---
title: "Consent and consent mode concepts | Optimize All Academy"
description: "Consent is a legal requirement, not a banner design choice Many privacy laws and regulations — the EU's GDPR and ePrivacy rules, the UK GDPR and PECR…"
url: https://optimizeall.com/learn/web-analytics-with-ga4/consent-mode-concepts
updated: 2026-10-05
---

Web Analytics with Google Analytics 4 · Campaign tracking, consent and privacy · lesson 11 of 20 · 11 min

# Consent and consent mode concepts

## Consent is a legal requirement, not a banner design choice

Many privacy laws and regulations — the EU's GDPR and ePrivacy rules, the UK GDPR and PECR, and regimes in other regions — require a lawful basis for processing personal data and, in many cases, **prior consent** before setting non-essential cookies or similar identifiers. Analytics and advertising cookies are generally treated as non-essential in those regimes. Requirements vary by jurisdiction, so the right approach depends on where your users are. This lesson explains concepts; it is not legal advice — involve qualified counsel for your specific situation.

## Consent Management Platforms (CMPs)

A **CMP** displays the consent banner, records the user's choices, and exposes those choices to tags. Good practice includes:

- Options to accept and reject that are equally easy to use where the law requires it.
- Granular categories (for example analytics, advertising, functional).
- A way to change choices later (a persistent link or icon).
- Records of consent for accountability.

If you advertise with Google in the European Economic Area, Google's EU user consent policy requires you to obtain and pass consent signals; certified CMPs integrate with Google's systems.

## What is consent mode?

**Consent mode** is Google's framework for tags to adjust their behavior based on the user's consent choices. The CMP (or your code) sets consent states, and Google tags read them. Consent mode v2 uses these main signals:

| Signal | Controls |
|---|---|
| `analytics_storage` | Whether analytics cookies/identifiers may be stored |
| `ad_storage` | Whether advertising cookies/identifiers may be stored |
| `ad_user_data` | Whether user data may be sent to Google for advertising purposes |
| `ad_personalization` | Whether data may be used for personalized advertising (e.g. remarketing) |

A **default** state is set before any tags fire (often "denied" for regions requiring opt-in) and then **updated** when the user makes a choice.

## Basic versus advanced implementation

- **Basic consent mode**: Google tags are blocked entirely until the user consents. If they decline, nothing is sent. GA4 uses a general model for conversion estimation.
- **Advanced consent mode**: Google tags load with consent denied by default and send **cookieless pings** (no identifiers stored) when consent is denied. Google can then use **behavioral and conversion modeling** to estimate some of the missing data, subject to eligibility thresholds.

Advanced mode can recover more insight, but some organizations and legal advisers prefer basic mode because it sends nothing at all without consent. This is a **risk and policy decision**, not only a technical one — document who decided and why.

## Modeled data in GA4

When eligible, GA4 can fill gaps from consent-denied users with modeled estimates in reports using the **blended** reporting identity. Explain to stakeholders that some numbers are estimates, and that switching reporting identity changes what they see.

## Beyond Google tags

Consent mode governs Google tags. **Every other tag** — other ad pixels, heatmap tools, chat widgets — must also respect consent, usually through your tag manager's consent settings or the CMP's blocking features. Audit third-party tags regularly; old pixels from past campaigns are a common compliance leak.

## Worked example: a UK retailer's consent audit

A UK online retailer finds that its advertising pixel fires on page load before the banner appears. Audit steps:

1. Load the site in a clean browser profile; open the Network tab; do not interact with the banner.
2. Record every request to analytics and ad domains — these fired before consent.
3. Configure default consent states as denied for relevant regions and link each non-Google tag to the correct consent category in the tag manager.
4. Retest: reject all — confirm only permitted requests (for example cookieless pings if advanced mode is chosen) occur; accept all — confirm tags fire normally.
5. Document the configuration and schedule a quarterly re-audit.

## Regional reality

- In the EEA and UK, opt-in consent for non-essential cookies is the norm.
- In parts of the United States, state laws focus on notice and opt-out rights (for example for "sale" or "sharing" of data), and some honor browser signals such as Global Privacy Control.
- The UAE and Saudi Arabia have federal personal data protection laws; Pakistan has been developing dedicated legislation. Check the current status and implementing regulations for your markets.

A region-aware CMP configuration lets you apply the appropriate default per region, but when unsure, the more protective default is the safer choice.

