Is Google Analytics Legal in Luxembourg? The CNPD, the Amazon Case, and Your Cookie Banner

Is Google Analytics legal in Luxembourg? Yes, for now, as long as you collect cookie consent first. But "for now" is doing heavy lifting: the legal basis GA depends on is under appeal at the EU's highest court, and Luxembourg's own regulator issued the biggest GDPR fine in history, 746 million euros against Amazon. In March 2026 a court annulled that fine and sent the case straight back to the regulator's desk. The story behind that answer tells you everything about where your analytics stand.
- Google Analytics is legal in Luxembourg today only with cookie consent, and only because the EU-US Data Privacy Framework (July 2023) restored a legal basis for US data transfers. That framework is under appeal at the EU's highest court.
- Luxembourg's CNPD issued the largest GDPR fine in history: EUR 746 million against Amazon in July 2021. In March 2026 the Cour administrative annulled it on procedural grounds, affirmed the underlying violations, and sent the case back to the CNPD.
- CNPD guidelines classify analytics cookies as non-essential, so consent is required. A narrow exemption exists but demands first-party-only, anonymous statistics with no third-party transmission. A stock Google Analytics setup doesn't fit it.
- The CNPD has never ruled on Google Analytics by name. The three Luxembourg complaints from noyb's 101-complaints wave targeted Facebook's tools, and were closed in April 2022 without any ruling on the merits.
- CNPD complaints jumped from 516 in 2024 to 846 in 2025, while its sanctions committee issued 7 fines totaling EUR 216,061. Enforcement is accelerating from a slow start.
The rules you're subject to in Luxembourg
Luxembourg's cookie rules come from a 2005 law on privacy in electronic communications, and the CNPD, Luxembourg's data protection authority, interprets them through cookie guidelines published in late 2021. Non-essential cookies need consent before you load them. Analytics cookies count as non-essential. And consent has to meet the GDPR's demanding standard: active, informed, freely given.
The law itself is the "loi modifiée du 30 mai 2005," a 2005 statute on data protection in electronic communications, amended several times since. It's Luxembourg's transposition of the EU's ePrivacy Directive, which means the EU-wide cookie rule you've met everywhere else was copied into national law, specifically into Article 4.3, e) of that statute. The CNPD confirms this in its own cookie guidelines.
Article 4.3, e) exempts exactly one category of cookies from consent: those strictly necessary to transmit a communication or to deliver a service the visitor explicitly asked for. In plain English: the shopping-cart cookie's fine, the login cookie's fine, and almost everything else needs a yes from your visitor before you load it. That includes analytics.
The GDPR raised the bar on what that yes means. Since May 2018, consent under the ePrivacy rules has to meet the GDPR's definition: a clear, active choice. The CNPD leans on the EU Court of Justice's Planet 49 ruling from 2019, which killed pre-ticked boxes for good. Which means silence isn't consent, scrolling isn't consent, and a box someone else ticked for you isn't consent.
The CNPD published its "Lignes directrices en matière de cookies et autres traceurs" (guidelines on cookies and other trackers) in October 2021, with the current version dated 3 January 2022. I read them so you don't have to. Here's what they demand:
Cookie walls are banned for non-essential cookies. You can't lock your content behind "accept cookies or leave." The CNPD treats that as forced consent, and forced consent is no consent.
Dark patterns invalidate consent. The guidelines call out unequal button sizes, colors, and contrast on the banner's first layer. A big green "Accept" next to a grey "Refuse" link isn't a choice, it's a nudge. Refusing has to be as easy and as visible as accepting, on the first layer of the banner. If your visitor can't refuse in one click, you don't have a compliant banner.
Consent shouldn't outlive 12 months. The CNPD recommends re-asking after a year at most. That's a recommendation, not a hard legal deadline, but it tells you where the regulator's head is at. I'd follow it anyway.
If you're now wondering whether your site needs a banner at all, I wrote a decision flowchart for exactly that question.
Analytics cookies need consent. The exemption is narrower than you'd hope
The CNPD classifies audience-measurement cookies as non-essential by default, so they need prior consent, even when the privacy risk is low and your disclosure is spotless. A narrow exemption exists for strictly first-party, anonymous measurement. It parallels France's famous carve-out, but it's worded more restrictively. A stock Google Analytics setup doesn't fit it.
