10 ms·
Using Google Analytics without GDPR consent
- ddevault 6y agoTracking users is unethical. The law is there not so that you can wiggle your way around it, but to make a statement about this behavior. Laws are not scripts and they are not interpreted by computers. You are going to get fined for doing this, and it'll be well deserved. Do not spy on people. It's that simple. Don't use google analytics. Don't use any of the dozens of alternatives which are selling you "pro-privacy" analytics, which is a contradiction of terms. Just don't spy on people.
- SquareWheel 6y agoCalling it spying is hyperbole, and thrusting your personal ethics on others is nonproductive. If analytics turn you off, there are plenty of browser extensions which will block them on your behalf. uBlock Origin is the most common example. https://github.com/gorhill/uBlock https://github.com/gorhill/uBlock
- ddevault 6y agoDoes installing uBlock qualify as informed consent?
- toomanybeersies 6y agoUser tracking and analytics, like most technologies, is ethically neutral. It's how people utilise it that has an ethical/moral component.
- Nextgrid 6y agoEven if your use of the collected data is ethical, exposing your users to a third-party's unethical use of the collected data is itself unethical IMO. Using Google Analytics and similar services from companies whose entire business is built on stalking people is unethical and should be avoided.
- jwalton 6y ago> `/ip=([\d.]*)\n/` 1. This is going to break if your clients are using IPv6. 2. IP addresses are generally considered PII under GDPR[0], but IANAL and I don't know what that means as far as compliance. [0](https://www.groundlabs.com/blog/what-is-pii-for-gdpr/ https://www.groundlabs.com/blog/what-is-pii-for-gdpr/)
- dannyw 6y agoIf you hash your IP with a bunch of other fairly unpredictable and high cardinality information; it's no longer PII.
- dvdkhlng 6y agoThey are are using a 53-bit hash cyrb53 [1] of the string "IP address + website domain + user agent + language + validity days". It looks feasible that many of the generated IDs could be retroactively brute-force mapped back to an IPv4 address with high confidence (small chance of error due to hash collisions). [1] https://stackoverflow.com/questions/7616461/generate-a-hash-from-string-in-javascript/52171480#52171480 https://stackoverflow.com/questions/7616461/generate-a-hash-...
- grabeh 6y agoI wouldn't trust any article that purports to be about GDPR that uses the term 'PII' a term which itself isn't anywhere to be seen in the regulation! In reality an IP address is generally not PII, but it may be personal data - the case is Breyer which was decided on pre-GDPR law but still relevant. If you could use reasonable means to identify someone from the IP address then it will be personal data. I don't really agree with the outcome of the case because it implied it was easy to contact an ISP to get them to disclose details of the subscriber information associated with the IP address. In the UK at least it would require cause, and a court order.
- ilovefood 6y agoSo sending a request to cloudflare to get your users IP makes this GDPR compliant? This is not how any of this works. Be careful when using this script. In any case, the cloudflare dependency needs to be listed in your Data Protection page.
- evrimfeyyaz 6y agoThis is a fair point. I wish there was a way to get a visitor's IP without the need to call a server. That being said, my website is already served through Cloudflare, and this is an endpoint Cloudflare provides for debugging purposes. I think this is ethically safe, but legally it probably is not. I definitely agree.
- d0gbread 6y agoAnother frustrating "web analytics is evil" post, this time trying to not store PII in a service that disallows PII as part of their terms of service.
- weRnotU 6y agoWorse than that. It’s a “despite my awareness, I’m still ignorant and believe customer data is mine to do with as I see fit.” Everyone is a potential Zuckerberg or Bezos.
- tikkabhuna 6y agoDid you consider self-hosting Plausible? https://docs.plausible.io/self-hosting/ https://docs.plausible.io/self-hosting/
- ThePhysicist 6y agoGoogle recently introduced "Consent Mode" which basically disables cookie-based tracking and collects anonymous data only. I still find it problematic as Google probably doesn't need a cookie to identify you but it's at least something that is officially backed by Google, instead of a hack like this. BTW if you use client information to derive an identifier that is unique within a session and you send that identifier to a third-party (e.g. Google) this approach gives you zero benefits. In fact ePrivacy & GDPR don't mention cookies anywhere and don't care what technology you use to derive identifiers, if they can robustly identify an individual or device and you actually send them to another service (for purposes that are not strictly necessary for the performance of your service) you're obliged to asked for consent.
