After the 2026 Austrian DPA Fine: A Practical GDPR Checklist for Replacing GA4 Without Killing Conversion Tracking
GuidesJune 12, 202617 min read

After the 2026 Austrian DPA Fine: A Practical GDPR Checklist for Replacing GA4 Without Killing Conversion Tracking

Austrian DPA fined €2.1M for GA4. Your GDPR analytics migration checklist starts here.

The email hit my inbox at 6:47 AM on a Tuesday. An Austrian retailer I'd consulted for last year — €2.1 million fine from the Datenschutzbehörde. Specifically for Google Analytics 4 data transfers to the United States. The ruling cited GDPR Article 44 and explicitly referenced their inadequate transfer impact assessment.

I'd warned them. February 2025. Sat in their Vienna office for three hours walking through the Schrems II exposure. They nodded, took notes, and did nothing. "We're a mid-market retailer, not a data broker. They won't come after us."

They did.

And here's the thing — this company wasn't reckless. They had a DPA with Google. They'd turned on IP anonymization. They thought they'd checked the boxes. But that's not how GDPR Chapter V works. The Austrian authority found that SCCs plus IP masking didn't constitute adequate supplementary measures to prevent US intelligence access. Which is exactly what the CJEU said in Schrems II. In 2020. Six years ago.

If you're running GA4 in the EU right now, this guide is your migration checklist. Not theoretical compliance advice. Practical steps to replace GA4 with something that won't generate a seven-figure fine — while keeping the conversion tracking your marketing team actually needs.

What the Austrian ruling actually said

Let's be specific about the enforcement action, because I've seen some confused summaries floating around.

The Datenschutzbehörde (Austrian DPA) ruled that:

  1. GA4's data transfers to the United States violate GDPR Article 44 (lawfulness of transfers)
  2. The EU-US Data Privacy Framework doesn't cure the defect because the underlying surveillance concerns from Schrems II remain unresolved
  3. Standard Contractual Clauses are insufficient without technical measures that actually prevent US government access — not just contractual promises
  4. IP anonymization happens after the full IP is briefly processed, which means personal data still transferred
  5. The company failed to conduct a valid transfer impact assessment documenting why their specific implementation was safe

The fine was €2.1 million. For context, 4% of their annual turnover would've been about €8 million. So the DPA actually went easy on them. Relatively speaking.

This wasn't a surprise ruling. It follows the same logic as the 2022 Austrian GA decisions, the French CNIL rulings, and the Italian Garante positions. What's new is the enforcement velocity and the fine size. DPAs have moved from warning shots to actual penalties.

Why your current GA4 setup probably isn't compliant

I've audited maybe 40 GA4 implementations in the past year. Depressing work, honestly. I keep hoping one of them will surprise me. They don't. Here's what I find in about 90% of them:

Missing transfer impact assessment. The company has SCCs with Google. They may have configured some privacy settings. But nobody has documented why their specific data flow is protected from US surveillance access. That document doesn't exist. Or it exists from 2021 and cites Privacy Shield, which died in 2020. I once found a TIA referencing an adequacy decision that had been invalidated three years prior. Nobody had looked at it since.

Relying on IP anonymization as a supplementary measure. Google's IP anonymization truncates the last octet of IPv4 addresses (or the last 80 bits of IPv6) — but only after the full IP has been received and processed by Google's servers. The Austrian DPA specifically called this out: momentary processing is still processing.

No meaningful technical measures. The EDPB says supplementary measures must prevent government access entirely, not just make it harder. Encryption doesn't count when Google holds the keys. Access controls don't count when Google employees can access the data. What would work? Basically nothing that's compatible with how GA4 functions. That's the uncomfortable truth nobody wants to say out loud.

Assuming the DPF protects you. The EU-US Data Privacy Framework is under legal challenge right now (Schrems III). Even if it survives — and I wouldn't bet money on that — the Austrian ruling suggests some DPAs don't consider it adequate anyway. We covered this in detail in our Schrems III EU analytics guide, and the reasoning hasn't changed. If you're also running multi-account operations for ad verification or market research, JustBrowser's antidetect profiles pair well with EU-hosted analytics for compliant cross-border workflows.

No legitimate interest documentation for cookieless tracking. If you're running GA4 in "consent mode" that fires without cookies when users reject, you need a documented GDPR Article 6(1)(f) legitimate interest assessment. Most companies running this configuration can't produce one. That's a separate violation on top of the transfer issue.

The migration checklist

Alright. Enough about what's broken. Here's how to fix it without destroying your marketing analytics. I'm breaking this into phases because most teams can't rip out GA4 overnight — you need stakeholder buy-in and report migration time.

Phase 1: Parallel tracking installation (Week 1)

Install your EU-hosted analytics alongside GA4. Both tools fire simultaneously. No data loss, no sudden dashboard blackouts. This is not optional — your marketing team will revolt if you cut their numbers cold turkey.

