- GA4 can miss 30–60% of EU visitors due to five compounding factors, none of which you can fix in the dashboard.
- Depending on the study, consent banners alone hide 35–65% of European traffic; ad blockers, ITP, ETP, and DNS-level blocking erase another slice each.
- By never collecting personal data, privacy-first architecture can drastically reduce consent dependence — visitor counts become nearly complete.
- EU-only hosting keeps you independent of the Schrems II / Data Privacy Framework debate that comes with sending visitor data to US infrastructure.
If you run Google Analytics 4 on a European website, you are almost certainly making decisions based on incomplete data. Estimates across consent-rate and blocker studies suggest GA4 can miss between 30% and 60% of actual visitors on a typical EU site. This is not a bug — it is a structural consequence of how GA4 works, the legal environment it operates in, and the browser ecosystem it depends on.
This article breaks down exactly why GA4 loses data, what mechanisms are responsible, and how a fundamentally different architecture — one that minimises consent dependence by never collecting personal data — can deliver nearly full visibility while staying GDPR-compliant by design.
The five layers of data loss in GA4
GA4’s data gap is not caused by a single factor. It is the compound result of five independent mechanisms, each removing a slice of your visitors from the data set.
1. Consent mode and cookie banners
Under the GDPR and the ePrivacy Directive, any tool that sets cookies or processes personal data for analytics requires explicit, informed consent from the visitor before data collection begins. GA4 uses cookies (_ga, _ga_<container>) and transmits data to Google, which also processes personal signals in the United States — personal data processing under EU law either way.
Google’s “Consent Mode v2” attempts to patch this by sending cookieless pings for non-consented visitors, then using machine learning to model the missing data. But this introduces a different problem: the numbers in your dashboard are not measured data — they are statistical estimates.
2. Ad blockers
Ad blockers block requests to google-analytics.com and googletagmanager.com at the network level. Ad blocker usage in Europe:
- Desktop: studies put ad-blocker usage at 30–42% of users
- Mobile: 15–20% by most estimates, growing with Brave and Firefox Focus
- Tech-savvy audiences: an estimated 50–70% (developer sites, SaaS, fintech)
3. ITP and ETP
Apple’s Safari (ITP) caps JavaScript-set cookies to 7 days. Mozilla’s Firefox (ETP) blocks known tracking domains. Together they affect an estimated 30–40% of EU web traffic with corrupted session data.
4. Network-level blocking
Pi-hole, AdGuard Home, corporate firewalls, and VPNs with built-in blocking prevent google-analytics.com from resolving entirely. Zero signal reaches Google.
5. Data sampling and processing delays
GA4’s free tier applies data sampling to explorations over large date ranges. Combined with 24–48 hour processing delay, you’re making decisions on modeled, sampled, delayed data.
The compound effect: what you are actually seeing
These five factors stack. Each one cuts a slice from what remains after the previous one.
This is an illustrative model, not a measurement. The 19–29% figure assumes typical German B2B consent and blocker rates. For developer tools or fintech it can drop below ~15%.
How privacy-first architecture solves this
The core insight: if you never collect personal data, the consent question largely falls away. Remove the personal data, and most of the consent dependence goes with it.
“The visitor’s privacy is protected by architecture, not by a consent dialog. The outcome is better for both parties.”— Internal datataste design principle
1. First-party cookies, no personal data
datataste uses first-party cookies and localStorage for session continuity — a random id, no personal data. No _ga cookie, no third-party cookie. Safari's ITP caps that first-party cookie to 7 days like any script-set cookie — datataste stores a random first-party visitor id (cookie + localStorage) with no personal data in it, and sessions and pageviews don't depend on that cap the way GA4's Users metric does. And because datataste sets no cross-site cookies, it currently isn't on Firefox's tracker list, so ETP leaves its first-party state alone.
2. IP addresses are discarded, not stored
The raw IP is anonymized and used for a single city-level geo lookup, then immediately discarded. The full IP is never stored in analytics data.
3. First-party, same-origin requests
Data goes to collect.yourdomain.com, not google-analytics.com. Ad blockers have no reason to block it.
The ad-blocker resilience is not a hack. It’s a natural consequence of first-party architecture — no domain masking, no proxy trickery.
4. EU-only data residency
All data processed and stored on Hetzner Cloud in Germany — independent of the US-transfer debate.
What “100% tracking” actually means
Nearly every visitor who loads your page is counted — counting isn’t gated on banner acceptance, and no third-party domain gets blocked. This does not mean collecting personal data without consent — no personal data is collected.
Side-by-side: GA4 vs datataste
| Factor | GA4 | datataste |
|---|---|---|
| Consent required | ✕ Yescookies + data sent to Google | ✓ Minimizeddesigned to minimize consent dependence — no PII collected |
| Ad blocker impact | ✕ 30–42%blocked at network | ✓ Minimalfirst-party endpoint, not on common blocklists |
| ITP / ETP impact | ✕ Cookie cap7-day reset, inflated users | ✓ No session lossSame cap, but sessions & pageviews unaffected |
| Data sampling | ✕ Yeson long date ranges, free tier | ✓ Neverraw counts always |
| Processing delay | ✕ 24–48 hbatched processing | ✓ Real-timesub-second ingest |
| Data residency | ✕ USGoogle Cloud, multi-region | ✓ EU onlyHetzner, Germany |
| Schrems II risk | ✕ US transferUS transfer under the Data Privacy Framework | ✓ Nonedata never leaves EU |
| Typical data coverage | ✕ ~19–29%of actual EU visitors (illustrative model) | ✓ ~100%of actual EU visitors |
The legal argument: why this is not a loophole
GDPR’s purpose is to protect individuals from being identified, profiled, and targeted. Privacy-first analytics achieves this better than consent-based tools:
- Designed so that no personal data needs to be processed. The GDPR attaches only to personal data.
- No cross-site tracking. Each property is isolated.
- No profiling. No persistent identifiers tied to a person.
- Legitimate interest can apply under Art. 6(1)(f) — document your own balancing test.
Conclusion
GA4’s data gap is structural, not fixable. Privacy-first tools largely remove the consent dependence, the ad-blocker problem, and the browser-restriction problem at once. Nearly complete, accurate, real-time data — with a stricter privacy approach than GA4.
Sources cited
- Published consent-rate studies (Cookiebot, Usercentrics, IAB Europe TCF, 2025)
- IAB Europe TCF transparency reporting
- Published ad-blocker usage studies (Statista, 2025)
- CJEU C-582/14 (Breyer v. Bundesrepublik)
- CNIL Audience Measurement Exemption
See your real numbers in 14 days.
Drop the snippet, get full data from day one, and run a GA4-vs-datataste chart at the end of the week. No credit card. EU-hosted.