Consenter Risk Assessments

TPP Pre-Assessment

This work is licensed under CC BY-SA 4.0

Übersicht

TPPGruppe / Parent ServiceBadgeService-TypInfra Only?KontaktDetails
Google Analytics (Universal Analytics)Google Analytics⚠️ CautionParent serviceNoprivacy@google.com
Google Tag ManagerGoogle Tag Manager⬜ No badgeParent serviceNoprivacy@google.com
Google AdsGoogle Ads⚠️ CautionParent serviceNoprivacy@google.com
Google MapsGoogle Maps⚠️ CautionParent serviceNoprivacy@google.com
YouTubeYouTube⚠️ CautionParent serviceNoprivacy@google.com

Google Analytics (Universal Analytics)

Stammdaten
  • Service Name: Google Analytics (Universal Analytics)
  • Gruppe / Parent Service: Google Analytics
  • Service-Typ: Parent service
  • Infrastructure Only?: No
  • Sub-service / Relationship Note: Parent service
  • Kontakt (DPO / Privacy): privacy@google.com
  • Bewertungsdatum: 06/08/2026
  • Version: v2 (06/08/2026) | v1: 22/06/2026
Badge & Risikobewertung
  • Badge: ⚠️ Caution
  • Red Flags:
    • RF1 — Own advertising / cross-service profiling
    • RF2 — High-risk third-country exposure without meaningful mitigation
  • Risk Indicators:
    • Own-purpose data use (advertising)
    • Intrusive tracking
    • High-risk international transfers
Begründung & Quellen

Key Facts: Google processes GA data for its own advertising ecosystem, including audience building and cross-service profiling, unless the controller actively disables Advertising Features. Data is transferred to US servers. EU DPAs have ruled these transfers unlawful: Austria DSB (Jan 2022), French CNIL (Feb 2022), Italian Garante (Jun 2022), Danish Datatilsynet (Sep 2022), Swedish IMY (Jul 2023), Norwegian Datatilsynet (Jan 2025). While the EU–US Data Privacy Framework (Jul 2023) provides a current transfer basis, a CJEU appeal (Case C-703/25 P) challenging the DPF's adequacy is pending.

Framework Note (v2.2): RF2 (high-risk third-country exposure) is recorded here as a significant risk factor and lowers the domain E score. Under the revised framework, RF2 alone does not trigger Caution — the Caution badge for this service is driven by RF1. The US transfer risk is covered by DPF participation and/or SCCs, which GDPR treats as a compliant transfer mechanism.

Quellen:

  • Google Analytics Terms of Service (analytics.google.com/analytics/tos)
  • Google Privacy Policy (policies.google.com/privacy)
  • Austrian DSB decision (DSB-D123.270/0009-DSB/2021, Jan 2022)
  • CNIL order (Jan/Feb 2022)
  • Norwegian DPA guidance (Feb 2025)
  • CJEU case register
Verarbeitungszwecke (Consenter)
  • Support marketing analytics
Benachrichtigungs- & Widerspruchsstatus
  • TPP Notified?: Not yet notified
  • Decision Contested?:

Google Tag Manager

Stammdaten
  • Service Name: Google Tag Manager
  • Gruppe / Parent Service: Google Tag Manager
  • Service-Typ: Parent service
  • Infrastructure Only?: No
  • Sub-service / Relationship Note: Parent service
  • Kontakt (DPO / Privacy): privacy@google.com
  • Bewertungsdatum: 06/08/2026
  • Version: v2 (06/08/2026) | v1: 22/06/2026
Badge & Risikobewertung
  • Badge: ⬜ No badge (revised from Caution — v2.2)
  • Red Flags: Keine
  • Transfer Risk (RF2 — domain E = 1):
    • Google Tag Manager routes tag data through Google US infrastructure
    • Google is DPF-certified; SCCs available via Google's DPA
    • Standard US transfer profile: E = 1 (moderate exposure, lawful mechanism in place)
    • CJEU challenge to DPF (Case C-703/25 P) pending — noted but does not alone make the transfer unlawful as of the assessment date
Begründung & Quellen

Framework Change (v2.2): RF2 (high-risk third-country exposure) is no longer a standalone Caution trigger. Where a lawful transfer mechanism exists — such as DPF participation or SCCs — GDPR treats the transfer as compliant. RF2 is reflected in the domain E score rather than an automatic badge override.

No Other Red Flags: GTM does not profile visitors for its own advertising (no RF1). It does not share data broadly with unnamed partners for their own purposes (no RF3). Documentation is publicly available (no RF4).

