New · A dedicated AI SEO channel: see conversions from ChatGPT, Perplexity, Claude & Gemini →
← Blog
Part of: SEO Conversion Tracking: Measure Conversions and Value from Organic Search →

Consent Mode v2: Setup, Basic vs Advanced, and What It Does to Data

Portrait of Samy ThuillierBy ··13 min read
Diagram of consent mode v2 passing cookie banner choices to GA4 and Google Ads tags

Consent mode v2 is Google’s system for passing the choice a visitor makes on your cookie banner to Google tags like GA4 and Google Ads. It sends four signals, ad_storage, analytics_storage, ad_user_data and ad_personalization, and the tags change what they store and send based on them. Google requires it for full Ads measurement and audiences on traffic from the EEA, the UK and Switzerland.

This guide covers what changed from v1, basic versus advanced mode, how to set it up with a banner, Google Tag Manager or plain code, how to verify it, and the parts most guides skip: when Google’s modeling actually kicks in, what a partial consent rate does to your conversion numbers, and whether a US site needs any of it.

What Is Consent Mode v2?

Consent mode is an API built into Google’s tags (gtag.js, Google Tag Manager, GA4, Google Ads, Floodlight). It is not a cookie banner. The banner, usually from a consent management platform (CMP), asks the visitor. Consent mode is the wire that carries the answer to Google tags so they behave accordingly.

Google launched the first version in 2020. Version 2 arrived in late 2023, ahead of the Digital Markets Act obligations that applied to Google from March 2024, and added two signals about how data is used, not just whether cookies are stored. Since then, Google’s EU user consent policy expects advertisers to pass valid consent for users in the EEA, the UK and Switzerland, keep records of that consent, and let people withdraw it.

How it works, in order

  1. The page sets a default consent state for each signal, typically denied, before any Google tag runs.
  2. The banner appears and the visitor accepts, rejects or picks categories.
  3. The banner sends an update with the new state for each signal.
  4. Google tags read the state on every hit. With consent granted, they work normally. With consent denied, they either never loaded (basic mode) or send cookieless pings (advanced mode).
  5. Google Ads and GA4 use the observed data, plus modeling where eligible, to estimate what the denied visitors did.

The Four Consent Parameters (and What v2 Added)

Google’s consent mode overview lists seven consent types. Four matter for Google tags; the other three (functionality_storage, personalization_storage, security_storage) are there for your own tags to read.

ParameterControlsIn v1?
ad_storageStorage such as cookies related to advertising (for example the Google Ads click cookie)Yes
analytics_storageStorage such as cookies related to analytics, for example visit durationYes
ad_user_dataWhether user data can be sent to Google for online advertising purposesNo, added in v2
ad_personalizationWhether data can be used for personalized advertising, such as remarketing audiencesNo, added in v2

The practical difference: v1 signals were about storage on the device. The v2 signals are about what Google may do with the data once it has it. A visitor can allow ad cookies for measurement but refuse remarketing, and v2 can express that. A v1 setup keeps working, but Google has no signal for the two new purposes, so EEA audiences and some ad features stay limited.

Basic vs Advanced Consent Mode

You pick one of two implementations. Both are valid consent mode v2 setups; they differ in what happens before and after a rejection.

BasicAdvanced
When Google tags loadOnly after the visitor interacts with the banner and grants consentOn page load, in a denied state
Data sent before the choiceNone, not even the consent stateConsent state and cookieless pings
Data sent after a rejectionNoneCookieless pings: timestamp, user agent, referrer, ad click indicator, consent state, a random per-page number
Google Ads conversion modelingGeneral modelAdvertiser-specific model
GA4 behavioral modelingNot eligibleEligible if traffic thresholds are met
Typical choice ofTeams that want zero Google contact before consentAdvertisers who rely on modeled conversions

The ping contents and the general versus advertiser-specific model distinction come from Google’s overview. Which mode is acceptable in your market is a legal question as much as a technical one: some regulators and privacy teams consider any request to Google before consent a problem, which is why basic mode exists.

Who Needs Consent Mode v2

  • You advertise with Google Ads and get visitors from the EEA, UK or Switzerland. You need it to keep conversion measurement, remarketing and audience features for those users.
  • You use GA4 for European traffic. Not strictly required by Google for GA4 alone, but without it, a banner that blocks GA4 entirely gives you no consent signal and no modeling.
  • You use a CMP already. Most certified CMPs support v2 with a setting or template update; check that all four signals are actually sent.
  • You only have US or other non-European traffic and no Google ads. Google does not require it. See the decision rule below.

