France's privacy regulator has ruled that an unnamed website cannot use Google Analytics because it transfers personal data to the United States in violation of EU privacy law (GDPR).
See also: WhatsApp: €225 million fine for GDPR violation

“The CNIL considers these transfers to be unlawful and orders a French website operator to comply with the GDPR and, if necessary, to stop using this service under the current circumstances,” the regulator said in a statement.
See also: GDPR is being used as a bureaucratic dodge to avoid public scrutiny
The French regulator is the second European data protection authority to reach this conclusion. In January, the Austrian regulator decided that a website should stop using the Google Analytics tool. Finally, the Dutch regulator also issued warnings to this effect.
In August 2020, Max Schrems’s NGO noyb.eu filed 101 complaints against websites that have adopted web analytics technology developed by Google and Facebook. The organization argues that the use of the tools violates the so-called Schrems II ruling at the EU’s top court, which struck down a transatlantic data flow agreement due to a lack of privacy protections.

"Although Google has adopted additional measures to regulate data transfers within the framework of the Google Analytics functionality, these are not sufficient to exclude the accessibility of this data to US intelligence services," the CNIL wrote.
“There is therefore a risk for French website users who use this service and whose data is being exported,” he added. The CNIL gave the website a month to comply and said it has issued other orders for compliance.
See also: GDPR: How are remote workers at risk of violating it?
The French complaints target online news outlet HuffPost, retailers Leroy Merlin, Auchan and Decathlon, beauty store Sephora and telecoms company Free for using Google and Facebook tools. Auchan, Sephora and Decathlon use Google Analytics.
Source of information: politico.eu