The guidelines are blunt about the default. Even for plain visit counting, the CNPD says you must get your visitor's consent before placing analytics cookies. Low risk doesn't buy you an exemption. Good intentions don't either.
Then comes the interesting part. The CNPD carves out a narrow path for analytics cookies to skip consent, if you can show they're necessary to deliver your service (the examples given are server-capacity planning and bug detection), and all three of these conditions hold:
- The data isn't transmitted to third parties and isn't cross-referenced with other processing. Your measurement data stays between you and your site.
- The cookies can't follow a person across different apps or websites. No cross-site tracking, full stop.
- The data is collected exclusively for and by the site operator, and it's used to produce anonymous statistics only.
If you've read my France article, it'll look familiar. It's the same shape as CNIL's audience-measurement exemption: first-party only, no third-party sharing, no cross-site tracking, anonymous stats. As I read it, Luxembourg's version leans stricter, because you've also got to show the measurement is necessary to run the service at all. The UK's ICO, for contrast, never adopted this exemption model: analytics cookies there need consent with no carve-out.
So where does Google Analytics land? What follows is my analysis, not a CNPD quote, because no CNPD document names Google Analytics at all. A stock GA4 deployment sends your visitor data to Google's servers. That's transmission to a third party, which fails condition one. GA's identifiers are built to recognize activity across sites and devices, especially with Google signals on. That fails condition two. Two strikes out of three, and you only get to fail zero.
The flip side matters just as much. An analytics tool that's genuinely first-party, shares nothing with third parties, and produces anonymous statistics has a credible path to running without a consent banner in Luxembourg. That's the door the CNPD left open for you. Most Luxembourg site owners have never heard it exists.
The 746 million euro Amazon case
In July 2021 the CNPD fined Amazon 746 million euros, the largest GDPR fine ever issued at the time, for running targeted advertising on "legitimate interest" instead of consent. Amazon fought it for five years. In March 2026 Luxembourg's highest administrative court annulled the fine on procedural grounds, affirmed the underlying violations, and sent the case back to the CNPD.
Why did tiny Luxembourg end up policing one of the biggest companies on earth? Because of the GDPR's one-stop shop, which means the data authority in the country where a company has its EU headquarters leads all EU enforcement against it. Amazon's EU headquarters sits in Luxembourg City. So does PayPal's European entity, and a long row of other multinationals. A country of roughly 682,000 people supervises data processing for hundreds of millions of Europeans. That's the Luxembourg twist.
The case started in 2018, when the French digital-rights group La Quadrature du Net filed a collective complaint about Amazon's behavioral advertising. Under the one-stop shop it landed with the CNPD. On 15 July 2021, the CNPD fined Amazon Europe Core 746 million euros for processing personal data for ad targeting without valid consent, leaning on "legitimate interest" instead. Legitimate interest is the GDPR basis that lets you process data without asking, when your business need outweighs the person's rights. The CNPD said it didn't stretch that far. One odd detail: the decision text itself was never published, a point noted at the time by the law firm Hunton. Everything public traces to secondary reporting.
Amazon appealed in October 2021. It took until 18 March 2025 for the first-instance court, the Tribunal administratif, to rule. It upheld everything: the full 746 million, plus a penalty of 746,000 euros per day if Amazon didn't fix its practices. Which means every week of foot-dragging would have cost Amazon another 5.2 million euros. The effects were suspended while Amazon appealed again. Then the twist.
On 12 March 2026, the Cour administrative annulled the fine and handed the case back to the CNPD. Not because Amazon won on the facts. It didn't. The court leaned on two EU Court of Justice rulings from December 2023, Deutsche Wohnen and Nacionalinis, which established that a regulator must prove a company acted with intent or negligence before fining it, and must properly weigh softer measures first. The CNPD, the court found, had done neither. Put another way: the referee called the right foul but skipped the required steps, so the penalty was thrown out on procedure.
