Method & measurement
If you are searching for first-party analytics or measurement without cookies, you are usually here: the cookie banner is in place, and the numbers got worse. Marketing wants GA4 back the way it was. Legal wants no to mean no. Someone suggests Consent Mode, server-side tagging, or a "cookieless" script that still calls home to the same place.
The GDPR post is about the banner, the scripts, and the requests the browser actually makes. This one is about what you measure afterwards — when someone said yes, said no, or you chose not to set a cookie at all. First-party is not a new product name. It is an ownership and honesty question: if the visitor shuts third parties out, what are you still entitled to count, and what are you lying to yourselves about?
TL;DR
The main points
- First-party means you own the hit and the domain. It does not mean Google, Meta or a heat-map suddenly became "your" data.
- Measurement without cookies is possible. It is a coarser truth — not GA4 under another name.
- A no should make the number smaller. If the curve is unchanged after reject, you are still firing something you should not.
- Consent Mode and server-side tagging are pipes. They are not a legal basis, and they are not a loophole.
- The danger is not losing volume. It is steering by the people who say yes — and calling that "the traffic".
- Map who receives the URL and the id before you buy the next "privacy-friendly" script. Otherwise you changed the badge, not the owner.
Why this matters at all
An honest cookie choice cuts the measurement most marketing dashboards were built on. That is the point. Third-party cookies and pixels that build profiles across sites need a yes. When that yes is a real choice — reject as easy as accept — some of your visitors say no. Then sessions, "conversions" and the remarketing lists someone still treats as a force of nature all drop.
Teams react badly to the drop. They turn on Consent Mode and call the model the truth. They move the same Google tag behind your own subdomain and say "now it is first-party". They install a light script that promises cookieless, then find in the network tab that IP, URL and a fingerprint still leave the house. None of that answers the question: what can you stand behind when someone said no?
This is an SEO and product question as well, not only a compliance question. If you tune headlines, CTAs and landing pages from the slice that accepted tracking, you are steering by the most agreeable visitors. The ones who said no are still on the site. They click, they scroll, they submit the form. You just do not see them — or you see a model guessing them. That is a different problem from a banner that fires too early.
We write this because "first-party analytics" has become a sales word stacked on the same stack. An honest setup is boring: you know which hit you send, on which domain, to which service, on which basis — and you can turn it off. Without that sentence you have a dashboard. You do not have measurement you can defend.
What first-party actually means — and what it does not
First-party, in the browser's sense, is something you set or read on your own site. A cookie on flaretech.dk, set by flaretech.dk, is first-party. A cookie set by a script from another eTLD, or a request that takes an id to a foreign dashboard, is not — even if you CNAME tag.example.com onto your zone. CNAME cloaking changes the label. It does not change who ends up with the profile.
That is why "we run GA4 first-party" is often a sentence that does not survive the network tab. You can set _ga on your own domain. The hit still lands at Google, with URL, user-agent, and whatever user-id and events you configured. That can be legitimate after a yes. It is not cookieless, and it is not data you own if you switch tools tomorrow. You own an export for as long as the contract and the export allow.
Measurement without cookies is a different contract with the visitor. No id in storage. No profile across visits. Typically: a pageview to an endpoint you control, aggregated, without a way to point back at the person. Server logs, a light first-party beacon, or a tool that refuses to store a client-id on purpose. You get trends: which pages, which referrers, coarse geography if you insist. You do not get remarketing, user-id trails, or "this session became a meeting three weeks later" unless you bind that yourselves in your own system after an action the visitor took.
That last part is the honest first-party core most teams skip: events you write yourselves when someone submits a form, books, or signs in. That is your database. It does not need a marketing tag. It needs the product to count what you actually want to steer by — and for you not to glue a Google id on afterwards "so we can see the journey". The journey after a no is not yours unless the visitor gave it to you in an action, not in a hidden pixel.
