Is Google Analytics Legal in Ireland? The DPC, the One-Stop Shop, and What It Means for Your Site

Is Google Analytics legal in Ireland? Yes, for now. No Irish ruling has ever said otherwise, and that's the strange part. Seven European regulators ruled Google Analytics unlawful between 2022 and 2023, which means seven countries told their websites to stop. Ireland's Data Protection Commission didn't. Yet the entire European case against Google Analytics started in Dublin, with a complaint filed to that very regulator in 2013. Here's the full picture, and what it means for you.
- Ireland's DPC has never ruled on Google Analytics. Austria, France, Italy, Denmark, Finland, Norway and Sweden all ruled against it between January 2022 and July 2023. In Ireland, GA remains legal but still needs cookie consent.
- The whole European case against Google Analytics started in Dublin: Max Schrems' 2013 complaint to the Irish DPC became the CJEU's Schrems II ruling in July 2020, the legal basis for every GA ruling that followed.
- Ireland is the EU's one-stop-shop regulator for Google, Meta and TikTok. Its record: EUR 1.2 billion against Meta in 2023 for illegal EU-US transfers, EUR 530 million against TikTok in 2025, EUR 310 million against LinkedIn in 2024.
- Irish cookie law (S.I. 336/2011) has no analytics exemption. Unlike France, every analytics cookie needs prior consent, and a 2025 study of 254,148 sites found only 15% of consent banners are even minimally GDPR-compliant.
- The EU-US Data Privacy Framework keeps Google Analytics legal for now, but the challenge to overturn it is pending at the EU's highest court. Cookieless analytics avoids both the banner and the transfer question.
The rules you're subject to in Ireland
Irish cookie law comes from S.I. No. 336 of 2011, Ireland's version of the EU's ePrivacy Directive, enforced by the Data Protection Commission (DPC). It requires prior consent for analytics cookies. It doesn't have an analytics exemption, an approved tool list, or any grace for "harmless" measurement. If Google Analytics sets a cookie on an Irish visitor's device, you need their consent first.
Let me unpack that for you in plain words. The ePrivacy Directive is the 2002 EU law that governs cookies and trackers. Every EU country turned it into national law its own way. Ireland did it through the European Communities (Privacy and Electronic Communications) Regulations 2011, known as S.I. 336/2011. That statutory instrument is still the operative Irish cookie law today. A promised EU-wide replacement, the ePrivacy Regulation, never arrived.
Regulation 5(3) is the part that matters for analytics. It says you can only use tracking technologies if the visitor got clear, comprehensive, prominently displayed information about what you're doing, and gave consent. The DPC's cookie guidance spells out that the GDPR consent standard applies: "a clear, affirmative act, freely given, specific, informed, and unambiguous."
In practice, that standard kills every shortcut you've seen. Pre-ticked boxes don't count. Cookie walls don't count. "By continuing to browse you accept cookies" doesn't count. The visitor has to make a real choice.
There's one exemption, and it's narrow. Regulation 5(5) allows cookies that are strictly necessary to deliver a service the visitor explicitly asked for. A shopping cart qualifies. A login session qualifies. Analytics doesn't fall under it, and nothing in the DPC's guidance carves out an exception for measurement, which means the consent requirement applies to it in full.
Here's the contrast that matters for this series. France built a formal consent exemption for privacy-respecting analytics tools that meet CNIL's strict conditions. Ireland didn't build anything like it. You won't find an Irish list of exempt analytics tools, or a self-assessment framework either. That means the only way you escape the Irish banner requirement is a tool that doesn't touch the visitor's device at all: cookieless analytics.
One more piece of history. When the DPC published its cookie guidance on 6 April 2020, law firm client notes from Bird & Bird and LK Shields reported a six-month grace period, which means Irish sites had until roughly October 2020 to fix their banners before enforcement began. That deadline passed more than five years ago. The rules aren't new anymore.
Ireland is where the whole Google Analytics story started
Every ruling against Google Analytics in Europe traces back to one Irish case. In 2013, Max Schrems complained to the Irish DPC about Facebook's EU-US data transfers. That complaint became Schrems II, the July 2020 judgment of the EU's highest court that invalidated the Privacy Shield transfer deal. Schrems II is the legal foundation of every GA ruling that followed.
The story is worth knowing, because it explains why the tool you use became a legal question at all.
