The stop of Google Analytics by the regulator was just a matter of time, in fact, the transfer of data to the USA makes this product incompatible with the GDPR. It's useless to anonymize IPs, and above all, the regulator holds the website owner responsible and not Google LLC. Mountain View has not yet responded to the regulator, and there is no official note; it is rumored that GA4 compared to UA solves the problem, but that is not the case.

It is the transfer of data to the USA, not the level of security and privacy of the service, but due to the more permissive American regulations compared to European ones.

A perfect storm: without an agreement between the USA and Europe.

What is hoped for is that there will be an agreement between the USA and EUROPE to resolve the issue as there are many services at risk, having not been considered compliant with GDPR for some time. In practice, every service that transfers and/or processes data outside of Europe is affected. We are talking about many services, some of which have no European alternatives to replace them, including many social platforms like Facebook, Instagram, TikTok, etc., or email marketing services such as MailChimp, klaviyo, etc. The problem is not the legal headquarters of the service provider, but the physical location of the servers or the transfer of data (even a simple backup) to servers not located in Europe.

Not to mention CDN or DNS services like Cloudflare, although the authority seems to be primarily focused on tracking for marketing purposes. However, it should be noted that the recent reminder emphasizes an important concept: it is the website owner who must assess whether the service in use complies with GDPR. And this is where a perfect storm could arise, putting every SEO and SEM activity in Europe in serious crisis. This will have a very drastic impact, especially on small retailers and small agencies.

We were already in turmoil over the upcoming closure in July 2023 of Universal Analytics and the necessary migration to GA4: which we discussed here.

The problem is that transitioning from UA to GA4 is not simple; many software and platforms dedicated to SEO and SEM campaigns, not just Google products, require a connection with UA and are still not updated to use Google Analytics 4, let alone a varied ecosystem of alternative solutions. Only recently has the PrestaShop Metrics Module become compatible with GA4, but it is not compatible with alternatives such as Matomo and Shinystat.

We can certainly do without the PrestaShop Metrics module, which is not essential, but what about the advanced features of Semrush or SeoZoom? The UA metrics are also used by services such as Coobis, Link Building, and Getfluence, which facilitate the meeting between publishers and/or influencers and companies.

As users, we will still be followed by foreign advertising; the General Data Protection Regulation (GDPR) is, in my opinion, a blatant witch hunt that imposes regulatory duties and solves nothing.

It also seems to be a blatant mix of technical ignorance and paranoia that has guided the legislator.

Anonymization of IP addresses

The guarantor has been very clear, anonymizing IPs is not enough. Google can complete the data with what it already has, making the truncation of the user's IP address pointless. In reality, it is not about making the IP anonymous, but merely about truncation; in practice, UA truncates the last three numbers, thus maintaining a great ability to detect the user's location. For this reason, it would be better to talk about masking.

Make Matomo anonymous: Tracking Data

In the image, an example of how IPs are anonymized in Matomo Analytics. Google uses the same system, at 1 Byte.

Google Analytics 4 does not solve the problem; it is not enough to make IPs completely anonymous, in fact, in my opinion, GA4 makes it worse, as it is able to track the user even when they change devices. For example, I am on the train and use my phone for a search through an app, then I arrive at the office and refine the search from my PC, and finally, at home, I complete the order with my notebook. In Google's view, GA4 should track my entire purchasing journey. Here, the European regulators will have a lot to say.

The alternatives to Google Analytics

After this long introduction and digression, let's see what the alternatives to UA and GA4 are. There are several European and open-source projects, and certainly the most valid is Matomo, for which we have developed a free module for PrestaShop that allows for integration. The simplest, but more limited (in the free version) compared to UA is definitely ShinyStat: an all-Italian project. We have also developed a free module for PrestaShop for ShinyStat, which you can find here. Other alternatives that I will not discuss are: Pimik Pro, AT Internet, Fathom, Plausible. You will find many articles that mention them as alternatives, but I do not know them in depth.

Matomo Analytics

Among the alternatives, it is the most complete and promising project. Its strength is certainly scalability, meaning the ability to activate and add advanced functions through Plugins, some free and others paid. Matomo is very focused on privacy and can be downloaded for free and installed on your own hosting.

