---
title: "Google Consent Mode v2: basic vs advanced, done right"
description: "What Consent Mode does Google Consent Mode lets you communicate users' consent choices to Google tags (Google Analytics, Google Ads, Floodlight) so the…"
url: https://optimizeall.com/learn/privacy-first-measurement/google-consent-mode-v2
updated: 2026-10-05
---

Privacy-First Measurement: Server-Side Tagging, Consent Mode and Conversion APIs · Consent management and Google Consent Mode · lesson 4 of 14 · 8 min

# Google Consent Mode v2: basic vs advanced, done right

## What Consent Mode does

**Google Consent Mode** lets you communicate users' consent choices to Google tags (Google Analytics, Google Ads, Floodlight) so the tags adjust their behavior. It is not a CMP; your CMP collects consent and Consent Mode passes it to Google tags.

**Consent Mode v2** added two parameters to the original `ad_storage` and `analytics_storage`:

| Parameter | Controls |
|---|---|
| `ad_storage` | Storage (cookies) related to advertising |
| `analytics_storage` | Storage related to analytics |
| `ad_user_data` | Consent to send user data to Google for advertising purposes |
| `ad_personalization` | Consent to personalized advertising (e.g., remarketing) |
| `functionality_storage`, `personalization_storage`, `security_storage` | Other storage purposes |

For EEA traffic (and UK traffic), Google requires consent signals to use certain ads measurement and personalization features, including audience building and some conversion modeling. Without v2 signals, those features degrade.

## Basic vs advanced implementation

| | **Basic** | **Advanced** |
|---|---|---|
| Before consent | Google tags **do not load** | Tags load with default "denied" states |
| If user denies | Nothing sent to Google | Tags send **cookieless pings** (no cookies read or written) |
| Modeling | General model (less precise) | Advertiser-specific modeling (more precise) |
| Privacy posture | Most conservative | Requires legal comfort with cookieless pings |

Which to choose is a legal and business decision. In jurisdictions where regulators interpret device-access rules strictly, some organizations choose basic mode; others conclude advanced mode's cookieless pings are acceptable. Document the decision.

## Implementation with gtag.js

The default state must be set **before** any Google tag loads, then updated when the user chooses.

```html
<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}

  // Defaults for EEA + UK: denied until the user chooses
  gtag('consent', 'default', {
    ad_storage: 'denied',
    analytics_storage: 'denied',
    ad_user_data: 'denied',
    ad_personalization: 'denied',
    wait_for_update: 500,
    region: ['AT','BE','BG','HR','CY','CZ','DK','EE','FI','FR','DE','GR','HU','IS','IE','IT','LV','LI','LT','LU','MT','NL','NO','PL','PT','RO','SK','SI','ES','SE','GB']
  });
  // Default elsewhere (set according to your legal assessment per region)
  gtag('consent', 'default', {
    ad_storage: 'granted', analytics_storage: 'granted',
    ad_user_data: 'granted', ad_personalization: 'granted'
  });
  gtag('set', 'ads_data_redaction', true);   // redact ad click identifiers when ad_storage is denied
  gtag('set', 'url_passthrough', true);      // pass click info through URLs when cookies are denied
</script>
<!-- Google tag (gtag.js) loads after this -->
```

Then, when the CMP reports the user's choice:

```javascript
function onConsentChoice(choice) { // choice from your CMP
  gtag('consent', 'update', {
    ad_storage: choice.ads ? 'granted' : 'denied',
    ad_user_data: choice.ads ? 'granted' : 'denied',
    ad_personalization: choice.personalization ? 'granted' : 'denied',
    analytics_storage: choice.analytics ? 'granted' : 'denied'
  });
}
```

Region-specific defaults: the most specific region wins. Set defaults for other regions (KSA, UAE, US states) based on your legal assessment — for example, denied by default in KSA if your basis for marketing is consent.

## With Google Tag Manager

- Enable **Consent Overview** in the container; set built-in consent checks per tag.
- Use a **CMP template** from the Community Template Gallery (many CMPs publish certified templates) that sets defaults and updates.
- Fire the CMP's default command on the **Consent Initialization – All Pages** trigger.
- For non-Google tags (Meta, TikTok, LinkedIn), add **additional consent checks** (e.g., require `ad_storage`) or fire them only on consent events — they do not natively understand Consent Mode.

