Is Google Analytics Legal in 2026? EU Rulings, US Lawsuits

A side-by-side comparison. On the left, a Clickport panel titled How IP addresses are handled shows the flow: the IP arrives with the request, a local MaxMind geo lookup runs on our own server, a one-way keyed hash produces a daily-rotating user_id, and then the IP is discarded, with a ClickHouse schema below where the ip_address column is struck through and marked does not exist. Four labels read: IP used once then thrown away, no personal data in the schema, every request processed in the EU, and nothing to transfer to the US. On the right, a dimmed Google Analytics data-sharing menu with visitor data sent to US servers flagged in red and Google signals on by default flagged in amber, under four labels: visitor data crosses to US servers, EU regulators ruled this setup unlawful, IP counts as personal data under GDPR, and fines reach 4% of global revenue.

Picture this: a Google Analytics misconfiguration sent the health data of 4.7 million patients to Google Ads for three years. It wasn't a hack. Nobody broke in. It was a setting someone left on. It could be a setting you left on. That's the risk you sign up for when you run GA4 in 2026, and it's only one corner of the picture.

Quick disclosure before we start: I run Clickport, a cookieless analytics tool that sidesteps most of what follows, so I'm not a neutral narrator. Every ruling, fine, and lawsuit below is linked to its source, so weigh the evidence, not me.

Here's the full picture.

Key Takeaways
  • Seven EU data protection authorities have ruled Google Analytics illegal under GDPR. No authority has ever declared GA4 compliant.
  • The EU-US Data Privacy Framework keeping GA4 alive in Europe faces active legal challenges from CJEU appeals, NOYB/Schrems III, and PCLOB collapse.
  • In the US, 2,341 CIPA wiretapping lawsuits have been filed against websites running third-party analytics scripts. Statutory damages are $5,000 per violation.
  • Blue Shield of California disclosed that a GA misconfiguration sent 4.7 million patients' health data to Google Ads for three years.
  • Google's privacy policy permits using GA4 data for product improvement including AI. Analytics Advisor (Gemini) now reads your GA4 data. This creates compliance risks under GDPR Article 22.

Seven countries have already said no

In my read of it, between January 2022 and June 2023, seven European data protection authorities ruled that using Google Analytics violates the GDPR. Not "might violate." Violates. Full stop.

It started in Austria, and I remember the shockwave. On December 22, 2021, the Austrian DSB ruled that sending EU visitor data to Google's US servers via Google Analytics broke GDPR Chapter V (published by noyb in January 2022). Google's defense was IP anonymization. The DSB threw it out. So will yours, if it comes to that. Google can still re-identify people through the other data it already holds on them. Anonymization won't save you.

Then the rest of Europe followed, within months. You could feel it snowballing.

Timeline: DPA rulings against Google Analytics
Dec 2021
Austria (DSB) rules GA transfers to the US illegal under GDPR
Feb 2022
France (CNIL) orders three websites to stop using Google Analytics
Jun 2022
Italy (Garante) declares Google Analytics unlawful, sets 90-day compliance deadline
Sep 2022
Denmark (Datatilsynet) declares GA non-compliant without supplementary measures
Mar 2023
Norway (Datatilsynet) warns GA4 "will not necessarily correct" the problems
Apr 2023
Finland (tietosuojavaltuutettu) finds meteorological institute violated GDPR via GA
Jun 2023
Sweden (IMY) issues first-ever financial penalty for GA use: EUR 1 million
The Netherlands also formally reprimanded Takeaway.com in August 2024 for using GA. Germany, Belgium, Spain, and Ireland have not issued formal rulings.

All seven rulings turned on the same point, and I want you to see it clearly. Google LLC answers to US surveillance law (FISA Section 702), which lets US intelligence agencies reach data sitting on Google's servers. No technical fix changes that, not even IP anonymization. Nothing you toggle helps. It comes down to where Google sits and who can force it to hand your data over. You can't move Google.

