TL;DR, Quick Answer
7 min readGA4 includes privacy improvements, including not logging or storing IP addresses, but privacy concerns remain when analytics uses identifiers, advertising integrations, consent-dependent tracking, international transfers, or custom events that capture personal data.
Here, the topic Privacy issues with Google Analytics is covered with practical examples. Dropping IP logging closed one gap and left several open, so the privacy issues with Google Analytics now cluster in four places: identifiers, advertising integrations, international transfers, and the custom events your own team defined.
Google Analytics is not automatically unlawful, and GA4 is not the same product as Universal Analytics. But privacy concerns remain because GA is part of a larger advertising and data ecosystem, and many implementations collect more information than a website actually needs.
The practical question is not whether Google Analytics is "bad." It is whether your use of it is necessary, proportionate, transparent, consented where required, and legally supported for the countries and users involved.
GA4 privacy improvements do not end the analysis
Google says GA4 does not log or store IP addresses, and its documentation describes controls for advertising features, personalization, and retention (Google Analytics safeguards). That is a meaningful privacy improvement over older assumptions.
However, IP address handling is only one factor. GA4 can still collect event data, page URLs, device/browser data, campaign parameters, user IDs if configured, Google signals if enabled, ecommerce events, and custom dimensions. Some of that data may be personal or become personal when combined.
For example, a URL such as /reset-password?email=name@example.com should never reach analytics. A custom event that includes a user ID, search query about a medical condition, or free-text form input can create sensitive analytics records even if the tool itself has privacy controls.
Consent and cookies
GA4 commonly uses first-party cookies and identifiers to measure sessions and users. In many European contexts, non-essential analytics cookies require consent unless a narrow audience-measurement exemption applies. That exemption depends on local law and configuration and should not be assumed for full-featured analytics tied to advertising or cross-site services.
If GA fires before consent, you may have a cookie compliance problem independent of GDPR transfer questions. If GA fires only after consent, your data may become biased toward people who accept tracking. That is one reason cookieless analytics can produce more stable operational reporting.

Advertising integrations increase risk
GA becomes more privacy-sensitive when connected to Google Ads, remarketing, audiences, or signals that support advertising personalization. A reporting-only setup and an advertising-activation setup are different risk profiles.
If you use GA only to understand pages and conversions, disable features you do not need. If you use GA for remarketing, be explicit in notices and consent choices. Do not bury advertising purposes inside generic analytics language.
- Used to understand pages and conversions
- Unneeded features disabled
- Connected to Google Ads, remarketing, audiences, or signals
- Needs explicit notices and consent choices
EU-US transfer concerns
After Schrems II, European authorities scrutinized Google Analytics because data transferred to the US could fall under US access laws. CNIL's guidance on audience measurement and transfers discusses how analytics tools can be made compliant and how the EU-US Data Privacy Framework changed transfers to certified US entities (CNIL guidance).
The 2023 Data Privacy Framework reopened an adequacy route for certified organizations, but controllers still need to verify the mechanism, scope, and data flow. A privacy notice that says "we use Google Analytics" is not a transfer assessment.

