One of the most popular analytics services, Google Analytics has come under fire in recent months. The service is a statistics and analytical tool that helps businesses improve their search engine optimisation (SEO) and marketing. It’s available for free or paid to anyone with a Google account.

Various data protection authorities around Europe have declared the service unlawful for several reasons. But what does this mean for customers and web users in South Africa and different parts of the world? Can we align our data protection laws with global best practices? What are the best practices? We’ve provided some insights below.

What is Google Analytics?

Google Analytics gives you various statistics and analytics tools for several purposes. You can gain insight into user traffic, marketing campaigns, analytic patterns, and user behaviour.

Cookies

The service uses cookies to work, specifically Google Analytics cookies. Based on guidance from various authorities, it’s a common understanding that cookies are personal information. This means that if you use them on your website, mobile application or otherwise, you must comply with the data protection law that applies to you. Read more about cookie law in South Africa.

Google Analytics server location

Where does the information go when you use the service? Because of potential cross-border information transfers, it’s important to know the servers are. This means there are two key questions to answer.

  1. Where does the information flow to?
  2. If the information crosses state borders, what does the law require to transfer lawfully?

For example, if you use the service on a website or mobile application operated and located within South Africa, information will flow from South Africa to the location of the server. We know that the Google Analytics servers are located in the United States. This means a transfer of information (including personal information) from South Africa to the United States. Making it your responsibility to comply with the requirements for transfer outside of the country.

Transferring personal information out of South Africa

POPIA recognises the need to transfer personal information outside of South Africa. It provides various mechanisms for transfer into another country. POPIA also requires that the recipient of the personal information is subject to laws that provide an adequate level of protection and uphold the principles of reasonable processing. Adequate protection means that the personal information has the same level of protection in the recipient state, as it has in South Africa.

Transferring personal information into the United States

So, because the servers are located in the United States, what does it mean for you?

In the Schrems II case, the Court of Justice of the European Union (CJEU) held that when exporting personal information, the same level of protection must go with it to its destination. This means that when transferring data outside the EU, you must ensure that its destination will afford the same level of protection as under the GDPR. POPIA has essentially the same requirements.

The CJEU deemed the United States inadequate due to the government’s wide powers of surveillance. This means parties in the United States cannot guarantee the same level of protection. This obviously creates a significant hurdle for effective global business. However, President Biden’s recent executive order is aimed at a reboot of EU-US information transfers that is expected to make life easier for businesses.

The order requires that safeguards are put in place to ensure that personal information collected by US signals intelligence are necessary and proportional to achieve national security objectives. It also creates a mechanism for people to seek redress if they believe their information has been unlawfully processed due to US signals intelligence.

The European Data Protection Board (EDPB) also drafted guidelines on supplementary measures a responsible party should consider when transferring information to another country.

Supplementary measures can be contractual, organisational or technical. Often, the transfer tools may fall short of the level of protection because you cannot bind public authorities by contract. So, technical measures should be used to compliment supplementary contractual or organisational measures. Consider the following when you decide which supplementary measure is most effective:

  1. The format of the data being transferred.
  2. The nature of the data transferred.
  3. The complexity of the transfer.
  4. The possibility of onward transfers to the same third country or others.

What the European authorities have to say

Echoing the same requirement, the EU also uses the term ‘adequacy’ to describe other countries, territories, or international organisations that it deems to provide an ‘essentially equivalent level of data protection to that which exists within the EU. An adequacy decision can be a formal decision made by the EU.

The French Data Protection Authority, CNIL, along with the Austrian Data Protection Authority, has found website owners’ use of Google Analytics to breach the GDPR. Recently too, Italy’s data protection authority (the ‘Garante’) banned the use of Google Analytics because it was found to be unlawful. The authority found that websites using Google Analytics collected (via cookies) personal information including user interactions with the website, pages visited, browser information, operating system, screen resolution, selected language, date and time of page views, and user device IP address. This information is transferred to the United States, which cannot provide adequate protection, hence the service was found to be unlawful.

What does it mean for you in South Africa?

The South African Information Regulator hasn’t provided much guidance on this, but we suspect they will consider decisions made by other authorities around the world. POPIA has relatively clear requirements for transfer into another country as we’ve mentioned earlier in this article.

It is yet to be seen whether the Information Regulator will follow the steps taken by the various European authorities, and declare the use of Google Analytics unlawful. We do see this as a potential risk, primarily for the reasons outlined above.

What does it mean for the rest of the world?

This is a tricky question, because not all data protection laws are the same. A one size fits all approach is not always possible to take.

Data protection laws and regulations are not specific about the use of Google Analytics. Because data protection law is mainly principle-based, many countries share similar principles for compliance. While not the same, it does let us take learnings from other jurisdictions around the world.

International data protection authorities highlight transparency and informed consent with your data subjects. You must also ensure that destination countries, territories or organisations have adequate protection and safeguards in place.

Key takeaways

Here is a breakdown of the most common findings we’ve found:

  • You should map your activities to create a record of what information you have, why you’re processing it and where it flows to.
  • You must be transparent with your data subjects about your processing activities, including your use of Google Analytics.
  • You must give data subjects the tools to give proper consent and equally to withdraw it.
  • Make sure destination countries, territories and organisations have adequate protection and safeguards in place if you transfer personal information into another country.

Actions you can take

  • Let us assess the risk of your use of cookies and Google Analytics.
  • Let us help you lawfully use Google Analytics with services and software by getting our advice or getting a demo on a data governance software.
  • Ask us to draft bespoke wording for your cookie notice and policy.
  • Choose the software that works best for you, and let us help you implement it.
  • Keep up to date with data protection decisions and our insights, join the Michalsons data protection programme. You can also book a free programme tour with our programme manager.