An editorial illustration titled 'What happens to your EU visitor's data.' showing the flow from a Berlin visitor through a browser to Google's US servers. Three red annotations point at each stage. The first reads 'Visitor IP, browsing path, cookies, click events. All collected by gtag.js on page load.' The second reads 'Data leaves the EU within milliseconds. GDPR Article 44 requires a transfer mechanism. The Data Privacy Framework is the current one, and it is under active CJEU appeal.' The third reads 'Stored on Google servers in the US. FISA 702 applies. US intelligence agencies can compel access without notifying the data subject.' A footnote at the bottom reads 'Same legal flow that triggered seven DPA rulings against Google Analytics. December 2021 to June 2023.'
The legal flow the seven DPA rulings all turned on. Visitor data leaves the EU on the browser request itself. FISA 702 applies as soon as it lands on Google's US servers. Illustration.

One detail gets skipped a lot, and I keep pointing at it. Not a single EU data protection authority has ever said GA4 is compliant. Sweden's IMY put it plainly in its June 2023 ruling: GA4 doesn't fix the core transfer problem. So the question was never which version of Google Analytics you run. You can't configure your way out of it. Google is an American company bound by American surveillance law. New version, same flow.

If you want the technical and legal architecture behind cookieless tracking, my guide on how privacy-first analytics avoids these problems goes deeper.

After the 2022-2023 rulings, Google caught a break, and so did your GA4. On July 10, 2023, the European Commission adopted the EU-US Data Privacy Framework (DPF), the third attempt at a legal bridge for moving data across the Atlantic. Google self-certified under it. Regulators paused enforcement. GA4 was alive again, and so was your setup.

The first two bridges were both struck down by the EU Court of Justice. That's the court now weighing the third. Safe Harbor fell in 2015 (Schrems I). Privacy Shield fell in 2020 (Schrems II). Two for two. The third one is the one holding your GA4 up right now, and it's being attacked from several directions at once.

Three attempts at EU-US data transfers
Attempt 1
Safe Harbor
2000 - 2015
STRUCK DOWN
Schrems I
Attempt 2
Privacy Shield
2016 - 2020
STRUCK DOWN
Schrems II
Attempt 3
Data Privacy Framework
2023 - ?
UNDER ATTACK
Latombe + NOYB

The oversight body is gone. The DPF leans on the Privacy and Civil Liberties Oversight Board (PCLOB), an independent US agency that keeps an eye on intelligence activities. When it adopted the DPF in 2023, the European Commission named PCLOB's independence as one of the reasons it trusted the deal. On January 27, 2025, the Trump administration fired all three Democratic PCLOB members. That means the safeguard the deal rested on stopped working overnight. That left the board below quorum and unable to function. It's been non-operational for over a year. The safeguard the Commission counted on is no longer there.

The court challenge is live. Philippe Latombe, a French MP, took the DPF to the EU General Court. The General Court dismissed his challenge in September 2025. He didn't stop there. In October 2025, Latombe appealed to the full CJEU, the same court that struck down both Safe Harbor and Privacy Shield. A ruling is unlikely before late 2027.

Schrems III is coming. NOYB, the privacy organization run by Max Schrems, announced it's preparing a broader challenge built around the PCLOB collapse and Trump-era changes to US oversight. Schrems has argued the Commission may not even need to wait for a court. It could suspend the DPF on its own if it decides the oversight guarantees are gone.

Norway is already telling companies to prepare. In February 2025, Norway's DPA issued guidance: if the adequacy decision is revoked, "there will most likely not be a transition period." Build your contingency plan now, not later. I would.

So the DPF is valid today. I'll grant you that. But it sits in the same court that killed its two predecessors, its oversight body has been gutted, and regulators are telling companies not to treat it as permanent. Clifford Chance called the situation "legal uncertainty and a storm over the Atlantic."

If the DPF falls, every website running Google Analytics in the EU lands right back where it was in 2022. Yours included. No legal basis for the data transfer.

In the US, your analytics script might be a wiretap

The legal risk isn't only European, and that surprises people. In the United States, a 1967 California phone-tapping law called CIPA is being used to sue website owners for running Google Analytics.

Here's the theory you're up against. When a third-party script captures visitor behavior and sends it to the vendor's servers in real time, that counts as a third party intercepting a communication without consent. Courts have bought the argument. In Smith v. Google (2024), a federal court denied Google's motion to dismiss, finding that Google builds "detailed dossiers" from the data it collects and uses it for its own ad business. Google isn't a passive tool. In the court's eyes, it's a third-party eavesdropper, and you're the one who invited it in.