Schrems, an Austrian privacy lawyer, argued that data sent to US servers could be read by US intelligence agencies, and that EU citizens had no real way to fight that. His complaint went to Ireland because Facebook's European headquarters is in Dublin. The Irish High Court eventually referred 11 questions to the Court of Justice of the EU. In plain English, Dublin's court asked Europe's court whether US transfers were safe. That reference became case C-311/18.
On 16 July 2020, the court agreed with him. It struck down the Privacy Shield, the deal that had made EU-to-US data transfers routine. Ireland's own regulator put it plainly the same day: "EU citizens do not enjoy the level of protection demanded by EU law when their data is transferred to the United States."
Sit with that for a second. The Irish regulator said US data protection isn't good enough for EU citizens. Google Analytics sends visitor data to a US company. You can see where this is heading.
A month later, the privacy group noyb filed 101 complaints across 30 European countries against websites still using Google Analytics and Facebook's tools. Those complaints produced the rulings you've probably heard about: Austria first in January 2022, then France, Italy, Denmark, Finland, Norway and Sweden. Put another way, the complaint Ireland handled in 2013 grew into a Europe-wide finding that Google Analytics broke the law.
And the decade-long arc ended where it began. In May 2023, the DPC fined Meta EUR 1.2 billion for continuing EU-US transfers without adequate safeguards after Schrems II. That's the largest GDPR fine ever issued, which means the record fine for the exact legal problem behind the Google Analytics rulings was issued in Dublin. About ten years, complaint to conclusion. Ireland owns this story end to end.
The one-stop shop, and why Ireland never ruled on Google Analytics
Ireland never issued a Google Analytics ruling because of how EU enforcement is wired. The GDPR's one-stop shop means the regulator in the country where a company has its EU headquarters leads all EU enforcement against that company. Google, Meta, TikTok and LinkedIn are all headquartered in Dublin. So the DPC leads on Big Tech, and everything else queues behind that.
The one-stop shop is worth explaining properly, because it's the answer to the question this article asks.
When Austria and France ruled against Google Analytics in 2022, they weren't ruling against Google. They were ruling against local websites that used it. In other words, a French regulator can tell a French website to stop using GA without ever touching Google's Irish headquarters. That's why those rulings could happen outside the one-stop shop entirely.
Ireland could have done the same for Irish websites. It didn't. I checked the DPC's live cookie guidance while writing this, and Google Analytics isn't mentioned anywhere on it. Not once. And I couldn't find any Irish decision, guidance note or public statement naming GA anywhere else either. The DPC simply hasn't touched the question. Even Schrems, announcing the Austrian ruling in January 2022, predicted that "similar decisions" would "now drop gradually in most EU member states." Most member states. Ireland wasn't on anyone's list.
Why not? Capacity is the polite answer. The DPC is the lead regulator for the biggest data companies on earth, which means its docket holds cases like Meta's transfers and TikTok's China problem, not you and your cookie banner. The less polite answer comes from the Irish Council for Civil Liberties, which has spent years arguing the DPC is the bottleneck of GDPR enforcement in Europe: too slow, too fond of quiet settlement. By late 2022 the ICCL counted 50 compliance orders and 29 fines from the DPC, a total it considered far too small for the caseload Dublin controls. In other words, Europe's busiest docket produced one of its thinnest records.
There's evidence for the critique inside the DPC's own biggest wins. The WhatsApp fine of EUR 225 million in September 2021 only reached that size because the European Data Protection Board, the umbrella body of all EU regulators, required the DPC to increase its smaller proposed fine after eight other authorities objected. In plain English, Ireland's own peers overruled it into fining harder. The record Meta fine has the same shape. The DPC's initial proposal contained no fine at all, just a suspension order, and the EDPB stepped in and mandated the EUR 1.2 billion penalty.
So here's the honest summary of Ireland's position. The regulator that started the war on US data transfers never fired a shot at Google Analytics itself. That's not a clearance. It's a queue.
Where Google Analytics stands in Ireland today
Google Analytics is legal to use in Ireland in 2026, on two conditions. You need valid prior consent for its cookies under S.I. 336/2011, and its US data transfers rest on the EU-US Data Privacy Framework, the 2023 deal that replaced Privacy Shield. The first condition costs you data. The second is under appeal at the EU's highest court.
Let me take those one at a time, because they're different kinds of risk.
