---------------------------
Title: Google Analytics and CCPA: Support for Privacy Compliance in 2026
URL: https://www.cookiebot.com/us/google-analytics-ccpa/
---------------------------

# Google Analytics and CCPA: Support for Privacy Compliance in 2026

Google Analytics 4 assigns every visitor a Client ID, which qualifies as personal information under the CCPA/CPRA, even without a name or email address. This guide covers who the CCPA/CPRA applies to, what counts as personal information in GA4, and the steps for CCPA/CPRA compliance: privacy policy updates, opt-out links, honoring Global Privacy Control signals, and handling consumer requests.

## At a Glance

- Google Analytics 4 (GA4) assigns every visitor a Client ID, which the CCPA/CPRA classifies as personal information — even though it contains no name, email, or other direct identifier.
- The CCPA/CPRA only applies to for-profit businesses that meet at least one threshold: gross annual revenue over $26,625,000, buying/selling/sharing the personal information of 100,000+ California consumers or households, or deriving 50 percent or more of revenue from selling or sharing personal information.
- The CPRA added the right to limit the use of sensitive personal information and requires businesses to honor Global Privacy Control (GPC) signals automatically, not just a manual opt-out link.
- Universal Analytics was retired in 2023–2024. Every GA4 property today needs its own approach to disclosure and deletion requests, using the User Explorer report and GA4's Data Deletion Requests tool.
- Separately from CCPA/CPRA compliance, California's decades-old wiretapping law (CIPA) is fueling a wave of private lawsuits over tools like Google Analytics — a risk that exists even for businesses that meet no CCPA/CPRA threshold at all.
- A consent management platform such as Cookiebot™ CMP can automate the opt-out links and signal-honoring the CCPA/CPRA requires, alongside a full scan of every cookie and tracker on your site.

California's privacy law has moved a long way since Google Analytics first became a compliance question for U.S. businesses. Universal Analytics is gone, GA4 works differently under the hood, and the CPRA has added rights and obligations the original CCPA never had. Here's what Google Analytics and the CCPA/CPRA mean for your website today, and how to bring the two into alignment.

## What Is the CCPA and CPRA?

The [California Consumer Privacy Act (CCPA)](https://www.cookiebot.com/us/what-is-ccpa/) took effect January 1, 2020, as the first comprehensive data privacy law in the United States. The [California Privacy Rights Act (CPRA)](https://www.cookiebot.com/us/cpra/) amended and significantly expanded it, taking effect January 1, 2023, with enforcement beginning in February 2024. The two are not separate laws; CPRA is an amendment layered onto the CCPA, and most current guidance refers to the combined framework.

California residents ("consumers" under the law) have rights to:

- **Equal service**, meaning a business cannot discriminate against a consumer for exercising these rights
- **Know** what personal information a business collects, sells, or shares, and for what purpose
- **Access** the personal information collected about them
- **Correct** inaccurate personal information
- **Delete** personal information a business has collected
- **Opt out** of the sale or sharing of their personal information
- **Limit** the use of their sensitive personal information (added with the CPRA)

### Does Google Analytics Collect Personal Information Under the CCPA/CPRA?

Yes, while Google Analytics 4 (GA4) doesn't collect direct identifiers like names or email addresses by default, it does assign every visitor a **Client ID**, which is a unique string stored in a first-party cookie **(`_ga`)** that lets GA4 recognize the same browser or device across visits and sessions.

The CCPA/CPRA defines personal information broadly, as *"information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household."*

This explicitly includes unique and persistent identifiers capable of recognizing a device "over time and across different services," precisely what a Client ID does. Some sites also configure GA4's optional **User-ID** feature, a more direct identifier used to track a signed-in user across devices, which businesses typically link to internal account or CRM data.

So while Google Analytics data is often described as "anonymized," a Client ID meets the legal definition of personal information under California law regardless of whether it's tied to a name.

## Who Does the CCPA/CPRA Apply To?

The CCPA/CPRA applies to for-profit businesses that do business in California and meet at least one of these thresholds:

- Annual gross revenue exceeding USD 26,625,000 (the 2025 CPI-adjusted figure, with next adjustment due January 1, 2027)
- Buy, sell, or share the personal information of 100,000 or more California consumers or households annually
- Derive 50 percent or more of annual revenue from selling or sharing consumers' personal information

These thresholds apply regardless of where your business is physically located. A company outside California, or outside the U.S. entirely, is covered if it meets at least one of them and processes California residents' data. If your business runs Google Analytics and meets any of the three thresholds, the obligations apply to you.