When I first read the annulment coverage, I assumed Amazon had walked away clean. It hadn't. Here's what didn't get thrown out. The court confirmed that Amazon's reliance on legitimate interest for its ad targeting "was not justified," and that its transparency toward users fell short of the GDPR at the time. The violations stand. The compliance order became moot only because Amazon had already changed its advertising practices before the January 2026 hearing.
Both sides declared victory, which tells you something. Amazon's statement: the court "overturned the CNPD's decision and recognized our position." The CNPD's own release says it "will continue to handle the case in a way to ensure the efficient application of the GDPR." No timeline. As of August 2026, no new decision has been announced. The case is live, and the CNPD gets a second swing.
One thing the Amazon case isn't: a Google Analytics case. The substance was ad-targeting consent, not data transfers to the US. I keep the two threads separate on purpose, because plenty of coverage mashes them together. What the Amazon case proves is simpler and more useful for you: the CNPD is willing to issue a company-breaking fine, and Luxembourg's courts will hold it to strict procedure when it does. If you're betting on this regulator staying quiet forever, you're taking the wrong lesson.
So is Google Analytics legal in Luxembourg right now?
Legal with consent, yes, for now. The CNPD's never issued a Google Analytics ruling the way Austria and France did in 2022. The noyb complaints that reached Luxembourg targeted Facebook's tools, and were closed in 2022 without a ruling on the merits. Since July 2023, the EU-US Data Privacy Framework gives GA's transfers a legal basis. That framework's being challenged at the EU's highest court.
Let me unpack that, because each piece changes what you should do.
The story starts with Schrems II, the July 2020 ruling where the EU Court of Justice struck down Privacy Shield, the deal that had legalized EU-to-US data transfers. The court's problem: US surveillance law gives American intelligence agencies access to data held by US companies, and Europeans don't get a real remedy. The CNPD welcomed the ruling, saying Privacy Shield "does not ensure a level of protection essentially equivalent to that guaranteed by the GDPR." It told Luxembourg companies to verify protections before transferring anything, and pointed them to EU-level guidance rather than writing its own.
One month later, the privacy group noyb filed 101 complaints across Europe against websites using Google Analytics and Facebook's business tools, arguing those tools transferred visitor data to the US with no valid legal basis. Three of the 101 landed in Luxembourg, and the targets are striking: the state savings bank (Banque et Caisse d'Epargne de l'Etat), the University of Luxembourg, and the media group Société Saint-Paul. Per noyb's own tracker, all three Luxembourg cases concerned Facebook's tools rather than Google Analytics. A state bank wired into a US ad platform was, for a while, a live GDPR complaint.
Here's where Luxembourg diverges from its neighbors. Austria's regulator ruled in January 2022 that using Google Analytics violated the GDPR. France's CNIL followed in February 2022 and ordered sites to stop using it. The CNPD did neither. It closed its three complaints on 15 April 2022 with what noyb's records list as an "other outcome": according to noyb, the websites had removed the tools by then, so the CNPD never ruled on whether the transfers had been lawful in the first place. No fine, no precedent, no answer.
I want to be precise here, because this gets misread in both directions. I couldn't find any CNPD decision, opinion, or statement naming Google Analytics, in either direction, and I looked. That's an absence of evidence, not a clearance. The CNPD hasn't said GA is illegal in Luxembourg. It also hasn't said it's fine. What binds you either way is the consent rule from the guidelines above, plus the GDPR's transfer rules that every EU regulator applies. Here's the uncomfortable part if you use GA: across the whole 101-complaints campaign, noyb notes, no European regulator ever ruled the GA transfers were legal. Every closed case ended in a finding of illegality or a procedural dismissal. Not one clean bill of health.
Then the ground shifted. In July 2023 the European Commission adopted the EU-US Data Privacy Framework, a new adequacy deal that restores a legal basis for transfers to certified US companies. Google's certified. Which means the specific violation Austria and France found in 2022 is, today, papered over. Google Analytics with a compliant consent banner is currently lawful in Luxembourg.
