Tutorials

A Practical Guide to Pii Identifiers

Taras Shynkarenko
Taras Shynkarenko
•Updated: •7 min read
A Practical Guide to pii identifiersA Practical Guide to pii identifiers

TL;DR, Quick Answer

7 min read

Google Analytics uses multiple identification mechanisms. Many are pseudonymous online identifiers rather than direct PII, but they can still be personal data under GDPR and can trigger ePrivacy consent when stored on or accessed from a user's device.

Every Google Analytics user ID GDPR regulators examine raises the same question, and it is not whether the value looks like a name: can it single out a browser, device, app install or account?

Google Analytics identifiers are not just technical implementation details. They are the mechanism that lets GA4 distinguish users, connect events into sessions, power advertising features, and create reports that feel more precise than aggregate page counters.

For privacy teams, the key question is not whether an identifier looks like a name. It is whether it can single out a browser, device, app installation, account, or person. Under GDPR, online identifiers can be personal data when they relate to an identifiable person.

That does not make every analytics identifier "PII" in the narrow everyday sense of name, email, phone number, or address. A Client ID is usually pseudonymous. It still deserves controls because pseudonymous identifiers can link behavior over time and may become identifiable when combined with other data.

Client ID

For websites, Google says Analytics stores a client ID in a first-party cookie named _ga to distinguish unique users and sessions (GA4 data collection). Google also says customers can control whether cookies are used to store a pseudonymous or random client identifier (Google Analytics safeguards).

A client ID is pseudonymous, not anonymous. It may not contain a name, but it can link page views and events from the same browser over time. Combined with IP-derived location, device information, page paths, campaign data, and event details, it becomes a behavioral record.

User ID

User ID is optional, but more sensitive. It lets a site send its own identifier for authenticated users so Analytics can connect activity across devices and sessions. If implemented carelessly, this can become direct personal data or a stable internal identifier that makes re-identification easy.

Never send email addresses, usernames, phone numbers, or CRM IDs into Google Analytics as User IDs or custom dimensions unless legal review explicitly approves it. Google Analytics policies prohibit sending personally identifiable information to Analytics, and privacy risk rises sharply when analytics joins to account data.

Session ID And Event Identifiers

GA4's event model groups interactions into sessions and events. Session identifiers help reports calculate engagement, conversions, and journeys. Even when a single session ID is short-lived, it can still reveal behavior within a visit: pages viewed, files downloaded, form steps reached, and outbound clicks.

That matters on sensitive sites. A session that includes visits to mental health, legal aid, political, or medical pages can reveal more than the user intended.

A person browsing an app on a smartphone, illustrating how mobile devices generate their own identifiers.

App Instance ID And Mobile Identifiers

For apps, Google says the Firebase SDK automatically generates and assigns an app-instance identifier to each app instance, and the SDK can collect mobile identifiers such as Android Advertising ID and iOS Identifier for Advertisers where available (GA4 data collection).

Mobile identifiers raise additional consent and platform-policy issues. On iOS, Apple's App Tracking Transparency framework may require user authorization for tracking across apps and websites owned by other companies. On Android, advertising ID behavior depends on platform settings and permissions.

Google Signals

Google Signals is a separate privacy consideration. Google says activating Google Signals can enable remarketing, advertising reporting features, and demographics and interests from users signed into Google accounts who have Ads Personalization enabled (Google Signals documentation).

That can be useful for advertisers, but it moves analytics closer to advertising identity. If you do not need remarketing or demographic reporting, disabling Google Signals reduces risk and simplifies the explanation in your privacy notice.

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

IP Addresses And Location

Google says GA4 does not log or store IP addresses, and uses IP addresses for purposes such as deriving location and protecting the service (Google Analytics safeguards). That is a meaningful control, but it does not make the rest of the analytics dataset anonymous. Client IDs, event sequences, device data, and account-linked features can still be personal data.

Avoid the common mistake of saying "GA4 is anonymous because IP addresses are not stored." Privacy law looks at the full dataset and reasonable identifiability, not only one field.

How GA4 identifiers escalate in sensitivity
1
Client ID. Pseudonymous, stored in the first-party _ga cookie, links page views from the same browser over time.
2
Session and event identifiers. Short-lived but can reveal pages viewed, files downloaded, form steps, and outbound clicks within a visit.
3
User ID. Optional identifier for authenticated users that can become direct personal data if implemented carelessly.
4
Google Signals. Enables remarketing and demographics from users signed into a Google account with Ads Personalization on, moving analytics closer to advertising identity.
5
Mobile identifiers. App Instance ID plus Android Advertising ID or iOS Identifier for Advertisers, which raise their own consent and platform-policy questions.
Each identifier layer in GA4 carries more re-identification risk than the one before it.

In Europe, storing or accessing identifiers on a device can trigger ePrivacy cookie consent rules. GDPR then governs the personal data processing that follows. These are related but separate questions: ePrivacy may require consent for the storage or access mechanism, while GDPR requires a lawful basis for the subsequent processing. That lawful basis is often consent for advertising or profiling, but it is not accurate to say every identifier always requires GDPR consent in every configuration.

Valid consent, when used, must be freely given, specific, informed, and unambiguous, as the EDPB explains (EDPB consent guidance).

If GA4 is configured with advertising features, long retention, User ID, or Google Signals, the consent and transparency burden increases. If it is configured only for limited measurement behind a CMP, the risk may be lower but not zero.

