TL;DR, Quick Answer
6 min readGoogle Analytics usually needs prior analytics-storage consent in the EU/UK unless a narrow exemption applies. Cookieless tools can reduce consent complexity only when configured without non-essential storage, persistent IDs, fingerprinting, or advertising reuse.
A Google Analytics cookie consent script that loads after GA4 has already fired is not consent at all, because the identifiers were stored and the data sent before anybody clicked anything.
In the EU and UK, that usually means Google Analytics should not load until the visitor gives valid consent for analytics storage, unless a narrow national exemption applies and the implementation qualifies. Most standard GA4 implementations do not.
Consent Must Come Before Tracking
A common mistake is showing a banner while Google Analytics has already fired. That is not consent. The page has already stored or accessed identifiers and sent data.
The correct sequence is:
- Page loads with non-essential analytics disabled.
- Banner or preference UI appears.
- Visitor accepts analytics.
- GA4 loads or receives updated consent signals.
- Analytics cookies and events begin only after consent.
If the visitor rejects analytics, GA4 should not set analytics cookies. If you use Google Consent Mode, configure defaults as denied before any Google tag runs.
- Identifiers already stored
- Data already sent to Google
- The click confirms nothing
- Analytics storage denied by default
- GA4 waits for an affirmative accept
- Cookies and events start only after consent
Understand Consent Mode
Google documents consent types such as analytics_storage, which controls storage related to analytics, and advertising-related signals such as ad_storage, ad_user_data, and ad_personalization.
Consent Mode can help tags adapt to consent choices, but it is not a substitute for a lawful consent interface. It also does not make every data flow anonymous or consent-free. Your CMP, tag configuration, regional settings, and vendor disclosures still matter.

Implementation Mistakes to Avoid
Loading GTM before consent without controls. Google Tag Manager can be configured carefully, but it can also load many third-party tags before consent if triggers are wrong.
Treating "continue browsing" as consent. EDPB consent guidance requires a clear affirmative act. Passive browsing is not enough.
Making reject harder than accept. Dark patterns can invalidate consent and create enforcement risk.
Forgetting linked products. GA4 linked to Google Ads, Google signals, or remarketing features creates a different privacy profile than basic measurement.
Sending personal data in events. Never send emails, names, phone numbers, account IDs, or form text to GA4.
Ignoring withdrawal. Users must be able to change choices, and tracking should stop after withdrawal.
Why Consent Creates Data Gaps
If consent is required and some users decline, your analytics will be incomplete. That is not a bug. It is the legal and ethical consequence of asking.
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
Expect gaps by:
- region
- browser
- device type
- traffic source
- audience privacy preference
- ad blocker usage
Do not "fix" the gap by firing tags before consent. Instead, interpret reports as consented-user analytics and use privacy-first aggregate tools when you need a fuller view of basic traffic.
A Safer GA4 Setup
If you keep GA4, configure it conservatively:
- default consent to denied in applicable regions
- disable Google signals where not needed
- disable granular location and device collection where appropriate
- avoid remarketing audiences unless consent explicitly covers them
- sanitize URLs and event parameters
- set retention deliberately
- document vendor terms and transfer mechanism
- test cookies before and after consent
Google says GA4 does not log or store IP addresses and offers EU-focused data controls, including EU collection routing and regional settings. Those controls are useful, but they do not remove cookie consent obligations where ePrivacy rules apply.
When to Use Cookieless Analytics Instead
For many teams, GA4 is more complex than the question they need answered. If you mainly need pageviews, referrers, campaigns, top pages, and conversions, a cookieless privacy-first analytics tool is simpler.
Look for:
- no cookies by default
- no cross-site tracking
- no ad network data sharing
- aggregate reports
- query-string sanitization
- short retention controls
- transparent data processing
This can reduce the need for analytics consent banners in some jurisdictions and reduce dependence on opt-in data, while still respecting visitors. The key is the actual configuration, not the cookieless label.
- pageviews, referrers, and campaigns
- top pages and conversions
- aggregate reporting, not individual visitors
- user-level tracking
- Google Signals or remarketing audiences
- GA4 linked to Google Ads
The Bottom Line
Google Analytics can be configured more carefully than many default installations, but it remains a consent-heavy tool in much of Europe. If you use it, load it only after valid consent and keep payloads minimal.
If you do not need user-level tracking or ad integration, choose analytics that was designed not to need them.
Consent QA Checklist
Record whether enhanced measurement, Google Signals, ads personalization, User-ID, BigQuery export, Consent Mode, cross-domain measurement, and region-specific settings are enabled. Then test consent like a feature, not a banner design. In a clean browser, load the site and reject analytics. Confirm no GA4, Google tag, GTM analytics tag, advertising pixel, or related storage fires before or after rejection. Accept analytics and confirm only the expected tags load. Change the choice and confirm the site updates state without requiring users to clear cookies. The EDPB's cookie banner taskforce report is useful because many failures are interface and implementation failures, not only legal wording failures.
Then test edge cases: landing on a deep link, navigating between pages, using embedded forms, submitting a conversion, switching language, and returning after consent expiry. Keep screenshots, network logs, CMP settings, and tag configurations as evidence. If GA4 is configured through GTM, test both the consent platform and the container. If your site needs only aggregate audience measurement, compare the operational cost of this QA process with a cookieless analytics setup that avoids consent-heavy identifiers in the first place.
Frequently Asked Questions
Does Google Analytics need cookie consent in the EU?
In the EU and UK, GA4 usually needs prior consent for analytics storage before it loads, unless a narrow national exemption applies and the implementation qualifies. Most standard GA4 setups do not meet that exemption. Consent Mode can help tags react to a visitor's choice, but it does not replace a lawful consent interface.
What is Google Consent Mode and does it replace a cookie banner?
Consent Mode is a Google framework that lets tags such as GA4 adapt to signals like analytics_storage, ad_storage, ad_user_data, and ad_personalization. It changes how tags behave after a choice is made, but it is not a substitute for a lawful consent interface, and it does not make data flows anonymous or consent-free on its own.
Why does showing a banner after GA4 already loaded not count as consent?
If GA4 has already fired, the identifiers were stored and the data was already sent to Google before the visitor saw any choice. A banner shown afterward only asks a question the tag already answered for itself. Valid consent has to happen before any non-essential storage or event collection.
What counts as an affirmative act of consent under EDPB guidance?
EDPB guidance requires a clear affirmative act, such as clicking accept, rather than continued browsing or scrolling. Treating "continue browsing" as consent does not meet that bar. Making the reject option harder to find than accept can also count as a dark pattern that invalidates consent.
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
Should personal data ever be sent to GA4 events?
No. Emails, names, phone numbers, account IDs, and form text should never be sent as GA4 event parameters. Sanitizing URLs and event parameters before they reach GA4 is part of a conservative setup.
What happens to GA4 data if a visitor withdraws consent?
Tracking must stop after withdrawal, and users need a way to change their choice at any time. A safer setup also tests that the site updates its state after a change without requiring the user to clear cookies. Ignoring withdrawal is one of the implementation mistakes that undermine an otherwise correct banner.

