Complete these steps in order. All require Admin access in GA4.
Step 1 — Data Retention
Admin → Data Settings → Data Retention
Set to 14 months maximum. This reduces the volume of personal data retained and is the minimum recommended setting for DPPA/GDPR alignment.
Step 2 — Google Signals
Admin → Data Settings → Data Collection → Google Signals
Disable Google Signals unless the client has a specific, documented need for cross-device tracking. Google Signals links analytics data to Google Account profiles — this is personal data linkage that requires explicit consent.
Step 3 — IP Anonymisation
Admin → Data Streams → [select stream] → Configure tag settings → Show all → Redact visitor IP addresses
Enable this setting. It masks the user's location to city level only — the user's precise IP address is not stored. This is recommended for all clients regardless of regulatory framework.
Step 4 — Consent Mode Configuration
Configure GA4 consent mode so the tag fires in "consent pending" state by default and only collects full analytics data after the user grants consent via the cookie banner. This requires integration between the consent management platform (CookieYes or equivalent) and the GA4 tag via Google Tag Manager.
Step 5 — Data Deletion Requests
Admin → Data Deletion
Document the process for responding to a user's right-to-erasure request. Under DPPA 2019, the client must be able to delete an individual user's data within a reasonable timeframe. In GA4, use the Data Deletion tool to remove data associated with a specific user identifier.
按以下顺序完成步骤,所有步骤均需GA4中的Admin权限。
步骤1——数据保留
Admin → Data Settings → Data Retention
设置为最长14个月。这将减少保留的个人数据量,是符合DPPA/GDPR要求的最低推荐设置。
步骤2——Google Signals
Admin → Data Settings → Data Collection → Google Signals
禁用Google Signals,除非客户有明确的、有文档记录的跨设备跟踪需求。Google Signals会将分析数据与Google账户资料关联——这种个人数据关联需获得明确同意。
步骤3——IP匿名化
Admin → Data Streams → [选择数据流] → Configure tag settings → Show all → Redact visitor IP addresses
启用此设置。它会将用户位置掩码至城市级别——不会存储用户的精确IP地址。无论适用何种监管框架,均建议所有客户启用此设置。
步骤4——同意模式配置
配置GA4同意模式,使标签默认处于“待同意”状态,仅在用户通过Cookie横幅授予同意后才收集完整分析数据。这需要通过Google Tag Manager将同意管理平台(如CookieYes)与GA4标签集成。
步骤5——数据删除请求
Admin → Data Deletion
记录响应用户删除权请求的流程。根据《2019年DPPA》,客户必须能够在合理时间内删除单个用户的数据。在GA4中,使用数据删除工具移除与特定用户标识符关联的数据。