• GDPR
  • Analytics Tools
  • Consent Mode
  • Privacy
  • GA4

GDPR-Compliant Analytics Tools: Do You Switch?

By Olam Sule · Published 28 Aug 2026 · Updated 1 Sept 2026

TL;DR

GDPR-compliant analytics is a configuration problem more than a tool choice. GA4 can run lawfully in the UK and EU with Consent Mode v2 and the EU-US Data Privacy Framework, so most teams do not have to switch. Privacy-first tools like Matomo, Plausible and Fathom cut the consent surface, but none of them remove your legal duties on their own. We configure lawful, accurate setups for clients most weeks.

Olamide Sule, founder of Dolphin Analytics: a digital analytics expert based in London who sets up compliant tracking for agency and in-house clients.

Search “GDPR-compliant analytics tools” and every result is a privacy vendor telling you to switch to them. That answers the wrong question. The question most teams actually have is narrower: do you have to drop the analytics you already run, or can you make it compliant where it sits? This compares the tools that show up for the query, GA4 included, and is honest about which decision is a tool choice and which is a configuration job. We configure lawful, accurate setups for clients most weeks, so this is the advice we give when a client asks whether to switch.

How we compared them: consent and cookie behaviour, where data is processed, marketing reporting depth, and what compliance work still falls on you after install. Product and hosting details checked 28 August 2026 against each vendor’s own pages; verify current terms before you buy.

What makes an analytics tool “GDPR compliant”?

No analytics tool is GDPR compliant on its own. Compliance is how you configure and run a tool, not a badge it ships with, so the same platform can be lawful on one site and unlawful on another. What the regulation actually asks for is a short list, and every tool below meets some of it for you while leaving the rest as your job.

Five requirements decide it:

  1. A lawful basis for processing. Under the UK’s PECR rules and the EU ePrivacy Directive, storing non-essential cookies needs consent before they fire.
  2. Lawful international data transfers. Sending personal data outside the UK or EU needs a valid transfer mechanism, such as the EU-US Data Privacy Framework or standard contractual clauses.
  3. Data minimisation and retention limits. Collect what you need, keep it no longer than you have to.
  4. A data processing agreement with the vendor that handles the data on your behalf.
  5. A way for people to exercise their rights, including access and erasure.

A privacy-first tool makes several of these easier: it may process data in the EU, skip cookies, or anonymise IP addresses by default. It does not sign your DPA, write your privacy notice, or configure your consent banner. Fines are set against the organisation running the site, not the analytics vendor, and they reach up to €20 million or 4% of annual global turnover, whichever is higher under GDPR Article 83.

Do you actually have to switch off GA4?

For most UK and EU teams, no. GA4 can be run compliantly with three configuration steps rather than a platform change: turn on Consent Mode v2 so Google’s tags respect a visitor’s choice, sign Google’s data processing agreement, and set data retention sensibly. The rulings that put GA4 in doubt came before the legal ground shifted underneath them.

Here is the history that the vendor listicles tend to skip. In 2022, data protection regulators in Austria, France and Italy found that sending Google Analytics data to the United States breached GDPR, because US surveillance law gave visitors no real protection. France’s regulator, the CNIL, ordered site operators to stop using it in that form. Those decisions were about data transfers, not GA4 the product.

The transfer problem was addressed in July 2023, when the European Commission adopted the EU-US Data Privacy Framework, an adequacy decision that covers transfers to certified US companies, Google among them. The UK added its own extension to the framework later that year. So the 2022 rulings, still quoted as proof that GA4 is illegal, rest on a legal gap that regulators have since closed for certified vendors.

That does not make GA4 automatically compliant. It means the compliant path is configuration, and a broken consent setup is the real risk. If your banner loads GA4 before anyone clicks “accept”, you are collecting data without a lawful basis regardless of which framework applies. That failure mode is common, and it is the same one that quietly drops a chunk of your data when consent is wired up wrong.

GDPR-compliant analytics tools compared

Six tools show up for this query. Here is how they line up on the things that decide compliance and fit, before the detail on each.