What you lose when someone says no — and what you should leave alone
A no removes what needed a yes. Third-party pixels. Session replay. Most chat widgets that send page content along. GA4, if you chose that it should wait. Cross-site remarketing. The detailed "user journey" in a foreign UI. That should hurt a vanity dashboard. If it does not, something is still firing.
What you do not need to lose: that a page was served (your own logs). That a form was submitted (your backend). That a payment went through (your payments). That a campaign landing got a hit, if you count first-party and aggregated — UTM in your own table, not a Google click id you keep forever "because it sat in the URL". URL parameters are also personal when you glue them onto an identity.
The dangerous compromise is keeping a coarse pageview without a cookie and then still sending IP and the full URL to five vendors. Cookieless is not a free pass to export the request. Minimisation still applies. An honest cookieless hit is short: path, maybe referrer, maybe a coarse country code you look up yourselves and then drop the IP. Not a user-agent hash plus time plus screen that is a fingerprint in practice.
SEO teams need to be especially honest here. Search Console and your own server logs tell you what Google crawls and what you serve. They do not replace on-page behaviour. They are also not an excuse to set GA4 without a yes "because SEO needs bounce". Bounce in a marketing tool is not a ranking factor. Core Web Vitals you measure with field data you have a basis for — or with the lab you run yourselves. Do not mix those conversations.
What teams call first-party — and what survives a no
What usually gets sold as first-party
The same hit, a new label, the same dashboard.
- GA4 or a pixel via a CNAME on your zone
- Consent Mode that models the people who said no
- Server-side GTM that still ends up at the same buyer
- A "cookieless" script with a fingerprint and a full URL export
What you can defend after a no
Short, yours, and off where it needed a yes.
- Your own logs and an aggregated pageview you host
- Events in your database when the visitor acts
- Search Console and lab measurement for SEO
- A yes that turns a named tool on — and a no that turns it off
An afternoon check before you buy another script
Without this order you change the badge and keep the leak.
- 01
Reject, then read the network tab
Hard reload, reject all, watch the requests. Anything that is not your origin, a font, or a strictly necessary host call needs an explanation. If you cannot give one, the first-party conversation is early. Go back to the data flows.
- 02
Write down who gets path, id and IP
One row per service: name, purpose, basis, what is sent, whether it waits for a yes. First-party is a column — "set on our own domain" — not an excuse to skip the others.
- 03
Separate product events from marketing hits
Forms, bookings, sign-in, payment are counted in your system. Pageviews and campaigns are a different pipe. If one tag is supposed to do both, you gave a marketing tool the keys to the truth.
- 04
Decide what a "no" is allowed to leave behind
Typically: an aggregated first-party pageview, your own logs, no client-id. Write it down. If someone later wants "just a user-id in GA", that is a new yes — not a setting.
- 05
Accept, and check that the yes turns on what you promised
A yes that does not fire the named tool is also a dishonest banner. First-party after consent means yes has one effect, and no has another.
“First-party is not a CNAME. It is that you can turn the hit off, and that what stays on lands somewhere you can explain.”
WordPress and Next.js — the same duty, different places you fool yourselves
On WordPress the typical lie is a plugin that says "anonymised analytics" and still fires a Google or Facebook request because someone pasted an ID into a field two years ago. Or a cookie plugin that hides the UI while header scripts in the theme run around it. First-party here starts with inventory: which plugins send what, before you talk about Plausible, Fathom or your own beacon. A new "GDPR-friendly" plugin on top of three old pixels is a fourth pipe.
On Next.js the typical lie is that you have control because you own the repo. next/script with afterInteractive and a GA id, a third-party embed in the layout, an analytics route that proxies to Google and is called before consent state is read. You can do it right: your own /api/collect that writes aggregates, a consent signal that gates the scripts you named, and product events in the database you already have. Control is an option. It is not the default just because the stack is yours.
