Consent Mode v2: Setup, Basic vs Advanced, and What It Does to Data

Consent mode v2 is Google’s system for passing the choice a visitor makes on your cookie banner to Google tags like GA4 and Google Ads. It sends four signals, ad_storage, analytics_storage, ad_user_data and ad_personalization, and the tags change what they store and send based on them. Google requires it for full Ads measurement and audiences on traffic from the EEA, the UK and Switzerland.
This guide covers what changed from v1, basic versus advanced mode, how to set it up with a banner, Google Tag Manager or plain code, how to verify it, and the parts most guides skip: when Google’s modeling actually kicks in, what a partial consent rate does to your conversion numbers, and whether a US site needs any of it.
What Is Consent Mode v2?
Consent mode is an API built into Google’s tags (gtag.js, Google Tag Manager, GA4, Google Ads, Floodlight). It is not a cookie banner. The banner, usually from a consent management platform (CMP), asks the visitor. Consent mode is the wire that carries the answer to Google tags so they behave accordingly.
Google launched the first version in 2020. Version 2 arrived in late 2023, ahead of the Digital Markets Act obligations that applied to Google from March 2024, and added two signals about how data is used, not just whether cookies are stored. Since then, Google’s EU user consent policy expects advertisers to pass valid consent for users in the EEA, the UK and Switzerland, keep records of that consent, and let people withdraw it.
How it works, in order
- The page sets a default consent state for each signal, typically denied, before any Google tag runs.
- The banner appears and the visitor accepts, rejects or picks categories.
- The banner sends an update with the new state for each signal.
- Google tags read the state on every hit. With consent granted, they work normally. With consent denied, they either never loaded (basic mode) or send cookieless pings (advanced mode).
- Google Ads and GA4 use the observed data, plus modeling where eligible, to estimate what the denied visitors did.
The Four Consent Parameters (and What v2 Added)
Google’s consent mode overview lists seven consent types. Four matter for Google tags; the other three (functionality_storage, personalization_storage, security_storage) are there for your own tags to read.
| Parameter | Controls | In v1? |
|---|---|---|
| ad_storage | Storage such as cookies related to advertising (for example the Google Ads click cookie) | Yes |
| analytics_storage | Storage such as cookies related to analytics, for example visit duration | Yes |
| ad_user_data | Whether user data can be sent to Google for online advertising purposes | No, added in v2 |
| ad_personalization | Whether data can be used for personalized advertising, such as remarketing audiences | No, added in v2 |
The practical difference: v1 signals were about storage on the device. The v2 signals are about what Google may do with the data once it has it. A visitor can allow ad cookies for measurement but refuse remarketing, and v2 can express that. A v1 setup keeps working, but Google has no signal for the two new purposes, so EEA audiences and some ad features stay limited.
Basic vs Advanced Consent Mode
You pick one of two implementations. Both are valid consent mode v2 setups; they differ in what happens before and after a rejection.
| Basic | Advanced | |
|---|---|---|
| When Google tags load | Only after the visitor interacts with the banner and grants consent | On page load, in a denied state |
| Data sent before the choice | None, not even the consent state | Consent state and cookieless pings |
| Data sent after a rejection | None | Cookieless pings: timestamp, user agent, referrer, ad click indicator, consent state, a random per-page number |
| Google Ads conversion modeling | General model | Advertiser-specific model |
| GA4 behavioral modeling | Not eligible | Eligible if traffic thresholds are met |
| Typical choice of | Teams that want zero Google contact before consent | Advertisers who rely on modeled conversions |
The ping contents and the general versus advertiser-specific model distinction come from Google’s overview. Which mode is acceptable in your market is a legal question as much as a technical one: some regulators and privacy teams consider any request to Google before consent a problem, which is why basic mode exists.
Who Needs Consent Mode v2
- You advertise with Google Ads and get visitors from the EEA, UK or Switzerland. You need it to keep conversion measurement, remarketing and audience features for those users.
- You use GA4 for European traffic. Not strictly required by Google for GA4 alone, but without it, a banner that blocks GA4 entirely gives you no consent signal and no modeling.
- You use a CMP already. Most certified CMPs support v2 with a setting or template update; check that all four signals are actually sent.
- You only have US or other non-European traffic and no Google ads. Google does not require it. See the decision rule below.
