ENSLČlanek je na voljo samo v angleščini.Slovenske novice →Book a free audit

Analytics & tracking

GA4 and Data Privacy in 2026: GDPR, Consent Mode and Key Settings

Updated

3D illustration of a smartphone with a padlock, a shield with a check mark and a server box with a key, representing data protection.

GA4 is more privacy-friendly than Universal Analytics was: it doesn’t log or store IP addresses, lets you shorten data retention, can redact emails and query parameters, and works with Google’s Consent Mode. But no analytics tool is GDPR or CCPA compliant on its own. Whether your GA4 setup is compliant depends on how you configure it, whether you ask for consent where the law requires it, and what your contracts and privacy policy say.

This guide covers what GA4 does with data, how consent works in 2026, the settings we check on every client property, and where server-side tagging helps. It’s practical guidance from analytics work, not legal advice; your lawyer or DPO has the final word.

Is GA4 GDPR compliant?

GA4 can be used in a GDPR-compliant way, but it isn’t compliant by default. Some background explains why the question keeps coming up.

In 2022, several EU data protection authorities ruled that specific websites’ use of Universal Analytics broke GDPR, mainly because personal data was transferred to the US without adequate protection. In July 2023 the EU adopted the EU-US Data Privacy Framework, which gives a legal basis for transfers to US companies certified under it, and Google relies on it. That removed the main transfer objection, but the rest of GDPR still applies to you as the website owner:

  • Consent. In the EU and UK, analytics cookies generally need consent before they are set, under the ePrivacy rules that sit alongside GDPR.
  • A processing agreement. Accept Google’s data processing terms in GA4’s account settings.
  • Transparency. Your privacy policy has to say that you use Google Analytics, what for, and how long you keep the data.
  • Minimisation. Collect only what you use, and never send personal data such as names or email addresses to GA4.

What does GA4 do with IP addresses and personal data?

GA4 uses the IP address to work out an approximate location and then discards it; it doesn’t log or store IP addresses. The old “anonymize IP” setting from Universal Analytics doesn’t exist in GA4 because it’s no longer needed.

Personal data is a different matter, and it’s usually the site’s own fault. Google’s terms forbid sending personally identifiable information to Analytics, and it leaks in more often than people think:

  • Email addresses in URLs, for example ?email= after a form submission or in a newsletter link.
  • Names or phone numbers in page titles, search terms or custom event parameters.
  • A raw email address used as the User-ID.

GA4’s data redaction setting (in the web data stream settings) can strip email addresses and query parameters you name before data is stored. Use it as a safety net, and fix the source as well.

Through Consent Mode. Your consent banner (a consent management platform, ideally one certified by Google) tells Google tags what each visitor agreed to, using four signals:

Consent signal Controls
analytics_storage Analytics cookies (GA4)
ad_storage Advertising cookies
ad_user_data Sending user data to Google for advertising
ad_personalization Personalised advertising, such as remarketing

The last two were added in Consent Mode v2. Since March 2024, Google has required Consent Mode v2 for traffic from the European Economic Area (and, in practice, the UK) if you want to keep using features such as remarketing audiences and ad measurement.

There are two ways to implement it:

  • Basic Consent Mode: Google tags don’t load until the visitor consents. Simple and conservative; you lose all data from visitors who decline.
  • Advanced Consent Mode: tags load with consent denied and send cookieless pings. GA4 can then model some of the missing behaviour once your property meets Google’s data thresholds.

Which one is appropriate depends on your legal advice and your market. Either way, test it: we often find banners that show up correctly while tags fire before the visitor has chosen anything.

Which GA4 settings should you check for privacy?

Setting Where in GA4 What we usually do
Data retention Admin → Data collection and modification → Data retention Set it to match your privacy policy. Standard properties offer 2 or 14 months for event-level data used in Explorations; standard reports aren’t affected.
Data redaction Admin → Data streams → web stream → Redact data Turn on email redaction; add query parameters that may carry personal data.
Google signals Admin → Data collection Only on if you need cross-device ad features and your consent text covers it.
Granular location and device data Admin → Data collection Can be switched off per region if you don’t need city-level or detailed device data.
Ads personalisation Admin → Data collection Can be disabled per region, which helps with US state opt-out rules.
Data sharing settings Admin → Account settings Share only what you need with Google.
Data processing terms Admin → Account settings Accept them.
User-ID Your tag setup Use an internal ID, never an email address.
User access Admin → Account / Property access Least privilege; review regularly and remove leavers.