ToolWhat it isData processing locationCookie banner still needed?Marketing depth
GA4 (Consent Mode v2)Free web and app analyticsGoogle-hosted; US transfer under the Data Privacy FrameworkYes, for its default cookiesHigh; native Google Ads link
MatomoPrivacy-focused web analyticsSelf-hosted anywhere, or Cloud in the EUOptional; can run cookielessMedium; marketing reports, weaker product depth
PlausibleLightweight, cookieless web analyticsEU (Germany)Positioned as consent-free; see the nuance belowLow; traffic and goals only
FathomSimple, cookieless web analyticsEU-isolated processing optionPositioned as consent-free; same nuanceLow; traffic and goals only
Simple AnalyticsMinimal, cookieless web analyticsEU (Netherlands)Positioned as consent-free; same nuanceLow; traffic and events
PostHogProduct analytics, replay and flagsEU or US cloud, or self-hostedDepends on config; can run cookielessProduct analytics, not marketing reporting

Details checked 28 August 2026; verify current terms before purchase.

GA4 is free, and its Google Ads integration is the strongest reason to keep it if paid search matters. Run compliantly it needs three things: Consent Mode v2 so tags hold back until a visitor opts in, Google’s data processing agreement signed in the admin settings, and data retention trimmed from the default. The catch is that none of this is on by default, so an untouched GA4 install on an EU site is usually the non-compliant one.

Matomo: the switch worth making when data control is the point

Matomo is the privacy-focused alternative most teams land on when they do decide to move. It can run fully self-hosted, so analytics data never leaves infrastructure you control, and Matomo Cloud hosts in the EU. It can operate without cookies, which lowers the consent burden. What it does not match is the marketing integration depth of GA4, and rebuilding those Google Ads imports is usually the biggest cost of a migration.

Plausible: cookieless traffic analytics, EU-hosted

Plausible is a lightweight, open-source web analytics tool hosted in the EU that runs without cookies and collects no personal data by design. It covers traffic sources, top pages and goal conversions, and little beyond that. For a content site or a marketing team that wants clean visitor numbers without a consent banner argument, it is a strong fit. For funnel analysis or campaign attribution, it will feel thin.

Fathom: the same idea, Canada-based with an EU data path

Fathom is a paid, cookieless analytics tool in the same mould as Plausible: simple dashboards, no personal data stored, no cookie banner in its own pitch. The company is Canadian, and it offers an EU-isolated processing option for European visitor data. Reporting depth is deliberately shallow, which is the point. It suits teams who want privacy and speed over deep analysis.

Simple Analytics: minimal and EU-hosted

Simple Analytics is a Netherlands-hosted, cookieless tool built around one dashboard and a short list of metrics. Like Plausible and Fathom, it trades depth for a small footprint and an easy privacy story. Choose it when you want a single clean numbers page and nothing that needs an analyst to read.

PostHog: product analytics, not a marketing swap

PostHog is a different category. It bundles product analytics, session replay, feature flags and experiments, and it offers an EU cloud region as well as self-hosting. It answers questions about in-product behaviour, not marketing performance, so it is not a like-for-like GA4 replacement. If your compliance question is really “which privacy-first tool measures marketing”, PostHog is the wrong shelf, though it can be configured to run without cookies. We go deeper on the tradeoffs in PostHog versus Google Analytics.

Not on its own, and this is where the privacy-first pitch oversimplifies. “No cookies” removes the PECR consent rule that applies specifically to storing information on a device. It does not remove your duty to have a lawful basis for processing any personal data, or to tell users what you collect. Cookieless and consent-free are two different claims.

In the UK, some limited audience-measurement setups may run without opt-in consent under the ICO’s statistical-purpose exception, but only when every condition is met: the technology is used solely for anonymised statistical measurement, with clear information given to users and a free way to opt out. A cookieless tool can help you meet those conditions. It does not decide, on its own, that you qualify. Read the exception before you drop the banner, not after.

Which GDPR-compliant analytics tool should you pick?

Start from the constraint, not the tool. Most teams do not have a GDPR problem that a platform change fixes; they have a consent setup that was never checked. Work down this list in order.