The paper's thin, though. French politician Philippe Latombe challenged the framework in court; the EU General Court dismissed his case on 3 September 2025, and he appealed to the Court of Justice on 31 October 2025. No hearing date yet. His argument: the US review court that's supposed to protect Europeans isn't independent, and US bulk surveillance is still too broad. This is the third framework of its kind. Safe Harbor was struck down in 2015, Privacy Shield in 2020. You'd be forgiven for noticing a pattern. The CNPD, for its part, hasn't published any position I could find on the framework or the appeal. Luxembourg's waiting like everyone else. If you run GA today, nothing in Luxembourg forces you to stop. Nothing protects you long-term either. I'd treat today's legality as a lease, not a deed.
What the CNPD enforces, and what it lets sit
The CNPD's record is genuinely mixed. It produced the biggest GDPR fine in history, and it's been sitting on noyb complaints for more than seven years. In 2025 it received 846 complaints, up from 516 in 2024, and issued 7 fines totaling 216,061 euros. Put another way: the typical fine here is closer to 30,000 euros than 746 million. The trend line points one way: busier, faster, less patient.
Start with the numbers from the CNPD's own 2025 annual report, covered by Paperjam. 846 complaints came in during 2025 against 516 the year before. That means complaints jumped by 330 in a single year, in a country you can drive across in an hour. The authority handled 1,909 complaint files in total and closed 737. Its sanctions committee issued 8 corrective-measure decisions, 7 of them with fines: five for inadequate processing registries, two for video surveillance, one for repeatedly ignoring people's data requests. It processed 425 data-breach notifications, slightly down from 442. And it's grown from 53 staff at the GDPR's start in 2018 to 79 in 2025. In plain English: the watchdog is half again bigger than when the GDPR began, and its inbox has never been fuller.
The individual fines are small next to Amazon's, but they're the ones that should worry you if you run a normal business. In January 2025, decision 1FR/2025 fined a credit institution 175,000 euros, reduced from an initial 493,560, for failing to answer 47 data-subject access requests on time. That means it argued the fine down by two thirds and still paid six figures. The bank blamed technical issues, pandemic disruption, and human error. The CNPD rejected all three excuses. In practice: the clock on a data request doesn't stop because your ticketing system is a mess.
Then there's the other side of the ledger, and I won't sugarcoat it. noyb tracks 12 complaints it has filed against companies under the CNPD's watch, and the tracker reads like a waiting room. A data-subject-rights complaint against Amazon filed in January 2019 is still pending, more than seven years later. A cookie-banner complaint against the media company EDITA, filed August 2021, is still pending after four-plus years. Two cookie-banner cases, against Luxauto.lu and Esso Luxembourg, were partly won. Complaints against Manpower, POST Luxembourg, and Amazon's own cookie banner were lost.
The sharpest episode involves two US data brokers, Apollo and RocketReach. noyb complained in January 2021; the CNPD refused to investigate, claiming it couldn't enforce against non-EU companies with no local representative. The courts disagreed, twice. In November 2023 the Cour administrative ruled the complaint admissible, and in September 2024 a tribunal found the CNPD had wrongfully refused to handle it and sent it back. Still no substantive decision, per noyb's reporting. The pattern I see across the CNPD's docket is patience, then a hammer. So the honest picture is this: a regulator that can end careers when it moves, courts that increasingly force it to move, and a complaint volume that jumped by 330 in a year. Slow isn't the same as safe, and a regulator's backlog is a bet you don't control.
Even with consent, your analytics are missing a big slice of traffic
Suppose you do everything right: compliant banner, equal buttons, consent before any cookie loads. You're now legal, and blind. Every visitor who clicks "Refuse" vanishes from your numbers, and the CNPD's equal-prominence rules make refusing genuinely easy. In a market of roughly 674,000 internet users, that missing slice hurts more than it would in a big country.
Luxembourg is one of the most connected countries on earth. DataReportal's Digital 2026 report puts internet penetration at about 98.8% of the population, roughly 674,000 people. In plain English: practically everyone you could reach is already online. That sounds great until you remember the population's about 682,000 total. Niche traffic segments in Luxembourg are small in absolute numbers. Lose half your sample to refused consent and your conversion data stops being statistics and starts being anecdotes.
