Questions and answers on formal notices from the CNIL concerning the use of Google Analytics

In the context of the formal notice, Google indicated that it uses pseudonymization measures, but not anonymization. Google does offer an IP address anonymization function, but this is not applicable to all transfers. In addition, the elements provided by Google do not make it possible to determine whether this anonymization takes place before the transfer to the United States.

Also, the sole use of unique identifiers to differentiate individuals can help make data identifiable, especially when combined with other information such as browser and operating system metadata. This data enables precise tracking of users, in some cases across multiple separate devices. If the EDPS admits in its recommendations of June 18, 2021. the possibility of using pseudonymization as an additional measure, its use is subject to an analysis aimed at ensuring that all the information transmitted does not in any way allow a re-identification of the person, even taking into account the substantial means available to the authorities likely to want to carry out such a re-identification.

Finally, using Google Analytics together with other Google services, including marketing, may amplify tracking risk. Indeed, these services, which are widely used in France, can allow the IP address to be cross-checked and thus trace the browsing history of the majority of Internet users on a large number of sites.

Difference Between Anonymization and Pseudonymization

The pseudonymization is a processing of personal data carried out in such a way that the data relating to a natural person can no longer be assigned without further information. In practice, pseudonymization consists of replacing the directly identifying data (last name, first name, etc.) of a data set with indirectly identifying data (alias, sequential number, etc.).

L’anonymization consists in using a set of techniques in such a way as to make impossible, in practice, any identification of the person by any means whatsoever and irreversibly. Anonymized data is no longer subject to the GDPR.