What Happens If You Do Not Implement It
For European traffic, Google Ads cannot build or grow remarketing audiences from users without valid signals, conversion measurement for those users shrinks, and modeling has nothing to work with. Google’s policy also lets it limit or suspend products for accounts that don’t meet the consent requirements. A broken setup can be worse than none: reporting granted when the visitor said no is a privacy problem, and reporting denied for everyone throws away data you were allowed to collect.
Consent mode transmits a choice. It does not ask for consent, store proof of it, or make your setup legal. The banner wording, the categories, the reject button and the record keeping are the CMP’s job and your legal team’s decision.
How to Implement Consent Mode v2
There are three routes: a certified CMP, Google Tag Manager with a CMP template, or hand-written gtag.js code. The steps below apply to all three.
Step 1: Pick a Google-certified CMP
Google keeps a list of certified CMP partners. A certified banner already knows how to send the four signals, often through a GTM template. A custom or non-certified banner (including some built into site platforms) may need development work to send ad_user_data and ad_personalization.
Step 2: Set the default state before any Google tag
In Google Tag Manager, enable the consent overview in container settings and fire your CMP template (or a consent default tag) on the Consent Initialization - All Pages trigger, which runs before every other trigger. Without GTM, put the default command in the page head, above the Google tag. Google’s setup guide is explicit that order matters: if the default runs after the tag, it does not apply.
<script>
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
// 1. Defaults: must run before any Google tag or config command
gtag('consent', 'default', {
'ad_storage': 'denied',
'ad_user_data': 'denied',
'ad_personalization': 'denied',
'analytics_storage': 'denied',
'wait_for_update': 500
});
</script>
<!-- 2. Then the Google tag (gtag.js) or the GTM container -->wait_for_update is in milliseconds. It tells tags to hold their first hit briefly so an asynchronous banner can send a stored choice (a returning visitor who accepted last week) before anything is sent with the default.
Step 3: Send an update when the visitor chooses
// 3. Called by your banner when the visitor makes a choice
gtag('consent', 'update', {
'ad_storage': 'granted',
'ad_user_data': 'granted',
'ad_personalization': 'granted',
'analytics_storage': 'granted'
});Send each signal separately according to the categories the visitor picked. The update must fire on the same page as the choice, so the landing page hit, which carries the traffic source, is sent with the right state.
Step 4: Choose basic or advanced
Basic: keep Google tags from firing until consent is granted, using GTM triggers or your CMP’s blocking. Advanced: let Google tags fire on every page, governed by the denied default. Most CMPs expose this as a single setting.
Step 5: Map consent requirements to every tag
In GTM’s Consent Overview, Google tags have built-in consent checks. Non-Google tags (Meta, LinkedIn, Hotjar and so on) do not read consent mode on their own, so add “additional consent” requirements to them, for example ad_storage for an ad pixel. A Google Ads conversion tag should depend on ad_storage and ad_user_data, and remarketing tags on ad_personalization too.
Step 6: Verify (next section)
If you upgrade from v1, the job is mostly steps 1, 3 and 6: update the CMP template, make sure the two new signals are in both default and update, then retest.
How to Verify Consent Mode v2 Is Working
- Tag Assistant / GTM preview. Open preview, load a page in a fresh private window, and check the Consent tab. You should see the default state on the Consent Initialization event, then an update after you click the banner. Our GA4 DebugView guide covers the GA4 side of the same session.
- Network tab. Filter for
collectorgoogle-analytics.com. Each request carries agcsparameter (ad and analytics storage) and a longergcdparameter that encodes all four signals and whether they came from a default or an update. - Test both paths. Reject in one private window and accept in another. Then test a returning visitor who already chose.