Retention and access
Google Analytics retention settings affect how long user-level and event-level data is retained for certain reports. Teams should set retention deliberately, export only what they need, and avoid keeping raw data indefinitely in BigQuery or data warehouses without a purpose.
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
Access control matters too. Analytics often contains commercially sensitive and potentially personal data. Limit who can view, export, and connect GA data to other systems.
A safer implementation checklist
If you keep GA4, at minimum:
- disable advertising features unless actively needed and consented;
- avoid user IDs unless there is a strong reason;
- block analytics until consent where required;
- audit all custom events and parameters;
- strip personal data from URLs before analytics receives them;
- configure retention intentionally;
- review transfer mechanisms and vendor documentation;
- document why GA4 is necessary compared with less invasive options;
- test rejection paths in the browser;
- compare analytics conversions with backend records.
When switching is cleaner
If your organization needs advanced attribution, ad audiences, and Google Ads integration, GA4 may still be part of the stack. If you need basic website analytics, it may be excessive.
Privacy-first analytics is attractive because it narrows the problem. No cookies, no personal profiles, no ad network enrichment, minimal retention, and aggregate reporting can answer most website-performance questions with less legal and reputational risk.
Good analytics should help improve the site. It should not require visitors to become part of a cross-service tracking system just so you can see which blog post converted.
Decide what you actually need from analytics
A useful internal exercise is to list every recurring analytics report and the decision it supports. If a report has no owner or decision, retire it. If a decision can be made with aggregate data, do not collect user-level data for it. If a metric is needed only for advertising optimization, keep it behind advertising consent rather than mixing it into general site analytics.
This exercise often reveals that a company uses Google Analytics out of habit, not necessity. The team may need reliable campaign reporting, conversion goals, landing-page performance, and funnel drop-off. Those needs can be met with a smaller, privacy-first data footprint.
Privacy concerns become easier to manage when the measurement plan is smaller. Reducing scope is not a downgrade if it removes data nobody acts on.
GA4 Configuration Audit
Do not review Google Analytics as one yes-or-no tool. Inventory enhanced measurement, Google Signals, ads personalization, User-ID, BigQuery export, Consent Mode, cross-domain measurement, product links, and region-specific settings.
For each setting, name the business decision it supports and the consent, transfer, retention, and access controls around it. If a setting exists only because it was enabled by default, turn it off and keep the measurement plan smaller.
Frequently Asked Questions
Does GA4 still collect personal data even though it doesn't log IP addresses?
GA4 not logging IP addresses closed one gap, but it can still collect event data, page URLs, device and browser data, campaign parameters, user IDs, Google signals, and custom dimensions. Combined, this data can become personal, for example a URL that carries an email address or a custom event with a search query. IP handling was only one factor among several.
Do I need cookie consent for GA4 in Europe?
In many European contexts, non-essential analytics cookies need consent unless a narrow audience-measurement exemption applies. That exemption depends on local law and configuration and shouldn't be assumed for a full-featured setup tied to advertising or cross-site services. If GA fires before consent, there's a cookie compliance problem separate from any GDPR transfer question.
Is Google Analytics illegal under GDPR?
Google Analytics is not automatically unlawful, and GA4 differs from Universal Analytics. The real question is whether the use is necessary, proportionate, transparent, consented where required, and legally supported for the countries and users involved. After Schrems II, some European authorities scrutinized GA specifically over EU-US data transfers.
What is the difference between a reporting-only GA4 setup and one used for advertising?
A reporting-only setup only measures pages and conversions, with features you don't need turned off. An advertising-activation setup connects GA to Google Ads, remarketing, audiences, or signals that support ad personalization. These carry different risk profiles, so an advertising setup calls for explicit notices and consent choices rather than being folded into generic analytics language.
Does the EU-US Data Privacy Framework fix Google Analytics transfer concerns?
The 2023 Data Privacy Framework reopened an adequacy route for certified US organizations, which changed the transfer picture after Schrems II. Controllers still need to verify the mechanism, scope, and actual data flow for their own setup. A privacy notice that just says "we use Google Analytics" is not a transfer assessment.
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
What personal data can accidentally end up in Google Analytics?
Anything captured in a URL or custom event ends up in GA4. That includes an email address on a password-reset link, a user ID, a search query about a medical condition, or free-text form input. GA4's own privacy controls don't prevent this, because the data comes in through parameters your own team defined. It has to be stripped before it reaches analytics, not filtered out afterward.
Should I disable Google Signals and User-ID in GA4?
Disable Google Signals and avoid user IDs unless there's a strong reason to use them, since both increase how identifiable your analytics data is. The configuration audit calls for naming the business decision each setting supports, along with its consent, transfer, retention, and access controls. If a setting is only on because it was the default, turn it off.
Why does blocking analytics until consent bias my data?
If GA fires only after consent, the resulting data skews toward people who accept tracking, a form of selection bias. That is one reason cookieless analytics can produce more stable operational reporting. The tradeoff sits between complete data before consent and biased but compliant data after it.
How long should Google Analytics retain user-level data?
The post doesn't give a specific retention period, but it says retention should be set deliberately rather than left at a default. Teams should export only what they need and avoid keeping raw data indefinitely in BigQuery or other data warehouses without a purpose. Access to that data should also stay limited to people who need it.
What should a GA4 configuration audit actually check?
Rather than treating Google Analytics as one yes-or-no tool, inventory enhanced measurement, Google Signals, ads personalization, User-ID, BigQuery export, Consent Mode, cross-domain measurement, product links, and region-specific settings. For each one, name the business decision it supports and the consent, transfer, retention, and access controls around it. Anything on only because it was enabled by default should be turned off.
Was This Article Helpful?
Let us know what you think!
See us more often in Google
One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.
Before you go...
Flowsery
Revenue-first analytics for your website
Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.
Real-time dashboard
Goal tracking
Cookie-free tracking
Related Articles


A Practical Guide to Is Google Analytics and GA4 GDPR Compliant
Is GA4 GDPR compliant? Not by default. The risk sits in consent, Google Signals, contracts, transfer basis and the fields you send. The audit checklist.


Useful Context - Server-Side Tagging GDPR Compliant
A server-side tagging GDPR compliant claim has to survive CNIL's proxy conditions. What server-side GA improves, what it never fixes, and when to switch.


A Practical Guide to CCPA Compliance and Web Analytics
Identifiers, browsing activity and event histories can count as personal information. What to review before choosing or configuring an analytics tool.