- grabeh 6y agoWe do see a few references to cookies in the ePrivacy Directive but absolutely right to drive home the point that it's technology agnostic!
- gchambert 6y agoWhat is forbidden by GDPR isn't specifically cookie or IP, but but any tracking mechanism which allows to identify an individual uniquely with some amount of certainty, and without prior consent. What he is doing is illegal.
- zepolen 6y agoDoesn't that make access log files illegal?
- simpss 6y agolog files have a different original purpose. But yes, if you repurpose your log files to track individual users granularly, that processing would be illegal without gathering informed consent first.
- Dayshine 6y agoThe key caveat here is: Unless it's necessary. The legitimate interests basis of the GDPR allows you to make a balanced decision of your business requirements against user privacy expectations.
- eclat 6y agoThat’s not a justification to process personal data for marketing or analytics purposes. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/legitimate-interests/what-is-the-legitimate-interests-basis/ https://ico.org.uk/for-organisations/guide-to-data-protectio...
- simpss 6y agoyes, and you have to line out how the processing is necessary for providing the service, there has to be no less-intrusive method of achieving the desired result and be ready to prove it. hint, user-level analytics rarely is. And in this specific example, repurposing logs kept for one purpose(ex, security/auditing) to user analytics is definitely not something you can just do
- grabeh 6y agoLove the contrast between the title and the text. This isn't even about GDPR, it's about a completely different piece of legislation, the E-Privacy Directive. This is completely agnostic on personal data and so the post is largely flawed. Even if you're not dealing with any personal data, if you're placing a cookie (or doing anything analogous device fingerprinting etc) you are in scope of the Directive and need consent, irrespective of GDPR. The new E-Privacy Regulation is looking to implement an exception to consent for analytics but that would have providers like Google Analytics out of scope. Anyway, it's stuck in the mud at present...
- eclat 6y agoGDPR doesn’t apply to personal sites like blogs either.
- krsdcbl 6y agoNot a lawyer myself, but as far as my understanding goes you are identifying your user already by determining his ip, and all the transformations you do to create an id is still reversible with the fixed seeds in your script - so you'll end up sending data to google that makes the user idenfiable nonetheless, so i HIGHLY doubt this is a legitimate way around gpdr. correct me if I'm making wrong assumptions here, as staid - not a lawyer either, just having lots to do with the topic as a EU based webdeveloper.
- brtkdotse 6y agoThis is my understanding as well - no matter how obfuscated the final identifier is, if you derived it from PII then it’s considered PII as well. However, IANAL.
- slake 6y agoIf the final identifier can't be reverse engineered to identify the specific individual is it PII? So A user visited me on the 12th. That user visited me again on the 15th. Is that PII?
- ablu 6y agoAdditionally you are now doing an additional request to Cloudflare, which probably requires you to link to their privacy policy for that service?
- Puts 6y agoThis is probably little of a grey area. I don't think that the IP-address by itself is considered personal data since it usually doesn't single out a specific living person. Unless you pair it with other information, like date and time. But if IP was considered personal data you would need an active consent from the user where you also inform them why you are doing this, which paragraph in GDPR gives you legal right to do this, how long the data is stored and you will need a data processing agreement with Cloudflare. You will also need to be able to prove that you made sufficient effort to make sure you are not handling data of someone under 16 years of age. People often think that GDPR is made to forbid processing of personal data. Actually you can pretty much do anything with peoples information and still be GDPR compliant. It's more that it becomes such a hassle to do it and still be compliant that it's just not worth it to collect personal data "just because you can".
- dustinmoris 6y agoHonestly, if you’re just a small personal website or blog then just don’t bother with those idiotic cookie consent banners. Use Google Analytics or whatever makes you happy and nobody will ever say anything to you unless you’re an extremely famous person and even then the chances of someone ever bothering you regarding a GA cookie is very unlikely. Especially if you’re a tech blog your readers know how cookies work and how to protect themselves from “tracking” so you’re not even doing anyone a favour. It’s pure annoyance with zero benefit. Obviously if you’re a big corp you’ll have to comply, but I’d even question then what the EU is really going to do. Just write a page of how you use data and be honest, transparent and ethical about it and spare yourself to bastardise your beautiful website with EU shenanigans. And I’m from the EU and even dislike it.