Your situationPick
You run Google Ads and want marketing depthGA4, configured with Consent Mode v2 and a signed DPA
Data location or vendor jurisdiction rules out a US platformMatomo, self-hosted or EU Cloud
You want clean traffic numbers with no consent argumentPlausible, Fathom or Simple Analytics
You measure in-product behaviour, not campaignsPostHog, EU cloud or self-hosted
You are an agency covering all of the above across clientsGA4 for marketing, plus the privacy tool that fits each client’s policy

The switch to Matomo or a cookieless tool is worth it when data control is a real requirement, common for public sector, healthcare and legal clients, not because GDPR bans Google as a blanket rule. If your driver is paid search performance, a compliant GA4 setup will serve you better than a privacy tool that cannot import Ads data. For the wider tradeoffs across platforms, see our digital analytics tools comparison.

The compliance risk is usually in the setup, not the tool

A GDPR fine follows a data-handling failure, and those almost always live in the configuration, not the vendor name. A banner that fires tags before consent, a missing data processing agreement, retention left on the default, transfers with no valid mechanism: any of these breaks compliance no matter which tool from this list sits on top. Switching platforms without fixing the setup just moves the same fault to a new logo.

That is the work we do. One agency engagement helped a client avoid exposure to a potential GDPR fine of up to €20M by getting their tracking and consent handling right. If you are not sure whether your current setup is compliant, or whether you actually need to switch tools at all, describe the problem by talking to us and we will come back with how we read it. You can also scan what is tracking on your site right now before deciding anything. Fix the configuration first; re-platform only if a real constraint still points you there.

This page is general information about analytics configuration, not legal advice. GDPR and PECR obligations depend on your own circumstances, so confirm your position with a data protection specialist before acting on it.

Frequently asked

Which analytics tools are GDPR compliant?

No analytics tool is GDPR compliant on its own, because compliance depends on how you configure and run it, not the logo. GA4 can be run compliantly in the UK and EU with Consent Mode v2 and a Google data processing agreement. Matomo, Plausible, Fathom and Simple Analytics reduce the consent and data-transfer surface by processing data in the EU and, in several cases, without cookies. PostHog can be run in its EU cloud or self-hosted. All of them still need a lawful basis, honest information for users, and a way to exercise data rights.

Is Google Analytics 4 GDPR compliant?

GA4 can be run compliantly for most UK and EU teams, but it is not compliant by default. You need Consent Mode v2 so that Google's tags respect a visitor's choice, a signed Google data processing agreement, and sensible data retention settings. The 2022 rulings that found Google Analytics unlawful predate the EU-US Data Privacy Framework, which the European Commission adopted in July 2023 and which now covers transfers to certified US companies including Google.

Do privacy-first analytics tools need a cookie banner?

Often they still do, and "no cookies" is not the same as "no consent". Cookieless tools like Plausible and Fathom avoid the PECR consent rule that applies to storing cookies, but you still need a lawful basis for processing any personal data and clear information for users. In the UK, some limited audience-measurement setups may run without opt-in consent under the ICO's statistical-purpose exception, but only when every condition is met, including a sole statistical purpose, anonymised data and a free opt-out.

Do I have to switch off GA4 to be GDPR compliant?

Usually not. For most UK and EU marketing teams the compliant path is configuration, not a platform change: turn on Consent Mode v2, sign Google's data processing agreement, shorten data retention, and make sure your consent banner actually blocks tags before opt-in. You would switch to Matomo or a privacy-first tool when data location, vendor jurisdiction or your own data policy rules out a US-based platform, not as a blanket GDPR requirement.

What makes an analytics tool GDPR compliant?

Five things, none of which come from the tool alone: a lawful basis for processing (consent for non-essential cookies under PECR), lawful international data transfers, data minimisation and retention limits, a data processing agreement with the vendor, and a way for people to exercise their rights. A privacy-first tool makes several of these easier to satisfy, but you still have to configure and document them.

Talk to us

Where does your data stop making sense?

Tell us what's broken, or grab a time. Either way you hear from a person, not a sales script.

Send a message

We reply within one working day.

Add a few details (optional) The more we know up front, the faster we can tell you what's wrong and how to fix it.

Protected by an invisible spam check. Prefer email? olam@dolphinanalytics.co.uk

Calendly · 30 min

Book a call

Thirty minutes on Google Meet with the founder.

The booking lands on the same record as your message.