The short answer
Yes, for visitors in the EU and the EEA. GA4 writes the cookies _ga and _ga_<container-id> to the visitor’s browser. Storing or reading them needs prior consent under Article 5(3) of the ePrivacy Directive, because analytics is not strictly necessary.
In the UK the answer is almost always yes. The Data (Use and Access) Act 2025 added a statistics exemption on 5 February 2026, but a standard GA4 setup does not meet its conditions. In the US you need no opt-in, but visitors can opt out, and California requires you to honour Global Privacy Control. In Switzerland, informing visitors and offering an objection is usually enough, unless GA4 feeds advertising or cross-site tracking.
None of this changed when the EU-US Data Privacy Framework arrived in 2023. That framework covers data transfers. It does not touch the cookie rule.
What GA4 stores and sends
Google’s own documentation lists two cookies for a standard GA4 tag.
_gadistinguishes users. It holds the client ID and expires after 2 years by default._ga_<container-id>keeps the session state. It also expires after 2 years by default.
On every page view, the tag sends a request to Google that carries the client ID as the cid parameter, plus the page, the referrer and browser details.
On IP addresses, Google makes three specific claims for GA4. It does not log or store individual IP addresses from EU, Swiss or UK users. It performs the IP lookup for coarse location on servers in the EU, Switzerland or the UK. And it drops the IP address before the data is logged. The IP still reaches Google, as every request carries one.
Google does not promise that GA4 data stays in the EU. Its transfer page says that Google relies on the Data Privacy Framework to move EEA personal data to the US, and on standard contractual clauses where no framework applies.
The rules by region
EU and EEA
Two laws apply side by side. The ePrivacy Directive, Article 5(3), covers storing or reading anything on the visitor’s device. It needs consent unless the storage is strictly necessary for a service the visitor asked for. The GDPR then covers what happens to the personal data, including the client ID, which the CNIL and the Austrian DSB both treated as personal data in 2022.
The EDPB’s Guidelines 2/2023 make the scope wide. They cover cookies, local storage and pixels, and scripts that make the browser send information. Some regulators exempt limited audience measurement from consent. The CNIL is the best-known example. Its exemption requires information, an objection route, measurement as the only purpose and a cookie lifetime of at most 13 months. The CNIL also says most large audience measurement offerings fall outside the exemption, whatever their configuration.
United Kingdom
The UK rule is Regulation 6 of PECR. Since 5 February 2026, a new Schedule A1 lets you store or read data without consent for statistical purposes. The conditions are strict.
- The purpose is to learn how your service is used, to improve it.
- The data is not shared, except with someone who helps you make those improvements.
- You give clear and comprehensive information about the purpose.
- You offer a simple, free way to object, and the visitor has not objected.
The ICO’s final guidance adds that a third-party analytics provider has to be your processor, not a joint controller. It may only use the data to help you improve your service. A standard GA4 property sends data to Google under Google’s terms, and some sharing settings let Google use it for its own purposes. As we set out in our post on the UK cookie rules, GA4 with every sharing setting off is arguable, and the ICO has not endorsed it. The conservative reading keeps GA4 behind consent in the UK. The maximum PECR fine is now £17.5 million or 4 percent of global annual turnover, whichever is higher.
United States
No federal law requires opt-in consent for analytics cookies. The state privacy laws work on opt-out instead. Under the CCPA as amended by the CPRA, Californians can tell you to stop selling or sharing their personal information. Sharing means passing it on for cross-context behavioural advertising.
Plain GA4 measurement is usually not a sale or a share. Linking GA4 to Google Ads for personalised advertising, or turning on Google signals, can change that. California treats Global Privacy Control, a browser setting, as a valid opt-out request. Several other states, Colorado among them, also require you to honour universal opt-out signals.
Switzerland
Article 45c of the Telecommunications Act allows storage on a device if visitors are told about it and its purpose, and are told they can object. The revised Federal Act on Data Protection, in force since 1 September 2023, governs the personal data itself. The FDPIC’s factsheet of 31 March 2026 says explicit prior consent is needed when processing is unexpected, high risk or involves sensitive data. Its guidelines put personalised advertising with third-party cookies and cross-site tracking in that group. GA4 used only for measurement usually needs information and an opt-out. GA4 that feeds advertising moves into the opt-in cases.
The 2022 rulings and the Data Privacy Framework
In 2020 the Court of Justice struck down the Privacy Shield in its Schrems II judgment. The privacy group noyb then filed 101 complaints against websites using US tools. Three decisions on Google Analytics followed in 2022.
- Austria, January 2022. The DSB published a decision finding that a health website’s use of Google Analytics breached Article 44 GDPR. It held that Google’s technical measures did not prevent access by US intelligence agencies.