The banner isn't the only leak. Per StatCounter's July 2026 figures, Safari holds 22.25% of Luxembourg's browser market, Firefox 13.58%, and Brave 1.99%. That means roughly 38% of Luxembourg browsing happens in browsers that block or restrict third-party tracking out of the box, before anyone even sees your banner. Ad blockers cut further still, and they don't ask first. Cookie-based analytics in Luxembourg isn't measuring your audience. It's measuring the subset that uses a permissive browser and clicks yes.
There's a different way to do this, and it's the same door the CNPD's own exemption points at: measurement that never touches personal data in the first place. That's what I built Clickport to be. No cookies, nothing stored on the visitor's device, data processed in the EU, bots filtered out at ingestion, and no consent banner needed for the analytics itself. Every visitor counted, including the 38% with hostile browsers and everyone who'd have clicked refuse. I look at analytics dashboards all day, so I know what losing half a sample does to the confidence you can put in your numbers. I think that trade's worth it for most content and commerce sites. You give up ad-platform integration and get your data back.
What's coming next
I'm watching three open threads for Luxembourg site owners: the Amazon remand at the CNPD, the Data Privacy Framework appeal at the EU Court of Justice, and the EU's Digital Omnibus proposal, which would extend consent-free analytics measurement across all 27 member states. Any one of them could move your compliance goalposts.
The Amazon case, round two. The CNPD has the file back and says it will keep handling it "to ensure the efficient application of the GDPR." No timeline. Whatever it decides, it now has to clear the procedural bar the court set: prove intent or negligence, and weigh softer measures. Watch this one, because it'll define how aggressive the CNPD dares to be with businesses your size.
The DPF appeal. Latombe's challenge is pending at the EU Court of Justice, with no hearing date as of August 2026. If the framework falls the way Safe Harbor and Privacy Shield fell, Google Analytics loses its legal basis for US transfers overnight, and the 2022 Austria and France rulings become the template again. Your cookie banner won't save you from that one. It's a transfer problem, not a consent problem.
The Digital Omnibus. Proposed by the European Commission in November 2025, it would write a consent exemption for privacy-respecting audience measurement into EU law directly, EU-wide. In plain English: the deal France pioneered and Luxembourg gestures at would become the rule everywhere. It's still a proposal, and proposals change. But the direction of travel is clear, and it favors analytics tools that were built cookieless from day one over tools retrofitting privacy onto an advertising engine.
What this means for your website
Here's my practical read if your site serves Luxembourg visitors, whether you're a Kirchberg fund, a Grund café, or anything between.
If you're using Google Analytics with a cookie banner: you're inside the law today, provided the banner meets the CNPD's standard: refuse as easy as accept, no cookies before consent, no cookie wall, re-ask within about 12 months. But you're paying for it in data. Refusers and privacy browsers aren't visible to you, and the legal basis under your US transfers is one CJEU ruling away from disappearing. You're compliant and exposed at the same time.
If your banner cuts corners: unequal buttons, pre-loaded trackers, a wall in front of your content, that's exactly what the CNPD's guidelines call out, and its complaint volume grew by 330 in one year. Enforcement's been slow here, which means the record shows years of patience, then a decision like 1FR/2025 landing at 175,000 euros. I wouldn't bet a business on the regulator staying slow. The courts are already pushing it to move faster.
If you want every visitor counted with no banner at all: use a tool that fits the exemption's shape: first-party, no third-party transmission, no cross-site tracking, anonymous statistics. That's how Clickport works by design, and it's the model both the CNPD's exemption and the Digital Omnibus point toward. The analytics stop being a legal question and go back to being a product question.
A closing note, because this is a legal topic: I'm not a lawyer and this isn't legal advice. It's a founder's map of the terrain, with every ruling linked to the regulator's own release wherever one exists. If your setup is complicated, show this to your DPO or lawyer, and if something here doesn't match what you're seeing on the ground in Luxembourg, email me.
If you want to try the banner-free route, you can try Clickport free for 30 days, no credit card needed. And switching from Google Analytics takes one snippet: swap the tag, keep your history, and you'll see your full traffic by tomorrow.

Comments
Loading comments...
Leave a comment