Sultan Kautsar Get a quote

Consent Mode V2

Privacy regulation and data quality are usually treated as a trade-off: tighten one and you lose the other. Most sites “handle” consent by putting a cookie banner on top of their existing tags and calling it compliant. Then either the tracking keeps firing when it should not, or it stops completely and half the data disappears the moment someone clicks “reject.”

The banner is only the visible part of Consent Mode V2. Underneath, it is a signaling layer between the site, Google Tag Manager, and Google's platforms, and when that layer is built properly you can stay compliant and still see what is happening. This note is one of four on the measurement stack, together with Google Analytics 4 and Google Ads Conversion Tracking.

5 min read

The Problem

A banner collects a choice. Something else has to carry that choice to every tag, at the right moment and for the right region. When that part is missing, consent fails in one of two directions:

  • Too permissive: tags fire before a “reject” or in spite of it, which is a compliance risk.
  • Too strict: tags are blocked with no fallback, and reporting and bidding lose a large share of their signal.

From the outside, both look fine. The banner appears and the site works. The problem shows up later, in an audit or as a slow decline in reported conversions.

Consent Mode is a small set of commands that tell Google tags what the visitor agreed to, and the tags adjust their own behavior to match.

  1. Page starts loading
  2. Default consent state is set (usually denied)
  3. Consent banner (CMP) appears
  4. Visitor accepts, rejects, or customizes
  5. Consent update is sent with the new state
  6. Google tags adjust what they store and send

The order matters. The default has to be set before any Google tag runs, and the update has to arrive the moment the visitor chooses. Waiting for the next page load is too late.

The Four Signals

Version 2 added two signals to the original two. Google requires them for advertising features when visitors are in the European Economic Area.

Signal What it controls
analytics_storage Whether analytics cookies, such as GA4’s, may be stored.
ad_storage Whether advertising cookies may be stored.
ad_user_data Whether user data may be sent to Google for advertising. New in V2.
ad_personalization Whether data may be used for personalized ads, such as remarketing. New in V2.

Basic and Advanced Mode

Basic mode
Google tags do not load at all until the visitor consents, so nothing is sent before the choice. It is simple, but when a visitor declines, Google gets no signal and has nothing to model from.

Advanced mode
Google tags load with consent denied by default and send cookieless pings without identifiers. When a visitor declines, Google can use those pings to model the conversions it cannot observe directly.

The right mode depends on the legal advice for the business and the regions it serves. Pick one deliberately, because that choice decides whether modeled conversions are possible.

What a Good Setup Includes

  • All four signals are set and updated in real time as the visitor uses the banner, and again on later pages.
  • Default states are correct for the split second before the visitor has chosen anything. Most “compliant” setups leak data or break tracking right here.
  • Each tag in the Tag Manager container checks consent on its own. GA4, Ads, Meta, and everything else respect the consent state individually, instead of relying on the CMP to block everything.
  • The configuration follows the regions. GDPR, ePrivacy, and other frameworks ask for different things, and one global on/off switch for every visitor does not match any of them.
  • Modeled conversions are enabled, so when someone declines cookies Google can estimate the gap instead of leaving a hole in reporting and bidding.

Where It Fits

Consent is the first gate in the measurement chain, and every layer after it inherits its decisions.

  1. A visitor lands on the site
  2. Consent defaults load, then update on their choice
  3. The site pushes events into the data layer
  4. Google Tag Manager fires the tags consent allows
  5. GA4 records the journey, Google Ads receives the conversions

Google Tag Manager enforces the consent state on each tag. Depending on how this layer was built, Google Analytics 4 and Google Ads Conversion Tracking then receive full data, modeled data, or nothing.

Common Mistakes

  • The default arrives too late: a tag fires before the default state is set and runs as if consent was granted.
  • The update never arrives: the banner records the choice, but the CMP is not connected to Consent Mode, so the tags never hear about it.
  • Only the old signals are set: ad_user_data and ad_personalization are missing, which limits advertising features for EEA traffic.
  • Non-Google tags ignore consent: Google tags read the signals natively, but other pixels need their own consent checks in Tag Manager.
  • Only “accept all” is tested: most bugs are in the reject and custom paths.

Why It Matters

Get it wrong in one direction and the site is non-compliant, exposed to fines and to platform penalties that can shut down ad accounts overnight. Get it wrong in the other and you are legally safe but flying without instruments. Reporting undercounts conversions, bidding learns from incomplete signals, and performance slides for reasons that do not show up anywhere.

The regulation is staying, and so is the expectation that the data holds up. The businesses that handle this well plan consent as part of the tracking architecture from the start, before launch, instead of adding it afterward for the lawyers.

How I Approach It

1. Audit the current consent setup
Which signals exist, which ones the tags actually respect, and where compliance and data quality are working against each other.

2. Map the regulatory footprint
Where the users are, what the law requires there, and what is only best practice.

3. Architect the consent signal flow
In Google Tag Manager, connected to the CMP and to every tag downstream.

4. Configure conversion modeling
So a declined consent leads to modeled data instead of a gap.

5. Test every consent state
Accept, reject, and each custom combination. I check the state in Tag Manager’s Preview mode and in the network requests the tags send.

6. Document
So the setup stays compliant when someone else adds tags later.

Privacy and data quality only conflict when nobody has designed the system to handle both. If you want a second look at your setup, get in touch.

Related Notes

  1. Google Tag Manager

    Clean up, speed up, and secure your Google Tag Manager container: GTM audits, server-side tagging, and a data layer the site and the container can both rely on.

  2. Google Analytics 4

    Google Analytics 4 setup and full customer-journey tracking by a Google Tag Manager expert, built so the reports hold up when someone asks them a hard question.

  3. Google Ads Conversion Tracking

    Google Ads conversion tracking, including server-side setups, by a Google Tag Manager expert. Accurate attribution so automated bidding learns from conversions that really happened.

Next step

Have a project in mind? Let's talk.

Tell me what you have and what you need. I'll usually reply within one working day with how I'd approach it.