The Problem
A banner on its own only collects a choice. Something still has to carry that choice to every tag, at the right moment, in the right region. When that part is missing, consent fails in one of two directions:
- Too permissive: tags fire before or despite a “reject,” which is a compliance risk.
- Too strict: tags are blocked with no fallback, so reporting and bidding lose a large share of their signal.
Both failures look fine from the outside. The banner appears, the site works, and the problem only shows up in an audit or in a slow decline of reported conversions.
How Consent Mode Works
Consent Mode is a small set of commands that tell Google tags what the visitor has agreed to. The tags then adjust their own behavior.
Page starts loading ↓ Default consent state is set (usually denied) ↓ Consent banner (CMP) appears ↓ Visitor accepts, rejects, or customizes ↓ Consent update is sent with the new state ↓ Google tags adjust what they store and send
The order matters. The default has to be set before any Google tag runs, and the update has to arrive the moment the visitor chooses, not on the next page load.
The Four Signals
Version 2 added two signals to the original pair. Google requires them for advertising features with visitors in the European Economic Area.
| Signal | What it controls |
|---|---|
analytics_storage |
Whether analytics cookies, such as GA4's, may be stored. |
ad_storage |
Whether advertising cookies may be stored. |
ad_user_data |
Whether user data may be sent to Google for advertising. New in V2. |
ad_personalization |
Whether data may be used for personalized ads, such as remarketing. New in V2. |
Basic and Advanced Mode
Basic mode
Google tags do not load at all until the visitor consents. Nothing is sent before that choice. It is simple, but when a visitor declines, Google receives no signal and has nothing to model from.
Advanced mode
Google tags load with consent denied by default and send cookieless pings without identifiers. When a visitor declines, Google can use those pings to model the conversions it cannot observe directly.
Which one is right depends on the legal advice for the business and the regions it serves. The important part is choosing deliberately, since the choice decides whether modeled conversions are possible.
What a Good Setup Includes
- Correct consent signal wiring: all four signals are set and updated in real time as the user interacts with the consent banner, not just at page load.
- Consent-aware default states: tags behave correctly for the split second before a user makes any choice at all. This is where most “compliant” setups quietly leak data or silently break tracking.
- Tag-level consent checks: built directly into the Tag Manager container, so every tag (GA4, Ads, Meta, and anything else) respects consent state individually instead of relying on the CMP alone to gate everything.
- Regional configuration: respects the actual legal requirements of GDPR, ePrivacy, and other regional frameworks, not a single global on/off switch applied everywhere regardless of where the visitor is.
- Modeled conversions: when a user declines cookies, Google can still statistically model the gap instead of leaving a hole in reporting and a blind spot in bidding.
Where It Fits
Consent is the first gate in the measurement chain. Every layer after it inherits its decisions.
A visitor lands on the site ↓ Consent defaults load, then update on their choice ↓ The site pushes events into the data layer ↓ Google Tag Manager fires the tags consent allows ↓ GA4 records the journey, Google Ads receives the conversions
Google Tag Manager enforces the consent state on each tag. Google Analytics 4 and Google Ads Conversion Tracking then receive either full data, modeled data, or nothing, depending on how this layer was built.
Common Mistakes
- The default arrives too late: a tag fires before the default state is set, so it runs as if consent was granted.
- The update never arrives: the banner records the choice, but the CMP is not connected to Consent Mode, so tags never learn about it.
- Only the old signals are set:
ad_user_dataandad_personalizationare missing, which limits advertising features for EEA traffic. - Non-Google tags ignore consent: Google tags respect the signals natively, but other pixels need their own consent checks in Tag Manager.
- Only “accept all” is tested: the reject and custom paths are where most bugs hide.
Why It Matters
Get this wrong in one direction and you are non-compliant, exposed to fines and platform penalties that can turn off ad accounts overnight. Get it wrong in the other direction and you are technically safe but flying without instruments: reporting undercounts conversions, bidding algorithms optimize on incomplete signals, and nobody notices until performance quietly degrades for reasons that do not show up anywhere.
The regulation is not going away, and neither is the expectation that the data holds up. The businesses that get ahead of this treat consent as an architecture decision, not a legal checkbox bolted on after launch.
How I Approach It
1. Audit the current consent setup
Which signals exist, which are actually respected by the tags, and where compliance and data integrity are quietly working against each other.
2. Map the regulatory footprint
Where the users actually are, and what that legally requires versus what is just best practice.
3. Architect the consent signal flow
In Google Tag Manager, wired into the CMP and every downstream tag.
4. Configure conversion modeling
So declined consent means modeled visibility, not lost visibility.
5. Test every consent state
Accept, reject, and each custom combination, checking the consent state in Tag Manager's Preview mode and in the network requests the tags actually send.
6. Document
So what is compliant today stays compliant as tags get added later by someone who is not me.
Privacy compliance and data integrity are only in tension when nobody has architected the system properly. If you want a second look at your setup, get in touch.