The numbers back this up, and they're not small. 2,341 lawsuits filed. $5,000 per violation, and you don't have to prove any harm was done. In plain English: $5,000 a head, no injury required. 70% of web privacy claims come from just four law firms. The reform bill (SB 690) stalled in the California Assembly in July 2025 and became a two-year bill. No legislative fix until 2026 at the earliest.

I wrote a full deep-dive on this: Is Your Analytics Script a Wiretap Under California Law? It covers which tools are at risk, how plaintiffs find targets, why cookie banners don't protect you, and what to do about it.

The short version. If your vendor uses the data it collects for its own purposes, like ad targeting, model training, or cross-site profiling, that vendor is a third-party eavesdropper under CIPA. If the data never leaves your control, the party exception defense applies and the whole CIPA theory falls apart. That's the escape hatch you want.

The breaches that proved the risk

Legal theories get real when the data leaks for real, and it does. In 2024 and 2025, Google Analytics was directly behind two of the largest healthcare data breaches ever recorded.

Blue Shield of California: 4.7 million patients. Between April 2021 and January 2024, Google Analytics sent protected health information to Google Ads. Insurance plan names, patient names, doctor names, medical service dates, the amount each person owed, and what they typed into the "Find a Doctor" search. All of it went out because of how Google Analytics was set up to share data with Google's advertising products. Class action lawsuits were filed the day after the breach was disclosed.

Kaiser Permanente: 13.4 million members. In April 2024, Kaiser notified 13.4 million members that web tracking tools on its sites and apps had sent personal data to Google, Microsoft, and X (formerly Twitter). Kaiser agreed to pay up to $47.5 million to settle the class action that followed. That means a single tracking-pixel mistake, priced at eight figures.

Healthcare data breaches caused by Google Analytics
Blue Shield of California
Disclosed April 2025
Patients affected4.7 million
Duration3 years
Data sent toGoogle Ads
CauseGA misconfiguration
Kaiser Permanente
Disclosed April 2024
Members affected13.4 million
Settlement$47.5 million
Data sent toGoogle, Meta, X
CauseWeb tracking pixels
Google does not sign HIPAA Business Associate Agreements. Any healthcare organization using GA4 is accepting full liability for data that reaches Google's servers. If that's you, read that twice.

These aren't edge cases. They're what happens when Google Analytics works exactly as designed. GA4 sends data to Google's servers, where it feeds into Google's advertising products. When that data includes anything sensitive, like health information, financial data, or form submissions, nothing in the tool stops it from reaching Google's ad infrastructure. You're the one on the hook.

The Swedish DPA reinforced this principle in August 2024, fining two pharmacies EUR 3.9 million combined for a Meta Pixel that leaked health data. The ruling made one thing clear. The website operator, not the tracking vendor, is responsible for whatever the third-party script sends. In plain English: that's on you, not Google.

Google Analytics is no longer an analytics tool

Most articles skip this part, and I think it changes the whole legal picture.

In December 2025, Google rolled out Analytics Advisor to all English-language GA4 accounts. It's a Gemini-powered AI agent that reads your property's behavioral data and answers questions about your visitors. Your visitors, feeding Google's AI. In January 2026, Google added cross-channel budgeting and conversion attribution analysis betas. These forecast advertising returns across channels and work out where to spend your budget. That's media planning, not analytics, and you didn't sign up for it.

A screenshot of the Google Analytics 4 interface with the Analytics Advisor side panel open. The panel is labeled 'Analytics Advisor', subtitled 'Powered by Gemini', and shows a predicted-conversion bar chart in response to a user prompt. Action chips below read 'View segment in Audiences', 'Export to Google Ads', and 'Refine prediction'. Three red annotations sit in the margins. One reads 'Released December 2025. The AI reads every behavioral event in your GA4 property.' Another reads 'Automated predictions about individual visitor segments. GDPR Article 22: visitors have the right not to be subject to decisions based solely on automated processing.' A third reads 'Insights flow back into Google's ad-bidding models. Your visitors' behavioral data improves the platform that funds Google's advertising business.'
Analytics Advisor in action. The Gemini-powered agent reads your property's behavioral data and produces predictions about individual visitor segments. The "Export to Google Ads" action chip on each prediction is not subtle. Recreated for illustration.

But the deeper problem hides in a setting most GA4 users never really read, and you probably haven't either.