## Hands-on: consent mode defaults and updates in code

Your CMP normally does this for you (many CMPs have Google-certified integrations and Tag Manager templates), but you should be able to read it. The default must run **before** any Google tag:

```html
<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}
  // Opt-in regions: deny by default (example list; your CMP/legal team decides the regions)
  gtag('consent', 'default', {
    ad_storage: 'denied', ad_user_data: 'denied', ad_personalization: 'denied',
    analytics_storage: 'denied',
    region: ['GB', 'AT', 'BE', 'DE', 'FR', 'IE', 'IT', 'NL', 'ES', 'SE'],
    wait_for_update: 500
  });
  // Elsewhere, a different default may apply per your legal advice
  gtag('consent', 'default', {
    ad_storage: 'granted', ad_user_data: 'granted', ad_personalization: 'granted',
    analytics_storage: 'granted'
  });
</script>
<!-- then the Google tag or GTM container -->
```

When the user chooses, the CMP calls an update:

```javascript
gtag('consent', 'update', { analytics_storage: 'granted', ad_storage: 'denied',
                            ad_user_data: 'denied', ad_personalization: 'denied' });
```

## What consent does to your data (2026 view)

- **Behavioral modeling** in GA4 fills gaps only when the property is eligible. Google's documented thresholds include at least 1,000 events per day with `analytics_storage` denied for at least 7 days, and at least 1,000 daily users with `analytics_storage` granted for at least 7 of the previous 28 days, with consent mode implemented on all pages in the advanced setup. Many small sites never qualify, so their reports show observed data only.
- **BigQuery export contains no modeled data.** In advanced mode, consent-denied "cookieless pings" do appear in the export, but without `user_pseudo_id` or session identifiers, and with `privacy_info.analytics_storage = 'No'` (case-sensitive). User and session counts from the export will therefore be lower than blended reports.
- **Google Ads and signals.** Since the June 15, 2026 data-controls change, Ads cookie and identifier collection is governed by consent mode (`ad_storage`), and Google signals only affects behavioral reporting in GA4.

Quantify the consent effect with the export:

```sql
SELECT privacy_info.analytics_storage AS analytics_consent, COUNT(*) AS events
FROM `my-project.analytics_123456789.events_*`
WHERE _TABLE_SUFFIX BETWEEN '20260901' AND '20260930'
GROUP BY 1 ORDER BY events DESC;
```

## Second worked example: a Pakistani retailer expanding to the UK

A Karachi fashion brand opens UK shipping. Previously it had no consent banner. It adds a CMP with region-specific defaults (denied for the UK and EEA), chooses advanced consent mode after documenting the decision with legal advice, and tells stakeholders that UK observed users will fall and that modeling may not apply until volumes meet the thresholds. The weekly report gains a "consent granted share" line so nobody mistakes a consent effect for a demand drop.

## Common mistakes

- Tags firing before the banner loads.
- A "reject" option hidden on a second screen where the law requires parity.
- Treating consent mode as a substitute for a CMP.
- Forgetting non-Google tags.
- Never re-testing after adding new tags.

## Video lecture: Consent and consent mode concepts

Lecture coming soon · 15 chapters · about 9 minutes. Read the full transcript below.

1. Consent mode concepts
2. Why it matters
3. The CMP
4. Consent mode signals
5. Basic versus advanced
6. Modeling eligibility
7. Consent and the export
8. Example 1: a UK consent audit
9. Example 2: expanding to the UK
10. Watch me do it, part 1
11. Watch me do it, part 2
12. Beyond Google tags and regions
13. Common mistakes
14. Recap
15. Try this now

## Lecture transcript

### Consent mode concepts

Here's a scenario that happens every week somewhere. A UK retailer launches a new consent banner on Monday. By Wednesday, G A four users are down sharply, and the marketing director asks what broke. Nothing broke. The site started respecting people's choices. In this lecture you'll learn why consent is a legal requirement, what a consent management platform does, how Google's consent mode works with its four signals, the difference between basic and advanced mode, and exactly what consent does to your reports, your modeling and your BigQuery export.

### Why it matters

Why does this matter? Because many privacy regimes, including the E U's G D P R and e-privacy rules and the U K's G D P R and P E C R, require a lawful basis for processing and, in many cases, prior consent before non-essential cookies. Analytics and advertising cookies are generally treated as non-essential there. Requirements differ by jurisdiction, so this lecture explains concepts, not legal advice. Involve qualified counsel for your situation. But every analyst must understand how consent shapes the data they report.

### The CMP

First, the consent management platform, or C M P. It displays the banner, records choices, and exposes them to tags. Good practice includes accept and reject options that are equally easy where the law requires it, granular categories like analytics, advertising and functional, a persistent way to change choices later, and records of consent for accountability. If you advertise with Google in the European Economic Area, Google's E U user consent policy requires you to obtain and pass consent signals, and certified C M Ps integrate with Google's systems.

### Consent mode signals

Now consent mode. It's Google's framework for tags to adjust behavior based on consent. Think of it like traffic lights for data. The C M P sets the lights, and Google tags obey them. There are four signals. Analytics storage: may analytics cookies be stored? Ad storage: may advertising cookies be stored? Ad user data: may user data be sent to Google for advertising? And ad personalization: may data be used for personalized ads, like remarketing? A default is set before any tag fires, then updated when the user chooses.

### Basic versus advanced

Basic versus advanced. In basic consent mode, Google tags are blocked entirely until the user consents. If they decline, nothing is sent. In advanced mode, tags load with consent denied by default and send cookieless pings, with no identifiers stored, when consent is denied, which lets Google model some of the missing data if you're eligible. Advanced can recover more insight. But some organizations prefer basic, because it sends nothing without consent. It's a risk and policy decision, not just a technical one. Document who decided and why.

