What it is
Google Analytics 4 measures traffic, engagement and conversions. It identifies a returning browser with a client ID stored in the `_ga` cookie, and records events against it. The measurement itself is aggregate, but the identifier is per-browser and persistent, which is what puts it inside the consent rule.
GA4 can arrive directly through a Google tag, through Google Tag Manager, or through a theme, plugin, app or platform integration. Inventory each delivery path because controlling one installation does not disable a duplicate installed elsewhere.
What a scan matches
A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Google Analytics is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.
- google-analytics.com and analytics.google.com
- googletagmanager.com/gtag/js: the gtag loader, matched by path and reported as Google Analytics rather than as a tag manager
- google.<tld>/g/collect and /j/collect: where GA4 actually posts measurement, on the plain Google domain
Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.
| Cookie | What it is for |
|---|---|
| _ga | The client identifier that distinguishes returning browsers |
| _ga_<container> | GA4 session state, one per measurement ID |
| _gid | A legacy Universal Analytics identifier; current GA4 documentation lists _ga and _ga_<container> instead |
| _gat | Legacy Universal Analytics request throttling |
| __utm* | Legacy Universal Analytics cookies, still found on older installs |
| _gac_* | Campaign information linked to Google Ads |
Controlling it with consent
With the named adapter, enter a GA4 measurement ID in the property’s technology list and remove the direct, theme, plugin and container duplicates. Before analytics consent, and after an initial rejection, the managed gtag script is not loaded at all. After approval it loads and sends updated Google consent signals as choices change.
On withdrawal the adapter updates Google consent and removes the managed loader. What it cannot undo is SDK behaviour that already executed, or cookieless signals your own tag configuration may still be sending, both of which need checking against your setup rather than assuming.
This one has a first-class adapter
Enter the identifier in the property’s technology list and the runtime applies that adapter’s control strategy. Depending on the vendor, that means withholding the loader, establishing denied defaults, or loading a functional surface with tracking opted out; the article above describes the exact behavior. Remove copies installed in a theme, plugin, app or tag manager first, or another installation can remain outside that control.
What breaks if it is refused: nothing a visitor can see. Your reporting loses the sessions that refused, which is the expected and correct outcome rather than a fault.
Verifying it
Check the Google tag loader, Analytics requests, Google’s DebugView and duplicate events in each consent state. Treat duplicate loaders and repeated events as separate conditions: one managed loader does not prove that an app or container did not install another.
- Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
- After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
- After granting the relevant category: the expected loader or embed appears and the feature behaves normally
- After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior
Common questions
Does Google Analytics need consent in the EU?
Treat it as consent-required. A few supervisory authorities publish narrow conditions under which a tightly configured first-party audience measurement may be exempted, but the conditions are strict and national. The defensible default, and the one the product ships, is that analytics is an optional category.
Is Consent Mode enough on its own?
Consent Mode carries a decision to Google’s tags; it does not make one, record one, or prove one. It also has to be initialised with the intended defaults before the container loads, so ordering must be verified rather than inferred from the presence of configuration code.
Why does a scan report Google Analytics on a googletagmanager.com URL?
Because /gtag/js on that host is the GA loader, not a container. The classifier matches the path so the finding names what it actually is.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Google Analytics: cookie usage on websites
Vendor documentation
Checked
- Google: set up consent mode on websites
Vendor documentation
Checked
- Google Analytics: 2026 data-control updates
Vendor documentation
Checked
- Google Analytics: Universal Analytics migration timeline
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.