When you turn on "Google products and services" in GA4 and accept Google's Measurement Controller-Controller Data Protection Terms, Google becomes an independent controller of your visitor data. Google's own documentation says this data can be used to "improve Google products and services," including the Google Ads system. Your visitors' data, in other words. Under those terms, your visitors' data becomes Google's data. Not yours anymore.

GA4 in 2020 vs. GA4 in 2026
GA4 at launch (2020)
Page views and events
User flow reports
Basic conversion tracking
Custom dimensions
BigQuery export (360 only)
Analytics tool with advertising hooks
GA4 today (2026)
Gemini AI Analytics Advisor
Predictive Audiences (ML on your data)
Enhanced Conversions (hashed PII to Google)
Cross-channel budget planning
Attribution analysis with AI modeling
Controller-controller data sharing
AI advertising platform wearing an analytics label
For a full feature-by-feature breakdown, see Clickport vs Google Analytics: The Honest Comparison.

And in October 2025, Google officially killed Privacy Sandbox. Third-party cookies stay in Chrome for good. The promise of a more private web, from the world's largest advertising company, turned out to be a four-year PR exercise. I'm not shocked, and you shouldn't be either.

This matters for the legal side because of legitimate interest, the legal basis you might be leaning on for analytics. It requires a balancing test, and you probably haven't run it. When someone browses a website, they don't expect their behavior to feed an AI system that trains advertising bidding models and predicts what they'll buy next. That gap between what a visitor expects and what really happens collapses the legitimate interest argument you were relying on. The Cologne Regional Court reached the same conclusion in March 2023 when it ruled Deutsche Telekom's use of Google Analytics violated GDPR, upheld on appeal in November 2023.

20 US states, 12 requiring Global Privacy Control

The EU debate gets the headlines, but the US is quietly building its own privacy rules, and they'll reach you too. As of January 2026, 20 states have comprehensive privacy laws in effect. That means the US patchwork is catching up to Europe fast. Three new ones came online on January 1, 2026: Indiana, Kentucky, and Rhode Island. That means three more states you may now answer to.

Twelve states now require businesses to honor Global Privacy Control (GPC) signals: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. California, Colorado, and Connecticut ran a joint enforcement sweep in 2025, going after businesses that ignored GPC.

US state privacy laws: the 2026 landscape
20
States with privacy laws
12
Require GPC honoring
3
New laws Jan 1, 2026
4+
States with pending bills
Key: all US frameworks use opt-out, not opt-in. But tools collecting IP addresses, cookie identifiers, or browsing paths handle "personal information" under CCPA and most state laws, requiring opt-out mechanisms, GPC compliance, and data subject rights. Tools collecting only aggregate, non-identifiable data fall outside these definitions entirely.

This is where the distinction matters most for you. Under CCPA and every Virginia-model state law, "personal information" is data that's "linked or reasonably linkable to an identified or identifiable natural person." Google Analytics collects IP addresses, cookie identifiers, and browsing paths. All of that's personal information. It triggers opt-out requirements, GPC obligations, and data subject rights in every state with a privacy law.

Now picture analytics you run that collects no IP addresses, sets no cookies, builds no per-user profiles, and produces only aggregate page-level counts. That falls outside the definition of personal information in every current US state privacy framework. No compliance overhead, by design. That's the version I'd want running.

For a fuller look at the regulatory landscape, our privacy-friendly analytics guide covers both EU and US compliance requirements in detail.

What 40% of your traffic is doing that GA4 can't see

Even if Google Analytics were fully legal everywhere, it has a growing accuracy problem most website owners never hear about. Between ad blockers, browser privacy features, and consent rejection, GA4 misses a large and growing chunk of your real traffic.

Ad blockers are eating GA4 alive. 42.7% of global internet users run ad-blocking tools on at least one device. That means GA4 starts blind to nearly half the web. On tech-savvy audiences it gets far worse. One controlled study found that 58% of Hacker News and Reddit readers block Google Analytics outright, and 88% of the Firefox users in the sample blocked it. Tools like uBlock Origin and Brave Shields stop google-analytics.com at the network request level, before it ever loads.

Browsers are tightening the screws. Safari 26 activates Advanced Fingerprinting Protection by default for all browsing, and its Advanced Tracking and Fingerprinting Protection (default in Private Browsing) blocks Google Tag Manager from loading at all. Safari 26 also strips Google click IDs (gclid) from URLs, which breaks paid search attribution. Firefox 145 added anti-fingerprinting protections that cut trackable users in half. That means every Firefox update makes GA4 a little blinder. And Firefox's Enhanced Tracking Protection has now blocked more than 1 trillion tracking attempts in total.