Both stacks can run honest cookieless measurement. Both can run GA4 after a yes. Both can lie with a CNAME. Pick the tool for the question you want to answer in three months — "which pages are read" is a different job from "who should see an ad". You can often own the first. The second needs a yes and a vendor you can delete.
If you are considering a stack change to "get first-party analytics", be honest: you are changing where the script can sit. A Next.js site with the same GTM container is not a new legal basis. Change stack if you have other reasons too. Do not change because a slide said edge and your own domain make measurement invisible to the rules. The rules look at purpose and data flow. Not at your bundler.
What you should typically do in the situation you are in
The left is what you typically say. The right is the next step we typically recommend.
Situation
The numbers dropped after an honest banner, and someone wants Consent Mode as the truth
Next step
Keep a dark number if you want. Steer SEO and product from logs, your own events, and the yes you actually got
Situation
You CNAMEd GA or a pixel onto your zone and call that first-party
Next step
Read who gets the profile. The label is yours. The data is not — and a no must still turn it off
Situation
You want to measure without cookies and still see "user journeys"
Next step
You want two things. Cookieless is coarse and yours. Journeys across visits need a yes or your own sign-in
Situation
Marketing and legal each have a dashboard and each have a truth
Next step
One inventory list. One no. Product events in your database as the truth you share
Situation
You are considering a new "privacy" script without reject-testing the old one
Next step
Reject first. Turn off what you cannot explain. Do not buy a fifth pipe for a leak you have not mapped
Checklist before you say "we run first-party"
If you are missing several of these, the sentence is a slide — not a setup.
- Reject leaves only what you wrote as coarse, yours, and without a client-id
- Each service has a purpose, a basis, and a sentence about what is sent
- Product actions are counted in your system, not only in a marketing tag
- Yes turns named tools on; no turns them off — both visible in the network tab
- A CNAME or server-side proxy has not been allowed to mean "owned data"
- SEO uses Search Console and your own logs for crawl and delivery — not a GA bounce as a ranking argument
Questions we get again and again
Is GA4 first-party if the cookie sits on our domain?
The cookie can be first-party. The hit and the profile usually are not. You gave Google a URL, context, and whatever user-id and events you set. That can be fine after a yes and a DPA you actually read. It is not measurement without cookies, and it is not data you take with you the day you switch tools. Say "GA4 after consent". Do not say "we own analytics" unless you can export and switch off without losing your mind.
Can we measure without cookies and still see campaigns?
Coarsely: yes. You can count landings on your own paths and store UTM in an aggregated table without setting an id in the browser. You cannot honestly reconstruct a person-journey over weeks unless you bind it yourselves to an action — a form, a sign-in — the visitor took. If "see campaigns" means remarketing lists and cross-site, you need a yes and a real ad tool. Do not mix those two jobs in one script.
Is server-side tagging the right compromise?
It is a pipe you control, with fewer third-party cookies in the browser and more control over what is sent. That is useful. It is not a legal basis. If you server-side send the same events to the same buyers without a yes, you moved the leak behind your edge. Use it to trim and to honour the consent signal. Do not use it to hide a no.
What about Plausible, Fathom, or a script we host ourselves?
They are often the right answer to "which pages are read", if you have read what they actually send, and if a no still makes sense in your model — some run them as limited, coarse statistics on a different basis than a marketing pixel. That is a legal call you make on your inventory, not on the product name. A self-hosted script that stores a unique id and a full URL history is not innocent because the repo is yours.
May we use Search Console and server logs without a banner?
Search Console is a relationship between you and Google as a search engine — not a script you put on the homepage. Your own server logs are typically operations. Neither replaces a behaviour dashboard, and neither is an excuse to fire GA in the head. Use them for crawl, errors, and what you actually serve. Do not fold them into a sentence about "we already measure, so the pixel is fine".
If the numbers only add up when someone said yes
Let us separate what you own from what you rented.
An afternoon of reject, inventory and your own events beats a new script you buy to get the old curves back.