What Happens If You Do Not Implement It

For European traffic, Google Ads cannot build or grow remarketing audiences from users without valid signals, conversion measurement for those users shrinks, and modeling has nothing to work with. Google’s policy also lets it limit or suspend products for accounts that don’t meet the consent requirements. A broken setup can be worse than none: reporting granted when the visitor said no is a privacy problem, and reporting denied for everyone throws away data you were allowed to collect.

Consent mode is not compliance

Consent mode transmits a choice. It does not ask for consent, store proof of it, or make your setup legal. The banner wording, the categories, the reject button and the record keeping are the CMP’s job and your legal team’s decision.

How to Implement Consent Mode v2

There are three routes: a certified CMP, Google Tag Manager with a CMP template, or hand-written gtag.js code. The steps below apply to all three.

Step 1: Pick a Google-certified CMP

Google keeps a list of certified CMP partners. A certified banner already knows how to send the four signals, often through a GTM template. A custom or non-certified banner (including some built into site platforms) may need development work to send ad_user_data and ad_personalization.

Step 2: Set the default state before any Google tag

In Google Tag Manager, enable the consent overview in container settings and fire your CMP template (or a consent default tag) on the Consent Initialization - All Pages trigger, which runs before every other trigger. Without GTM, put the default command in the page head, above the Google tag. Google’s setup guide is explicit that order matters: if the default runs after the tag, it does not apply.

<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}

  // 1. Defaults: must run before any Google tag or config command
  gtag('consent', 'default', {
    'ad_storage': 'denied',
    'ad_user_data': 'denied',
    'ad_personalization': 'denied',
    'analytics_storage': 'denied',
    'wait_for_update': 500
  });
</script>
<!-- 2. Then the Google tag (gtag.js) or the GTM container -->

wait_for_update is in milliseconds. It tells tags to hold their first hit briefly so an asynchronous banner can send a stored choice (a returning visitor who accepted last week) before anything is sent with the default.

Step 3: Send an update when the visitor chooses

// 3. Called by your banner when the visitor makes a choice
gtag('consent', 'update', {
  'ad_storage': 'granted',
  'ad_user_data': 'granted',
  'ad_personalization': 'granted',
  'analytics_storage': 'granted'
});

Send each signal separately according to the categories the visitor picked. The update must fire on the same page as the choice, so the landing page hit, which carries the traffic source, is sent with the right state.

Step 4: Choose basic or advanced

Basic: keep Google tags from firing until consent is granted, using GTM triggers or your CMP’s blocking. Advanced: let Google tags fire on every page, governed by the denied default. Most CMPs expose this as a single setting.

Step 5: Map consent requirements to every tag

In GTM’s Consent Overview, Google tags have built-in consent checks. Non-Google tags (Meta, LinkedIn, Hotjar and so on) do not read consent mode on their own, so add “additional consent” requirements to them, for example ad_storage for an ad pixel. A Google Ads conversion tag should depend on ad_storage and ad_user_data, and remarketing tags on ad_personalization too.

Step 6: Verify (next section)

If you upgrade from v1, the job is mostly steps 1, 3 and 6: update the CMP template, make sure the two new signals are in both default and update, then retest.

How to Verify Consent Mode v2 Is Working

  1. Tag Assistant / GTM preview. Open preview, load a page in a fresh private window, and check the Consent tab. You should see the default state on the Consent Initialization event, then an update after you click the banner. Our GA4 DebugView guide covers the GA4 side of the same session.
  2. Network tab. Filter for collect or google-analytics.com. Each request carries a gcs parameter (ad and analytics storage) and a longer gcd parameter that encodes all four signals and whether they came from a default or an update.
  3. Test both paths. Reject in one private window and accept in another. Then test a returning visitor who already chose.
  4. Check regions. If you use region-specific defaults, test with a VPN from an EEA country and from outside it.
gcs valuead_storageanalytics_storage
G100denieddenied
G110granteddenied
G101deniedgranted
G111grantedgranted

