Web Analytics with Google Analytics 4Campaign tracking, consent and privacy · Lesson 11 of 20

Consent and consent mode concepts

Article · 11 min · 9 min lecture

Video lecture

Consent and consent mode concepts

15 chapters · about 9 min · full transcript

Coming soon

Chapter 1 of 15

Consent mode concepts

  • Consent is a legal requirement
  • What a CMP does
  • Consent mode's four signals
  • Basic versus advanced
  • What consent does to your data

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Many privacy laws and regulations — the EU's GDPR and ePrivacy rules, the UK GDPR and PECR, and regimes in other regions — require a lawful basis for processing personal data and, in many cases, prior consent before setting non-essential cookies or similar identifiers. Analytics and advertising cookies are generally treated as non-essential in those regimes. Requirements vary by jurisdiction, so the right approach depends on where your users are. This lesson explains concepts; it is not legal advice — involve qualified counsel for your specific situation.

A CMP displays the consent banner, records the user's choices, and exposes those choices to tags. Good practice includes:

  • Options to accept and reject that are equally easy to use where the law requires it.
  • Granular categories (for example analytics, advertising, functional).
  • A way to change choices later (a persistent link or icon).
  • Records of consent for accountability.

If you advertise with Google in the European Economic Area, Google's EU user consent policy requires you to obtain and pass consent signals; certified CMPs integrate with Google's systems.

Consent mode is Google's framework for tags to adjust their behavior based on the user's consent choices. The CMP (or your code) sets consent states, and Google tags read them. Consent mode v2 uses these main signals:

SignalControls
analytics_storageWhether analytics cookies/identifiers may be stored
ad_storageWhether advertising cookies/identifiers may be stored
ad_user_dataWhether user data may be sent to Google for advertising purposes
ad_personalizationWhether data may be used for personalized advertising (e.g. remarketing)

A default state is set before any tags fire (often "denied" for regions requiring opt-in) and then updated when the user makes a choice.

Basic versus advanced implementation

  • Basic consent mode: Google tags are blocked entirely until the user consents. If they decline, nothing is sent. GA4 uses a general model for conversion estimation.
  • Advanced consent mode: Google tags load with consent denied by default and send cookieless pings (no identifiers stored) when consent is denied. Google can then use behavioral and conversion modeling to estimate some of the missing data, subject to eligibility thresholds.

Advanced mode can recover more insight, but some organizations and legal advisers prefer basic mode because it sends nothing at all without consent. This is a risk and policy decision, not only a technical one — document who decided and why.

Modeled data in GA4

When eligible, GA4 can fill gaps from consent-denied users with modeled estimates in reports using the blended reporting identity. Explain to stakeholders that some numbers are estimates, and that switching reporting identity changes what they see.

Beyond Google tags

Consent mode governs Google tags. Every other tag — other ad pixels, heatmap tools, chat widgets — must also respect consent, usually through your tag manager's consent settings or the CMP's blocking features. Audit third-party tags regularly; old pixels from past campaigns are a common compliance leak.

A UK online retailer finds that its advertising pixel fires on page load before the banner appears. Audit steps:

  1. Load the site in a clean browser profile; open the Network tab; do not interact with the banner.
  2. Record every request to analytics and ad domains — these fired before consent.
  3. Configure default consent states as denied for relevant regions and link each non-Google tag to the correct consent category in the tag manager.
  4. Retest: reject all — confirm only permitted requests (for example cookieless pings if advanced mode is chosen) occur; accept all — confirm tags fire normally.
  5. Document the configuration and schedule a quarterly re-audit.

Regional reality

  • In the EEA and UK, opt-in consent for non-essential cookies is the norm.
  • In parts of the United States, state laws focus on notice and opt-out rights (for example for "sale" or "sharing" of data), and some honor browser signals such as Global Privacy Control.
  • The UAE and Saudi Arabia have federal personal data protection laws; Pakistan has been developing dedicated legislation. Check the current status and implementing regulations for your markets.

A region-aware CMP configuration lets you apply the appropriate default per region, but when unsure, the more protective default is the safer choice.

Your CMP normally does this for you (many CMPs have Google-certified integrations and Tag Manager templates), but you should be able to read it. The default must run before any Google tag:

<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}
  // Opt-in regions: deny by default (example list; your CMP/legal team decides the regions)
  gtag('consent', 'default', {
    ad_storage: 'denied', ad_user_data: 'denied', ad_personalization: 'denied',
    analytics_storage: 'denied',
    region: ['GB', 'AT', 'BE', 'DE', 'FR', 'IE', 'IT', 'NL', 'ES', 'SE'],
    wait_for_update: 500
  });
  // Elsewhere, a different default may apply per your legal advice
  gtag('consent', 'default', {
    ad_storage: 'granted', ad_user_data: 'granted', ad_personalization: 'granted',
    analytics_storage: 'granted'
  });
</script>
<!-- then the Google tag or GTM container -->

When the user chooses, the CMP calls an update:

gtag('consent', 'update', { analytics_storage: 'granted', ad_storage: 'denied',
                            ad_user_data: 'denied', ad_personalization: 'denied' });
  • Behavioral modeling in GA4 fills gaps only when the property is eligible. Google's documented thresholds include at least 1,000 events per day with analytics_storage denied for at least 7 days, and at least 1,000 daily users with analytics_storage granted for at least 7 of the previous 28 days, with consent mode implemented on all pages in the advanced setup. Many small sites never qualify, so their reports show observed data only.
  • BigQuery export contains no modeled data. In advanced mode, consent-denied "cookieless pings" do appear in the export, but without user_pseudo_id or session identifiers, and with privacy_info.analytics_storage = 'No' (case-sensitive). User and session counts from the export will therefore be lower than blended reports.
  • Google Ads and signals. Since the June 15, 2026 data-controls change, Ads cookie and identifier collection is governed by consent mode (ad_storage), and Google signals only affects behavioral reporting in GA4.

Quantify the consent effect with the export:

SELECT privacy_info.analytics_storage AS analytics_consent, COUNT(*) AS events
FROM `my-project.analytics_123456789.events_*`
WHERE _TABLE_SUFFIX BETWEEN '20260901' AND '20260930'
GROUP BY 1 ORDER BY events DESC;

Second worked example: a Pakistani retailer expanding to the UK

A Karachi fashion brand opens UK shipping. Previously it had no consent banner. It adds a CMP with region-specific defaults (denied for the UK and EEA), chooses advanced consent mode after documenting the decision with legal advice, and tells stakeholders that UK observed users will fall and that modeling may not apply until volumes meet the thresholds. The weekly report gains a "consent granted share" line so nobody mistakes a consent effect for a demand drop.

Common mistakes

  • Tags firing before the banner loads.
  • A "reject" option hidden on a second screen where the law requires parity.
  • Treating consent mode as a substitute for a CMP.
  • Forgetting non-Google tags.
  • Never re-testing after adding new tags.

Key takeaways

  • Consent obligations depend on jurisdiction; involve legal counsel for decisions.
  • Consent mode v2 signals: analytics_storage, ad_storage, ad_user_data, ad_personalization.
  • Basic mode blocks tags until consent; advanced mode sends cookieless pings and enables modeling.
  • Every non-Google tag must also respect consent choices.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Under advanced consent mode, what happens when a user denies consent?
  2. Which consent mode v2 signal controls whether data may be used for remarketing and personalized ads?
  3. A site uses consent mode correctly, but a third-party chat widget sets tracking cookies before consent. What is true?

Put it into practice

Run the clean-browser consent audit from this lesson on a site you manage and list every request that fires before a consent choice.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.