- jraph 6y agoHonestly, please respect the laws (unless you are doing civil disobedience, I won't judge you) and people even if they are techies. You don't want to show me a banner because it's painful? Right, I agree. Just don't opt me in into this crap and then you don't need to show me the banner. You can use your server logs to measure your audience.
- yostrovs 6y agoYou want the warning banners simply because it's a law or do they actually help you with something? Out of curiosity, do you ever break driving laws such as speed limits?
- oarsinsync 6y agoThe position was “don’t break laws that provide my right to privacy” The response is “what about all these laws you break yourself?” I don’t think that’s particularly valuable.
- yostrovs 6y agoI think it is helpful to point out that some laws are poorly written, are pointless, too aggressive, or impossible to comply with properly. When someone realizes that there are laws they themselves break, hopefully they tone down their conviction that they're law abiding and others are not. This then helps to process the actual problems with individual laws.
- Tepix 6y agoThis article is quite fishy, by including the Google Analytics snippet you are always exposing your visitor's IP to Google.
- XCSme 6y agoNot only that, but you empower Google with data about your site (eg. visitor numbers).
- asp_net 6y agoFor anyone looking for a GDPR-compliant solution without Google, take a look at Plausible. Not at all as mighty as GA, but it delivers the most important data IMHO. https://plausible.io/ https://plausible.io/
- tlarkworthy 6y agoThis is great info on how to substitute IP address or turn off user tracking. I do think the replacement is dubious ( especially forwarding to CF) and not GDPR compliment so I would use something else like user agent, timezone, languages to form a hash. It's doesn't need to be precise and in some ways it's good if it's a bit rough. I only want general trends on a website.
- krsdcbl 6y agoin fact it can't and shouldn't be precise, as this would still make the iser clearly identifiable. You have to discern between GDPR (which governs tracking purposes as well) and E-Privacy laws (which concern PII) here
- rzwitserloot 6y agoQuick question on cookies in general: Let's say I write a site that doesn't set any cookies when you load it, but, it does have a login form on a few pages. If you fill in the form and click submit, a cookie is set by that site (not by some auth server, SSO system, adserver, etc) which keeps you logged in for future visits. It contains a unique token. You know, the usual way to do basic web form -> server checks via bcrypt or some other password hashing scheme -> generates a long unique token and saves it in a DB -> sends it to the client via a cookie -> that cookie is looked up in the DB for a period of time which will then authenticate the incoming request. This does not require a cookie banner whatsoever. Right?
- Dayshine 6y agoNo, in the majority of cases, cookies required for the website to function do not require prior consent nor notification. You should still have a notice somewhere that explains this though.
- simpss 6y agoexactly, this does not require a cookie notice. See here for explanations: https://europa.eu/youreurope/business/dealing-with-customers/data-protection/online-privacy/index_en.htm https://europa.eu/youreurope/business/dealing-with-customers... Consent is mainly required for cookies that are not technical requirements for providing the service.
- lucb1e 6y agoCorrect. You only need a banner for invasive tracking. Normal visitor counting, login handling, preference setting, etc. is all allowed by default. Only when you don't have a valid reason to process the user's data, then you need to ask them for consent, and that's the only time you need a cookie wall. Everything else is opt-out. Would be a crazy world if I ask the pizza store to deliver my pizza but I need to consent to them using my address to deliver it. It's obviously essential. Many people see it as such, though, and they resort to including weird clauses like "by hitting submit I consent to the processing of the data in the contact form for the purpose of fulfilling my request". That is like the definition of one of the legal bases you can use (aside from consent) and definitely does not require consent. The law is quite readable and not overly elaborate, see Article 6(1) of the GDPR: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679#d1e1888-1-1 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... Example, 6(1)(a) says: "in order to take steps at the request of the data subject", so you don't need to have any GDPR checkboxes or banners when you have a contact form.
- BasDirks 6y agoRemember the time when every serious homepage had a visitor counter? I don't recall any issues with privacy laws in those days. I think "tracking" back then was decentralized?