Failure Modes and How to Debug Them

SymptomLikely causeFix
Consent tab empty in Tag AssistantNo default command, or CMP template not firingFire the CMP or default tag on Consent Initialization - All Pages
First hit shows granted, then deniedDefault set after the Google tag loadedMove the default above the tag; in GTM, check the trigger is Consent Initialization, not All Pages
gcs stays G100 after acceptingBanner sends no update, or uses different category namesMap each CMP category to the four signals and call update on click
ad_user_data and ad_personalization missing from gcdv1 setup or outdated CMP templateUpdate the template; add both signals to default and update
Spike in Direct or Unassigned traffic after rolloutBasic mode: landing page hit blocked, a later page fires after consent and loses the sourceFire a page_view on the update event on the same page, or move to advanced mode
Google Ads conversions drop when ad_storage is deniedClick ID cannot be stored in a cookieEnable url_passthrough so click info is passed in URLs; decide on ads_data_redaction
Non-EEA traffic suddenly dropsGlobal denied default with an opt-in banner shown everywhereUse region-specific defaults (next sections)
No modeled data in GA4Basic mode, or the property is below the thresholdsCheck eligibility in the next section

url_passthrough and ads_data_redaction are documented in Google’s setup guide. The first passes ad click information in URL parameters when cookies are denied. The second redacts ad click identifiers from Google Ads and Floodlight requests when ad_storage is denied.

Will Modeling Fill the Gap? GA4’s Thresholds

Most guides say modeling recovers the data you lose to rejections. For GA4, that depends on traffic. According to Google’s help page on behavioral modeling for consent mode, a property is eligible only if all of these are true:

  • Consent mode runs on all pages, in the advanced implementation (tags load in all cases, not only after consent).
  • The property collects at least 1,000 events per day with analytics_storage denied, for at least 7 days.
  • The property has at least 1,000 daily users sending events with analytics_storage granted, on at least 7 of the previous 28 days.

Even then, modeled data shows only when the reporting identity is set to Blended (Admin > Reporting identity). Changing it does not change data collection.

Daily users needed for GA4 modeling = 1,000 / analytics consent rate

Illustrative: at a 55% acceptance rate you need about 1,000 / 0.55 = 1,818 daily users before the granted-users threshold is even reachable. At 40%, you need 2,500. Many small and mid-size sites will never see modeled GA4 data, so plan reporting on observed numbers.

Worked Example: What a 55% Consent Rate Does to Your Reports

All numbers in this example are illustrative. A store gets most of its traffic from Europe, runs basic mode, and 55% of visitors accept analytics. In one month it really receives 1,000 orders with an average order value of $80.

ChannelReal ordersSeen in GA4 (x 0.55, rounded)Real revenueSeen revenue
Organic search400220$32,000$17,600
Google Ads350193$28,000$15,440
Email15082$12,000$6,560
Direct10055$8,000$4,400
Total1,000550$80,000$44,000
Illustrative gap
Revenue invisible to GA4: $80,000 - $44,000 = $36,000
Share of orders seen: 550 / 1,000 = 55%
Your shop backend still shows all 1,000 orders

Three things to take from it:

  • Compare to the backend, not to last year. A drop after rollout is often a measurement change, not a sales change. Divide GA4 orders by backend orders each month to get your effective observed rate.
  • Uniform scaling is a simplification. Consent rates differ by device, country and channel (returning email subscribers may accept more often than first-time search visitors), so some channels will be undercounted more than others. If you scale numbers back up, say so in the report.
  • Organic and landing page reports suffer most in basic mode. If the landing page hit is blocked, the session source is lost for that visit. Our guide to SEO conversion tracking explains how to report conversions by organic landing page so you can check whether pages you care about lost visibility in reports or in reality.

Google’s modeling helps Google Ads and, above the thresholds, GA4. It does not rebuild your SEO or AI-assistant landing page reports. Some teams add a first-party, cookieless measure alongside GA4 for that view; see cookieless conversion tracking for how that works and what it can and cannot count. SEOConversion is one such tracker: it reports conversions and value from Google, Bing and AI assistants by landing page, without cookies, and honors GPC and DNT. Whether any tool needs consent in your EU market is still a question for your legal team.

