Skip to content
Sultan Kautsar

Home / Notes /

Consent Mode V2

Privacy regulation and data quality are usually treated as opposites: tighten one, lose the other. Most sites “handle” consent by dropping a cookie banner on top of their existing tags and calling it compliant. The tracking either still fires when it should not, or it stops firing entirely and half the data disappears the moment someone clicks “reject.” Neither actually solves the problem.

Consent Mode V2 done properly is not a banner. It is a signaling layer between the site, Google Tag Manager, and Google's platforms, and getting it right is what lets you stay compliant without flying blind. This note is one of four on the measurement stack, together with Google Analytics 4 and Google Ads Conversion Tracking.

The Problem

A banner on its own only collects a choice. Something still has to carry that choice to every tag, at the right moment, in the right region. When that part is missing, consent fails in one of two directions:

  • Too permissive: tags fire before or despite a “reject,” which is a compliance risk.
  • Too strict: tags are blocked with no fallback, so reporting and bidding lose a large share of their signal.

Both failures look fine from the outside. The banner appears, the site works, and the problem only shows up in an audit or in a slow decline of reported conversions.

Consent Mode is a small set of commands that tell Google tags what the visitor has agreed to. The tags then adjust their own behavior.

Page starts loading
   ↓
Default consent state is set (usually denied)
   ↓
Consent banner (CMP) appears
   ↓
Visitor accepts, rejects, or customizes
   ↓
Consent update is sent with the new state
   ↓
Google tags adjust what they store and send

The order matters. The default has to be set before any Google tag runs, and the update has to arrive the moment the visitor chooses, not on the next page load.

The Four Signals

Version 2 added two signals to the original pair. Google requires them for advertising features with visitors in the European Economic Area.

Signal What it controls
analytics_storage Whether analytics cookies, such as GA4's, may be stored.
ad_storage Whether advertising cookies may be stored.
ad_user_data Whether user data may be sent to Google for advertising. New in V2.
ad_personalization Whether data may be used for personalized ads, such as remarketing. New in V2.

Basic and Advanced Mode

Basic mode
Google tags do not load at all until the visitor consents. Nothing is sent before that choice. It is simple, but when a visitor declines, Google receives no signal and has nothing to model from.

Advanced mode
Google tags load with consent denied by default and send cookieless pings without identifiers. When a visitor declines, Google can use those pings to model the conversions it cannot observe directly.

Which one is right depends on the legal advice for the business and the regions it serves. The important part is choosing deliberately, since the choice decides whether modeled conversions are possible.

What a Good Setup Includes

  • Correct consent signal wiring: all four signals are set and updated in real time as the user interacts with the consent banner, not just at page load.
  • Consent-aware default states: tags behave correctly for the split second before a user makes any choice at all. This is where most “compliant” setups quietly leak data or silently break tracking.
  • Tag-level consent checks: built directly into the Tag Manager container, so every tag (GA4, Ads, Meta, and anything else) respects consent state individually instead of relying on the CMP alone to gate everything.
  • Regional configuration: respects the actual legal requirements of GDPR, ePrivacy, and other regional frameworks, not a single global on/off switch applied everywhere regardless of where the visitor is.
  • Modeled conversions: when a user declines cookies, Google can still statistically model the gap instead of leaving a hole in reporting and a blind spot in bidding.

Where It Fits

Consent is the first gate in the measurement chain. Every layer after it inherits its decisions.

A visitor lands on the site
   ↓
Consent defaults load, then update on their choice
   ↓
The site pushes events into the data layer
   ↓
Google Tag Manager fires the tags consent allows
   ↓
GA4 records the journey, Google Ads receives the conversions

Google Tag Manager enforces the consent state on each tag. Google Analytics 4 and Google Ads Conversion Tracking then receive either full data, modeled data, or nothing, depending on how this layer was built.

Common Mistakes

  • The default arrives too late: a tag fires before the default state is set, so it runs as if consent was granted.
  • The update never arrives: the banner records the choice, but the CMP is not connected to Consent Mode, so tags never learn about it.
  • Only the old signals are set: ad_user_data and ad_personalization are missing, which limits advertising features for EEA traffic.
  • Non-Google tags ignore consent: Google tags respect the signals natively, but other pixels need their own consent checks in Tag Manager.
  • Only “accept all” is tested: the reject and custom paths are where most bugs hide.

Why It Matters

Get this wrong in one direction and you are non-compliant, exposed to fines and platform penalties that can turn off ad accounts overnight. Get it wrong in the other direction and you are technically safe but flying without instruments: reporting undercounts conversions, bidding algorithms optimize on incomplete signals, and nobody notices until performance quietly degrades for reasons that do not show up anywhere.

The regulation is not going away, and neither is the expectation that the data holds up. The businesses that get ahead of this treat consent as an architecture decision, not a legal checkbox bolted on after launch.

How I Approach It

1. Audit the current consent setup
Which signals exist, which are actually respected by the tags, and where compliance and data integrity are quietly working against each other.

2. Map the regulatory footprint
Where the users actually are, and what that legally requires versus what is just best practice.

3. Architect the consent signal flow
In Google Tag Manager, wired into the CMP and every downstream tag.

4. Configure conversion modeling
So declined consent means modeled visibility, not lost visibility.

5. Test every consent state
Accept, reject, and each custom combination, checking the consent state in Tag Manager's Preview mode and in the network requests the tags actually send.

6. Document
So what is compliant today stays compliant as tags get added later by someone who is not me.

Privacy compliance and data integrity are only in tension when nobody has architected the system properly. If you want a second look at your setup, get in touch.

Related notes

  1. Google Tag Manager
  2. Google Analytics 4
  3. Google Ads Conversion Tracking

All notes →