GA4 is unforgiving of sloppy implementation: miss an event parameter and your ecommerce reports lie for months before anyone notices. On Magento, a correct setup means a disciplined data layer, consent-aware firing, and purchase deduplication - and for some stores, a server-side layer on top. Here is the setup that produces numbers you can trust.
Client-Side Foundation: GTM + Data Layer
Google Tag Manager, not hardcoded gtag, is the maintainable path. The work is the data layer: Magento must push structured events - view_item, add_to_cart, begin_checkout, purchase - with item arrays carrying item_id (SKU), item_name, price, quantity, currency.
A module or GTM-focused extension renders these pushes on the right actions. The purchase event fires on the success page with the full order: transaction_id, value, tax, shipping, currency, items. Test every event in GTM Preview before publishing - the data layer either matches GA4’s schema exactly or reports silently degrade.
Consent Mode v2
For UK/EU traffic this is not optional. GTM consent defaults (denied) must be set before any Google tag fires, updated by your CMP’s consent signals. With consent mode v2, ad_user_data and ad_personalization signals gate remarketing and ad features. Firing tags before consent is both unlawful and a data-quality problem - consent-denied traffic should flow as modelled pings, not pageviews.
Purchase Deduplication
The classic Magento GA4 bug: refreshed success pages and payment-gateway returns fire purchase twice, inflating revenue. Deduplicate on transaction_id - GTM’s “fire once per transaction ID” logic, or a data-layer flag marking the event as already pushed. Verify by comparing GA4 revenue against Magento order totals weekly for a month; a persistent delta over a few percent means a tracking bug, not a business insight.
Server-Side: When It Is Worth It
Server-side GTM moves event dispatch from the browser to your server container:
- Recovers what ad blockers and ITP strip from client-side
- Controls exactly what leaves your domain - privacy and data governance
- Improves page performance by moving vendor pixels off the client
It costs real infrastructure (Cloud Run or App Engine bills scale with traffic) and ongoing care. Worth it when: paid spend is large enough that attribution gaps change budget decisions, or privacy requirements demand data-flow control. Not worth it for a small store that would not act on the recovered precision - client-side done properly beats server-side done poorly.
The Trust Test
GA4 is useful only while its numbers are believed. Monthly: GA4 vs Magento order revenue, GA4 vs ad-platform click counts, consent-rate trend. When the numbers reconcile, every marketing decision downstream of them gets better. When they do not, fix tracking before spending another pound on ads - a broken measurement layer silently taxes every channel.