Guide

Sensitive Data and GA4: Avoiding Violations Under US State Laws

US state privacy laws single out sensitive personal information for stricter treatment, usually requiring opt-in consent rather than just an opt-out right. Here's what that means for common GA4 configurations.

Published August 29, 2026·Last updated August 29, 2026

Most of what GA4 collects by default, page views, device type, general location, session duration, doesn’t fall into any special legal category. But several US state privacy laws carve out “sensitive personal information” for stricter treatment than ordinary data, usually requiring opt-in consent rather than an opt-out right, and a handful of common GA4 features and configurations can drift into that category without anyone realizing it.

What counts as “sensitive” under US state laws

Definitions vary slightly by state, but there’s substantial overlap. Categories that show up consistently under CPRA, CDPA, CPA, TDPSA and similar laws include:

  • Precise geolocation (typically defined as accurate to within a radius of 1,750 feet or less)
  • Racial or ethnic origin
  • Religious beliefs
  • Health condition, diagnosis, or status
  • Sexual orientation or gender identity
  • Citizenship or immigration status
  • Genetic or biometric data used for identification
  • Personal data of a known child (under 13, overlapping with COPPA, see our COPPA compliance checklist for that specific overlap)
  • Precise information revealing financial account details, in some states

Where standard GA4 configurations can drift into this territory

  • Precise geolocation reporting. GA4’s default geo dimensions (country, region, city) generally don’t reach the “precise” threshold most laws use, but if you’ve layered in a third-party geolocation API or a custom dimension capturing device GPS coordinates, that can qualify as sensitive and require opt-in consent, not just a working opt-out.
  • Health, wellness, or medical-adjacent sites. If your GA4 event structure tracks specific content categories (e.g., “viewed [condition] treatment page”) in a way that reveals health status, that combination of behavior and content context can itself be sensitive data, even though no one typed a diagnosis into a form.
  • Demographic and interest reports. Google Analytics’ built-in demographics and interests reporting (age, gender, interest categories) is derived from Google’s own ad-ecosystem signals and can intersect with sensitive categories depending on the interest segments involved.
  • Financial services and precise transaction data. E-commerce or fintech sites passing detailed account or transaction identifiers into GA4 custom parameters should confirm those don’t cross into a state’s sensitive-financial-data definition.

What “opt-in” means differently here than the rest of your GA4 setup

The rest of this series has focused on opt-out rights, the CCPA/CPRA “Do Not Sell or Share” model most US laws use. Sensitive data is the exception: most of these statutes require affirmative, opt-in consent before processing begins, not just an opt-out available afterward. That’s closer to GDPR’s default-off model than to the rest of US privacy law, and it means:

  • Sensitive-data-adjacent GA4 features should be off by default for all US visitors, not just gated behind a link.
  • Consent needs to be specific, a general “I accept cookies” banner likely isn’t sufficient affirmative consent for a sensitive data category if one applies to your setup.
Our recommendation

CookieYes

Because sensitive data categories require opt-in rather than opt-out handling, this is one area where a general-purpose cookie banner often isn't granular enough. CookieYes supports category-specific consent, letting you keep standard analytics on an opt-out model while gating anything sensitive behind explicit opt-in.

Try CookieYes

A practical audit to run

  1. List every custom dimension and event parameter flowing into GA4 and check each one against the sensitive categories above, not just the default fields.
  2. Confirm precise geolocation isn’t enabled unless you have a specific opt-in flow for it.
  3. Review demographic/interest reporting if your site serves a population where those signals could intersect with sensitive categories (health, LGBTQ+, immigration-status-adjacent content, etc.).
  4. Check whether your consent platform distinguishes between standard analytics consent and sensitive-data consent, or treats everything as one bucket.

This guide is educational and not legal advice. What qualifies as sensitive personal information, and what consent model it requires, varies by state and depends on your specific data flows. Consult a privacy attorney before relying on any specific GA4 configuration.