Tell Google's tags what visitors agreed to,
before they fire.
Google Consent Mode v2 is how your cookie banner passes a visitor's choice to Google Analytics and Google Ads. This guide covers the four signals, basic and advanced mode, how to set it up with a consent management platform and Google Tag Manager, and how to check it works. A practical guide, not legal advice.
Last updated Published by TryTrustableNot legal advice
Google Consent Mode is the way a website tells Google's tags (Google Analytics, Google Ads, Floodlight) what a visitor agreed to on the cookie banner, so the tags change their behaviour to match. Version 2 added two signals, ad_user_data and ad_personalization, to the original ad_storage and analytics_storage. Google has required them for visitors in the European Economic Area since March 2024, and its EU user consent policy covers the UK and Switzerland too. Without them, remarketing and audience features stop working for those visitors.
What is Google Consent Mode v2?
Google Consent Mode is an API built into Google's tags. Your cookie banner, or consent management platform (CMP), sets a default state for each consent type when the page loads, then sends an update when the visitor chooses. Google Analytics 4, Google Ads, Floodlight and the other Google tags read that state and change what they store and send.
Consent Mode is not a cookie banner. It does not ask the visitor anything and it does not record proof of consent. It only carries the answer from the banner to Google. You still need a banner that collects valid consent where the law requires it (see our guide to cookie compliance), and you still need to block non-Google trackers, which Consent Mode does not touch.
Version 2 is the same API with two more signals, ad_user_data and ad_personalization. They separate two questions the original ad_storage lumped together: may Google receive this visitor's data for advertising, and may it use that data to personalise ads.
The four Consent Mode signals, and the optional three
Google defines seven consent types. Four of them matter for advertising and analytics, and those are the ones Google checks for European traffic. The other three let a banner pass functional and security choices through the same mechanism.
| Signal | What it controls | If denied |
|---|---|---|
ad_storage | Cookies and identifiers used for advertising | No new advertising cookies are written; ad click identifiers can be redacted |
analytics_storage | Cookies used for analytics, such as visit duration | No analytics cookies; Google Analytics can send cookieless pings used for modelling |
ad_user_data (v2) | Whether user data may be sent to Google for advertising | User data is not used for advertising, which limits conversion and audience features |
ad_personalization (v2) | Whether data may be used for personalised advertising | Remarketing and personalised ads are switched off for that visitor |
functionality_storage | Storage that makes the site work, such as language | Optional; set by your banner if you use it |
personalization_storage | Storage for personalisation, such as recommendations | Optional |
security_storage | Authentication, fraud prevention and security | Usually left granted: it covers strictly necessary storage |
The first four are the ones Google Ads and Analytics check for EEA traffic. Source: Google tag platform documentation.
Is Consent Mode v2 mandatory? The EEA and UK requirement
Google's EU user consent policy applies to end users in the European Economic Area, the UK and Switzerland. It requires sites that use Google's advertising and measurement products to get legally valid consent for cookies where the law requires it and for the use of personal data to personalise ads, to keep records of that consent, and to tell users how to withdraw it.
From March 2024, Google began requiring the two v2 signals for EEA users. If ad_user_data and ad_personalization are not passed as granted, data from those users is not used for ad personalisation: remarketing lists stop growing, Customer Match cannot use them, and conversion features that depend on user data are limited. Google's help pages describe the requirement in terms of the EEA; because the policy itself names the UK and Switzerland, treat them the same way.
Consent Mode is a Google contract requirement, not a law. The legal duty to ask for consent before setting non-essential cookies comes from the ePrivacy Directive in the EU and PECR in the UK. Passing the signals does not make a banner lawful, and a lawful banner without the signals still loses Google features.
US and Australia. Google does not require Consent Mode outside Europe today, but it is still the cleanest way to honour an opt-out. Under the CCPA a visitor who opts out of sale or sharing, or whose browser sends Global Privacy Control, should have ad_user_data and ad_personalization set to denied so their data is not used for cross-context behavioural advertising.
Basic vs advanced consent mode
Google describes two ways to implement it. The difference is what happens before the visitor answers.
| Basic consent mode | Advanced consent mode | |
|---|---|---|
| Before the visitor chooses | Google tags do not load at all | Google tags load with every signal set to denied |
| Data sent before consent | None | Cookieless pings: no cookies, no advertising identifiers |
| After the visitor refuses | Nothing is sent | Cookieless pings continue |
| Conversion and behaviour modelling | General model only | Model trained on your own site's pings |
| Set-up effort | Simpler: the banner holds the tags | Defaults must load before any Google tag, every time |
| When it fits | You want nothing sent to Google without consent | You accept cookieless pings and want better modelling |
Both satisfy Google's requirement to pass the signals. Which one your legal basis supports is a question for your counsel.
In basic mode the banner holds every Google tag until the visitor chooses, so Google receives nothing from a visitor who refuses. In advanced mode the tags load straight away with everything denied and send cookieless pings (no cookies, no ad identifiers) that Google uses to model the conversions and behaviour it cannot observe. Google says that blocking its tags until consent means you will not get the full benefit of consent mode. Some regulators and DPOs prefer basic mode because nothing leaves the browser without consent. Decide deliberately, write the decision down, and make sure your banner and your Tag Manager set-up do the same thing.
How to implement Consent Mode v2 with a CMP
Most sites should not hand-write Consent Mode. A CMP that supports it sets the defaults, maps its own categories to Google's signals and sends updates. What to check in any CMP:
- The default is set first. The consent default must run before any Google tag on the page parses. That means the banner script goes first in the <head>, loaded synchronously, not deferred.