## Worked example: a Kuwait-and-KSA electronics retailer

The retailer uses advanced mode for KSA and UAE traffic after legal review, basic mode for EU visitors (conservative choice), and GTM additional consent checks on Meta and TikTok tags. After rollout, GA4's consent settings page confirms consent signals are received, and Google Ads diagnostics show Consent Mode active.

## Verifying it works

- Tag Assistant: consent tab shows default and update states in order.
- Network: requests to Google include `gcs` (consent state) and `gcd` parameters; with denied storage, no `_ga`/`_gcl` cookies are set.
- GA4 Admin: **Data collection and modification > Consent settings** shows whether ad_user_data and ad_personalization are being received.

## Pitfalls

- Default set after the Google tag loads (race condition).
- Forgetting v2 parameters, so EEA audiences stop growing.
- Assuming Consent Mode controls non-Google tags.
- Granting everything by default everywhere without a legal basis.

## How to measure success

Consent Mode status "active" in Google Ads diagnostics and GA4, correct defaults per region in Tag Assistant, and no Google cookies set before consent where required.

## Video lecture: Google Consent Mode v2: basic vs advanced, done right

Lecture coming soon · 14 chapters · about 8 minutes. Read the full transcript below.

1. Google Consent Mode v2
2. Why it matters
3. What it is
4. Why v2 matters
5. Basic vs advanced
6. Simple example: the event sequence
7. gtag implementation
8. Optional settings
9. With Tag Manager
10. Example: Gulf electronics retailer (illustrative)
11. Verify three ways
12. Mistakes + try this now
13. Watch me do it: verifying Consent Mode (illustrative)
14. Recap and next step

## Lecture transcript

### Google Consent Mode v2

If you advertise to Europe or the UK with Google and your audiences have quietly stopped growing, or your conversion modeling looks thin, the cause is often one missing detail in Consent Mode. In this lecture you'll learn what Consent Mode version two actually does, the difference between basic and advanced implementations, how to set it up with code or Tag Manager, and three ways to verify it's working.

### Why it matters

Why does this matter? Because Consent Mode is the difference between Google's tools working properly under consent rules and silently degrading. Here's an analogy. Think of a hotel with a do not disturb sign. The guest decides, the sign communicates the decision, and housekeeping adapts. Your CMP is the guest's decision. Consent Mode is the sign hanging on the door. Google's tags are housekeeping. Without the sign, housekeeping either barges in, which is a compliance problem, or stays away from every room, which is a measurement problem. Consent Mode lets them do the right thing for each room.

### What it is

First, what it isn't. Consent Mode is not a consent banner. Your consent platform collects choices. Consent Mode passes those choices to Google's tags, like Analytics, Google Ads and Floodlight, so they change their behavior. Version two added two parameters to the original storage settings: ad user data, which covers sending user data to Google for advertising, and ad personalization, which covers things like remarketing.

### Why v2 matters

Why does v2 matter? For traffic from the European Economic Area and the UK, Google requires these consent signals before it uses data for certain ads features, including building audiences and some measurement. Without them, remarketing lists stop growing and some features degrade. So if you only implemented the original two parameters years ago, you're probably missing out, even if users are consenting.

### Basic vs advanced

Now the big choice: basic or advanced. In basic mode, Google tags don't load at all until the user chooses. If they say no, nothing goes to Google. In advanced mode, tags load immediately with a default of denied. If the user says no, the tags send cookieless pings, which don't read or write cookies, and Google uses them for more precise, advertiser-specific modeling. Advanced gives better data. Basic is more conservative. It's a legal and business decision, so document it.

### Simple example: the event sequence

Here's a simple worked example of the event sequence. A visitor from Germany lands on your store. First, the consent default command runs: ad storage, analytics storage, ad user data and ad personalization all denied, with a five hundred millisecond wait for update. Then the Google tag loads. In advanced mode it sends a cookieless ping. The visitor clicks accept all on the banner. The CMP fires a consent update with all four set to granted. Now the Google tag sets its cookies and sends full measurement. In Tag Assistant, you should see exactly that order: default, then update. If you see the tag fire before the default, you've found a race condition.

### gtag implementation

Implementation has one golden rule: set the default before any Google tag loads. With gtag, you push a consent default command with all four key parameters, typically denied for EEA and UK regions, with a short wait for update so the banner can respond. You can set different defaults for other regions based on your legal assessment. Then, when the user chooses, you send a consent update with their choices. The lesson has copy-ready code.

