HomeBlogIs Google Analytics POPIA Compliant?

Is Google Analytics POPIA Compliant?

Analytics is not compliant or non-compliant on its own. Four things decide it: consent, a cross-border transfer, who Google is to you, and your settings.

General information, not legal advice, and not reviewed by a lawyer. Google's terms, defaults and settings change without notice, so confirm the current position in your own property before relying on any of it.

The question does not quite work

Google Analytics is a tool. Tools are not compliant or non-compliant, in the same way a filing cabinet is not compliant. What can be compliant, or not, is what you do with it: whether you asked permission before switching it on, what you told people, who else gets the data, and how long it is kept.

That distinction matters commercially, because most pages answering this question are published by companies selling consent banners, and their answer tends to be that you have a problem only they can fix. You do have things to fix. They are more specific and more boring than that, and three of the four have nothing to do with a banner.

Four questions decide it. Do you have consent before the script fires? Have you dealt with the fact that this is a cross-border transfer? Is Google your operator or a responsible party in its own right? And are the settings in the property itself defensible?

First, yes, it is personal information

This is settled by the definitions rather than by argument. Section 1 of POPIA includes online identifiers within personal information, and an analytics cookie exists precisely to assign a persistent identifier to a visitor so their behaviour can be recognised across pages and visits.

So running analytics is processing personal information, and every condition for lawful processing applies. We have set out the reasoning and a five-minute test you can run on your own site in is your cookie banner POPIA compliant, and the document side in do you need a cookie policy. The short version for this page: analytics is not strictly necessary to deliver the page somebody asked for, so it does not ride along on the same basis as a login session cookie. The script should not fire until the visitor has chosen.

Second, and mostly missed: it is a transfer out of the country

This is the part the banner vendors skip, and it is the more substantial obligation.

Google processes analytics data on infrastructure outside South Africa. The moment a visitor's identifier reaches Google, personal information has left the Republic, and section 72 applies. You may not transfer personal information to a third party in a foreign country unless one of five gates is satisfied.

A banner does not solve this by itself. Consent is one of the five gates, so a genuinely free and informed opt-in does give you a basis. But it is a fragile one to build infrastructure on, because consent can be withdrawn, and the practical answer for most businesses is the first gate: a binding agreement with the recipient that provides adequate protection and controls onward transfers.

The useful consequence: accepting Google's data processing terms is not administrative box-ticking. It is the thing that makes your section 72 position hold up when consent is withdrawn or disputed.

Third: is Google your operator, or its own responsible party?

This one has a switch attached to it, and almost nobody knows where the switch is.

Under Google's own analytics terms, Google acts as a processor where you have disabled sharing with other Google products and services. Those terms are drafted against European law, so "processor" is Google's label rather than POPIA's; but POPIA's operator means much the same thing — someone processing on your behalf under a contract, without coming under your direct authority — and the roles line up closely enough to reason with. Leave that sharing enabled and the relationship changes: Google is then using the data for its own purposes, which makes it a responsible party in its own right rather than somebody processing on your behalf.

Both arrangements can be lawful. They are not the same arrangement, and they need different things from you.

  • If Google is your operator, section 21 requires a written contract obliging it to maintain the security safeguards in section 19 and to notify you of unauthorised access. Google's published data processing terms are that contract. You have to actually accept them.
  • If sharing is on, you are disclosing personal information to a third party for that party's own purposes. That is a different thing to describe in your privacy notice, and it is much harder to characterise as a narrow analytics purpose under section 13.

Whichever you choose, choose it deliberately and write down which one you are in. A business that cannot say whether Google is its operator has not answered the question, it has just not asked it.

The European rulings, and why not to copy the conclusion

You will find confident statements online that Google Analytics is illegal. That comes from a real line of decisions: the Austrian authority in early 2022, the French CNIL in February 2022, and the Italian Garante in June 2022 all found that using Google Analytics involved an unlawful transfer of personal data to the United States.

Two reasons not to import that conclusion into a South African analysis.

