The Problem
A banner collects a choice. Something else has to carry that choice to every tag, at the right moment and for the right region. When that part is missing, consent fails in one of two directions:
- Too permissive: tags fire before a “reject” or in spite of it, which is a compliance risk.
- Too strict: tags are blocked with no fallback, and reporting and bidding lose a large share of their signal.
From the outside, both look fine. The banner appears and the site works. The problem shows up later, in an audit or as a slow decline in reported conversions.
How Consent Mode Works
Consent Mode is a small set of commands that tell Google tags what the visitor agreed to, and the tags adjust their own behavior to match.
- Page starts loading
- Default consent state is set (usually denied)
- Consent banner (CMP) appears
- Visitor accepts, rejects, or customizes
- Consent update is sent with the new state
- Google tags adjust what they store and send
The order matters. The default has to be set before any Google tag runs, and the update has to arrive the moment the visitor chooses. Waiting for the next page load is too late.
The Four Signals
Version 2 added two signals to the original two. Google requires them for advertising features when visitors are in the European Economic Area.
| Signal | What it controls |
|---|---|
analytics_storage |
Whether analytics cookies, such as GA4’s, may be stored. |
ad_storage |
Whether advertising cookies may be stored. |
ad_user_data |
Whether user data may be sent to Google for advertising. New in V2. |
ad_personalization |
Whether data may be used for personalized ads, such as remarketing. New in V2. |
Basic and Advanced Mode
Basic mode
Google tags do not load at all until the visitor consents, so nothing is sent before the choice. It is simple, but when a visitor declines, Google gets no signal and has nothing to model from.
Advanced mode
Google tags load with consent denied by default and send cookieless pings without identifiers. When a visitor declines, Google can use those pings to model the conversions it cannot observe directly.
The right mode depends on the legal advice for the business and the regions it serves. Pick one deliberately, because that choice decides whether modeled conversions are possible.
What a Good Setup Includes
- All four signals are set and updated in real time as the visitor uses the banner, and again on later pages.
- Default states are correct for the split second before the visitor has chosen anything. Most “compliant” setups leak data or break tracking right here.
- Each tag in the Tag Manager container checks consent on its own. GA4, Ads, Meta, and everything else respect the consent state individually, instead of relying on the CMP to block everything.
- The configuration follows the regions. GDPR, ePrivacy, and other frameworks ask for different things, and one global on/off switch for every visitor does not match any of them.
- Modeled conversions are enabled, so when someone declines cookies Google can estimate the gap instead of leaving a hole in reporting and bidding.
Where It Fits
Consent is the first gate in the measurement chain, and every layer after it inherits its decisions.
- A visitor lands on the site
- Consent defaults load, then update on their choice
- The site pushes events into the data layer
- Google Tag Manager fires the tags consent allows
- GA4 records the journey, Google Ads receives the conversions
Google Tag Manager enforces the consent state on each tag. Depending on how this layer was built, Google Analytics 4 and Google Ads Conversion Tracking then receive full data, modeled data, or nothing.
Common Mistakes
- The default arrives too late: a tag fires before the default state is set and runs as if consent was granted.
- The update never arrives: the banner records the choice, but the CMP is not connected to Consent Mode, so the tags never hear about it.
- Only the old signals are set:
ad_user_dataandad_personalizationare missing, which limits advertising features for EEA traffic. - Non-Google tags ignore consent: Google tags read the signals natively, but other pixels need their own consent checks in Tag Manager.
- Only “accept all” is tested: most bugs are in the reject and custom paths.
Why It Matters
Get it wrong in one direction and the site is non-compliant, exposed to fines and to platform penalties that can shut down ad accounts overnight. Get it wrong in the other and you are legally safe but flying without instruments. Reporting undercounts conversions, bidding learns from incomplete signals, and performance slides for reasons that do not show up anywhere.
The regulation is staying, and so is the expectation that the data holds up. The businesses that handle this well plan consent as part of the tracking architecture from the start, before launch, instead of adding it afterward for the lawyers.
How I Approach It
1. Audit the current consent setup
Which signals exist, which ones the tags actually respect, and where compliance and data quality are working against each other.
2. Map the regulatory footprint
Where the users are, what the law requires there, and what is only best practice.
3. Architect the consent signal flow
In Google Tag Manager, connected to the CMP and to every tag downstream.
4. Configure conversion modeling
So a declined consent leads to modeled data instead of a gap.
5. Test every consent state
Accept, reject, and each custom combination. I check the state in Tag Manager’s Preview mode and in the network requests the tags send.
6. Document
So the setup stays compliant when someone else adds tags later.
Privacy and data quality only conflict when nobody has designed the system to handle both. If you want a second look at your setup, get in touch.