information they share online.

Article 4 of the GDPR defines quite clearly what the European Union considers personal data:

[…] any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

General Data Protection Regulation

In short, virtually all the data a user shares with a platform should be considered, in some way, personal.

A key to understanding what is happening is the GDPR’s distinction between Data Controller and Data Processor: the former hold their customers’ personal data and are responsible for it, while the latter record and process that data on behalf of the former.

Put simply, Data Controllers are the companies and organizations that run a website or an app, while Data Processors are all the services that use and manage that data, such as Google Analytics.

If something goes wrong in handling customers’ personal data, under the GDPR responsibility lies with both the Data Controller and the Data Processor; depending on the EU country and its legislation, this responsibility may be weighed differently when GDPR rules are breached.

The GDPR expects the Data Controller to appoint a DPO (Data Protection Officer), a person who essentially makes sure that policies on handling users’ sensitive data are followed internally.

Why does Google Analytics 3 violate the GDPR?

Google Analytics is not illegal in itself, but like many services owned by a US-based company, it transfers part of the data collected in Europe from its servers in Ireland to servers in the USA.

That’s where the problem starts: under the 2020 Schrems II ruling of the Court of Justice of the European Union, any data transfer between the European Union and the United States is prohibited unless the parties involved implement additional safeguards in line with GDPR standards.

Google did not guarantee compliance with these additional safeguards in Google Universal Analytics (also known as Google Analytics version 3): users’ IP addresses, which count as personal data, are shared with the United States, albeit anonymized. Incidentally, at the request of federal law enforcement, US companies are required to make the content of their servers available when it is part of an investigation, without even having to inform users that they are being monitored.

Within the European legal framework, the problem is clear without needing to say more.

Did the Italian Data Protection Authority condemn Google?

No. The Authority’s ruling concerns one specific Italian website, which it found non-compliant with the GDPR precisely because personal data was transferred to the United States.

You can read in the ruling how this connects to what we wrote above:

[…] the use of GA by website operators – such as Caffeina Media S.r.l. – entails the transfer of the personal data of those websites’ visitors to Google LLC, based in the United States. Since these transfers are made to a third country that does not guarantee an adequate level of protection under data protection law (namely the United States), they must be carried out in compliance with Chapter V of the Regulation.

Although the problem lies in how Google handles the data, responsibility stays with the website owner, who is the Data Controller, and with the DPO acting on their behalf:

It is therefore precisely the controller’s task to decide independently the methods, safeguards and limits of personal data processing in compliance with the relevant legislation. Indeed, the Regulation strongly emphasizes the “accountability” of the controller, that is, the adoption of proactive behavior demonstrating the concrete adoption of measures aimed at ensuring the application of personal data protection rules (see, in particular, Art. 24 of the Regulation).

In short, the Data Processor is chosen by the Data Controller, so any ruling falls on the latter. So it is not Google that is breaking data protection law.

While it’s important to take the necessary precautions, remember that the Authority’s ruling is specific to this case and has no general legal force: it’s important to get ready, but there’s no need to panic!

What should Italian companies and organizations do?

It depends on which version of Google Analytics you use to track traffic on your website. If it’s Universal, the most widespread one, it’s time to move to Google Analytics 4.0. GDPR aside, the switch would be advisable anyway, since version 3.0 will no longer be supported from 2023.

Depending on how deeply you use Analytics and how many services are connected to it, moving to the new version could take a few minutes or several hours; ask the team or digital partner that manages your Analytics property for an estimate of the migration time. You can also find a guide at this official link.

How to tell which version of Analytics is active

There are many ways; the fastest is to log in to Analytics and check the code shown with each property. Just click “All accounts” in the top-left corner.

Properties in the right-hand column show a code at the bottom: if it starts with “UA-”, it’s an old Universal Analytics property. Otherwise, the tracking code belongs to Google Analytics 4.

Another way is to check the source code and search for “Google”: if you find “UA-” followed by the code, or “G-” followed by the code, the latter means it’s Google Analytics 4.

How to set up Google Analytics 4

Changing the code isn’t enough: although GA 4 does a good job of anonymizing IPs, you need to adjust the tracking settings to avoid potential issues with the Data Protection Authority.

That’s why it’s important to make sure, in the property settings, that:

  • Google Signals is turned off;
  • the granular location data is not tracked;
  • you have restricted advertising features unless they are crucial to the business.

Also, as a strictly precautionary measure, it may be a good idea to look into proxying data collection to avoid unlawful transfers abroad, as recommended by the CNIL in this article (in French).

If these concepts are new to you, contact us and let’s find a solution together.

The thorny (but not that thorny) case of Federico Leva

Many people, including some of our clients, received an email from Federico Leva, an activist for a free and anonymous web, asking Data Controllers to delete his tracking data where present.

It isn’t spam, and the request must indeed be fulfilled within thirty days of receiving the email, though without going through the form it asks you to fill in.

Simply write to Mr. Leva at the email address given at the end of the letter, asking for the Analytics client ID and the date and time of access to the website.

This lets you delete the user in Analytics via Audience > User Explorer: just enter the code provided in the search field and click the result, if any.

The user’s detail view will open, where you can delete the user with one click on the button at the bottom left.

Then contact Mr. Leva to confirm that his personal data has been deleted. Any request from a private individual to remove Analytics tracking for all users is essentially inadmissible, regardless of what we said earlier.

This case caused understandable panic because it reached tens of thousands of Italian websites, but it shouldn’t be considered thorny: Federico Leva simply exercised a right that has existed for years. Ruling or no ruling, if a user whose personal data you manage asks for it, you must be able to provide the list of their personal data within 30 days of the request.

Users must be able to view, edit and delete their data. All of it. So this is nothing new, but the fact that it hadn’t happened before, at least not on this scale, let us forget how crucial it is to handle users’ sensitive data transparently.

It’s probably time to take the issue seriously again.

Protect yourself by protecting your users’ data

Every case is different, and you can’t always solve such complex (and evolving) issues on your own.

First of all, I recommend contacting a lawyer with prior experience in digital privacy; it’s a fast-growing field, and finding a lawyer who can advise you is easier than it seems.

Then choose a DPO and give them enough time to get up to speed on the subject to protect your interests (and theirs, since they are the one responsible!).

Finally, contact your digital partner to bring your website tracking, your contact database (you’ll probably need a re-permissioning campaign) and your online ad campaigns into compliance.

If you’re interested, Cantiere Creativo is here to support you through this delicate transition. Good luck!

footer