FR EN

Toute l'actualité d'Altij

17.08.2026 11:13

Fuite de données à la DGFIP : sept actions pour votre organisation cette semaine

La confirmation par Bercy d’une intrusion au système d’information des Finances publiques dépasse...


Cat: Données - Bases de données – RGPD / DPO - Big Data et intelligence artificielle, Les essentiels, Veille Juridique
09.08.2026 16:20

Démarchage téléphonique à partir du 11 août 2026 le possible et l’interdit

Démarchage téléphonique : ce qui change à partir du 11 août

Plus aucun appel commercial vers un consommateur sans consentement préalable. Fin de Bloctel, fin...


Cat: Données - Bases de données – RGPD / DPO - Big Data et intelligence artificielle, Les essentiels, Veille Juridique
29.07.2026 09:35

Procédure simplifiée : 23 nouvelles sanctions de la CNIL depuis janvier 2026

Dans un bilan publié le 6 juillet 2026, la CNIL indique avoir prononcé, depuis janvier 2026, 23...


Cat: Données - Bases de données – RGPD / DPO - Big Data et intelligence artificielle, Les essentiels, Veille Juridique
29.07.2026 09:29

IA générative : le CEPD encadre l'anonymisation et le moissonnage de données

Le 7 juillet 2026, le Comité européen de la protection des données (CEPD) a adopté des lignes...


Cat: Données - Bases de données – RGPD / DPO - Big Data et intelligence artificielle, Les essentiels, Veille Juridique
29.07.2026 09:13

NIS2 : la transposition française tarde, mais l'anticipation s'impose

Le 8 juillet dernier, la Commission européenne a annoncé avoir saisi la Cour de justice européenne...


Cat: Données - Bases de données – RGPD / DPO - Big Data et intelligence artificielle, Les essentiels, Veille Juridique
29.07.2026 09:02

Cyber Resilience Act : êtes-vous concerné par l’écheance du 11 septembre 2026 ?

Le règlement européen Cyber Resilience Act (CRA) vise à renforcer la cybersécurité des produits...


Cat: Données - Bases de données – RGPD / DPO - Big Data et intelligence artificielle, Les essentiels, Veille Juridique
27.07.2026 20:54

Publication du Digital Omnibus : quelles conséquences pour votre projet d'IA ?

Le Règlement (UE) 2026/1744 aussi appelé « Digital Omnibus » a été publié au Journal officiel de...


Cat: Données - Bases de données – RGPD / DPO - Big Data et intelligence artificielle, Les essentiels, Veille Juridique
29.06.2026 12:06

Pixels de suivi dans vos mails : assurez votre conformité avant le 14 juillet 2026

La CNIL vient de fixer le cadre applicable à l'utilisation des pixels de suivi intégrés dans les...


Cat: Données - Bases de données – RGPD / DPO - Big Data et intelligence artificielle, Les essentiels, Veille Juridique
voir les archives ->
< UTILISATION DE GOOGLE ANALYTICS « ILLÉGALE » : QUELLES RECOMMANDATIONS DE LA CNIL ?
12.07.2022 11:24 Il y a: 4 yrs
Categorie: Données - Bases de données – RGPD / DPO - Big Data et intelligence artificielle, Veille Juridique

USE OF GOOGLE ANALYTICS “ILLEGAL” ON FRENCH WEBSITES WITHOUT PROXY SERVERS


After issuing official warnings to various website operators, the CNIL has confirmed that the use of Google Analytics in its standard version should now be considered “illegal”.

 

In a question-and-answer section on its website, the French data protection regulator states that none of the extra safeguards presented to it satisfies GDPR standards.

The sole option it proposes to enable the compliant use of Google Analytics is to use a proxy server to stop Google identifying the end user. Website operators will therefore need to review whether this is a cost-effective and technically viable option.

 

In summary, the CNIL indicates that:

  1. The use of Google Analytics on French websites infringes GDPR because it implies transfers of personal data to the United States,
  2. The additional technical measures proposed to reduce the risks of such transfers do not meet EU legal requirements,
  3. Website operators cannot adopt a risk-based approach based on the probability of access to data by US surveillance authorities. The mere possibility of such access infringes GDPR.
  4. The CNIL has issued official warnings to several French, website operators, ordering them to demonstrate their compliance on this issue within one month.
  5. All data controllers using Google Analytics in a similar way to the website operators who were the subject of official warnings must, as of now, consider that this use is illegal because it contravenes GDPR.
  6. It may be possible to use Google Analytics legally through proxy servers, thus preventing all contact by HTTPS between the end user’s terminal equipment and servers managed by Google.
  7. This solution would need to meet strict technical criteria to ensure there is no possibility for Google to re-identify the data subjects. More details on this “proxyfication” proposal are available on the CNIL’s website.

French website operators therefore need to review (1) whether they use Google Analytics and (2) whether proxyfication is a viable option for them.

 

The legal background

In February 2022, the CNIL issued its first an official warning to a website publisher which used Google Analytics, because this implied “illegal” transfers of personal data to the United States.

There have been similar findings by regulators in Austria and Italy, demonstrating a movement towards stricter enforcement of GDPR restrictions on data transfers to third countries.

These different regulatory decisions apply the Schrems II judgment of the Court of Justice of the European Union (CJEU) in July 2020, which held that, under American law, US intelligence authorities had excessive access to personal data.

As a result, the court invalidated the Privacy Shield framework (at the time widely used to justify data transfers from the EU to the USA) and restricted the possibility to use contracts known as Standard Contractual Clauses (SCCs) for the same purpose.


The CNIL decision of February 2022 followed a series of complaints by the data protection activist group NOYB about websites using Google Analytics and Facebook Connect cookies. NOYB’s argument was that, applying Schrems II, the signature of SCCs was not capable of justifying data transfers to the USA by Google and Facebook. The CNIL essentially concurred, considering that, although Google had adopted additional measures to protect data transfers, these were not sufficient to exclude the possibility of access to this data by US intelligence services and that transfers of personal data to the US in this context therefore violated GDPR.

 

For more information or to discuss your data transfers from the EU, please contact our data protection team.