Privacy-First Measurement: Server-Side Tagging, Consent Mode and Conversion APIsConsent management and Google Consent Mode · Lesson 4 of 14

Google Consent Mode v2: basic vs advanced, done right

Article · 8 min · 8 min lecture

Video lecture

Google Consent Mode v2: basic vs advanced, done right

14 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 14

Google Consent Mode v2

  • What it does
  • Basic vs advanced
  • Implementation
  • Verification

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Google Consent Mode lets you communicate users' consent choices to Google tags (Google Analytics, Google Ads, Floodlight) so the tags adjust their behavior. It is not a CMP; your CMP collects consent and Consent Mode passes it to Google tags.

Consent Mode v2 added two parameters to the original ad_storage and analytics_storage:

ParameterControls
ad_storageStorage (cookies) related to advertising
analytics_storageStorage related to analytics
ad_user_dataConsent to send user data to Google for advertising purposes
ad_personalizationConsent to personalized advertising (e.g., remarketing)
functionality_storage, personalization_storage, security_storageOther storage purposes

For EEA traffic (and UK traffic), Google requires consent signals to use certain ads measurement and personalization features, including audience building and some conversion modeling. Without v2 signals, those features degrade.

Basic vs advanced implementation

BasicAdvanced
Before consentGoogle tags do not loadTags load with default "denied" states
If user deniesNothing sent to GoogleTags send cookieless pings (no cookies read or written)
ModelingGeneral model (less precise)Advertiser-specific modeling (more precise)
Privacy postureMost conservativeRequires legal comfort with cookieless pings

Which to choose is a legal and business decision. In jurisdictions where regulators interpret device-access rules strictly, some organizations choose basic mode; others conclude advanced mode's cookieless pings are acceptable. Document the decision.

Implementation with gtag.js

The default state must be set before any Google tag loads, then updated when the user chooses.

<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}

  // Defaults for EEA + UK: denied until the user chooses
  gtag('consent', 'default', {
    ad_storage: 'denied',
    analytics_storage: 'denied',
    ad_user_data: 'denied',
    ad_personalization: 'denied',
    wait_for_update: 500,
    region: ['AT','BE','BG','HR','CY','CZ','DK','EE','FI','FR','DE','GR','HU','IS','IE','IT','LV','LI','LT','LU','MT','NL','NO','PL','PT','RO','SK','SI','ES','SE','GB']
  });
  // Default elsewhere (set according to your legal assessment per region)
  gtag('consent', 'default', {
    ad_storage: 'granted', analytics_storage: 'granted',
    ad_user_data: 'granted', ad_personalization: 'granted'
  });
  gtag('set', 'ads_data_redaction', true);   // redact ad click identifiers when ad_storage is denied
  gtag('set', 'url_passthrough', true);      // pass click info through URLs when cookies are denied
</script>
<!-- Google tag (gtag.js) loads after this -->

Then, when the CMP reports the user's choice:

function onConsentChoice(choice) { // choice from your CMP
  gtag('consent', 'update', {
    ad_storage: choice.ads ? 'granted' : 'denied',
    ad_user_data: choice.ads ? 'granted' : 'denied',
    ad_personalization: choice.personalization ? 'granted' : 'denied',
    analytics_storage: choice.analytics ? 'granted' : 'denied'
  });
}

Region-specific defaults: the most specific region wins. Set defaults for other regions (KSA, UAE, US states) based on your legal assessment — for example, denied by default in KSA if your basis for marketing is consent.

With Google Tag Manager

  • Enable Consent Overview in the container; set built-in consent checks per tag.
  • Use a CMP template from the Community Template Gallery (many CMPs publish certified templates) that sets defaults and updates.
  • Fire the CMP's default command on the Consent Initialization – All Pages trigger.
  • For non-Google tags (Meta, TikTok, LinkedIn), add additional consent checks (e.g., require ad_storage) or fire them only on consent events — they do not natively understand Consent Mode.

Worked example: a Kuwait-and-KSA electronics retailer

The retailer uses advanced mode for KSA and UAE traffic after legal review, basic mode for EU visitors (conservative choice), and GTM additional consent checks on Meta and TikTok tags. After rollout, GA4's consent settings page confirms consent signals are received, and Google Ads diagnostics show Consent Mode active.

Verifying it works

  • Tag Assistant: consent tab shows default and update states in order.
  • Network: requests to Google include gcs (consent state) and gcd parameters; with denied storage, no _ga/_gcl cookies are set.
  • GA4 Admin: Data collection and modification > Consent settings shows whether ad_user_data and ad_personalization are being received.

Pitfalls

  • Default set after the Google tag loads (race condition).
  • Forgetting v2 parameters, so EEA audiences stop growing.
  • Assuming Consent Mode controls non-Google tags.
  • Granting everything by default everywhere without a legal basis.

How to measure success

Consent Mode status "active" in Google Ads diagnostics and GA4, correct defaults per region in Tag Assistant, and no Google cookies set before consent where required.

Key takeaways

  • Consent Mode passes CMP choices to Google tags; v2 adds ad_user_data and ad_personalization.
  • Basic mode blocks Google tags until consent; advanced mode sends cookieless pings when denied and enables better modeling — choose deliberately.
  • Set defaults before any Google tag loads, per region, then update on choice.
  • Consent Mode does not control Meta, TikTok or LinkedIn tags — add GTM consent checks.
  • Verify with Tag Assistant, gcs/gcd parameters and GA4 consent settings.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Which two parameters were added in Consent Mode v2?
  2. In advanced Consent Mode, what happens when a user denies consent?
  3. Why must the consent default command run before the Google tag loads?

Put it into practice

Implement or audit Consent Mode on a test page: record defaults per region, the update on accept and reject, gcs values in network requests, and GA4's consent settings status.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.