- France, 10 February 2022. The CNIL ordered a website operator to bring its Google Analytics use into line with Chapter V GDPR within one month. It noted that IP anonymisation was optional and possibly applied only after transfer.
- Italy, 9 June 2022. The Garante found that a publisher’s transfers through Google Analytics lacked adequate safeguards and ordered it to comply or stop.
Those decisions concerned Universal Analytics and transfers, not cookies. Two things changed since. GA4 now handles EU IP addresses as described above. And on 10 July 2023 the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework. Google LLC has certified under it, and Google says it has relied on it for its ads and analytics products since 1 September 2023. The General Court upheld the framework on 3 September 2025 in Latombe v Commission. An appeal to the Court of Justice is pending.
Why the DPF does not remove the consent requirement
The DPF answers one question: may personal data travel to a certified US company? The cookie rule answers a different one: may you store or read data on this visitor’s device? Article 5(3) applies whatever happens to the data afterwards, and even if the data never leaves the EU. A valid transfer basis is necessary. It is not a substitute for consent.
Where Consent Mode fits
Google Consent Mode v2 is a signal, not a banner and not a blocker. Our Consent Mode guide covers the seven signals in detail. For GA4, the one that matters is analytics_storage. Google offers two implementations.
- Basic mode. Google tags do not load until the visitor consents. Google’s documentation says no data is sent before consent.
- Advanced mode. Tags load at once with all signals set to denied. Until consent, they send cookieless pings. Google lists their content as a timestamp, the user agent, the referrer, the consent state, a random number per page load and whether an ad click ID is present. Google uses them for modelling.
In a GA4 request, the gcs parameter shows the storage consent state. It reads G1, then one digit for ad_storage and one for analytics_storage. So gcs=G100 means both are denied, and G111 means both are granted.
Whether advanced mode is lawful before consent is debated. Google’s position is that the pings set no cookies and carry no identifiers. The counter-argument points to the EDPB’s 2023 guidelines, which bring scripts that make the browser send information within Article 5(3). We found no EU regulator decision on advanced-mode pings as of 23 September 2026. Basic mode avoids the question. That is why CookieCrumbs defaults to basic and supports both.
GA4 settings that lower the risk
These settings reduce what GA4 collects. None of them removes the consent requirement in the EU.
- Data retention at 2 months. Standard properties offer 2 or 14 months for user-level and event-level data. The setting affects explorations, not standard aggregated reports.
- Google signals off. Signals add data from signed-in Google users for cross-device reporting. Switch it off under Admin, Data collection, or per region.
- Granular location and device data off for the EU. This stops collection of city, city coordinates, browser minor version, the user agent string, device brand, model and name, and screen resolution.
- Ads personalisation off per region. This keeps GA4 data out of personalised advertising where you do not need it.
- Data sharing settings reviewed. Under Account settings, switch off the sharing options you do not need.
GA4 does not store EU IP addresses, so there is no IP anonymisation switch to set.
Does server-side tagging remove the consent requirement?
Not by itself. Server-side tagging moves the tag logic from the browser to a server you control. The browser still talks to that server, and GA4 still needs a client identifier to count users. That identifier usually lives in a first-party cookie set by your own domain. Setting or reading it is still access to the device under Article 5(3).
What server-side tagging does give you is control. You can strip fields, shorten data and decide what reaches Google. It does not replace the banner.
Cookieless analytics
Some analytics tools set no cookies and store nothing on the device. They count visits from server logs or from requests without identifiers. In the EU that can remove the need for consent, but only if the tool truly neither stores nor reads anything on the device. Check the vendor’s documentation against the EDPB’s 2023 guidelines, and scan your site to confirm. If you keep GA4, it stays behind consent.
Decision table: does your GA4 setup need consent?
| Region and setup | Consent needed? | What to do |
|---|---|---|
| EU or EEA, standard GA4 | Yes | Block GA4 until the analytics category is granted. |
| EU or EEA, Consent Mode basic | Yes | Tags load only after consent. This is the clean setup. |
| EU or EEA, Consent Mode advanced | Yes, pings debated | Cookies wait for consent. Declare the cookieless pings in your privacy policy. |
| EU or EEA, server-side tagging | Yes | The identifier cookie still needs consent. |
| UK, standard GA4 | Yes | Keep opt-in, with Reject as easy as Accept. |
| UK, GA4 with signals and sharing off | Arguable | The ICO has not endorsed it. Consent is the safe reading. |
| Switzerland, measurement only | Usually opt-out | Inform visitors and offer a way to object before GA4 runs. |
| Switzerland, GA4 feeding advertising | Yes | Ask for explicit consent. |
| US states | No opt-in | Offer an opt-out of sale and sharing, and honour GPC. |
| EU or EEA, analytics that stores nothing | Check first | Verify that nothing is stored or read on the device. |
Check your site in DevTools
- Open a private window. Load your live site, not a staging copy.