## How to Use Google Analytics in CCPA/CPRA Compliance

Bringing Google Analytics into compliance comes down to five things:

- Privacy policy
- Opt-out links
- Honoring automated opt-out signals
- Process for consumer requests
- Consent management platform (for full compliance support across your whole site, not just GA4)

### 1. Update Your Privacy Policy

Your [privacy policy](https://www.cookiebot.com/us/how-to-write-privacy-policy-guide/) needs to be clearly written in plain language, and kept up to date. It needs to communicate to visitors that:

- Your website uses Google Analytics to measure traffic and performance
- This involves placing cookies on their device, including a Client ID that qualifies as a persistent identifier under the CCPA/CPRA
- This data is shared with Google as a third party
- They have the right to know, access, correct, delete, and opt out of the sale or sharing of this data, and to limit the use of any sensitive personal information collected

### 2. Add the Required Opt-Out Links

If your business sells or shares personal information, your site needs a clearly visible "[Do Not Sell or Share My Personal Information](https://usercentrics.com/guides/website-disclaimers/do-not-sell-my-personal-information/)" link. If it uses or discloses sensitive personal information, it also needs a "[Limit the Use of My Sensitive Personal Information](https://usercentrics.com/guides/website-disclaimers/limit-the-use-of-my-sensitive-personal-information/)" link. Businesses can combine both into a single link if it lets consumers exercise both rights. These links must also appear in your notice at collection, which is the disclosure shown at or before the point of data collection.

### 3. Honor Global Privacy Control (GPC) Signals

The CPRA requires businesses to treat a [Global Privacy Control (GPC)](https://www.cookiebot.com/us/global-privacy-control-gpc/) signal as a valid opt-out request, equivalent to a visitor clicking your "Do Not Sell or Share" link manually. This is an automated, browser-level opt-out preference that individuals set once in their browser settings or using a plugin.

At least a dozen U.S. states now require honoring GPC or an equivalent universal opt-out mechanism (UOOM), and it's a stated enforcement priority for the [California Privacy Protection Agency (CPPA)](https://www.cookiebot.com/en/escalating-cppa-enforcement/).

### 4. Respond to Disclosure and Deletion Requests

A request to see, correct, or delete the data your website has collected through Google Analytics is a [data subject access request (DSAR)](https://usercentrics.com/knowledge-hub/data-subject-access-requests/), which is the same category of request the CCPA/CPRA, GDPR, and most other privacy laws grant consumers the right to make.

Handling a Google Analytics DSAR well means having a verification process, a tracking log, and a consistent response time in place before the request arrives, not just knowing which button to click in GA4.

Universal Analytics, the version of Google Analytics this guidance used to reference, stopped processing data in mid-2023 and was fully shut down by July 2024. Every business now runs on **GA4**, which handles consumer requests differently:

- **Disclosure requests:** Use the **User Explorer** report in GA4's Analysis section. Filter or segment by the visitor's Client ID or User-ID (whichever your setup uses) to locate and export their data.
- **Deletion requests:** Use GA4's **Data Deletion Requests** tool, found under **Admin > Data Collection and Modification**. Deletion requests go through a short grace period before becoming permanent, so build that into your response timeline.

The CCPA/CPRA gives you 45 days to respond to a verifiable consumer request (extendable by another 45 days when reasonably necessary), and 15 days to act on an opt-out request.

### 5. Use a Consent Management Platform to Support Full Compliance

Google Analytics is rarely the only tool collecting data on a website. Real, ongoing CCPA/CPRA compliance means knowing every cookie and tracker your site runs, even as they change over time and some are set by third parties.

[Cookiebot CMP](https://www.cookiebot.com/us/cookie-consent-solution/) deep-scans your entire site to find every cookie and tracker in use, then generates a cookie declaration and can configure the "Do Not Sell or Share" link automatically for visitors it detects are in California. Automated scans help you make sure that you're covered as cookies and trackers on your site change over time.

Cookiebot CMP also supports [Google Consent Mode](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/), which forwards a visitor's consent state to Google's tags. This is useful for advertisers who also need to meet Google's EEA/UK requirements for Consent Mode v2, though Consent Mode itself isn't a CCPA/CPRA requirement.

For U.S. compliance specifically, what matters is that GPC and other opt-out signals reach GA4 and are honored consistently.

Get every cookie under control
Cookiebot™ CMP scans your site to detect, categorize, and keep every cookie and tracker current in your banner and declaration. And it can block them from firing until consent is given.

[Start Free Scan](https://www.cookiebot.com/us/cookie-checker/)

## Google Analytics, CCPA/CPRA, and GDPR: Not the Same Compliance Job

If your site also has EU/EEA visitors, don't assume CCPA/CPRA compliance covers you for the [GDPR](https://www.cookiebot.com/us/gdpr/) too. The two laws differ in fundamental ways:

- **Consent model:** The CCPA/CPRA is opt-out, so you generally don't need prior consent to collect or process personal information (minors under 16 are the exception). The GDPR is opt-in, so you need a valid legal basis, most often consent, before processing begins.
- **Scope:** The CCPA/CPRA only applies to businesses meeting a revenue, data-volume, or data-sale threshold. The GDPR applies to any organization processing the personal data of people in the EU/EEA, with no threshold, including nonprofits.
- **Enforcement:** The CCPA/CPRA is enforced by the California Attorney General and the CPPA, with penalties up to USD 2,663 per unintentional violation and USD 7,988 per intentional one. GDPR fines run far higher: up to 4 percent of global annual turnover or EUR 20 million, whichever is greater, for the most serious violations.