Do US Sites Need Consent Mode v2? A Decision Rule

Google’s requirement is about EEA, UK and Swiss users. US state privacy laws mostly follow an opt-out model, so a global denied default throws away US data you may be allowed to collect. Use this rule:

Your situationWhat to do
No European visitors to speak of, no Google Ads in EuropeNot needed. Honor opt-out signals such as GPC as your US obligations require.
Some European visitors, Google Ads or GA4 in useSet up consent mode v2 with region-specific defaults: denied for EEA, UK and Switzerland, granted elsewhere.
Mostly European audienceDenied by default everywhere is simpler and safer; choose basic or advanced with your privacy team.
Global brand with a strict internal policyDenied by default everywhere, banner everywhere.

The region parameter takes country or subdivision codes (ISO 3166-2) and the more specific region wins when two defaults overlap, per Google’s setup guide. A sketch:

// Deny by default only where your policy requires opt-in
gtag('consent', 'default', {
  'ad_storage': 'denied',
  'ad_user_data': 'denied',
  'ad_personalization': 'denied',
  'analytics_storage': 'denied',
  'region': ['AT','BE','BG','HR','CY','CZ','DK','EE','FI','FR','DE','GR','HU',
             'IS','IE','IT','LV','LI','LT','LU','MT','NL','NO','PL','PT','RO',
             'SK','SI','ES','SE','GB','CH']
});
// Everywhere else
gtag('consent', 'default', {
  'ad_storage': 'granted',
  'ad_user_data': 'granted',
  'ad_personalization': 'granted',
  'analytics_storage': 'granted'
});

Check the country list against your own legal advice before using it. Most CMPs do this geolocation for you; if yours does, configure it there instead of in code.

Where the Top Guides Disagree

  • Does basic mode get any modeling? Some guides say basic mode still allows conversion modeling; others say Google does no modeling at all in basic mode. Both are partly right. Google’s overview says Google Ads uses a general model in basic mode and an advertiser-specific one in advanced mode. GA4 behavioral modeling, per the help page above, requires advanced mode.
  • How much data does modeling recover? Guides quote ranges from 60 to 70% up to 80% or more, with no source. Google does not publish a recovery rate that applies to every site, and GA4 modeling does not run at all below the thresholds. Treat any single figure as marketing.
  • Is it a legal requirement? Consent mode is a Google product requirement for European traffic. The legal requirement is to get valid consent; consent mode only carries the result to Google.

FAQ

What is Google consent mode and how does it work?

Consent mode is a Google API that passes the choice a visitor makes on your cookie banner to Google tags such as GA4, Google Ads and Floodlight. Tags start from a default state, usually denied, and switch to granted only when the visitor accepts. When consent is denied, tags either do not load (basic mode) or send cookieless pings that Google uses for modeling (advanced mode).

What does opt-in consent mean?

Opt-in means nothing non-essential happens until the person actively says yes, for example by clicking Accept on a banner. Silence, scrolling or a pre-ticked box does not count. Opt-out is the reverse: tracking runs by default and the person has to switch it off. Consent mode v2 supports both, because you choose the default state per region.

Does GDPR require cookie consent?

In the EU, the requirement to ask before storing non-essential cookies comes mainly from the ePrivacy Directive, and the GDPR defines what valid consent looks like: freely given, specific, informed and unambiguous. Strictly necessary cookies, such as a shopping cart or login session, do not need consent. Analytics and advertising cookies generally do. Check the rules for your country with a qualified advisor.

How do you stop Google from collecting your data for ads?

As a visitor, reject advertising cookies on site banners, turn off ad personalization in your Google account, and use a browser that honors Global Privacy Control. Rejecting on a site that uses consent mode sets ad_storage, ad_user_data and ad_personalization to denied, so Google tags there cannot set ad cookies or use your data for personalized ads. Advanced mode can still send cookieless pings without identifiers.

Is consent mode v2 mandatory?

Google requires valid consent signals for traffic from the EEA, the UK and Switzerland if you want full use of Google Ads measurement, audiences and personalization there. It is not a law, and it is not required for visitors elsewhere. A site with no visitors from those regions and no Google ads loses nothing by skipping it, though many sites set it up with region-specific defaults anyway.

Does consent mode v2 work with server-side tagging?

Yes. The consent state set in the browser travels with each request, and a server-side Google Tag Manager container reads it and passes it on to Google tags. Server-side tagging does not remove the need to collect consent: if the visitor denied it, your server container should respect that too.

See the conversions your consent banner hides from GA4.

SEOConversion is a first-party, cookieless tracker that shows which conversions and how much value come from Google, Bing and AI assistants, by landing page. One script, and it honors GPC and DNT.

Start free