Tracker library

Google Analytics: what it is, what it sets, and how to gate it.

A web-measurement service that may be installed directly, through a tag manager, or through a platform integration—sometimes by more than one path.

Vendor
Google
Scanner category
analytics
Consent category
Analytics
Control
Named adapter

What it is

Google Analytics 4 measures traffic, engagement and conversions. It identifies a returning browser with a client ID stored in the `_ga` cookie, and records events against it. The measurement itself is aggregate, but the identifier is per-browser and persistent, which is what puts it inside the consent rule.

GA4 can arrive directly through a Google tag, through Google Tag Manager, or through a theme, plugin, app or platform integration. Inventory each delivery path because controlling one installation does not disable a duplicate installed elsewhere.

What a scan matches

A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Google Analytics is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.

  • google-analytics.com and analytics.google.com
  • googletagmanager.com/gtag/js: the gtag loader, matched by path and reported as Google Analytics rather than as a tag manager
  • google.<tld>/g/collect and /j/collect: where GA4 actually posts measurement, on the plain Google domain

Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.

CookieWhat it is for
_gaThe client identifier that distinguishes returning browsers
_ga_<container>GA4 session state, one per measurement ID
_gidA legacy Universal Analytics identifier; current GA4 documentation lists _ga and _ga_<container> instead
_gatLegacy Universal Analytics request throttling
__utm*Legacy Universal Analytics cookies, still found on older installs
_gac_*Campaign information linked to Google Ads

Controlling it with consent

With the named adapter, enter a GA4 measurement ID in the property’s technology list and remove the direct, theme, plugin and container duplicates. Before analytics consent, and after an initial rejection, the managed gtag script is not loaded at all. After approval it loads and sends updated Google consent signals as choices change.

On withdrawal the adapter updates Google consent and removes the managed loader. What it cannot undo is SDK behaviour that already executed, or cookieless signals your own tag configuration may still be sending, both of which need checking against your setup rather than assuming.

This one has a first-class adapter

Enter the identifier in the property’s technology list and the runtime applies that adapter’s control strategy. Depending on the vendor, that means withholding the loader, establishing denied defaults, or loading a functional surface with tracking opted out; the article above describes the exact behavior. Remove copies installed in a theme, plugin, app or tag manager first, or another installation can remain outside that control.

What breaks if it is refused: nothing a visitor can see. Your reporting loses the sessions that refused, which is the expected and correct outcome rather than a fault.

Verifying it

Check the Google tag loader, Analytics requests, Google’s DebugView and duplicate events in each consent state. Treat duplicate loaders and repeated events as separate conditions: one managed loader does not prove that an app or container did not install another.

  • Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
  • After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
  • After granting the relevant category: the expected loader or embed appears and the feature behaves normally
  • After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior

Common questions

Does Google Analytics need consent in the EU?

Treat it as consent-required. A few supervisory authorities publish narrow conditions under which a tightly configured first-party audience measurement may be exempted, but the conditions are strict and national. The defensible default, and the one the product ships, is that analytics is an optional category.

Is Consent Mode enough on its own?

Consent Mode carries a decision to Google’s tags; it does not make one, record one, or prove one. It also has to be initialised with the intended defaults before the container loads, so ordering must be verified rather than inferred from the presence of configuration code.

Why does a scan report Google Analytics on a googletagmanager.com URL?

Because /gtag/js on that host is the GA loader, not a container. The classifier matches the path so the finding names what it actually is.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.