Running Google Analytics compliantly for a global audience generally means treating GDPR's stricter opt-in requirement as your default, then layering the CCPA/CPRA's specific opt-out links and GPC-honoring on top for California visitors.

### Google Analytics and CIPA: A Separate Litigation Risk

CCPA/CPRA compliance doesn't make Google Analytics lawsuit-proof. The [California Invasion of Privacy Act (CIPA)](https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/) is a 1967 wiretapping law and is a second, unrelated California statute. It's become the basis for a wave of private lawsuits and demand letters targeting exactly the kind of tracking GA4 does by default.

The theory: CIPA's pen-register and trap-and-trace provision ([Penal Code § 638.51](https://california.public.law/codes/penal_code_section_638.51)), originally written for law enforcement tracking phone calls, prohibits capturing "routing" or "addressing" information without authorization.

Plaintiffs argue that Google Analytics, Google Tag Manager, and similar tools do exactly this when they collect IP addresses and identifiers and transmit them to Google before a visitor has consented.

A separate wiretapping provision ([§ 631](https://california.public.law/codes/penal_code_section_631)) is used to make a similar argument about the data itself. Courts are genuinely split. Some 2026 rulings have allowed these theories to proceed, others have dismissed them outright, and two California Courts of Appeal are currently reviewing the question.

Unlike the CCPA/CPRA, CIPA carries no business-size threshold and lets a plaintiff sue directly for the greater of USD 5,000 per violation or treble damages, with no need to prove actual harm. This is what's fueled the current — and significantly increasing — volume of demand letters and lawsuits since 2022.

A California bill, [SB 690](https://legiscan.com/CA/text/SB690/id/3186917?__cf_chl_tk=N5QCckBHlsL5_CTrgDAj1qpe2sCCSrlnCPgOZmngNrk-1786566906-1.0.1.1-nMGKF37qgnkt1A6XJeQ9QocG1msqJisGj2otmfp3gL0), would curb part of this, but only part. As currently drafted and still pending in the legislature (with an August 31, 2026 deadline to pass the current session), it would eliminate the private right to sue over the pen-register theory specifically, leaving that enforcement to the California Attorney General.

It would not touch the wiretapping theory under § 631, which remains the more commonly used claim in suits. In other words: even if SB 690 passes in its current form, using Google Analytics or other tools on a California-facing site doesn't become risk-free.

This is a genuinely unsettled area of law, not a compliance checklist item. A consent management platform like Cookiebot™ that delays GA4 and any other cookies or trackers from firing until after a visitor has made a consent choice is the most direct mitigation step businesses are taking today, but this isn't a substitute for legal advice.

### Bringing It All Together

Google Analytics hasn't gotten simpler to run compliantly. If anything, GA4, the CPRA, and the current wave of CIPA litigation have added more moving parts than existed under the CCPA alone. But the core task hasn't changed: know what GA4 collects, disclose it, give visitors real control over it, and respond to their requests on time.

For most sites, that means five concrete things:

- Updated privacy policy
- Required opt-out links
- Automatic honoring of Global Privacy Control signals
- Working process for disclosure and deletion requests
- Consent setup that governs *when* GA4 fires, not just whether it's disclosed

That last point is what separates CCPA/CPRA compliance from CIPA risk mitigation. They're related, but they're not the same job, and treating them as one is how gaps get missed.

None of this is a substitute for legal counsel, particularly while SB 690 and the underlying CIPA case law are still unsettled. But a business that has the five items above in place is in a materially stronger position than one relying on Google Analytics' default settings alone.

Ready to simplify CCPA/CPRA compliance?
See how Cookiebot™ CMP handles cookie scanning, consent, and opt-out signals for U.S. and global privacy laws in one setup. Try it free for 14 days.

[Start Free Trial](https://admin.cookiebot.com/signup?lang=en)

*Usercentrics does not provide legal advice, and information is provided for educational purposes only. We recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.*

## Summary

Google Analytics 4 assigns every visitor a Client ID, which qualifies as personal information under the CCPA/CPRA, even without a name or email address. This guide covers who the CCPA/CPRA applies to, what counts as personal information in GA4, and the steps for CCPA/CPRA compliance: privacy policy updates, opt-out links, honoring Global Privacy Control signals, and handling consumer requests.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/us/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/us/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/us/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)
- [View all regulations](/us/regulations-and-frameworks/#united-states-state&united-states-federal)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Customer stories](https://www.cookiebot.com/us/customer-stories/)
- [Customer directory](https://www.cookiebot.com/us/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)