Consent rejection piles on top. In the EU, between 30% and 70% of visitors decline analytics cookies, depending on the country and how the banner is built. Every one of those visitors is invisible to GA4.

What GA4 actually sees: the data loss funnel
1,000 actual visitors land on your site
100%
Consent banner shown (EU sites)
500 consent to cookies (50% rejection rate)
50%
Ad blockers and browser protections
350 not blocked by ad blockers (30% blocked)
35%
Safari ITP, Firefox ETP, browser-level blocking
~250 visitors GA4 actually reports
~25%
For a typical EU website, GA4 may report only 25-40% of actual traffic. On tech-heavy audiences, it can be worse. Google's Consent Mode "behavioral modeling" fills some gaps, but uses data from non-consenting users to do it, which is itself legally questionable.

Google's answer to consent rejection is Consent Mode v2. It sends "cookieless pings" to Google even when people decline cookies, then builds "behavioral models" from that non-consented data to fill the gaps. Whether modeling from users who explicitly said no is itself a GDPR violation is still legally unresolved. Which means you'd be building on unsettled ground.

First-party analytics sidesteps all three layers of loss, and that's what you want. The tracker is served from your own domain, so ad blockers can't tell it apart from your site's own code. No cookies means no consent banner and nothing to reject. And first-party requests aren't caught by Safari ITP or Firefox ETP. The result is that you see the visitors GA4 loses at the banner, close to your real total.

This is also why your bounce rate measurements might be off. When GA4 only sees a fraction of your visitors, every metric you read off that data is distorted.

EUR 7.1 billion in fines and counting

Maybe you're thinking regulators don't really enforce any of this. I hear that a lot. The numbers say otherwise.

Total GDPR fines since May 2018 have reached EUR 7.1 billion, according to DLA Piper's January 2026 survey. That means enforcement is a bill, not a bluff. EUR 1.2 billion was issued in 2025 alone, roughly matching 2024. In plain English: the pace isn't slowing. Breach notifications hit an average of 443 per day, a 22% jump and the first time the daily count topped 400 since the GDPR took effect. In plain English: a breach reported every few minutes.

Cookie enforcement in particular keeps climbing.

  • September 2025: CNIL fined Google EUR 325 million for ads in Gmail without consent and dark patterns in cookie acceptance. This was Google's third CNIL cookie fine, after EUR 100 million (2020) and EUR 150 million (2021). CNIL counted the repeat offending against it.

  • September 2025: CNIL fined SHEIN EUR 150 million for setting cookies on devices before users had even touched the consent banner. 12 million French users per month were affected. That means the fine scaled with the audience.

  • August 2024: Sweden's IMY fined two pharmacies EUR 3.9 million combined for a Meta Pixel that leaked health data.

  • April 2025: The Netherlands' DPA launched a proactive monitoring program, scanning about 10,000 websites a year and warning 500 organizations a year about cookie compliance.

GDPR enforcement: the escalation curve
2020
EUR 0.3B
2021
EUR 1.3B
2022
EUR 1.6B
2023
EUR 2.1B
2024
EUR 1.2B
2025
EUR 1.2B
Cumulative total: EUR 7.1 billion across all GDPR fines since May 2018. Source: DLA Piper January 2026 Survey.

The trend is clear. DPAs are getting tougher, not softer. Fines are growing. Enforcement is becoming proactive instead of waiting for someone to complain. And cookie and analytics violations sit near the top of the priority list.

The law that could change everything

On November 19, 2025, the European Commission published the Digital Omnibus, a sweeping proposal to simplify the EU's digital rulebook. Tucked inside it's a change that could reshape the whole analytics market.

The proposal moves cookie consent rules out of the ePrivacy Directive and into the GDPR as a new Article 88a. This one's worth your attention. That article creates a whitelist of purposes that need no consent. One of them is audience measurement.

Article 88a(3)(c) exempts "creating aggregated information about the usage of an online service to measure the audience of such a service, where it is carried out by the controller of that online service solely for its own use."

The conditions are specific.

