Categories: Insights

Tag: #dati personali, GDPR


18 Aug 2022

Google Analytics: red light from the Data Protection Authority  

Websites that use Google Analytics (GA), without the guarantees provided for in Regulation (EU) 2016/679 (the “Regulation“), violate data protection legislation because they transfer user data to the United States which lacks adequate protection. The Data Protection Authority (“Garante“) made its ruling with a 9 June 2022 measure, adopted after a preliminary investigation initiated based on several complaints, in coordination with other European Privacy Authorities, and published the following 23 June.

GA is a web tool provided by Google to website operators that allows them to analyse detailed statistics on users to optimise the services offered and monitor marketing campaigns.

The Authority assessed the processing carried out using this tool and showed that website operators (such as the sanctioned company) use cookies transmitted to the user’s browser to collect information on how these interact with the website, individual pages, and services offered. The data collected consists of: unique online identifiers that allow the identification of the user’s browser or device while visiting the website, and the website operator (through the Google Account ID); address, website name and navigation data; IP address of the user’s device; information on the browser, operating system, screen resolution, language selected, and date and time of website visit.

This information is transferred to the United States of America, a country that, as the Data Protection Authority has repeatedly stated, does not guarantee a personal data protection system equivalent to that of the European Union. The US regulatory system allows US government and intelligence authorities to access personal information for national security purposes without the guarantees provided by European legislation.

The Data Protection Authority stated that the IP address is personal data to all intents and purposes as it enables the identification of an electronic communication device, thus indirectly making the data subject identifiable as a user. This data, even if truncated, is not anonymous, given Google’s ability to associate it with other data in its possession, allowing the user re-identification.

For these reasons, the Data Protection Authority adopted the first of a series of measures with which it cautioned the company that managed the website under investigation, ordering it to comply with the Regulation within 90 days. The Data Protection Authority considered the deadline appropriate to allow the website to adopt the required transfer measures, under the penalty of suspending the data flow to the United States using GA.

At the end of the 90 days, the Data Protection Authority will conduct inspections to verify compliance with the Regulation of the transfers carried out by data controllers.

◊◊◊◊

While waiting for the European Union and the United States of America to reach a legally binding agreement that guarantees an international transfer with protections equivalent to what is required in Europe, website operators must comply with applicable legislation. This includes relying on European providers that process users’ personal data within the EU.

Other related insights:

Subscribe to our newsletter

Contact

Need information? Write to us and our team of experts will respond as soon as possible.

Fill in the form

More news and insights

30 Apr 2026

Webinar “Bonuses: What Do You Need to Know About Objectives?” – HR Coffee with De Luca & Partners

Yesterday, during our first webinar “HR Coffee with De Luca & Partners", the speakers Vittorio De Luca, Managing Partner, and Alessandra Zilla, Managing Associate at De Luca &…

27 Apr 2026

Gestione della posta elettronica aziendale dopo la cessazione del rapporto di lavoro: il Garante estende il diritto di accesso a tutte le mail della casella e-mail nominativa 

“Il lavoratore può accedere ai messaggi del proprio account e-mail aziendale e ai documenti presenti nel pc dopo la fine del rapporto di lavoro. Eventuali limitazioni devono essere…

27 Apr 2026

NASpI e dimissioni per trasferimento oltre 50km: per la Cassazione non basta la distanza, va provato l’inadempimento del datore di lavoro 

Con la recente ordinanza n. 10559 del 21 aprile 2026, la Corte di Cassazione si è pronunciata in tema di indennità di disoccupazione (NASpI) a seguito di dimissioni per giusta causa dovute a trasferimento del…

27 Apr 2026

Lo sai che… il patto di prova è nullo se le mansioni sono indicate in modo generico? 

Il Tribunale di Milano, Sezione Lavoro, con sentenza n. 683 del 3 aprile 2026, ha ribadito che il patto di prova è valido solo se contiene una specifica…

17 Apr 2026

Criminal penalties are being introduced for those who fail to protect remote workers (The Platform, 17 April 2026 – Vittorio De Luca e Martina De Angeli)

The provision amends Legislative Decree 81/2008 by introducing a new Article 3, paragraph 7-bis, which makes compliance with safety obligations conditional upon the delivery—at least annually—of a written…

15 Apr 2026

Dismissal deemed valid based on a message sent in a WhatsApp chat (Camera di Commercio Italo-Francese – Vittorio De Luca, Silvia Zulato)

With Order No. 7982 of March 31, 2026, the Italian Supreme Court (Labour Section) held that a message sent within a private chat may constitute just cause for…