Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Statistics

_ga_ Cookie (Google Analytics 4) — What It Is and How to Block It

_ga_ is a cookie used by Google Analytics 4 (GA4) to distinguish unique visitors and link sessions from the same user across visits. The full name includes a unique suffix for each GA4 data stream, for example _ga_ABC123XYZ. It is a statistics cookie and, under ePrivacy/GDPR, requires the visitor's consent before being set.

Name
_ga_…
Provider
Google Analytics
Category
Statistics
Type
HTTP cookie
Lifetime
2 years
Domain / notes
site-ul vizitat · urmat de ID-ul fluxului GA4, ex. _ga_ABC123XYZ
Consent
Yes, before it is set (GDPR / ePrivacy)
Prevalence
found on 3 Romanian sites scanned by CookieFix

What is the _ga_ cookie?

_ga_ is the main user-identification cookie used by Google Analytics 4, the current version of Google's web analytics service. Unlike the older _ga cookie (Universal Analytics), _ga_ includes a unique measurement ID in its name, for example _ga_ABC123XYZ, because a single site can have several GA4 properties configured at once.

The cookie is set by the gtag.js tracking code or Google Tag Manager, typically as soon as the GA4 script runs on the page — meaning on the first page load if no prior blocking of statistics scripts is in place.

What data it stores

_ga_ stores a session identifier and session state (session number, start timestamp) so that Google Analytics can recognize whether a visitor is new or returning within the same session or across later sessions. The value is an alphanumeric string generated by Google; its exact internal format is not publicly documented in detail.

Data collected through this cookie is sent to Google's servers (potentially outside the European Economic Area, depending on the analytics account configuration) and aggregated into the site owner's GA4 reports.

What it is used for

For the site administrator, _ga_ underpins Google Analytics 4 traffic reports: visitor counts, sessions, page views, bounce rate, traffic sources, and user behavior across multiple visits.

For Google, the cookie is part of the technical infrastructure delivering the analytics service, allowing statistical distinction between users at the browser level, without normally using directly identifying data such as names or email addresses.

Does it require consent?

  • CookieFix category: statistics (analytics)
  • Not strictly necessary for the site's technical operation — requires the visitor's prior consent under the ePrivacy Directive (implemented in Romania via Law 506/2004) and GDPR data-processing principles
  • The site administrator must declare it in the cookie policy, list it correctly under the „statistics” category in the banner, and avoid activating it before the visitor gives explicit consent

How to block or delete _ga_

A visitor can manually delete or block _ga_ from browser settings (Chrome, Firefox, Safari, Edge — per-site cookie management), or install the official Google Analytics Opt-out Browser Add-on, which stops data from being sent to GA on all visited sites.

For site administrators, blocking must happen before consent is given, not just by deleting the cookie afterward. A CMP such as CookieFix handles this technically by automatically blocking the GA4 script (gtag.js/GTM) until the visitor accepts the „statistics” category, preventing the _ga_ cookie from being set prematurely.

Frequently asked questions

The suffix is the GA4 measurement ID for that site, for example _ga_ABC123XYZ. Each GA4 property configured on a site can have its own suffix.

_ga is the cookie used by older versions (Universal Analytics), while _ga_ (with a suffix) is specific to Google Analytics 4 and stores the current session state.

Google's typical duration is 2 years from the last update, unless the visitor deletes it manually or withdraws consent.

No, it is strictly optional from a technical standpoint — it only serves statistical analysis purposes, which is why it requires the visitor's explicit consent.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.