The ground has moved even in Europe. Those decisions rested on the Schrems II judgment and the absence of an adequacy finding for the United States. The EU-US Data Privacy Framework adopted in 2023 changed that premise, and it survived its first annulment challenge in the General Court in September 2025, though an appeal is pending. Citing the 2022 decisions as the current European position is out of date.

More importantly, it was never our question. Those rulings interpret Chapter V of the GDPR. POPIA has no equivalent adequacy machinery, the Information Regulator has published no list of adequate countries, and as far as we are aware it has issued no decision on Google Analytics at all. Section 72 asks whether the recipient is bound by law, corporate rules or agreement to protection substantially similar to POPIA's conditions. That is a question about your contract with Google, not about American surveillance law.

That is not a green light. It is a different question with a different answer, and the honest position is that it is unsettled and contract-shaped rather than decided against you. See POPIA vs GDPR for where the two regimes genuinely diverge.

Fourth: the settings inside the property

Minimality under section 10 and retention under section 14 are not satisfied by a banner. They are satisfied in the admin panel, and the defaults are not always what you would choose.

  • Data retention. A standard property defaults to two months for user and event data, and can be set to a maximum of fourteen. Longer is not available on the free tier, which is convenient: the ceiling is doing some of your section 14 work for you. Decide the number deliberately and record why.
  • Data sharing settings. The switch discussed above. Open the property's account settings and look at what is shared with Google products and services.
  • Google Signals. If enabled, this associates behaviour with signed-in Google accounts and turns an analytics purpose into something closer to advertising. Check whether it is on. If it is, that is a purpose your notice needs to describe.
  • IP addresses. Google states that its current analytics does not log or store IP addresses, using them transiently for coarse location and then discarding them. Useful, and worth knowing, but it does not remove the cookie identifier, which is the thing that made this personal information in the first place.
  • Anything you put in a URL. Analytics records page paths. If your site puts an email address, an order reference tied to a person, or an ID number into a query string, you are sending that to Google in the page path. This is a genuinely common and entirely self-inflicted problem.

What your documents need to say

Section 18 requires telling people what you collect, why, who receives it, and whether it goes to a third country and the level of protection there. For analytics that means your privacy notice should name the fact of analytics, the recipient, the offshore transfer, and the retention period. A notice that says "we may use cookies to improve your experience" does none of that.

Practically, three documents carry this: the privacy notice, the cookie policy listing the actual cookies with their purposes and lifetimes, and whatever record you keep of the decisions above. See how to write a POPIA privacy policy.

If this all sounds like a lot

It is worth asking a question nobody selling you a banner will ask: do you use the data?

A great many small South African sites run analytics because it came with the theme, and nobody has opened the reports in a year. If that is you, the cheapest compliance decision available is to remove the script. No consent, no transfer, no operator question, no retention setting.

If you do use it, keep it and do the four things above. Both are defensible. What is not defensible is collecting a persistent identifier for every visitor, sending it offshore, and not being able to say why.

A short checklist

  • Does the analytics script wait for consent, or fire on page load?
  • Can a visitor change their mind afterwards?
  • Have you accepted Google's data processing terms, and do you know where they are?
  • Do you know whether sharing with other Google products is on or off?
  • Is Google Signals on, and does your notice describe what that means?
  • What is the retention period set to, and did somebody choose it?
  • Does your privacy notice say the data goes offshore?
  • Does any personal information end up in your URLs?
  • Has anyone actually looked at the reports this year?

POPIA Ready generates a privacy policy and cookie policy that cover analytics, offshore processing and retention, plus five other documents customised to your business, free to preview. The free checklist will show you what else is missing.

General guidance on South African law as at September 2026, not legal advice. The position on analytics turns on your configuration and on Google's terms as you accepted them, and a business relying heavily on advertising data deserves a professional opinion.

Get Compliant Today

Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.

Generate Documents - Free to Preview

Continue Reading

Your WhatsApp Messages Are Records You Must Keep for Five Years

Read article →

Reading an Employee's Email Can Be a Criminal Offence

Read article →

Adding a Customer to a WhatsApp Group Shows Everyone Their Number

Read article →