Re-evaluated Domain Scores:

  • A = 1 (some own-purpose analytics of GTM usage by Google)
  • B = 1 (TMS container; can be consent-gated; no structural tracking of its own)
  • C = 1 (neutral defaults; requires configuration)
  • D = 1 (moderate data; depends on tags loaded)
  • E = 1 (US transfer; DPF/SCCs)
  • F = 1 (documentation available, generic for a TMS)
  • G = 1 (consent-compatible with effort)
  • H = 1 (Google sub-processors disclosed)
  • Weighted average ≈ 1.0 → above 0.9 threshold; no two core domains at 0. Privacy+ not met (C≠2, E≠2).

Key Facts: Google Tag Manager is a tag management system (TMS). It does not independently track users — it deploys and fires other tags on the controller's instruction. The transfer risk relates to the GTM container script loading from Google US servers (googletagmanager.com, googletagservices.com), transmitting visitor IP and basic HTTP headers on each page load. Server-side GTM deployment on EU infrastructure can eliminate this transfer risk entirely.

Quellen:

  • Google Tag Manager Terms of Service (marketingplatform.google.com/about/analytics/terms)
  • Google Privacy Policy (policies.google.com/privacy)
  • Google Ads Data Processing Terms (DPA, incorporating SCCs)
  • Google DPF certification (privacyshield.gov / DPF.gov)
Verarbeitungszwecke (Consenter)
  • Support marketing analytics
  • Receive personalised marketing offers
  • Customise online ads (non-TCF)
Benachrichtigungs- & Widerspruchsstatus
  • TPP Notified?: Not yet notified
  • Decision Contested?:

Stammdaten
  • Service Name: Google Ads
  • Gruppe / Parent Service: Google Ads
  • Service-Typ: Parent service
  • Infrastructure Only?: No
  • Sub-service / Relationship Note: Parent service
  • Kontakt (DPO / Privacy): privacy@google.com
  • Bewertungsdatum: 06/08/2026
  • Version: v2 (06/08/2026) | v1: 22/06/2026
Badge & Risikobewertung
  • Badge: ⚠️ Caution
  • Red Flags:
    • RF1 — Own advertising / cross-service profiling
    • RF2 — High-risk third-country exposure without meaningful mitigation
  • Risk Indicators:
    • Own-purpose data use (advertising)
    • Intrusive tracking
    • High-risk international transfers
Begründung & Quellen

Key Facts: Google Ads tags (conversion tracking, remarketing) transmit visitor data to Google for its own advertising ecosystem, building cross-publisher audiences. CNIL fined Google €325 million (Sep 2025) for showing promotional ads in Gmail without prior consent and for manipulative consent design. EU User Consent Policy mandates consent before personalised ads; Consent Mode v2 mandatory since Mar 2024. US transfer via DPF (contested: CJEU C-703/25 P pending).

Framework Note (v2.2): RF2 (high-risk third-country exposure) is recorded here as a significant risk factor and lowers the domain E score. Under the revised framework, RF2 alone does not trigger Caution — the Caution badge for this service is driven by RF1. The US transfer risk is covered by DPF participation and/or SCCs, which GDPR treats as a compliant transfer mechanism.

Quellen:

  • Google Ads Terms of Service
  • EU User Consent Policy (support.google.com/adspolicy)
  • CNIL Google fine (€325M, Sep 2025, cnil.fr)
  • Google Privacy Policy
Verarbeitungszwecke (Consenter)
  • Support marketing analytics
  • Receive personalised marketing offers
  • Customise online ads (non-TCF)
Benachrichtigungs- & Widerspruchsstatus
  • TPP Notified?: Not yet notified
  • Decision Contested?:

Google Maps

Stammdaten
  • Service Name: Google Maps
  • Gruppe / Parent Service: Google Maps
  • Service-Typ: Parent service
  • Infrastructure Only?: No
  • Sub-service / Relationship Note: Parent service
  • Kontakt (DPO / Privacy): privacy@google.com
  • Bewertungsdatum: 06/08/2026
  • Version: v2 (06/08/2026) | v1: 22/06/2026
Badge & Risikobewertung
  • Badge: ⚠️ Caution
  • Red Flags:
    • RF1 — Own advertising / cross-service profiling
    • RF2 — High-risk third-country exposure without meaningful mitigation
  • Risk Indicators:
    • Own-purpose data use
    • Intrusive tracking
    • High-risk international transfers
Begründung & Quellen

Key Facts: Embedding Google Maps transmits visitor IP, device data, and identifiers to Google US servers on every page load, before any user interaction. Google uses this data as part of its broader advertising and analytics ecosystem. Austrian DPA and German courts have held that Google Maps sets advertising cookies which cannot be justified as strictly necessary, meaning opt-in consent is required before the map loads. No purely EU-hosted alternative with equivalent functionality is offered.

Framework Note (v2.2): RF2 (high-risk third-country exposure) is recorded here as a significant risk factor and lowers the domain E score. Under the revised framework, RF2 alone does not trigger Caution — the Caution badge for this service is driven by RF1. The US transfer risk is covered by DPF participation and/or SCCs, which GDPR treats as a compliant transfer mechanism.