### Modeling eligibility

Here's what consent does to your data, and this is where most reporting confusion comes from. Behavioral modeling only applies when a property is eligible. Google's documented thresholds include at least a thousand events a day with analytics storage denied for at least seven days, and at least a thousand daily users with it granted for seven of the previous twenty-eight days, with advanced consent mode on all pages. Many small sites never qualify, so their reports show observed data only. That's not a bug. It's the rule.

### Consent and the export

And the BigQuery export contains no modeled data at all. In advanced mode, the consent-denied cookieless pings do appear in the export, but without a user pseudo id or session identifiers, and with a privacy info field showing analytics storage as No, capital N. So user and session counts from the export will be lower than the blended numbers in reports. And since the June twenty twenty-six data controls change, Ads identifier collection is governed by consent mode's ad storage, while Google signals affects only behavioral reporting in G A four.

### Example 1: a UK consent audit

First example, a simple one. A UK online retailer runs a consent audit. In a clean browser profile, with the network tab open, and without touching the banner, they record every request to analytics and ad domains. Their ad pixel fires on page load, before the banner even appears. They set default consent to denied for the relevant regions, link each non-Google tag to the right consent category in the tag manager, and retest: reject all, then accept all. Then they document the setup and schedule a quarterly re-audit.

### Example 2: expanding to the UK

Second example, a business case. A Karachi fashion brand starts shipping to the UK, where it previously had no banner at all. It adds a C M P with region-specific defaults, denied for the UK and the European Economic Area. It chooses advanced mode after documenting the decision with legal advice. And it tells stakeholders in advance that UK observed users will fall, and that modeling may not apply until volumes meet the thresholds. The weekly report gains a consent granted share line, so nobody mistakes a consent effect for a demand drop.

### Watch me do it, part 1

Watch me read the code, even if your C M P writes it. Before any Google tag loads, the page defines the data layer and the gtag function. Then gtag consent default: all four signals denied, for a list of opt-in regions, with wait for update set to five hundred milliseconds, so the C M P has time to load a returning visitor's choice. A second default applies elsewhere, according to your legal advice. When the visitor chooses, the C M P calls gtag consent update, for example granting analytics storage but denying the three advertising signals.

### Watch me do it, part 2

Then I quantify the effect in the export. I group September's events by privacy info analytics storage and count them. I see three values: Yes, No, and null. Null usually means consent wasn't set, which is itself a finding: maybe some pages load the tag without the consent default. Then I verify with Tag Assistant on those pages. That query turns a vague we lost some data into a precise share you can report every week.

### Beyond Google tags and regions

Remember that consent mode governs Google tags only. Every other tag, like other ad pixels, heatmap tools and chat widgets, must also respect consent, usually through your tag manager's consent settings or the C M P's blocking features. Audit third-party tags regularly; old pixels from past campaigns are a common compliance leak. And regionally: opt-in is the norm in the E E A and U K, several U S states focus on opt-out rights and some honor Global Privacy Control, and the U A E and Saudi Arabia have personal data protection laws. Check current rules for your markets.

### Common mistakes

Common mistakes. Tags firing before the banner loads. A reject option hidden on a second screen where the law requires parity. Treating consent mode as a substitute for a C M P. Forgetting non-Google tags. Never re-testing after adding new tags. And reporting a consent-driven drop as a demand problem.

### Recap

Recap. Consent obligations depend on jurisdiction, so involve counsel. A C M P records choices and exposes them. Consent mode's four signals tell Google tags what's allowed. Basic mode blocks tags until consent, advanced mode sends cookieless pings and enables modeling if eligible. Modeling has thresholds, and the BigQuery export has no modeled data. Every non-Google tag must respect consent too. And report the consent granted share, so nobody misreads the numbers.

### Try this now

Try this now. Run the clean-browser consent audit from the lesson on a site you manage, and list every request that fires before a consent choice. If you have the BigQuery export, run the consent-state query for last month and calculate the share of events with consent denied or unset. Share both with your team this week.

## Key takeaways

- Consent obligations depend on jurisdiction; involve legal counsel for decisions.
- Consent mode v2 signals: analytics_storage, ad_storage, ad_user_data, ad_personalization.
- Basic mode blocks tags until consent; advanced mode sends cookieless pings and enables modeling.
- Every non-Google tag must also respect consent choices.

## Try it

Run the clean-browser consent audit from this lesson on a site you manage and list every request that fires before a consent choice.

- [Previous: UTM discipline and channel groupings](https://optimizeall.com/learn/web-analytics-with-ga4/utm-discipline)
- [Next: Privacy by design and data governance](https://optimizeall.com/learn/web-analytics-with-ga4/privacy-by-design)
- [All lessons of Web Analytics with Google Analytics 4](https://optimizeall.com/learn/web-analytics-with-ga4)
