State by State: Which US Privacy Laws Impact Your GA4 Setup
Nearly 20 US states now have comprehensive privacy laws, and most of them treat analytics-driven advertising as a regulated data practice. Here's a state-by-state view of what that means for GA4.
Treating “US privacy compliance” as a single checkbox stopped being accurate years ago. As of 2026, close to 20 states have comprehensive consumer privacy laws in effect, and while they share a common structure, opt-out rights, disclosure requirements, sensitive data protections, they differ enough in scope and mechanics that a GA4 configuration built for one state doesn’t automatically satisfy another.
The states with comprehensive privacy laws in effect
- California — CCPA/CPRA (2020/2023), the most mature and the model most others followed
- Virginia — Consumer Data Protection Act (CDPA), effective 2023
- Colorado — Colorado Privacy Act (CPA), effective 2023
- Connecticut — Connecticut Data Privacy Act (CTDPA), effective 2023
- Utah — Utah Consumer Privacy Act (UCPA), effective 2023
- Texas — Texas Data Privacy and Security Act (TDPSA), effective 2024
- Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey and others with laws effective 2024–2026, plus more with laws passed but not yet in effect
Each has its own applicability thresholds, its own definition of “sale” or “targeted advertising,” and its own enforcement mechanism. We go deeper on two of the most-asked-about states in our Virginia CDPA guide and our Colorado Privacy Act guide.
The pattern that matters more than the differences
Despite the variation, almost every one of these laws regulates the same underlying behavior GA4 triggers when Google Signals or ads integrations are active: using an identifier to build a profile for targeted or cross-context advertising. Most of these statutes call this “targeted advertising” or “sale,” and most give consumers an opt-out right, whether phrased as “opt out of sale” (California model) or “opt out of targeted advertising” (Virginia/Colorado model, which doesn’t require a literal sale).
| Concept | States that use “sale” framing | States that use “targeted advertising” framing |
|---|---|---|
| Triggers on | Exchange for value | Use of personal data across sites/apps to select ads, no value exchange required |
| Practical effect on GA4 | Google Signals + ads integrations likely qualify if you receive any benefit | Google Signals + ads integrations likely qualify regardless of monetary exchange |
| GPC recognition | Required in CA; increasingly required elsewhere | Required in Colorado; growing but not universal |
The upshot: the “targeted advertising” framing used by Virginia, Colorado, Connecticut, and others is actually broader than California’s original “sale” concept, it doesn’t require any value exchange at all, just the underlying data use. A GA4 setup that only worries about “selling data” for money can still be out of compliance in these states.
A practical approach instead of 20 separate checklists
Trying to build 20 state-specific GA4 configurations isn’t realistic for most teams. The workable approach:
- Configure to the strictest applicable standard (usually California’s, since it has the most developed regulatory guidance) and treat states with narrower requirements as automatically covered.
- Honor GPC universally, not just where legally mandated, since it’s a low-cost technical control that satisfies the opt-out requirement in every state that recognizes it and causes no harm in states that don’t.
- Use a consent platform with geo-detection so visitors in different states can get the correct opt-out mechanics without you maintaining state-by-state logic manually.
Usercentrics
Managing consent logic across a growing patchwork of state laws is exactly the kind of multi-jurisdiction complexity Usercentrics' geo-detection and multi-domain rule sets are built to handle, useful once you're tracking more than two or three states' requirements.
Don’t forget the laws outside the US too
If you also have EU or UK visitors, your GA4 configuration needs to satisfy GDPR’s opt-in model on top of these opt-out-based US laws simultaneously. See our GDPR vs CCPA vs US state laws comparison for how the two models coexist on one site.
This overview reflects the state privacy law landscape as of publication; new states pass comprehensive privacy legislation regularly. Confirm current requirements for your specific jurisdictions with a privacy attorney.