Why identifiers trigger two separate questions
Identifier stored or accessed on a device
ePrivacy consent for the storage or access
Personal data processing begins
GDPR lawful basis required
ePrivacy governs the storage mechanism, then GDPR governs what happens to the data next.

Safer Configuration Checklist

For teams that keep GA4, consider these controls:

  • Disable Google Signals unless specifically needed
  • Do not enable ads personalization by default
  • Do not send User ID unless necessary and reviewed
  • Never send emails or other direct identifiers
  • Remove personal data from URLs before tracking
  • Keep event properties categorical and minimal
  • Use Consent Mode carefully and understand basic vs advanced mode
  • Shorten data retention where possible
  • Exclude internal traffic
  • Review linked Google Ads and BigQuery exports

For teams that only need website performance, campaigns, and conversions, consider privacy-first analytics that avoids persistent identifiers entirely.

An analyst reviews a spreadsheet on a laptop, reflecting the work of auditing which identifiers a system collects.

Identifier Audit Checklist

Separate direct identifiers, pseudonymous online identifiers, and aggregate metrics. Record whether enhanced measurement, Google Signals, ads personalization, User-ID, BigQuery export, Consent Mode, cross-domain measurement, and region-specific settings are enabled. For each identifier, document its purpose, lifespan, storage location, legal basis, consent dependency, and whether it leaves your organization.

Keep GA4 only where the Google ads or reporting ecosystem justifies the privacy, consent, and maintenance cost. For baseline pages, referrers, campaigns, goals, and aggregate funnels, privacy-first analytics may answer the question with fewer identifiers.

The Bottom Line

Identifiers are what turn analytics from aggregate counting into behavioral measurement. Sometimes that is justified. Often it is more than a marketing site needs.

Before enabling another identifier, ask what decision it supports. If the answer is vague, leave it off. The cleanest analytics stack is the one that measures outcomes without accumulating identity.

Audit Custom Dimensions

Custom dimensions are where many GA4 privacy problems enter. Review every dimension and parameter for direct identifiers, internal IDs, free text, and sensitive context. If a property is only useful to identify a person or account, it probably belongs in a CRM or product database with stricter access controls, not in a marketing analytics report.

Frequently Asked Questions

Is a Google Analytics client ID personal data under GDPR?

A client ID is pseudonymous, not anonymous. It can link page views and events from the same browser over time, and once combined with IP-derived location, device information, or campaign data it can become a behavioral record. Whether that counts as personal data under GDPR depends on whether it can single out an identifiable person.

What is the difference between GA4 Client ID and User ID?

Client ID is the pseudonymous identifier Google Analytics stores in the first-party _ga cookie to distinguish browsers and sessions. User ID is optional and lets a site send its own identifier for authenticated users so Analytics can connect activity across devices, which makes it more sensitive and closer to direct personal data if implemented carelessly.

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

Can I send email addresses to Google Analytics as a User ID?

No. Google Analytics policies prohibit sending personally identifiable information such as email addresses, usernames, phone numbers, or CRM IDs into Analytics as User IDs or custom dimensions, and doing so should go through explicit legal review. Joining analytics to account data sharply raises privacy risk.

Does GA4 store IP addresses?

Google says GA4 does not log or store IP addresses, though it uses them briefly to derive location and protect the service. That control does not make the rest of the dataset anonymous, since client IDs, event sequences, and device data can still be personal data.

Does disabling IP storage make GA4 anonymous?

No. Privacy law looks at the full dataset and reasonable identifiability, not just one field. Client IDs, event sequences, device data, and account-linked features can still combine into a behavioral record even when GA4 does not store IP addresses.

What does Google Signals do in GA4?

Activating Google Signals enables remarketing, advertising reporting features, and demographics and interests data from users signed into a Google account with Ads Personalization enabled. That moves analytics closer to advertising identity, so teams that do not need remarketing or demographic reporting can disable it to reduce risk.

The Firebase SDK assigns an app-instance identifier to each install and can collect the Android Advertising ID or iOS Identifier for Advertisers where available. On iOS, Apple's App Tracking Transparency framework can require authorization for tracking across apps and websites, and on Android the advertising ID depends on platform settings and permissions.

ePrivacy consent and GDPR consent are related but separate. ePrivacy may require consent for storing or accessing an identifier on a device, while GDPR requires a separate lawful basis, often consent, for the processing that follows. Configuring GA4 only for limited measurement behind a CMP can lower that burden, though not every configuration always needs consent.

What should teams check during an identifier audit?

An identifier audit separates direct identifiers, pseudonymous online identifiers, and aggregate metrics. The audit then records whether enhanced measurement, Google Signals, ads personalization, User-ID, BigQuery export, Consent Mode, cross-domain measurement, and region-specific settings are enabled. For each identifier it documents purpose, lifespan, storage location, legal basis, consent dependency, and whether the data leaves the organization.

What is a safer default configuration for GA4?

A safer GA4 setup disables Google Signals unless it is specifically needed, skips ads personalization by default, and avoids sending User ID unless reviewed. The same setup strips personal data from URLs before tracking, shortens data retention, excludes internal traffic, and reviews linked Google Ads and BigQuery exports. Sites that only need pages, campaigns, and conversions can answer the same question with less risk using privacy-first analytics without persistent identifiers.

Was This Article Helpful?

Let us know what you think!

See us more often in Google

One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.

Before you go...

Flowsery

Flowsery

Revenue-first analytics for your website

Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.

Real-time dashboard

Goal tracking

Cookie-free tracking

Related Articles