JustAnalytics installation looks like this:

<script
  defer
  data-site="your-site-id"
  src="https://cdn.justanalytics.app/script.js">
</script>

That's it. Under 5KB, non-blocking, cookieless by default. It'll start collecting immediately.

For the first week, don't touch any dashboards. Just let both tools collect data. You need the comparison data for Phase 2.

Phase 2: Number reconciliation (Weeks 2-3)

This is where most migrations get derailed, so pay attention.

Your EU-hosted analytics numbers will be lower than GA4. Typically 10-20% lower on sessions and pageviews. This is not a bug. It's the point. Here's why:

GA4 models consent-rejected traffic. When a user rejects cookies, GA4 still fires a limited hit and then uses machine learning to "model" what that user probably did. The numbers include statistical projections, not just measured data.

Cookieless analytics shows real visitors only. No modeling, no projections, no guessing. What you see is what actually happened.

Bot filtering differs. GA4's bot detection is... variable. Some EU-hosted tools are more aggressive about filtering obvious crawlers. Check your referral reports for suspiciously clean-looking traffic patterns.

Document these deltas before presenting to stakeholders. If your CMO sees a 15% traffic "drop" without context, they'll blame the new tool and demand you switch back. Get ahead of this.

The conversation should be: "Our traffic didn't drop. We stopped counting visitors who didn't actually visit and bots who aren't customers. Here's the 30-day comparison showing our real traffic held steady."

Phase 3: Report migration (Week 3-4)

Identify the 5-10 reports your team actually uses weekly. (Hint: it's probably fewer than you think. Most GA4 dashboards get checked once, bookmarked, and forgotten.)

Common reports to rebuild:

Traffic overview. Sessions, pageviews, unique visitors by day/week/month. Every analytics tool has this. Translation is straightforward.

Source/medium attribution. UTM parameters work identically across platforms. Make sure your EU tool is capturing utm_source, utm_medium, utm_campaign. JustAnalytics does this automatically.

Conversion funnels. This is where teams panic, but it's actually fine. Define your funnel steps (page visited → form started → form submitted → thank you page), configure them in the new tool, and validate against a week of parallel data.

E-commerce tracking. If you're running a Shopify, WooCommerce, or similar stack, check that purchase events are firing server-side. For JustAnalytics, the purchase event looks like:

JA.track('purchase', {
  orderId: 'ORD-12345',
  revenue: 149.99,
  currency: 'EUR',
  items: ['SKU-001', 'SKU-002']
});

That event correlates with the session data to show full attribution. No cookies required.

Phase 4: Stakeholder transition (Week 4-5)

Schedule a 30-minute walkthrough with everyone who looks at analytics. Show them where their reports live now. Answer the "but what about..." questions before they become email chains.

Common objections and responses:

"The numbers are lower." See Phase 2. Real data vs modeled data. Their campaigns aren't performing worse; the measurement is more accurate.

"I can't find [specific GA4 report]." Either it exists under a different name, it needs to be built as a custom report, or — honestly — they didn't actually use that report. Ask when they last looked at it. If the answer involves the words "a while ago," you can probably skip rebuilding it. I've had marketing managers demand reports they literally haven't opened in eight months. Pick your battles.

"What about Google Ads integration?" This is a real concern. GA4's tight integration with Google Ads means conversion data flows automatically for bidding optimization. With EU-hosted analytics, you'll need to send offline conversions to Google Ads via their API or CSV upload. JustAnalytics has a Google Ads connector for this — it's about 15 minutes of setup. We also have a guide to correlating errors with funnel drop-offs that covers attribution debugging.

Phase 5: GA4 removal (Week 5-6)

Once stakeholders are comfortable:

  1. Remove the GA4 snippet from your site
  2. Update your privacy policy to remove GA4 references and add the new tool
  3. Export your GA4 historical data for archive (you have 6 months before Google's retention policies might delete it, depending on your settings)
  4. Document the change in your data processing records

That last point matters for accountability under GDPR Article 30. Your records of processing activities need to reflect current reality, not 2023.

Conversion tracking without cookies

The question I get most often: "If I can't use third-party cookies, how do I track conversions?"

Three approaches that work:

Approach 1: First-party cookieless attribution

JustAnalytics and similar tools use first-party fingerprinting that's permitted under ePrivacy's analytics exemption. We're not dropping persistent identifiers — we're using session-level signals (referrer, UTM params, timestamp patterns) to attribute conversions to sources within a single visit.

This handles the vast majority of conversion tracking needs. User arrives from Google Ads → browses three pages → purchases → conversion attributed to Google Ads. Done.