- Open DevTools, then Network. Filter for
collectand reload. GA4 page views go to a URL containing/g/collect. - Read what you see before clicking the banner. In basic mode, there should be no request at all, and no
gtag/jsload. In advanced mode, you may see requests withgcs=G100, which means both storage signals are denied. - Check Application, then Cookies. There should be no
_gaor_ga_cookie yet. - Click Reject all and browse two more pages. Still no GA4 cookies, still nothing granted in
gcs. - Accept analytics in a fresh private window. Now
_gashould appear and requests should showG101orG111.
If you would rather not click through it, the free scan reads your homepage and lists the trackers it finds before consent.
Checklist
- The consent script is the first script in the head, above gtag.js and Google Tag Manager.
- Consent Mode defaults are set to denied for the EEA, the UK and Switzerland before any Google tag runs.
- GA4 loads, or sets cookies, only after the analytics category is granted.
- Reject all sits next to Accept all on the first layer. See our post on the CNIL’s first-layer rule.
- Every choice is recorded, so you can prove consent under Article 7(1) GDPR. See proof of consent.
- Data retention is 2 months, Google signals are off, and granular location and device data are off for the EU.
- US visitors get an opt-out link, and GPC is honoured.
- Your privacy policy names GA4, its cookies, the transfer basis and, in advanced mode, the cookieless pings.
The Consent Mode docs show how CookieCrumbs maps its categories to Google’s signals. CookieCrumbs is not a Google-certified CMP and does not emit IAB TCF strings. That matters for AdSense and Ad Manager, not for GA4.
FAQ
Does GA4 need cookie consent under GDPR?
For EU and EEA visitors, yes. Strictly, the consent rule comes from Article 5(3) of the ePrivacy Directive, because GA4 stores cookies on the device. The GDPR then sets the standard for that consent and governs the data afterwards.
Is GA4 legal in the EU now that the Data Privacy Framework exists?
The DPF gives a legal basis for transfers to Google LLC, which is certified. That settles the question the 2022 rulings raised, while the framework stands. It does not remove the need for consent before GA4 sets cookies.
Does Google Consent Mode make GA4 compliant without a banner?
No. Consent Mode only passes on a decision that your banner collects. Without a banner there is no decision, and in the EU you may not set GA4 cookies.
Can I use GA4 in the UK without consent after February 2026?
Only if you meet every condition of the statistics exemption. Google must act solely as your processor, and the data must only help you improve your site. A standard GA4 property does not meet that, so the safe reading is still consent.
Do US visitors need a cookie banner for GA4?
No opt-in banner is required. You do need a clear opt-out of sale and sharing where state law applies, and in California you must honour Global Privacy Control.
Sources
- Google Analytics Help, “Google Analytics cookie usage on websites”, read 23 September 2026
- Google Analytics Help, “EU-focused data and privacy”, IP handling and granular data settings, read 23 September 2026
- Google Analytics Help, “Data retention”, read 23 September 2026
- Google Analytics Help, “Activate Google signals for Google Analytics properties”, read 23 September 2026
- Google for Developers, “Consent mode overview”, read 23 September 2026
- Simo Ahava, “Consent Mode V2 for Google Tags”, on the gcs parameter, read 23 September 2026
- Google, “Advertising and analytics products: information about international data transfers”, read 23 September 2026
- Google Privacy and Terms, “Data transfer frameworks”, read 23 September 2026
- Directive 2002/58/EC (ePrivacy Directive), Article 5(3)
- EDPB, Guidelines 2/2023 on the technical scope of Art. 5(3) of the ePrivacy Directive
- CNIL, “Sheet n°16: Use analytics on your websites and applications”, read 23 September 2026
- noyb, “Austrian DSB: EU-US data transfers to Google Analytics illegal”, 13 January 2022
- CNIL, decision ordering a company to comply, Google Analytics, 2022, published by the EDPB
- EDPB national news, “Italian SA bans use of Google Analytics”, June 2022
- Commission Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy Framework, 10 July 2023
- IAPP, “European General Court dismisses Latombe challenge, upholds EU-US Data Privacy Framework”, September 2025
- Data (Use and Access) Act 2025, Schedule 12, new Schedule A1 to PECR
- ICO, “What are the exceptions?”, guidance on storage and access technologies, read 23 September 2026
- California Attorney General, “California Consumer Privacy Act”, read 23 September 2026
- FDPIC, factsheet “Use of cookies and other similar technologies in the context of online tracking”, 31 March 2026