- Check regions. If you use region-specific defaults, test with a VPN from an EEA country and from outside it.
| gcs value | ad_storage | analytics_storage |
|---|---|---|
| G100 | denied | denied |
| G110 | granted | denied |
| G101 | denied | granted |
| G111 | granted | granted |
Failure Modes and How to Debug Them
| Symptom | Likely cause | Fix |
|---|---|---|
| Consent tab empty in Tag Assistant | No default command, or CMP template not firing | Fire the CMP or default tag on Consent Initialization - All Pages |
| First hit shows granted, then denied | Default set after the Google tag loaded | Move the default above the tag; in GTM, check the trigger is Consent Initialization, not All Pages |
| gcs stays G100 after accepting | Banner sends no update, or uses different category names | Map each CMP category to the four signals and call update on click |
| ad_user_data and ad_personalization missing from gcd | v1 setup or outdated CMP template | Update the template; add both signals to default and update |
| Spike in Direct or Unassigned traffic after rollout | Basic mode: landing page hit blocked, a later page fires after consent and loses the source | Fire a page_view on the update event on the same page, or move to advanced mode |
| Google Ads conversions drop when ad_storage is denied | Click ID cannot be stored in a cookie | Enable url_passthrough so click info is passed in URLs; decide on ads_data_redaction |
| Non-EEA traffic suddenly drops | Global denied default with an opt-in banner shown everywhere | Use region-specific defaults (next sections) |
| No modeled data in GA4 | Basic mode, or the property is below the thresholds | Check eligibility in the next section |
url_passthrough and ads_data_redaction are documented in Google’s setup guide. The first passes ad click information in URL parameters when cookies are denied. The second redacts ad click identifiers from Google Ads and Floodlight requests when ad_storage is denied.
Will Modeling Fill the Gap? GA4’s Thresholds
Most guides say modeling recovers the data you lose to rejections. For GA4, that depends on traffic. According to Google’s help page on behavioral modeling for consent mode, a property is eligible only if all of these are true:
- Consent mode runs on all pages, in the advanced implementation (tags load in all cases, not only after consent).
- The property collects at least 1,000 events per day with
analytics_storagedenied, for at least 7 days. - The property has at least 1,000 daily users sending events with
analytics_storagegranted, on at least 7 of the previous 28 days.
Even then, modeled data shows only when the reporting identity is set to Blended (Admin > Reporting identity). Changing it does not change data collection.
Illustrative: at a 55% acceptance rate you need about 1,000 / 0.55 = 1,818 daily users before the granted-users threshold is even reachable. At 40%, you need 2,500. Many small and mid-size sites will never see modeled GA4 data, so plan reporting on observed numbers.
Worked Example: What a 55% Consent Rate Does to Your Reports
All numbers in this example are illustrative. A store gets most of its traffic from Europe, runs basic mode, and 55% of visitors accept analytics. In one month it really receives 1,000 orders with an average order value of $80.
| Channel | Real orders | Seen in GA4 (x 0.55, rounded) | Real revenue | Seen revenue |
|---|---|---|---|---|
| Organic search | 400 | 220 | $32,000 | $17,600 |
| Google Ads | 350 | 193 | $28,000 | $15,440 |
| 150 | 82 | $12,000 | $6,560 | |
| Direct | 100 | 55 | $8,000 | $4,400 |
| Total | 1,000 | 550 | $80,000 | $44,000 |
Three things to take from it:
- Compare to the backend, not to last year. A drop after rollout is often a measurement change, not a sales change. Divide GA4 orders by backend orders each month to get your effective observed rate.
- Uniform scaling is a simplification. Consent rates differ by device, country and channel (returning email subscribers may accept more often than first-time search visitors), so some channels will be undercounted more than others. If you scale numbers back up, say so in the report.
- Organic and landing page reports suffer most in basic mode. If the landing page hit is blocked, the session source is lost for that visit. Our guide to SEO conversion tracking explains how to report conversions by organic landing page so you can check whether pages you care about lost visibility in reports or in reality.
Google’s modeling helps Google Ads and, above the thresholds, GA4. It does not rebuild your SEO or AI-assistant landing page reports. Some teams add a first-party, cookieless measure alongside GA4 for that view; see cookieless conversion tracking for how that works and what it can and cannot count. SEOConversion is one such tracker: it reports conversions and value from Google, Bing and AI assistants by landing page, without cookies, and honors GPC and DNT. Whether any tool needs consent in your EU market is still a question for your legal team.