Strengths of Matomo:

  1. Open Source project that can be installed and managed internally, thus having complete control over the data.
  2. High scalability and the ability to add functions via Plugins
  3. Importing data from Google Analytics, through a free plugin it is possible to import all historical data from Google.
  4. Compliance with GDPR and a strong focus on privacy

Weaknesses of Matomo:

  1. Installing Matomo on your own hosting is not too difficult, but it requires technical skills and the MySQL configuration is not standard; it requires setting some parameters, especially for high-traffic sites. It is also available in Cloud configured and with support, in case you do not have your own VPS or Dedicated Server, the Cloud solution can be less costly for low volumes. For a volume of 50,000 visits/month, we are talking about 19 euros/month.

You can find the pricing list for the Cloud solution and the main Plugins here: https://matomo.org/pricing/

The reason to use Matomo Analytics is the exclusive ownership of the data; Google gives us a lot for free, but we share that data with Mountain View, and that data will also be used by our competitors and is worth much more than the economic savings obtained by sharing it.

ShinyStat Marketing Automation and Data Management

Before the dominance of Google Analytics, it was one of the most widely used statistics products in Italy, being one of the first, appearing in 1997. It is certainly the simplest and most immediate to integrate, in the absence of technical skills. The Free version is very limited, and the Pro versions may seem expensive, but they offer very valid tools and support in Italian, in fact, ShinyStat SPA is an Italian company based in Milan.

The free solution can be suitable for a small e-commerce, perhaps with our free module for PrestaShop
The ShinyStat interface is much more pleasant and simpler compared to Google Analytics and even Matomo. 

Strengths of ShinyStat:

  1. 100% Italian solution, founded in 1997.
  2. Support in Italian.
  3. Ease of implementation, even simpler than Google Analytics.
  4. Good scalability with Pro packages and advanced functions for Marketing Automation.

Weaknesses of ShinyStat:

  1. Like with Google Analytics, there is no ownership and complete control of the data, unlike Matomo.
  2. The free version is significantly limited, but the annual cost of the PRO versions is not excessive. For a site with 10,000 page views/month, we are talking about 58.80 euros + VAT per year. There is also a subscription for 3,000 page views/month that costs exactly half.

Conclusions

This stance by the Italian Privacy Authority had been in the air for months; our development of modules for ShinyStat and Matomo for PrestaShop began back in February 2022. Both the Austrian and French authorities had already expressed their opposition to Google Analytics; it is pointless to delude ourselves, unless there is a Europe/USA agreement (like the Safe Harbor that was in effect until 2015), using tools that transfer data outside of Europe is a violation of the GDPR, regardless of whether the data controller is aware of it or not. It doesn't even matter that Caffeina Media S.r.l., the subject of the complaint, failed to mention in the Privacy Policy generated with Iubenda that the data was transferred to a country lacking adequate measures for the protection of personal data. The issue is the transfer of data itself outside of Europe and it does not only concern Google Analytics.

Unfortunately, we professionals have been discussing this for a long time, but marketing needs and the perfect integration with platforms made us hope for a limbo. However, the Authority seems determined to quickly put an end to any circumvention of the regulations and has started with the new provisions regarding cookie consent and is now focusing on GA. Even Facebook is in the crosshairs, to the point that Meta has threatened to leave Europe.

Since the introduction of the GDPR, I refer to regulatory burdens, because that’s what they are, there is no protection for the user. However, it could be the push for companies to regain ownership of statistical data (taking advantage of the mandatory migration to GA4 by July 1, 2023), hoping that we are given time to migrate and, above all, to develop alternative SEO and SEM solutions. Personally, I have an aversion to solutions from Mountain View, which are confusing, unnecessarily complex, with interfaces that are constantly changing, and above all monopolistic. However, one is forced to use them due to the level of integration they offer.

The above is purely a technical point of view; for the legal issue, I refer you to the excellent article by LegalBlink:


https://legalblink.it/post/garante-privacy-dice-no-a-google-analytics.html

Author: Loris Modena

SENIOR DEVELOPER

Per Ind Loris Modena, owner of Arte e Informatica, started working in the IT sector in 1989 as a system administrator responsible for the maintenance and installation of computer systems. He began programming for the web in 1997, focusing on CGI programming in PERL and later transitioning to programming in PHP and JavaScript. During this time, he became familiar with the Open Source world and the management of Linux servers.

Product added to wishlist