- t0astbread 6y agoI don't know how these things worked but I guess either - the laws and public awareness just weren't there yet and it would be illegal without consent now or - it was something simple without cookies, like an image that automatically incremented a counter when requested
- XCSme 6y agoI keep saying this: centralization is the core issue of privacy. If every website would keep their own visitors data to themselves, no one would care and businesses would thrive. This is why I think the future is self-hosted, where every site is a complete platform that locally contains all the services it needs (eg. analytics, chat, etc.).
- detaro 6y agoMany of those also were incredibly simple, just counting requests, or at max setting a non-unique cookie to indicate "counted already", which has little privacy implications. And of course yes, privacy legislation and people's awareness of these things has evolved over time.
- CaptArmchair 6y agoThe GDPR is quite strict in that states in no uncertain terms when one needs to ask for consent. The notion "personal data" and "anonymized data" are quite clearly defined. [1][2] > Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible. [1] https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-personal-data_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... [2] https://gdpr.eu/eu-gdpr-personal-data/ https://gdpr.eu/eu-gdpr-personal-data/ Especially that last part is important. If the output of the algorithm can be reversed in a way that it can be tied to a person, you're violating the GDPR. The responsibility of choosing a good algorithm is very much yours. And so, that algorithm is a liability on your part. Implementing a proper consent banner and adding a page with the correct GDPR information poses less of a liability when it comes to becoming GDPR compliant. There's plenty of information out there on how to do that properly. The EC even has a handy checklist just to get started: [3] [3] https://gdpr.eu/checklist/ https://gdpr.eu/checklist/ The notion "personal data" should also be interpreted in the broadest terms possible. Barring a few exceptions, the definition of "personal data" is really a limited set of principles that you are required to apply to a dataset rather then "these types and groups of data are protected, these aren't". The GDPR acts akin to a "right of way" principle which you are required to apply regardless of the context. The nuclear way of becoming GDPR compliant without consent banners or GDPR notice pages is to not collect anything at all. Or even closer to home: not share anything with third party services. I've done that exercise for myself, and that's something to take extremely literal when you start to think hard about it. No Google Fonts. No analytics whatsoever. No using CDN's. No hotlinking. No embeds - No YouTube, Instagram, Google Maps, Vimeo,... - No collecting e-mail addresses for newsletters. No Avatars - no Gravatar - No comments - Not locally, not via Disquss. No keeping server side logs with IP addresses or any identifiable names. It's not mentioned all too often, but the GDPR isn't about restricting what you can and can't do. It tries to enforce website owners to make conscious choices over the technologies and the platforms they use and the content strategy they would like to apply. Looking at the author's site. Google Fonts is used, CloudFlare sets a cookie and the bottom of the page has a "subscribe to my newsletter" with a third party service. All of which are GDPR concerns.
- 6y ago
- rendall 6y agoPeripherally related question. Is it GDPR compliant to hash a user's IP address to just a wide region and store only that? e.g. "Finland", "California", "Chennai". Just to get an idea of from where visitors come? I'd like to add only usage tracking to my sites to see how they are used, but I have zero interest in selling or using user data for any other purpose. I could add a pop-up banner, but that's for consent on using personally identifiable information (and I associate it with sleaze, to be honest).
- xxs 6y ago>Is it GDPR compliant to hash a user's IP address It is not, hashing would be pretty much a bijection, anyways. Storing state would be fine, though.
- rendall 6y ago> hashing would be pretty much a bijection By "hash" I just meant its broader meaning of "converting": "IP address" to "broad geographical region". There would be no way to convert, say, "Monaco" back to an IP address
- CinzanoBianco 6y agoThe blog post is at best disinformation on this topic. GDPR does not require cookie banner at all for this use case. GDPR is not about cookie banners at all. It is about consent of using personal or identifiable information. It is about safely processing data and not collection personal information that you were not permitted to have. This gets tricky as IP is recognized as private information in EU. This can be solved by telling GA to not collect it. Google Analytics does not require you to post cookie banner, but you have to inform user on your privacy policy page that you are tracking their "anonymous" activity. How much it is anonymous knows only Google. Source: https://marketingplatform.google.com/about/analytics/terms/us/ https://marketingplatform.google.com/about/analytics/terms/u... section "7. Privacy" What requires consent banner is Google Ads! Google is through you creating unique profile for each visitor that makes him identifiable. This is in direct conflict of GDPR that prohibits such behavior without explicit consent. So mere "We are storing cookies. > Accept <" is actually also in direct conflict with GDPR as you are lying or hiding this information from the user. I am also not lawyer, but I was involved in implementation of this for e-commerce.
