This is the order I set up Google Analytics 4 and Google Tag Manager in on a UK business website, from the first decision about what to measure to the checks I repeat every month. It suits a new site, a site that has never had tracking set up properly, and a site where nobody is quite sure who installed what.
It is a setup list. Once everything is in place, my guide to testing whether your conversion tracking actually works walks through proving it with real test enquiries.
How to use this checklist
- Work in order. Each section assumes the one before it is done. Consent in particular has to be designed before any tag goes live, not added afterwards.
- Write down what you decide. A one-page note of event names, key events, filters and who has access saves hours the next time someone touches the setup.
- Expect menus to move. Google renames and relocates settings regularly. If a label here does not match your screen, look for the setting that does the same job.
- Use a test version of the site if you have one. If you do not, publish small changes at quiet times and check them straight away.
1. Decide what you are measuring
Most messy GA4 properties were set up tags-first. Start on paper instead.
- List the actions that make you money. For a service business that is usually an enquiry form, a phone call from the site, a booking and perhaps a WhatsApp or email click. For a shop it is a purchase.
- Pick three to five of those as your headline results. These become GA4 key events. Everything else is useful context, not a result.
- Fix a naming convention before you build anything. Lower case with underscores (generate_lead, phone_click) and Google’s recommended event names where one fits. Renaming events later breaks the history in your reports.
- Note what each event needs to carry. A form event might record which form and which service; a purchase needs an order ID, a value and the items. These details become event parameters.
- Agree who owns the accounts. The GA4 account and the Tag Manager account should belong to a Google login the business controls, with agencies and freelancers added as users. If the property sits in a former supplier’s account, you can lose years of data when the relationship ends, and getting it back depends on their goodwill.
2. GA4 account and property settings
- Account name is the business; property name is the website. One property per website, unless two sites genuinely share one customer journey.
- Reporting time zone: United Kingdom. Otherwise daily figures split at the wrong hour and never line up with your sales records. GA4 handles the switch between GMT and BST for you.
- Currency: British pound (GBP). Set it before revenue data arrives.
- Data retention: 14 months. The default is 2 months, which only limits the detailed explorations, but there is no reason to keep less than the maximum for a standard property.
- A web data stream for the site’s main domain. Copy the Measurement ID (it starts with G-); you need it in Tag Manager.
- Enhanced measurement: leave page views, scrolls, outbound clicks, site search and file downloads on. I usually switch off the automatic form interactions, because it fires on forms that fail validation and you will track real submissions properly in section 4.
- Redact data: turn on email redaction and add any query parameters that can carry personal details, such as email or name in a form’s confirmation URL.
- Internal traffic: define your office and home IP addresses as internal, then activate the internal traffic filter. Leave it in testing for a day first and check it catches only your own visits.
- Unwanted referrals: add payment and booking providers (PayPal, Stripe, a hosted booking system) so a customer returning from paying is not recorded as a new visit from that provider.
- Cross-domain measurement: if the journey crosses domains, for example from your site to a separate booking or shop domain, list both so the visit stays as one session. The cross-domain tracking entry explains what breaks without it.
- Google signals and ads personalisation: decide deliberately. Both relate to advertising features, and they belong in your privacy notice and cookie banner wording if you turn them on.
3. Tag Manager container
- One web container per website, in the same business-owned account structure.
- Install both parts of the container code: the script as high in the head as possible and the noscript part straight after the opening body tag. On WordPress or Shopify use a single, reputable method, and remove any other plugin or theme setting that also adds Google tags.
- Remove hard-coded tags. If GA4 or an old Universal Analytics snippet is pasted into the theme as well, you will count every page view twice or load tags outside your consent controls.
- Add the Google tag with your Measurement ID, firing on the Initialization trigger for all pages, so it loads after consent defaults are set but before other tags.
- Use variables, not pasted values. Store the Measurement ID and other IDs as constant variables so a change is made once.
- Name things so a stranger can follow them. A pattern such as GA4 – event – generate_lead for tags and Form – contact – success for triggers works well.
- Folders for GA4, Google Ads, Meta and consent tags keep the container readable as it grows.
4. Events and key events
The reliable way to track a form is from the confirmation, not from the click on the submit button. A click fires even when the form fails.
- Forms: trigger on a thank-you page that only loads after a successful submission, or on a success message the form pushes to the data layer. Ask your developer or form plugin for a data layer event if neither exists.
- Phone and email clicks: track clicks on tel: and mailto: links as their own events. They show intent, not a completed call, so be honest with yourself about how much weight they carry.
- Bookings and embedded tools: third-party booking widgets often run in a frame your container cannot see. Check whether the provider offers its own GA4 connection or a confirmation redirect before you promise anyone a booking figure.
- Parameters: send the details you planned in section 1, such as form_name or service, then register the ones you want in reports as custom dimensions in GA4. Unregistered parameters are collected but do not appear in standard reports.
- Key events: mark only the three to five headline actions as key events in GA4. Marking every scroll and click as a key event makes the figure meaningless.
- No personal details in events. Never send names, email addresses or phone numbers to GA4, in event parameters or in page URLs. Google’s terms forbid it, and it is personal data under UK GDPR that you would then have to account for.
5. Ecommerce, if you sell online
- Use the recommended ecommerce events: view_item, add_to_cart, begin_checkout and purchase at minimum, with the items array filled in. Most UK shop platforms and their GA4 integrations already push these to the data layer; check what yours sends before building anything.
- Every purchase carries a transaction ID, a value and currency GBP. The transaction ID lets GA4 ignore a repeat purchase event when a customer refreshes the order confirmation page.