For retention and scoping decisions in more depth, see GA4 data governance: retention and scoping.

What about CCPA and other US privacy laws?

The CCPA, as amended by the CPRA, gives California residents the right to know what is collected and to opt out of the “sale” or “sharing” of their personal information, which can include data used for cross-context advertising. A growing number of US states have passed similar laws, so a US-wide approach is often simpler than a California-only one.

In practice that means: a clear privacy notice, a working opt-out link, a banner or CMP that respects opt-out signals such as Global Privacy Control where required, and GA4’s ads personalisation switched off for the regions concerned. Analytics on its own is generally lower risk than advertising use; the risk rises once GA4 audiences feed Google Ads.

How does server-side tagging help with privacy?

Server-side tagging sends data from the browser to your own first-party endpoint first, and from there to Google, Meta and other platforms. That lets you control exactly what leaves: drop or trim fields, remove personal data before it reaches a vendor, and keep third-party scripts off your pages.

It doesn’t replace consent: the same rules apply to what the server forwards. But it turns “whatever each script decides to collect” into a pipeline you control. We use a first-party endpoint together with Meta’s Conversions API and Google’s Enhanced Conversions; for ATC Alert, server-side tagging was part of the rebuild (the ATC Alert case). The setup is explained in our server-side Google Tag Manager guide.

Do you have to choose between privacy and useful data?

Not really, but you trade some precision. With consent required, GA4 will see fewer users than actually visit, and models fill part of the gap. Three habits keep the data useful anyway:

  • Track decisions, not everything. Each event should answer a question someone will act on. Fewer, cleaner events are easier to defend and easier to read.
  • Lean on first-party data for outcomes. Revenue and qualified leads live in your CRM. Sending closed deals back to the ad platforms as offline conversions is more reliable than counting on browser tracking; see offline conversions via the GA4 Measurement Protocol.
  • Reconcile against the source of truth. Use GA4 for trends and behaviour, and your CRM or billing system for money.

How do you handle data deletion requests?

  • Single users: GA4’s User explorer can delete one user’s data, and the User Deletion API does it in bulk by user or client ID.
  • Data collected by mistake (for example, emails in URLs): use a data deletion request in GA4’s admin to remove the affected parameters for a date range, then fix the source so it doesn’t happen again.
  • Everything else is governed by your retention setting, so keep it no longer than you need.

What is a quick GA4 privacy checklist?

  1. A consent banner that blocks or adjusts tags before a choice is made, with Consent Mode v2 implemented and tested.
  2. Google’s data processing terms accepted.
  3. Data retention set to match your privacy policy.
  4. Email and sensitive query-parameter redaction turned on.
  5. No personal data in URLs, page titles, events or User-ID.
  6. Google signals and granular data collection on only where needed and disclosed.
  7. Ads personalisation switched off for regions with opt-out rules where required.
  8. Access reviewed, with least privilege.
  9. A documented process for deletion requests.
  10. A privacy policy that names Google Analytics and explains what you do with the data.

If you’re setting up a property from scratch, our GA4 setup to-do list covers the rest.

FAQ

Yes, it can be used lawfully in the EU, provided you get consent where required, accept Google’s processing terms, configure it to avoid personal data and explain it in your privacy policy. The 2022 rulings concerned specific Universal Analytics setups and data transfers; the 2023 EU-US Data Privacy Framework changed the transfer picture.

For visitors in the EU and UK, generally yes: GA4 sets analytics cookies, which normally require consent. In the US, most state laws work on an opt-out basis instead, so a notice and a working opt-out are the usual minimum.

Does GA4 store IP addresses?

No. GA4 uses the IP address to derive approximate location and then discards it; it doesn’t log or store IP addresses.

How long does GA4 keep data?

On standard properties, event-level data used in Explorations is kept for 2 or 14 months, depending on your setting; Analytics 360 offers longer options. Aggregated standard reports aren’t affected by the retention setting.

If you’d like your GA4 property and consent setup checked, our GA4 team does exactly that; get in touch.

Related reading