- jassany 6y agoGoogle has an extension on the Chrome Web Store that allows you to opt out of GA tracking. https://chrome.google.com/webstore/detail/google-analytics-opt-out/fllaojicojecljbmefodhfapmkghcbnh?hl=en https://chrome.google.com/webstore/detail/google-analytics-o...
- rcMgD2BwE72F 6y agoGDPR is neither opt-in nor opt-out. The users must consent or no personally identifiable data can be collected/processed.
- d1sxeyes 6y agoThis is not correct. There are six bases for processing personal data. Consent is only one.
- oxfordmale 6y agoIP address falls under GDPR unfortunately.
- ratherbefuddled 6y agoYou don't need consent to share personally identifiable data like IP addresses with Google. For GDPR purposes you need a legal basis and "your legitimate interest" is one. You need to honestly assess - ideally write down - your determination of how your need to analyse website performance is balanced against the user's right to privacy. One thing you might consider here is the impact on the user. Then you need to fulfil your duties as a data controller with respect to accuracy, security and so on. What you do need is consent for cookies (or local storage or similar)· That is required by the ePrivacy Directive (aka cookie law). If you want to persist an identifier on a user's device you need to get consent before you put it there. GDPR and ePrivacy are related but not the same. You can use GA without cookies (or with only "strictly necessary" cookies which are an exception to the consent rule) and therefore not fall foul of ePrivacy.
- GordonS 6y ago> For GDPR purposes you need a legal basis and "your legitimate interest" is one. You need to honestly assess - ideally write down - your determination of how your need to analyse website performance is balanced against the user's right to privacy Come on, analytics,especially 3rd party analytics, is never considered a "legitimate interest". As if it was needed, this is spelled out explicitly in the ePrivacy directive and official EU opinion documents.
- ratherbefuddled 6y agoLegitimate interest is a GDPR thing and you can indeed choose to share personal information under legitimate interest and you can do so for analytics. There are countless examples of privacy policies all over the web doing exactly that. The ePrivacy directive is much more proscriptive about consent but applies only very narrowly - to cookies and similar technology. Conflating GPDR and ePrivacy leads to much confusion, they are to all intents and purposes separate.
- dawnerd 6y agoHaving done a lot of gdpr work recently, this definitely will not fly. Nice idea if preventing cookies is all you care about.
- secondcoming 6y ago> IP address + website domain + user agent + language + validity days This is still a NOPE under GDPR.
- munchbunny 6y agoI think there are two misconceptions in this post. 1. Cookies do not automatically require consent. If you use a session cookie to remember someone's login session, that does not require consent. It's when you use that session cookie for analytics, advertising, etc. that consent enters the picture. 2. The fact that you can uniquely identify the user on an ongoing basis, even if you're not tying it to any actual personal details or an IP address, is what makes that identifier personal information. Just because you obfuscate it does not change that. A hash hides the original data but it does not change the fact that it's a unique identifier, and therefore it's still personal information. You have to anonymize the data in such a way that you couldn't pick out the specific individual from any stored data. A lossy anonymization step is one way to do it. A hash of a browser thumbprint is not, unless that hash also pools multiple users together and mixes the data up so that you can't pick them apart again.
- yuhong 6y agoThis is why my Wikipedia article about the history of AdWords/AdSense/DoubleClick is important: https://en.wikipedia.org/wiki/Draft:Effects_of_the_2007-2008_financial_crisis_on_Google https://en.wikipedia.org/wiki/Draft:Effects_of_the_2007-2008...
- 2Gkashmiri 6y agoHow does something like truecaller work with gdpr? I mean you are given some sort of one way access to names of contacts from their database and in return you pay them real money, you are shown ads based on your IP address, who you call, how long and other parameters and the most problematic is the fact that your phone contacts are taken as a payment. I came across this app back in 2011 and noped the fuck away. Never installed trucaller once and my details may be there but I don't want it. My question, can truecaller take your contacts not to serve you in particular but to build a wordwide database and they dont say that in clear terms from what I have asked its users. They DONT know the software is doing that