- Decide whether revenue includes VAT and delivery, write the decision down and keep it the same in GA4, Google Ads and Meta. Mixing gross and net figures across platforms is a common reason the numbers never agree.
- Refunds: send a refund event, or accept that GA4 revenue runs above your accounts and note the gap.
- Test a real order with a discount code or a low-priced product, then compare it line by line with the order in your shop’s back office.
6. Platform links and imports
- Google Ads: link the account in GA4’s product links and keep auto-tagging on in Google Ads. Then choose one source for each conversion: either import GA4 key events into Google Ads or use the Google Ads conversion tag, but do not count the same enquiry from both as primary conversions.
- Search Console: link it so search query and landing page data sit beside your GA4 figures.
- Merchant Center, for shops running Shopping or Performance Max campaigns.
- BigQuery export: worth switching on early if you expect to need raw data later. It only collects from the day you turn it on.
- Meta: the Meta pixel and Conversions API are set up in Meta’s Events Manager, not in GA4. If the pixel runs through Tag Manager, it follows the same consent rules as everything else. GA4 and Meta will still report different numbers, and the reasons are in why GA4 and Facebook conversion figures disagree.
- Campaign links: tag email, social and offline campaign links consistently with UTM parameters. My free UTM link builder keeps the source and medium names tidy.
7. Consent and privacy under UK GDPR and PECR
This is where UK setups differ most from the generic tutorials. Under the Privacy and Electronic Communications Regulations (PECR), storing or reading cookies that are not strictly necessary needs the visitor’s consent, and the ICO treats analytics and advertising cookies as not strictly necessary. In practice, GA4, Google Ads and the Meta pixel should not set cookies until the visitor has agreed.
The Data (Use and Access) Act 2025 includes changes to the consent rule for some cookies used only to produce statistics about your own site. How and when those changes apply, and whether they cover third-party analytics tools such as GA4, depends on commencement and on the ICO’s guidance, so check the ICO’s current position for the tools you actually use. Until you have done that, the cautious setup below is the one I follow.
- Use a consent management platform that offers a Tag Manager template and supports Google’s Consent Mode v2. If you also show Google ads on your own site, check the platform appears on Google’s approved list for publishers.
- Set defaults to denied before anything fires. The banner’s tag runs on the Consent Initialization trigger and sets ad_storage, analytics_storage, ad_user_data and ad_personalization to denied for visitors who have not chosen yet.
- Make refusing as easy as accepting. A “Reject all” button on the first layer, no pre-ticked boxes, and a way to change the choice later, such as a cookie settings link in the footer.
- Choose basic or advanced Consent Mode knowingly. Basic blocks Google tags entirely until consent. Advanced loads them in a restricted state and sends cookieless pings that let Google model some of the missing data. Some privacy advisers consider those pings still need consent under PECR, so I default to basic unless the business has taken advice and chosen otherwise.
- Gate non-Google tags yourself. Meta, LinkedIn and other pixels do not read Google’s consent signals. Add a trigger condition so they fire only once the matching consent category is granted.
- Check the cookies after a refusal. Reject everything, then look in the browser’s developer tools: there should be no _ga, _gcl_au or _fbp cookies.
- Update the privacy notice and cookie policy to list GA4, Google Ads, Meta and any other tool you run, with what each collects and how long it keeps it.
Expect fewer recorded visits once consent is working, because some visitors say no. That gap is the honest figure, not a fault to fix.
8. QA before you trust the data
- Tag Manager Preview: click through the journey and confirm each tag fires once, on the right trigger, and only after consent.
- GA4 DebugView: confirm events arrive with the parameters you expect and that key events are flagged.
- Repeat on a phone, and on the browser your customers use most, not only the one you build in.
- Submit a real test enquiry or order and follow it through to GA4 and any ad platform. The step-by-step method is in the conversion tracking test guide linked at the top of this page.
- Publish with a version name and a note of what changed, so you can roll back to a known good version in one click.
9. Reporting and maintenance
- Weekly for the first month: compare GA4 key events with the enquiries or orders you actually received. Some gap is normal once consent is in place, because visitors who refuse are not recorded. A sudden change in the gap, or GA4 recording more than you received, points to a fault.
- Monthly: look for a rise in unassigned or direct traffic, which usually means links have lost their tagging, and for events that have stopped firing after a site change.
- After every website change: new forms, themes, checkout updates and plugin swaps are the usual reasons tracking breaks. Re-run the QA checks the same day.
- Quarterly: review who has access to GA4, Tag Manager and the ad accounts, and remove former staff and suppliers.
- Keep annotations for launches, campaigns, site changes and tracking fixes, so a jump in the figures has an explanation attached.
Common setup faults to look for
- GA4 installed twice, once through a plugin and once through Tag Manager, doubling page views.
- Form tracking fired on the submit button click, counting failed and spam submissions as leads.
- Tags loading before the cookie banner has been answered, or a banner with no reject option.
- Time zone or currency left on the defaults, so daily and revenue figures never match the business’s own records.
- Payment providers showing up as the top referral source because unwanted referrals were never set.
- Email addresses appearing in page URLs in GA4 reports after a form submission.
- The same enquiry counted as a conversion in Google Ads twice, once from the GA4 import and once from the Google Ads tag.
- The GA4 property sitting in a former agency’s account, with nobody at the business holding admin access.
When to hand it over
If your tracking feeds paid campaigns, every fault in this list costs money, because the bidding systems optimise towards whatever you tell them is a result. I check and fix tracking as part of running Google Ads campaigns for UK businesses and Facebook and Instagram advertising, and I also offer GA4 and Tag Manager setup and audits on their own. If you would rather someone else worked through this list, send me the site address and tell me what you are trying to measure.
Updated
