Is Google Analytics Legal in Sweden? IMY's View
By CodexierPublished 6 min read
In 2023 the Swedish privacy authority IMY ruled that four Swedish companies had transferred personal data to the United States unlawfully by using Google Analytics, and fined two of them. Weeks later the EU adopted a new adequacy decision for the United States, and the legal ground shifted again. Business owners are left with a reasonable question: can we use Google Analytics or not? This guide gives the honest answer, which is that it depends on how you use it and how much risk you accept.
The short answer
We configure both in our tracking and analytics work. This is not legal advice; it is what we tell clients before they choose.
What IMY decided and why
The decisions followed complaints filed across Europe after the EU Court of Justice's Schrems II judgment in 2020, which invalidated the previous EU-US transfer arrangement. IMY examined four companies using Google Analytics and found that the data sent to Google in the US, including identifiers that could be combined with other data to single out a person, was personal data, and that the standard contractual clauses and the technical measures the companies had added did not sufficiently protect it against US surveillance law. Two companies received administrative fines; all were ordered to stop using the tool as configured. The core finding was about the transfer, not about analytics as such.
| Question IMY asked | Finding |
|---|---|
| Is a Google Analytics client ID personal data? | Yes, because it can be combined with IP address and other data to identify a visitor |
| Did standard contractual clauses suffice? | No, without effective supplementary measures |
| Did IP anonymisation and similar settings help? | Not enough; the data was still identifiable at Google before truncation |
| Was consent a way out? | Not as applied; the companies had not relied on explicit consent to the transfer |
The EU-US data framework
In July 2023 the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework. Companies in the US that certify under it are treated as offering adequate protection, and transfers to them do not need the standard contractual clauses and supplementary measures that IMY found lacking. Google LLC is certified. In practical terms, the specific reason IMY gave for the decisions no longer applies to a transfer covered by the framework. The caveat every careful adviser adds: the previous two arrangements were struck down by the court, the current one has been challenged, and a business that builds its measurement entirely on it should know that the ground could move again.
Consent and configuration
The transfer question was never the only one. Google Analytics sets cookies, which under the Swedish Electronic Communications Act require prior consent, and it processes personal data, which under GDPR requires a legal basis, a processor agreement and transparency. A GA4 setup that would satisfy a careful review looks like this:
- Consent banner with reject as easy as accept, and consent mode configured so that no GA4 request is sent before consent.
- Google's data processing terms accepted in the property's admin, and Google listed as a processor in your privacy policy with the US transfer explained.
- Google Signals off unless you have a specific need, so that data is not linked to signed-in Google accounts for advertising.
- Data retention set only as long as you need, user-level data deletion requests handled, and no personal data such as email addresses sent in URLs or events.
- Ideally server-side tagging in an EU region, so that IP addresses and identifiers can be trimmed before anything reaches Google.
Our GA4 setup guide walks through the configuration side of that list step by step.
Alternatives with EU hosting
The simplest way to avoid the whole discussion is to measure without transferring personal data to the US and, ideally, without cookies. Tools such as Plausible, Matomo, Fathom and Umami can be hosted in the EU or on your own server, count visits without a cookie, and produce reports that cover what most small companies actually look at: visits, pages, sources, countries and a handful of goals. What you give up is Google's audience demographics, the deep integration with Google Ads, and the free price. We compare them in our guide to cookie-free analytics alternatives.
A risk-based decision
Low risk: keep GA4
You run Google Ads, need campaign attribution, have a proper consent banner and can configure consent mode and minimal data. Accept that the transfer basis may be challenged again and keep an exit plan.
Low effort: switch to EU-hosted
You run little or no paid advertising, want visit statistics without a banner, and value not having to follow the next court case. Switch, and keep GA4 only if a specific integration needs it.
Sensitive sectors: switch
Healthcare, legal, financial or public-sector sites, where a visit itself can reveal something about a person. Do not transfer that to the US at all; use an EU-hosted tool without cookies.
Both, briefly
Run an EU tool in parallel for a quarter to see what you would lose, then decide with data rather than opinion.
When you do not need help with this: a site that already has a compliant banner and no advertising can switch to a cookie-free tool in an afternoon with the tool's own guide. When you do: if you spend on Google Ads and need attribution that satisfies both your marketing and your privacy review, the configuration is fiddly and worth doing once, properly. Book a call with your current setup and we will tell you which of the four cases you are in; the fixed price for a full tracking setup is on the pricing page.
Frequently asked questions
Did IMY ban Google Analytics?
No. It found that specific companies' transfers to the US were unlawful under the rules and measures in place at the time, and ordered them to stop using the tool as configured. It did not rule that analytics tools are unlawful, and the legal basis for US transfers has changed since.
If Google is certified under the Data Privacy Framework, is GA4 automatically fine?
The transfer has a legal basis while the framework stands, but you still need cookie consent before the tool loads, a processor agreement, transparency in your privacy policy, and a configuration that does not send more personal data than needed. Most non-compliant GA4 installations fail on consent, not on transfers.
Does anonymising IP addresses make GA4 compliant?
GA4 does not store full IP addresses, but IMY found that truncation alone did not solve the transfer problem, and it does nothing for the cookie consent requirement. It is a good setting to have, not a solution.
What is the safest choice for a small Swedish company?
An EU-hosted, cookie-free analytics tool, unless you depend on Google Ads attribution. It removes the banner for analytics purposes, avoids the transfer question and covers the reports most small companies use. If you need GA4 for advertising, configure it properly and accept the residual risk knowingly.
Want to know whether your analytics setup would survive a review?
Tell us what you run today and whether you advertise. In fifteen minutes we tell you whether to keep GA4, fix its configuration or switch to an EU-hosted tool, and what each option costs.
Book a free 15-minute call