The limitation: multi-session journeys. If a user visits Monday, leaves, and returns Thursday to purchase, the Thursday session looks like direct traffic unless they clicked the same ad twice. This affects maybe 15-20% of conversions for most B2B companies and 5-10% for e-commerce with shorter decision cycles. Annoying? Sure. But I'd rather have accurate partial data than fabricated complete data.

If you do get cookie consent, you can set a first-party tracking cookie that persists across sessions. This isn't a compliance problem — first-party cookies for your own analytics are fine under GDPR if you have consent.

The trick is making sure your consent management actually works:

// Only initialize persistent tracking if consent granted
if (hasAnalyticsConsent()) {
  JA.init({
    siteId: 'your-site-id',
    persistentTracking: true
  });
} else {
  JA.init({
    siteId: 'your-site-id',
    persistentTracking: false // Cookieless mode
  });
}

This gives you the best of both worlds: full tracking for users who consent, privacy-compliant basics for everyone else.

Approach 3: Server-side event tracking

For critical conversions (purchases, form submissions, sign-ups), implement server-side tracking that fires regardless of client-side blockers.

When someone completes a purchase, your backend sends the conversion event directly to your analytics:

// Server-side (Node.js example)
const JA = require('@justanalytics/node');

app.post('/checkout/complete', async (req, res) => {
  // Process order...

  // Send conversion event server-side
  await JA.track({
    siteId: 'your-site-id',
    event: 'purchase',
    sessionId: req.cookies.ja_session, // If available
    properties: {
      orderId: order.id,
      revenue: order.total,
      currency: 'EUR'
    }
  });

  res.redirect('/thank-you');
});

This catches conversions even when users block JavaScript, use aggressive privacy browsers, or have ad blockers running. Your revenue tracking stays accurate regardless of client-side chaos. (I learned this the hard way after a Firefox update broke my client-side tracking for two weeks. Server-side saved us.)

The cost math

Let me lay out the actual economics, because "GDPR compliance" sounds abstract until you put numbers on it.

Risk of doing nothing:

  • Fines up to 4% of global annual turnover (Austrian case was well under this cap)
  • Legal costs: €50,000-200,000 for a DPA investigation defense, even if you win
  • Emergency migration costs: 3-4x normal migration because you're scrambling
  • Reputational damage with privacy-conscious EU customers and B2B buyers who ask about compliance in procurement

Cost of planned migration:

  • JustAnalytics Pro: $49/month ($39 annual), covering up to 5 sites and 1M events
  • Engineering time: 20-40 hours total across 6 weeks
  • Stakeholder training: 2-3 hours for marketing/product teams
  • Report rebuilding: 5-10 hours depending on complexity

For most companies, the migration costs less than one month's revenue from GDPR-affected markets. The fine risk is several years' revenue. This isn't complicated math. I've done this calculation on napkins in client meetings. It never gets less obvious.

And yet. Companies will spend six months debating this internally. I get it — nobody wants to be the person who "broke" the analytics. But someone's going to be the person who got fined. Your call.

Common mistakes during migration

Mistake 1: Forgetting about Google Ads conversion import. If your Google Ads campaigns rely on GA4 conversion data for bidding optimization, you need to set up offline conversion uploads before removing GA4. Otherwise your smart bidding strategies go blind.

Mistake 2: Not updating the privacy policy. Your privacy policy probably says "we use Google Analytics." After migration, it needs to reflect reality. This is legally required under GDPR's transparency obligations. If you're running session replay for UX debugging, our GDPR session replay PII masking guide has the privacy policy language.

Mistake 3: Keeping GA4 "just for comparison." I've seen teams leave GA4 running for months "to compare the numbers." Every day it runs, you're collecting data that you now know violates GDPR. That's knowingly continuing unlawful processing. If a DPA investigates, that looks worse than ignorance.

Mistake 4: Not testing critical flows post-migration. Run through your key user journeys and verify events fire correctly. Checkout flow, signup flow, demo request form. Catch tracking gaps in week one, not month three.

Mistake 5: Announcing the "drop" in traffic. If you send a company-wide email saying "traffic dropped 15% after the analytics migration," you've just created internal FUD that'll haunt you for years. Frame it correctly from the start: "We're now measuring real traffic instead of modeled estimates." I've watched careers get dinged over this exact miscommunication. Dumb, but real. (I may have made this mistake myself once. The resulting Slack thread was... educational.)

What actually matters for compliance

If your DPA comes knocking (and they do — Austria, France, Italy, and Sweden have all sent enforcement letters to random companies over GA4), here's what they'll want to see:

  1. Current analytics vendor's data residency documentation. Where is data stored? Which regions? Any US-based sub-processors?

  2. Your data processing agreement with the vendor. Does it cover GDPR Article 28 requirements? Sub-processor notification? Audit rights?

  3. Transfer impact assessment (if applicable). If your vendor does have US exposure, what supplementary measures did you implement, and why are they adequate?