The consent condition is yours to carry. GA sets cookies, cookies need consent in Ireland, and there's no analytics exemption to save you. That means you need a compliant banner, a real reject button, and no measurement of anyone who declines. This isn't theoretical. It's the same consent standard the DPC's guidance has carried since the 2020 grace period ended, and I'll show you below what it does to your data.
The transfer condition is out of your hands entirely. The 2022 rulings found GA unlawful because it moved EU visitor data to US servers without adequate protection. The Data Privacy Framework, adopted in July 2023, patched that hole. Google is certified under it. So the specific violation Austria and France identified doesn't exist right now, and I want to be straight with you about that: nobody can honestly claim GA is flat-out illegal in Europe today.
But the patch has a history of failing. Safe Harbor was struck down in 2015. Privacy Shield was struck down in 2020, by the case Ireland's own regulator carried. That means the Data Privacy Framework is attempt number three, and it's already been challenged. The EU General Court dismissed that challenge in September 2025, but the appeal reached the Court of Justice in October 2025 and is pending as I write this. Translation: this isn't settled. The court even noted the European Commission must step in if US conditions change. Two frameworks died at that court. You'd be brave to bet your analytics stack on the third.
For the full ruling-by-ruling history, I keep a dedicated legal-status page updated. The short version for Irish site owners: legal today, consent-gated always, and standing on a foundation that has failed twice before.
Worth repeating what makes Ireland unusual here. In Austria or Sweden, a regulator has told site owners like you to drop GA, with Sweden attaching a fine of roughly EUR 1 million. In Ireland, no regulator ever has. In practice, that's a real difference in enforcement risk. It's not a difference in what the law requires of your cookie banner.
What the DPC does enforce
The DPC doesn't chase analytics scripts. It chases the biggest data cases on the continent, and its fines run into the billions since 2018. Meta, TikTok, WhatsApp and LinkedIn have absorbed the headline numbers. For ordinary Irish websites, the enforcement that matters is the cookie standard set in 2020 and the sheer volume of complaints the DPC processes every year. Here's the record, and every figure links to the DPC's own announcement.
Two of those entries deserve a second look if you run analytics.
The LinkedIn fine of EUR 310 million is the closest the DPC has come to your world. Which means this: LinkedIn analysed member behaviour for targeted ads, and the DPC found its consent wasn't freely given or specific, its "legitimate interest" argument failed, and its contractual argument was wrongly invoked. Behavioural tracking without a valid legal basis cost EUR 310 million. That's the same legal territory every cookie-based analytics setup lives in.
And the TikTok China decision of May 2025 shows the transfer logic of Schrems II is alive and expanding. EUR 485 million of that fine was specifically for moving data to a country whose surveillance laws the EU doesn't trust. In other words, swap China for the US and you've described the Google Analytics cases. Same doctrine, bigger number.
What about ordinary websites? The DPC ran a cookie sweep of around 40 organisations between August and December 2019 and found widespread failures, with one law firm summary reporting pre-ticked consent boxes at 26% of respondents. In plain English, a quarter of the swept sites were faking consent. The follow-up was the April 2020 guidance and the six-month grace period. Since then the pressure has been complaint-driven: the DPC's 2024 annual report logged 11,091 new individual cases in one year and 7,781 valid breach notifications, up 11% on 2023. In other words, the DPC may be slow with Big Tech, but the complaint pipeline that reaches small sites is very much running.
Don't read Ireland's silence on GA as safety. Read it as an overloaded regulator that hasn't gotten to you yet.
Your cookie banner is costing you most of your Irish traffic
Even with Google Analytics perfectly legal, the consent requirement means you only measure the visitors who say yes. Nobody has studied Irish accept rates specifically, but the EU-wide evidence is grim: in a 2025 study of 254,148 sites, only 15% of consent banners were even minimally GDPR-compliant. In plain English, compliant banners lose most of their traffic. Non-compliant ones break the law.
This is the part of the story that hits your bottom line, so let's be concrete.
Ireland is a small, extremely online country. The CSO puts the population at 5,458,600 as of April 2025, with 95% of adults using the internet. Put another way, almost the whole country is online. It counts 401,359 active enterprises, and 92.6% of them have fewer than 10 employees. That means the burden of getting cookie consent right falls mostly on businesses with nobody whose job is compliance. You're probably one of them.
Now the measurement math. Nouwens and colleagues published a study at CHI 2025 covering 254,148 sites across 31 countries. They found 67% of top sites show a consent banner, only 45% offer any reject option at all, and just 15% meet even a minimal GDPR compliance bar. Put another way, most banners you see in Ireland are likely unlawful in some detail, and the lawful ones invite refusal.