Quellen:

  • Google Maps Platform Terms of Service (cloud.google.com/maps-platform/terms)
  • Google Privacy Policy
  • Complianz GDPR analysis of Google Maps (complianz.io/google-maps-gdpr)
  • German Landgericht analysis
Verarbeitungszwecke (Consenter)
  • Unlock additional website features
Benachrichtigungs- & Widerspruchsstatus
  • TPP Notified?: Not yet notified
  • Decision Contested?:

YouTube

Stammdaten
  • Service Name: YouTube
  • Gruppe / Parent Service: YouTube
  • Service-Typ: Parent service
  • Infrastructure Only?: No
  • Sub-service / Relationship Note: Parent service
  • Kontakt (DPO / Privacy): privacy@google.com
  • Bewertungsdatum: 06/08/2026
  • Version: v2 (06/08/2026) | v1: 22/06/2026
Badge & Risikobewertung
  • Badge: ⚠️ Caution
  • Red Flags:
    • RF1 — Own advertising / cross-service profiling
    • RF2 — High-risk third-country exposure without meaningful mitigation
  • Risk Indicators:
    • Own-purpose data use (advertising)
    • Intrusive tracking
    • High-risk international transfers
Begründung & Quellen

Key Facts: Embedding a YouTube video causes data transmission to Google/YouTube US servers even before the video is played, including visitor IP and identifiers used for advertising profiling. CNIL fined YouTube €90 million (Dec 2021) specifically for setting advertising cookies without valid consent. The youtube-nocookie.com embed domain reduces but does not eliminate tracking. DPF provides current transfer basis (contested: CJEU C-703/25 P pending).

Framework Note (v2.2): RF2 (high-risk third-country exposure) is recorded here as a significant risk factor and lowers the domain E score. Under the revised framework, RF2 alone does not trigger Caution — the Caution badge for this service is driven by RF1. The US transfer risk is covered by DPF participation and/or SCCs, which GDPR treats as a compliant transfer mechanism.

Quellen:

  • YouTube Terms of Service (youtube.com/t/terms)
  • Google Privacy Policy
  • CNIL YouTube fine (€90M, Dec 2021, cnil.fr/en)
  • CNIL cookie enforcement analysis
Verarbeitungszwecke (Consenter)
  • Unlock additional website features
  • Receive personalised marketing offers
  • Customise online ads (non-TCF)
Benachrichtigungs- & Widerspruchsstatus
  • TPP Notified?: Not yet notified
  • Decision Contested?:

Prüfbedarf

Folgende Auffälligkeiten wurden beim Übertrag festgestellt und sind nicht durch eigenständige Interpretation aufgelöst worden:

  • Google Analytics (Universal Analytics) — Verarbeitungszwecke: Die Tabellenzelle enthält nur „Support marketing analytics". Angesichts der dokumentierten Advertising Features (Audience-Building, Remarketing) wäre zu prüfen, ob zusätzliche Zwecke wie „Receive personalised marketing offers" oder „Customise online ads (non-TCF)" ergänzt werden sollten. Der Tabellenwert wurde unverändert übernommen.
  • Google Tag Manager — Verarbeitungszwecke: GTM ist eine Tag-Management-Plattform, die selbst keine Endnutzerdaten für Werbezwecke verarbeitet, aber alle drei Werbezwecke aus der Tabelle wurden übernommen. Es ist zu prüfen, ob diese Zwecke dem Container selbst oder den darin geladenen Tags zuzurechnen sind.
  • Alle fünf TPPs — TPP Notified?: Alle fünf Einträge tragen den Status „Not yet notified". Es liegt noch kein Ergebnis einer Vorab-Benachrichtigung vor; die Spalte „Decision Contested?" ist dementsprechend überall „—". Sobald Benachrichtigungen versendet wurden, sind diese Felder zu aktualisieren.
  • RF2-Kennzeichnung — Google Ads, Google Maps, YouTube: In der Quellspalte lautet die RF2-Beschreibung „High-risk third-country exposure without meaningful mitigation". Gemäß Framework v2.2 ist RF2 kein alleiniger Caution-Auslöser mehr; die Bezeichnung „without meaningful mitigation" in der Zelle selbst wurde nicht angepasst, da die Tabelle nicht verändert wurde. Prüfen, ob die Zellenwerte der Reasoning-Spalte in der Tabelle entsprechend aktualisiert werden sollen.

Shape Consenter Together

Consenter is built on an open and participatory process that grows through community collaboration. Whether you share feedback, improve the documentation, or contribute to the Risk Configuration Guides or Technical Integration Guides, your expertise helps make Consenter more privacy-friendly, interoperable, and useful for everyone—including your own users and services: Get finally your benefits and control the risks when sharing personal data.

Last updated on

On this page