### Optional settings

Two optional settings are worth knowing. Ads data redaction removes ad click identifiers from requests when ad storage is denied. URL passthrough carries click information through your URLs between pages, so conversions can still be connected without cookies. Consider both with your legal team.

### With Tag Manager

If you use Google Tag Manager, enable Consent Overview, use your CMP's template from the Community Template Gallery, and fire the default on the Consent Initialization trigger, which runs before everything else. Then the crucial bit: Consent Mode only controls Google tags. Meta, TikTok and LinkedIn tags don't understand it. Add additional consent checks in Tag Manager, for example requiring ad storage, or fire them only after a consent event.

### Example: Gulf electronics retailer (illustrative)

Here's an illustrative example. An electronics retailer in Kuwait and Saudi Arabia uses advanced mode for Gulf traffic after legal review, and basic mode for EU visitors as a conservative choice. They add consent checks to their Meta and TikTok tags in Tag Manager. After rollout, GA4's consent settings confirm signals are arriving, and Google Ads diagnostics show Consent Mode as active.

### Verify three ways

Verify three ways. In Tag Assistant, the consent tab should show the default and then the update, in that order. In the network panel, Google requests carry g c s and g c d parameters describing consent state, and with storage denied, no Google Analytics or Ads cookies should appear. And in GA4 admin, under data collection, the consent settings page shows whether ad user data and ad personalization signals are being received.

### Mistakes + try this now

Common Consent Mode mistakes. Setting the default after the Google tag has already loaded. Implementing only the original two parameters and missing ad user data and ad personalization. Assuming Consent Mode controls Meta, TikTok and LinkedIn. Granting everything by default in every region without a legal basis. And never checking GA4's consent settings. Try this now: open Tag Assistant on your site, load a page without touching the banner, and read the consent tab. Write down the default values you see. Then accept, and check the update values. If you can't find a default at all, that's your first fix.

### Watch me do it: verifying Consent Mode (illustrative)

Watch me do it. Let's verify Consent Mode on an illustrative London shoe retailer after deployment. First, I open Tag Assistant and connect to the site. On the first page view, the consent tab shows a default command: ad storage denied, analytics storage denied, ad user data denied, ad personalization denied, with region set for the UK. Good, and it appears before the Google tag, which is the order we need. Second, I open the network tab and find a request to Google Analytics. The g c s parameter shows everything denied, and no underscore g a cookie exists. That confirms advanced mode's cookieless ping. Third, I click accept all. Tag Assistant now shows an update with all four granted, and the next request's g c s shows granted, with cookies now set. Fourth, I test the partial path: manage choices, analytics on, ads off. The update shows analytics granted, ad storage denied, and the Meta tag doesn't fire because of its additional consent check. Fifth, in GA4 admin, consent settings shows ad user data and ad personalization signals being received. Five checks, fifteen minutes, and I can sign off with evidence.

### Recap and next step

Recap. Consent Mode passes choices to Google tags, and version two adds ad user data and ad personalization. Choose basic or advanced deliberately. Set defaults before tags load, per region, and update on choice. Add separate checks for non-Google tags. Your next step: implement or audit Consent Mode on a test page, recording defaults, updates, the g c s values and GA4's consent status.

## Key takeaways

- Consent Mode passes CMP choices to Google tags; v2 adds ad_user_data and ad_personalization.
- Basic mode blocks Google tags until consent; advanced mode sends cookieless pings when denied and enables better modeling — choose deliberately.
- Set defaults before any Google tag loads, per region, then update on choice.
- Consent Mode does not control Meta, TikTok or LinkedIn tags — add GTM consent checks.
- Verify with Tag Assistant, gcs/gcd parameters and GA4 consent settings.

## Try it

Implement or audit Consent Mode on a test page: record defaults per region, the update on accept and reject, gcs values in network requests, and GA4's consent settings status.

- [Previous: Consent management: CMPs, IAB TCF 2.3 and GPP](https://optimizeall.com/learn/privacy-first-measurement/consent-management-cmps-and-tcf)
- [Next: GA4 with consent: modeling, settings and the Measurement Protocol](https://optimizeall.com/learn/privacy-first-measurement/ga4-with-consent)
- [All lessons of Privacy-First Measurement: Server-Side Tagging, Consent Mode and Conversion APIs](https://optimizeall.com/learn/privacy-first-measurement)