And refusal is what you get. There's no Ireland-specific accept-rate study, so I won't invent one for you. But across the countries I've covered in this series, a fair banner typically loses somewhere between half and three quarters of visitors; in France, fewer than a quarter accept analytics cookies at all. Ireland's visitors see the same banners in the same browsers. I'd be surprised if they behave differently.
Then subtract the blockers. The most recent Ireland-specific figure I could find is old, and I'll flag that honestly: at the end of 2016, the Irish Times reported 39% of Irish internet users ran an ad blocker, joint-second in the world at the time. Translation: treat it as history, not a current figure. What isn't stale is browser behaviour: Safari holds 27.44% of the Irish market per StatCounter's July 2026 snapshot, and Safari's tracking prevention caps or blocks analytics cookies on its own. You don't get a say in that.
Here's what this adds up to for an Irish site running GA with a fair banner. You're legal. You're also making decisions on a fraction of your traffic, skewed toward the kind of person who clicks Accept. The visitors who refuse aren't random, which means the conversion rates, channel mix and top pages you act on are all quietly wrong. This is the problem cookieless analytics exists to solve: no cookies, no banner needed for analytics, every visitor counted. It's how I built Clickport, with processing in the EU, so the transfer question doesn't even come up.
What's coming next
Three open threads will decide how this story ends. The EU's Digital Omnibus proposal would allow consent-free audience measurement across all 27 member states. The Data Privacy Framework appeal is pending at the CJEU. And the ePrivacy Regulation that was supposed to replace Ireland's 2011 rules never materialised, so S.I. 336/2011 remains the law you comply with.
The Digital Omnibus could remove the banner requirement for analytics. Proposed in November 2025, it would extend consent-free measurement, roughly the deal France already gives qualifying tools, to the whole EU. In plain English, that would transform Irish law, which currently has no analytics exemption at all. It's still a proposal. It hasn't changed anything yet, and I break down the details in my Digital Omnibus analysis.
The DPF appeal is the sword over Google Analytics. If the CJEU overturns the framework the way it overturned Privacy Shield and Safe Harbor, the 2022 rulings snap back into relevance overnight. Every GA installation in Ireland would again depend on transfer mechanisms a court has questioned. I'm not predicting that outcome. I'm noting the court's record: two frameworks reviewed, two struck down.
And the DPC is under permanent pressure to move faster. The EDPB has twice forced its fines upward, and the bottleneck critique isn't going away. If Brussels keeps pushing Dublin toward harder enforcement, the gap between "Ireland never ruled on GA" and "Ireland enforces cookie consent like everyone else" narrows. The safe assumption for you is simple. Plan as if Irish enforcement will look European, because structurally it already answers to Europe.
What this means for your website
If your site serves Irish visitors, here's my practical read of where you stand in 2026.
If you're using Google Analytics with a cookie banner: You're legal, on both counts that matter. But you're only measuring the visitors who click Accept, your data skews toward them, and the transfer framework GA depends on is at the same court that killed its two predecessors. You're compliant and half-blind at once.
If your cookie banner isn't compliant: You're in the majority, and that's not comfort. The EU-wide study found only 15% of banners meet even a minimal bar, which means most sites are exposed on a rule the DPC settled back in 2020. The DPC took in over 11,000 cases in 2024 alone, and in practice, complaints are how small sites like yours get noticed. My cookie banner flowchart walks through what a valid Irish banner needs, and the GDPR guide covers the wider obligations.
If you want to see all your traffic and skip the whole question: Use analytics that doesn't touch the visitor's device. No cookies means no consent requirement under S.I. 336/2011, no banner for analytics, and no US transfer to defend. Every visitor counted from day one, with bots filtered out at ingestion. Here's how that works, and here's the wider field of European options if you want to compare.
A closing note, because this is a legal topic: I'm not a lawyer and this isn't legal advice. It's a founder's map of the Irish terrain, with the major rulings and fines linked to their primary sources. If your situation is complicated, show this to your DPO or solicitor.
If you want the cookieless route, you can try Clickport free for 30 days, and switching from Google Analytics takes one snippet. And if you're weighing an Irish analytics decision and something here doesn't match what you're seeing, email me.

Comments
Loading comments...
Leave a comment