GA4 and the CCPA: What California Businesses Must Know
If you run Google Analytics 4 and have California visitors, the CCPA almost certainly applies to your setup. Here's what that actually requires, in plain terms.
If your site runs Google Analytics 4 and gets traffic from California residents, the California Consumer Privacy Act (CCPA), as amended by the CPRA, almost certainly has something to say about your setup. GA4 itself isn’t illegal under the CCPA, but the way most businesses configure it by default routes straight into what the law calls a “sale” or “share” of personal information, and that triggers obligations most sites haven’t actually implemented.
Why GA4 is a CCPA issue at all
The CCPA doesn’t regulate analytics tools by name. It regulates what businesses do with personal information, and it defines “sale” and “share” broadly enough to catch standard ad-tech and analytics behavior. Google Analytics collects identifiers (client ID, IP address, device data) and, if you have Google Signals or any ads-linked integration enabled, that data can be used for cross-context behavioral advertising. Under the CCPA/CPRA, that combination is generally treated as a “share” for cross-context behavioral advertising purposes, whether or not money changes hands. The statute’s definition of “sale” was never about a literal cash transaction, it’s about the exchange of personal information for valuable consideration, which includes the value an ad network gets from using your visitors’ data to build audiences.
Does the CCPA actually apply to your business?
The CCPA only applies to businesses that meet at least one threshold: over $26,625,000 in annual gross revenue (adjusted periodically), buy/sell/share personal information of 100,000+ CA consumers/households annually, or derive 50%+ of annual revenue from selling/sharing personal information. A lot of smaller sites assume they’re exempt because they’re not “big,” but the 100,000-consumer threshold is lower than it sounds, mid-traffic e-commerce or SaaS sites can hit it without realizing it. If you’re unsure, treat GA4 configuration as CCPA-relevant by default rather than gambling on an exemption you haven’t actually verified.
What the CCPA requires if it applies to you
- A “Do Not Sell or Share My Personal Information” link (or equivalent opt-out mechanism) accessible from your homepage and privacy policy.
- Honoring Global Privacy Control (GPC) signals as a valid opt-out request, GPC has legal weight under the CCPA specifically; we cover the mechanics in our dedicated GPC and GA4 piece.
- Disabling Google Signals and ads personalization for visitors who’ve opted out, not just hiding a link that doesn’t actually change what GA4 sends.
- Disclosing GA4’s use in your privacy policy, including what categories of personal information it collects and whether that counts as a sale/share under your specific configuration.
- A mechanism to actually process opt-outs, which for most sites means gating GA4 and Google Signals behind a consent management platform rather than a static link that does nothing.
Usercentrics
A DIY 'Do Not Sell' link rarely holds up to scrutiny because it doesn't actually stop GA4 from firing. Usercentrics ties the opt-out mechanism directly to your GA4 and Google Signals configuration, so the visible link and the actual behavior match.
The gap between “we have a link” and “we’re compliant”
The most common failure mode isn’t missing a link, it’s having one that doesn’t do anything. If a California visitor clicks “Do Not Sell or Share” and GA4 keeps firing with Google Signals still active, you have a compliance gap that’s fairly easy for a plaintiff’s attorney or the California Privacy Protection Agency to demonstrate with browser dev tools. The link has to be wired to an actual technical control, typically consent-mode-gated tags or a server-side rule that suppresses the ads-linked signals once an opt-out is recorded.
How this fits with the rest of US privacy law
CCPA/CPRA is the most mature US state privacy law, but it’s not the only one your GA4 setup might need to account for. See our state-by-state breakdown and our GDPR vs CCPA vs US state laws comparison if you also have EU traffic or customers in other US states with their own privacy statutes.
This guide is educational and not legal advice. Whether your business meets the CCPA’s applicability thresholds, and what your specific GA4 configuration requires, depends on facts a privacy attorney should review.