Do US Sites Need Consent Mode v2? A Decision Rule
Google’s requirement is about EEA, UK and Swiss users. US state privacy laws mostly follow an opt-out model, so a global denied default throws away US data you may be allowed to collect. Use this rule:
| Your situation | What to do |
|---|---|
| No European visitors to speak of, no Google Ads in Europe | Not needed. Honor opt-out signals such as GPC as your US obligations require. |
| Some European visitors, Google Ads or GA4 in use | Set up consent mode v2 with region-specific defaults: denied for EEA, UK and Switzerland, granted elsewhere. |
| Mostly European audience | Denied by default everywhere is simpler and safer; choose basic or advanced with your privacy team. |
| Global brand with a strict internal policy | Denied by default everywhere, banner everywhere. |
The region parameter takes country or subdivision codes (ISO 3166-2) and the more specific region wins when two defaults overlap, per Google’s setup guide. A sketch:
// Deny by default only where your policy requires opt-in
gtag('consent', 'default', {
'ad_storage': 'denied',
'ad_user_data': 'denied',
'ad_personalization': 'denied',
'analytics_storage': 'denied',
'region': ['AT','BE','BG','HR','CY','CZ','DK','EE','FI','FR','DE','GR','HU',
'IS','IE','IT','LV','LI','LT','LU','MT','NL','NO','PL','PT','RO',
'SK','SI','ES','SE','GB','CH']
});
// Everywhere else
gtag('consent', 'default', {
'ad_storage': 'granted',
'ad_user_data': 'granted',
'ad_personalization': 'granted',
'analytics_storage': 'granted'
});Check the country list against your own legal advice before using it. Most CMPs do this geolocation for you; if yours does, configure it there instead of in code.
Where the Top Guides Disagree
- Does basic mode get any modeling? Some guides say basic mode still allows conversion modeling; others say Google does no modeling at all in basic mode. Both are partly right. Google’s overview says Google Ads uses a general model in basic mode and an advertiser-specific one in advanced mode. GA4 behavioral modeling, per the help page above, requires advanced mode.
- How much data does modeling recover? Guides quote ranges from 60 to 70% up to 80% or more, with no source. Google does not publish a recovery rate that applies to every site, and GA4 modeling does not run at all below the thresholds. Treat any single figure as marketing.
- Is it a legal requirement? Consent mode is a Google product requirement for European traffic. The legal requirement is to get valid consent; consent mode only carries the result to Google.
FAQ
What is Google consent mode and how does it work?
Consent mode is a Google API that passes the choice a visitor makes on your cookie banner to Google tags such as GA4, Google Ads and Floodlight. Tags start from a default state, usually denied, and switch to granted only when the visitor accepts. When consent is denied, tags either do not load (basic mode) or send cookieless pings that Google uses for modeling (advanced mode).
What does opt-in consent mean?
Opt-in means nothing non-essential happens until the person actively says yes, for example by clicking Accept on a banner. Silence, scrolling or a pre-ticked box does not count. Opt-out is the reverse: tracking runs by default and the person has to switch it off. Consent mode v2 supports both, because you choose the default state per region.
Does GDPR require cookie consent?
In the EU, the requirement to ask before storing non-essential cookies comes mainly from the ePrivacy Directive, and the GDPR defines what valid consent looks like: freely given, specific, informed and unambiguous. Strictly necessary cookies, such as a shopping cart or login session, do not need consent. Analytics and advertising cookies generally do. Check the rules for your country with a qualified advisor.
How do you stop Google from collecting your data for ads?
As a visitor, reject advertising cookies on site banners, turn off ad personalization in your Google account, and use a browser that honors Global Privacy Control. Rejecting on a site that uses consent mode sets ad_storage, ad_user_data and ad_personalization to denied, so Google tags there cannot set ad cookies or use your data for personalized ads. Advanced mode can still send cookieless pings without identifiers.
Is consent mode v2 mandatory?
Google requires valid consent signals for traffic from the EEA, the UK and Switzerland if you want full use of Google Ads measurement, audiences and personalization there. It is not a law, and it is not required for visitors elsewhere. A site with no visitors from those regions and no Google ads loses nothing by skipping it, though many sites set it up with region-specific defaults anyway.
Does consent mode v2 work with server-side tagging?
Yes. The consent state set in the browser travels with each request, and a server-side Google Tag Manager container reads it and passes it on to Google tags. Server-side tagging does not remove the need to collect consent: if the visitor denied it, your server container should respect that too.
See the conversions your consent banner hides from GA4.
SEOConversion is a first-party, cookieless tracker that shows which conversions and how much value come from Google, Bing and AI assistants, by landing page. One script, and it honors GPC and DNT.
Start free