  • The analytics must produce aggregated information, not individual user profiles
  • It must be carried out by the controller of the online service (the website owner)
  • It must be used solely for that controller's own use
  • The analytics provider must not reuse the data for its own commercial purposes
  • Data must not be combined with other datasets from other services
Digital Omnibus: who qualifies for the consent exemption?
QUALIFIES
Privacy-first analytics
Data processed per-customer, isolated
Vendor doesn't reuse or pool data
Aggregate statistics only
No cross-site tracking
No advertising integration
DOES NOT QUALIFY
GA4 (standard configuration)
Google processes data on shared infrastructure
Terms permit use for Google's own products
Linked to Google Ads ecosystem
Correlates users across properties
Controller-controller data sharing
The EDPB/EDPS supports the direction and encourages a shift toward contextual over behavioral advertising. The analytics exemption itself has not attracted significant opposition. See what cookie-banner-free analytics means for your site.

This isn't law yet, so don't bank on it. The proposal is still in early legislative procedure at the European Parliament. Legal analysts expect the analytics exemption could take effect by mid-2027 at the earliest.

But the direction is clear, and I'd plan for it. The EU is heading toward a world where privacy-first, first-party analytics runs without consent requirements, while tools that share data with third parties for advertising still need the full consent machinery. You'll want to be on the right side of that line. IntelligentCIO Europe quoted Mateusz Krempa: "this will give privacy-friendly European analytics providers an edge compared to US-based platforms."

The tools that win here aren't the ones scrambling to redesign. You'll want one that didn't have to. They're the ones that were built this way from the start.

What you should actually do

I'm not going to pretend there's one answer that fits everyone. I wish I could hand you one. It depends on where you operate, what industry you're in, and what you really need from your analytics.

If you're in healthcare, finance, or education: remove Google Analytics now. The Blue Shield and Kaiser cases show you that GA4's design clashes with HIPAA, and the data flow to Google's ad infrastructure is a built-in risk that no setting fully removes. Use a first-party analytics tool that processes data on EU infrastructure and shares nothing with third parties.

If you're in the EU and want to keep GA4: you need explicit, informed consent before any tracking fires. Not "by browsing you agree." A real consent banner that blocks every GA4 script until the user clicks Accept. You'll build it and maintain it. You'll need a Data Processing Agreement with Google. And you need to accept that 50-70% of your visitors will decline consent, which leaves your analytics showing a minority of your real traffic.

If you're in the US: audit your tracking stack for CIPA exposure. Every third-party script that captures visitor behavior and ships it to a vendor that uses it for its own purposes is a potential $5,000-per-violation liability. That includes the one on your site. Our CIPA deep-dive covers the specific tools at risk and what you should do about each one.

If you want to stop worrying about all of this: switch to analytics that never create the legal exposure in the first place. Our comparison of the leading Google Analytics alternatives walks through what each privacy-first tool does and which one fits which kind of site.

Decision guide: what should you do?
Need Google Ads retargeting? GA4 is the only option for native audience export. Accept the legal and data-loss trade-offs.
Need cross-device tracking? GA4 can link sessions across devices via Google account identity. No privacy tool replicates this.
Need to understand traffic sources, content performance, and visitor engagement? A privacy-first tool gives you this with deeper engagement metrics, no consent banner, and far fewer blind spots.
Need conversion tracking and goal measurement? Most privacy-first tools, including Clickport, support goals, form tracking, and custom event tracking without cookies.
Want to be ready for the Digital Omnibus? Tools that qualify for the Article 88a exemption will operate without consent barriers. Tools that don't will still need banners.

The honest answer to "is Google Analytics legal in 2026?" is that it depends on who you ask, where you are, and how much risk you're willing to carry. Seven EU countries have called it illegal. The legal bridge keeping it alive is under attack. US wiretapping lawsuits are surging. The tool has turned into an AI advertising platform. Browsers are blocking it. And a proposed EU law would hand privacy-first analytics a clear legal edge.

You can wait for the courts and regulators to sort it out. Or you can decide now. I'd decide now.

And if you're unsure whether your own setup is exposed, email me what you're running. I answer every email.

Get analytics without the legal uncertainty
No cookies. No consent banners. No third-party data sharing. EU-hosted.
Start your free trial
30-day free trial. GDPR-compliant from day one.
David Karpik

David Karpik

Founder of Clickport Analytics
Building privacy-focused analytics for website owners who respect their visitors.

Comments

Loading comments...

Leave a comment