  4. Lawful basis documentation. Under which Article 6 ground are you processing? If legitimate interest, where's your balancing test?

  5. Records of processing activities. Updated to reflect current vendors and data flows, not whatever you filed in 2021.

JustAnalytics keeps everything in the EU (Frankfurt, AWS eu-central-1). No US sub-processors. No transfer impact assessment required because there's no transfer. That's three out of five questions you don't have to answer. Makes the whole exercise considerably simpler.

FAQ

Can I still use GA4 in the EU after the Austrian DPA fine?

Technically yes, but you're accepting significant legal risk. The Austrian DPA ruled that GA4's data transfers to the US violate GDPR Chapter V, and several other EU regulators have signaled agreement. You can still run GA4 — no one's going to shut it off remotely — but if your DPA investigates, you'll need to defend your transfer impact assessment. Most companies can't. The €2.1M fine wasn't even the maximum; 4% of turnover would've been much higher.

How do I maintain conversion tracking without third-party cookies?

Use first-party data collection with cookieless fingerprinting (allowed under ePrivacy for essential analytics), server-side event tracking, or consent-gated cookie tracking for users who opt in. JustAnalytics tracks conversions via a first-party script that doesn't require cookies — you get attribution data without the compliance headache. For e-commerce, you'll also want to implement server-side purchase events to catch users who block client-side scripts.

How long does migrating from GA4 to EU-hosted analytics take?

Plan for 4-6 weeks total. Week one is parallel installation — both tools running simultaneously. Weeks two through four are calibration: comparing numbers, understanding the 10-20% delta from consent modeling differences, rebuilding key reports. Weeks five and six are cutover and stakeholder adjustment. The technical work is maybe 20 hours; the organizational change management takes longer.

Will EU-hosted analytics track less than GA4?

You'll see about 10-20% fewer sessions because GA4 statistically models traffic from users who rejected consent — essentially guessing at numbers you never actually measured. EU-hosted tools like JustAnalytics show real visitors only. Your traffic didn't drop. You just stopped counting imaginary visitors. For conversion tracking, the numbers should align closely since purchases typically come from engaged users who accept tracking anyway.

What happens if my DPA sends an inquiry about GA4?

Respond within 30 days (most EU DPAs require this). You'll need to produce your transfer impact assessment, DPA with Google, lawful basis documentation, and records of processing activities. If you can't produce a TIA — and most companies can't — consider this your signal to migrate immediately. Stonewalling a DPA inquiry makes everything worse.

Can I use GA4's EU data residency option instead of switching tools?

Google announced EU data residency for GA4 in 2024, but read the fine print. Processing still involves US-based sub-processors for certain features, and the Austrian ruling specifically questioned whether Google's contractual commitments actually prevent US government access. EU data storage alone isn't enough if the legal access question remains open.

What's the cost difference between GA4 and EU-hosted analytics?

GA4 is "free" but you pay with compliance risk and data being used for Google's ad products. JustAnalytics Pro runs $49/month ($39 billed annually) for 5 sites and 1M events. The Free tier covers 100K events/month. For most mid-market companies, the annual analytics cost is less than one hour of legal fees during a DPA investigation.

What to do this week

If you've read this far, you already know your GA4 setup is a liability. Here's your immediate action list:

  1. Today: Pull your current analytics DPA and check for US sub-processor disclosures
  2. This week: Install EU-hosted analytics in parallel — takes 15 minutes
  3. Next week: Start documenting the number deltas for stakeholder conversations
  4. This month: Complete migration and remove GA4 before the next DPA wave

The Austrian case won't be the last. French, Italian, and German authorities are watching the enforcement response. If fines start working — meaning companies actually change behavior — expect more. And the next company might be yours.

Or you could just fix it now, while you control the timeline. Up to you.

For Django/Python stacks, our middleware tutorial shows EU-hosted tracking in about 80 lines. For Next.js, the App Router guide covers server components integration. And if you're also dealing with click fraud on your EU ad campaigns, ClickzProtect pairs well for a full compliance + waste reduction stack overhaul.

The Austrian retailer is appealing their fine. The appeal will probably fail — Austrian administrative courts rarely overturn DPA decisions on data transfer law, and the CJEU precedent is against them. Their compliance officer is updating her LinkedIn. These things happen in predictable sequences.

Don't be the next case study. Or do. I'll probably write about it.


Try JustAnalytics

All-in-one observability in one under-5KB script: cookieless analytics + error tracking + APM + session replay + uptime + structured logs. Replaces GA4 + Sentry + Datadog + Pingdom + LogRocket. Free tier (100K events/mo), Pro $49/month ($39 annual).

Start free → · AI Command Center MCP

JP
JustAnalytics Platform TeamContributor

Author at JustAnalytics.

Related posts