
We now have a new agreement between the U.S. and Europe for the transfer of personal data.
Again.
That makes three.
We'll see how long it lasts.
I'll explain the reasons for the uncertainty in a moment, but first I'll try to make the issue a little clearer because it has deep roots, so let's start at the beginning:
The first and most important thing to be clear about is that Google Analytics has never been illegal in Spain.
It was illegal in France for a few months in 2022.
The same happened in Austria.
And in Italy or Denmark.
That was the trend in several European countries in 2022, but it was never made illegal in Spain. Although last year there were rumours that it would be.
But since last week (10 July 2023), with the signing of the new treaty, as I said, we can relax.
At least for a while, because if you've followed the subject with even a little attention, you'll know this goes back a long way.
Specifically, since September 11, 2001.
The day the world changed.
Roots of the problem
It's already been 22 years since that day, which is saying something.
Back then Google Analytics didn't even exist, although Urchin, the technology Google bought in 2005, did, and it became the seed of the first version of Google's digital analytics tool.
That fateful day, all of us, but especially the U.S., realised that the apparent security we live with in the developed Western world was little more than an illusion.
And the systems that were thought necessary were put in place so that an event like that would not happen again.
Perhaps because of its more liberal character, perhaps because of its more military character, or perhaps because it was the first time something with such an impact had happened on its territory, the United States deployed a brutal global surveillance network.
One that collected huge amounts of communications data between civilians anywhere in the world on the internet, with the main U.S. tech companies—the GAFA (Google, Amazon, Facebook and Apple)—involved to a greater or lesser extent.
This network operated outside any law for 12 years, from 2001 to 2013. Then a certain Edward Snowden — an employee of the then fairly unknown NSA and also of the CIA — exposed the scandal: the NSA had developed an infrastructure that made it possible to collect practically any data about anyone in the world, including:
- Your emails.
- Your phone number. Or your wife's. Or your friends'.
- Your passwords.
- Your bank card usage.
- Your call records.
All in pursuit of and under that very ambiguous umbrella of National Security.
If you're interested in the subject, it's explained very well in the documentary Citizenfour , which contains Edward Snowden's statements. I highly recommend it, although if you're more into films, Oliver Stone directed the entertaining Snowden , telling the same story from a more commercial point of view.
Reactions to the scandal
Well, when the whole thing came to light, there were timid reactions in Europe. So timid they seemed staged. In other words, it couldn't be said publicly, but privately it seemed our politicians agreed with what the U.S. government had done.
But there was one small detail still missing. At that point it was not yet known that world political leaders were also being spied on.
The final straw was the monitoring of the mobile communications of the German chancellor and de facto European leader Angela Merkel, who had a heated public clash with Barack Obama, the U.S. president at the time.
That changed things.
Because, my friend, spying on the masses is one thing and spying on officials is quite another…
Administrative agreements: from Safe Harbor to Privacy Shield

So, very annoyed at being spied on, European leaders declared invalid the laws governing Safe Harbor, the communications protocol between U.S. companies and European customers and citizens that had been in force since 2001.
15 years and one PRISM program later, privacy had to be regulated differently. So a new agreement was created in 2016, the Privacy Shield, whose biggest impact was that it prevented U.S. companies from storing European citizens' personal data on servers located in America.
In other words:
- It specifically defined what personal data consisted of: beyond names and email accounts, it also included things such as the IP used to connect to the Internet.
- If a U.S. company had been storing any of this data on its servers, it had two options: Stop storing it and delete it.
- Keep storing it, justify why, and do so on servers outside the U.S., so that it was not accessible (or not easily accessible) to the NSA and similar agencies.
And everyone was happy.
Except Max Schrems, an Austrian privacy activist and lawyer who managed to get the European Court of Justice to overturn this agreement in 2020.
This has meant that for the past three years, personal-data transfers between Europe and the U.S. have not been governed by any looser joint agreement, but by the strict GDPR (EU General Data Protection Regulation).
And this is the context for France making Google Analytics illegal, since the tool collects French citizens' IPs on servers located on U.S. territory.
Why don't the other European countries declare it illegal? In principle, because the IP record is encrypted, so they do not consider it personal data as such.
A matter of nuance.
New treaty in 2023. For how long?

Well, as you've probably heard, since last week we have a new privacy framework agreement between Europe and the United States.
And that makes using Google Analytics legal.
Perhaps the arrival of GA4 had something to do with it.
Perhaps it's a coincidence.
What doesn't seem like a coincidence is that Google has opened access to its Bard AI in Europe three days after the agreement was approved. Especially considering that the reason given for not offering it here from the start was precisely that it did not comply with Europe's strict data-regulation policy.
So what happens now? First, Max Schrems will appeal to the CJEU again on the grounds that U.S. rules on mass surveillance remain in force, no matter how much the new agreement limits its use to “proportionate””.
It's an ambiguous word that does not make clear which private data belonging to European citizens the U.S. administration can access.
Therefore, it is possible that in the coming months we'll get more news on the matter, one way or another. And that's when we'll really know whether we can continue using GA4 legally or not.
Until then, time to implement.
Or to switch.
Or to pray. After all, this whole mess started for religious reasons.
You couldn't make it up.


Leave a Reply