- All four signals are sent. A banner that only sets
ad_storageandanalytics_storageis v1, and Google will treat the v2 signals as missing. - Categories map sensibly. Marketing consent should drive
ad_storage,ad_user_dataandad_personalization; analytics consent drivesanalytics_storage. - Returning visitors are handled. A stored choice should be re-applied on every page load, with
wait_for_updategiving it time to land. - Regions are right. Denied by default for the EEA, UK and Switzerland; opt-out regions can start granted but must flip to denied on an opt-out or a Global Privacy Control signal.
- Companion settings.
ads_data_redactionredacts ad click identifiers whilead_storageis denied, andurl_passthroughcarries click IDs in the URL so conversions can still be attributed without a cookie.
Google lists CMPs it has certified as partners. Certification is a Google programme; it does not change what the law requires of your banner.
Google Tag Manager cookie consent set-up
In Google Tag Manager the pattern is the same, expressed as tags and triggers.
| Step | With gtag.js in the page | With Google Tag Manager |
|---|---|---|
| 1. Set defaults | gtag('consent', 'default', {...}) in the <head>, before the Google tag | A consent template or CMP tag on the Consent Initialization: All Pages trigger |
| 2. Choose regions | Add region: ['AT','BE', ...] for denied-by-default countries | Region field in the template, using ISO 3166-2 codes |
| 3. Wait for the banner | wait_for_update: 500 so a stored choice can land first | Same setting in the template; Google suggests at least 500 ms for asynchronous CMPs |
| 4. Update on choice | gtag('consent', 'update', {...}) when the visitor accepts or refuses | The CMP calls the update API; tags re-evaluate on the next event |
| 5. Gate other tags | Your banner blocks non-Google scripts until consent | Use Consent Overview and additional consent checks on non-Google tags |
Run one source of consent updates per page. Two writers on the same dataLayer race each other.
Turn on Consent Overview in the container settings. It shows every tag with its consent settings in one list. Google's own tags have built-in consent checks and adjust themselves. Non-Google tags (a Meta pixel, LinkedIn Insight, Hotjar) do not understand Consent Mode, so give each one an additional consent check, for example require ad_storage for an ad pixel, or let your banner block them before Tag Manager can fire them.
If your CMP already sets Consent Mode in the page, do not also add a consent template in Tag Manager. One writer per page.
How to verify Consent Mode is working
- Tag Assistant. Open tagassistant.google.com, connect your site, and select the earliest Consent event in the summary. The Consent tab shows the On-page Default for each type: for an EEA visitor all four should read denied. Accept on the banner, select the latest Consent event, and check the On-page Update column changed.
- Order. If any Google tag fires before the default, Tag Assistant shows it. Defaults must not be set asynchronously.
- Network requests. In browser developer tools, filter requests to google-analytics.com and googleadservices.com. Requests carry a consent state parameter (look for
gcs); its value should change after you accept. In basic mode there should be no requests at all before you choose. - Regions. Test from an EEA location and a US one (a VPN or browser location override) and check the defaults differ the way you intended.
- Cookies. Before consent there should be no
_ga,_gcl_auor similar cookies. Our free cookie scanner runs a pass before and after consent and lists what was set in each.
How TryTrustable handles Consent Mode v2
The TryTrustable consent banner sets Google Consent Mode v2 for you. It is on by default:
- The banner script declares the consent default as soon as it parses, before Google tags later in the <head>: all seven types denied except
security_storage, withwait_for_updateof 500 ms,ads_data_redactionandurl_passthroughon. - Each choice sends an update: analytics consent grants
analytics_storage; marketing grantsad_storage,ad_user_dataandad_personalization; preferences grants the two functional types. A stored choice is re-applied on every page load. - Rules follow the visitor's region: opt-in for the EU and UK; for US states, measurement runs until the visitor opts out, and Global Privacy Control is honoured as an opt-out.
- By default the banner also holds Google's tag scripts until consent (the basic pattern). The list of held hosts is yours to change, so you can let Google tags load with denied defaults if you choose advanced mode.
- If you already run your own Consent Mode wiring, you can switch ours off so there is only one writer.
Every choice is written to a tamper-evident consent ledger with the notice version the visitor saw, which is the record Google's policy asks you to keep. TryTrustable is not a Google-certified CMP partner.
The things people ask us
What is Consent Mode v2?
The second version of Google's consent API. It adds ad_user_data and ad_personalization to ad_storage and analytics_storage, so a site can say separately whether Google may receive a visitor's data for advertising and whether it may personalise ads with it.
Is Google Consent Mode v2 required?
For visitors in the EEA, Google has required the v2 signals since March 2024 if you want remarketing, audiences and personalised advertising to work for them. Google's EU user consent policy also covers the UK and Switzerland. It is a Google requirement, not a law.
What is the difference between basic and advanced consent mode?
Basic mode blocks Google tags until the visitor chooses, so nothing is sent without consent. Advanced mode loads the tags with everything denied and sends cookieless pings that Google uses for modelling.
How do I set up cookie consent in Google Tag Manager?
Use your CMP's Tag Manager template, or a consent template, on the Consent Initialization: All Pages trigger to set defaults, let the CMP send updates, turn on Consent Overview, and add consent checks to non-Google tags.
Does Consent Mode make my cookie banner GDPR compliant?
No. Consent Mode passes the choice to Google. Whether the choice is valid depends on your banner: a clear reject option, no pre-ticked boxes, and no non-essential cookies before consent.
How do I check Consent Mode is working?
Use Google Tag Assistant: the earliest Consent event shows your defaults and the latest shows the update after you accept. Then check network requests and cookies before and after consent.
Is TryTrustable a Google certified CMP partner?
No. Our banner sets all Consent Mode v2 signals, but we have not completed Google's CMP partner certification.
Consent Mode v2, set before your tags fire.
Thirty minutes: we scan your site before and after consent and show the Consent Mode defaults and updates landing in Tag Assistant.