Why do consent-based analytics reports show data gaps?
Once consent is required, users who decline leave a gap in reporting by region, browser, device type, traffic source, audience privacy preference, and ad blocker usage. That gap is the expected result of asking, not a bug to patch by firing tags early. The right response is to treat the reports as consented-user analytics and pair them with privacy-first aggregate tools when a fuller view of basic traffic is needed.
Does linking GA4 to Google Ads change its privacy profile?
Yes. GA4 linked to Google Ads, Google Signals, or remarketing features creates a different privacy profile than basic measurement alone. A conservative setup disables Google Signals where it is not needed and avoids remarketing audiences unless consent explicitly covers them.
What should a consent QA test check before and after rejection?
In a clean browser, load the site, reject analytics, and confirm that no GA4, Google tag, GTM analytics tag, advertising pixel, or related storage fires before or after rejection. Then accept and confirm only the expected tags load, and change the choice again to confirm the site updates without a cookie clear. Edge cases worth testing include deep links, page navigation, embedded forms, conversions, language switches, and consent expiry.
When is a cookieless analytics tool a better fit than GA4?
A cookieless tool fits well when the reporting need is limited to pageviews, referrers, campaigns, top pages, and conversions, without user-level tracking or ad integration. Look for no cookies by default, no cross-site tracking, no ad network data sharing, aggregate reports, query-string sanitization, short retention controls, and transparent data processing. The configuration matters more than the cookieless label itself.
Was This Article Helpful?
Let us know what you think!
See us more often in Google
One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.
Before you go...
Flowsery
Revenue-first analytics for your website
Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.
Real-time dashboard
Goal tracking
Cookie-free tracking
Related Articles


Explained Clearly - Block Google Analytics Safari
Apple's ITP does not block Google Analytics Safari requests outright; it strips the cookies behind them. What breaks in GA4, and how to read the gaps.


A Practical Guide to Apple Privacy Features and Analytics Accuracy
Apple iOS privacy features impact analytics through ITP, App Tracking Transparency and mail privacy. What to expect in the reports, and how to adapt.


A Practical Guide to Bot Traffic Filtering for Analytics Accuracy
Crawlers, uptime monitors, scrapers and your own automation all land in the same reports. How to audit them out before they distort conversion rates.

