Google Consent Mode v2: the four signals and default denied
Consent Mode v2 sends ad_storage, analytics_storage, ad_user_data and ad_personalization. Set all four to denied before tags load, then update on consent.
LLaunchScaler·Published ·8 min read
Google Consent Mode v2 is the consent API that tells Google tags what a visitor agreed to through four signals: ad_storage, analytics_storage, ad_user_data and ad_personalization. You set all four to 'denied' with a default command before any Google tag loads, then send an update command with the visitor's choice when they click your banner.
Google updated consent mode in November 2023, adding ad_user_data and ad_personalization, and requires advertisers with visitors in the European Economic Area to pass consent signals to keep using its tags for measurement, ad personalization and remarketing. This guide gives the calls in the order they must run, the basic and advanced modes, the Tag Manager setup, and how to verify all of it in Tag Assistant.
What are the four Consent Mode v2 signals?
Each signal takes 'granted' or 'denied' and controls one thing Google tags may do. Two govern storage on the visitor's device, and the two added in version 2 govern what advertising data Google may receive and use. The table gives what each one controls and what switches off when it is denied.
Signal
What it controls
When denied
Questions, answered
What people ask about this
01
What is Google Consent Mode v2?
It is the version of Google's consent mode API updated in November 2023, which added ad_user_data and ad_personalization to the original ad_storage and analytics_storage. Your banner reports the visitor's choice through these four signals, and Google tags change what they store and send.
Google Analytics does not read or write its first-party cookies; in advanced mode it sends cookieless pings instead
ad_user_data
Sending user data related to advertising to Google
Google's reference says click-ID keyed conversion data export to Ads is limited, for example bidding based on Google Analytics conversions
ad_personalization
Personalized advertising
Remarketing in Google Ads, Display & Video 360 and Search Ads 360 receives no data
Google's consent mode reference adds that both ad_user_data and ad_personalization must be granted for personalized advertising to work in its advertising platforms. If you set the older allow_ad_personalization_signals as well and the two conflict, personalization is disabled.
Why does Google require Consent Mode v2?
Because Google's EU user consent policy requires consent, and consent mode is how its tags learn the answer. The policy requires you to obtain valid consent from users in the EEA, the UK and Switzerland for cookies or local storage where legally required, and for the use of personal data to personalize ads.
Google's Tag Manager help states the consequence for EEA traffic plainly: to keep using its tags for measurement, ad personalization and remarketing, you must collect consent from end users based in the EEA and share consent signals with Google. The same applies when you use Google Analytics data in Google Ads, Search Ads 360 or Display & Video 360.
What consent mode does not do matters just as much. Google's own help says it "doesn't provide a consent banner or widget." You still need a banner that meets the consent rules, covered in the guide to cookie banner requirements, and consent mode sits behind it.
How do you set the default to denied before the banner?
Call gtag('consent', 'default', ...) on every page before any command that sends measurement data, such as config or event. Google's guide is explicit about order: "If your consent code is called out of order, consent defaults won't work." In practice the default goes in the first script in the <head>, above the Google tag snippet.
wait_for_update is for banners that load asynchronously. It gives your consent tool that many milliseconds, 500 in Google's example, to call update before tags send data. Google's troubleshooting guide also says not to set default consent states asynchronously; the default itself must run inline, first.
Scoping the default to EEA and UK visitors
Google recommends scoping defaults to the regions where you show a banner, using ISO 3166-2 codes in a region array. A default command without region applies to everyone not covered by a regional one, and when a region and a subregion both match, the more specific one wins.
List every EEA country you serve plus GB (the example above is shortened). If your banner shows worldwide, the simpler choice is one default with no region, denied for everyone. Google's own warning applies either way: its examples are placeholders, and you are responsible for defaults that match your organisation's policy.
How do you update consent when the visitor chooses?
Call gtag('consent', 'update', ...) as soon as the visitor clicks a banner button, on the page where they clicked, before any navigation. Google's guide notes that consent mode does not save choices, so you persist the choice yourself, in a first-party cookie or local storage, and call update with it on every later page load.
Wire update to every path: Accept all, Reject all, per-category saves, and the "Cookie settings" link that lets a visitor change their mind later. Google's troubleshooting page asks for an update mechanism for every parameter you set a default for, in both directions.
Should you use basic or advanced consent mode?
The two modes differ in what happens before consent. In basic mode, Google tags are blocked until the visitor interacts with the banner, and no data is sent before consent, not even the default state. In advanced mode, tags load with defaults set to denied and send cookieless pings while consent is denied.
Basic
Advanced
Tag loading
Blocked until the visitor interacts with the banner
Loads with defaults set to denied
Data before consent
None
Consent state and measurements without cookies
What a denied ping holds
Nothing is sent
Functional information such as a timestamp, user agent and referrer, plus the consent state
Modeling
General model
Advertiser-specific model, more detailed
Google's Tag Assistant guide adds a warning for basic setups: if you block the Google tag until consent, modeled conversions are less accurate and behavioral modeling in Google Analytics is unavailable.
The legal side is yours to decide, not Google's. Advanced mode sends requests to Google before consent, and the EDPB's Guidelines 2/2023 analyse pixel and URL tracking as falling within Article 5(3) of the ePrivacy Directive. Whether cookieless pings are acceptable for your visitors is a question for your own legal advice. Consent mode satisfies Google's requirement, and it does not make a banner lawful by itself.
How do you set up Consent Mode v2 in Google Tag Manager?
Use a consent management platform's template, fired on the Consent Initialization trigger. Google recommends a CMP template from the Community Template Gallery, and warns against calling the gtag consent command from a Custom HTML tag in Tag Manager.
In your GTM workspace, open Tags and create a new tag.
Click Tag Configuration, open the Community Template Gallery, find your CMP's template and click Add to workspace.
Fill in the template fields, including the default state for all four parameters and any regions.
Under Triggering, select Consent Initialization - All Pages. Google's troubleshooting guide says the consent tag must fire on this trigger so the defaults exist before other tags use consent.
Fire all your other tags after consent is initialised, for example on Initialization - All Pages or later.
Save, click Preview and verify with Tag Assistant as below.
If you build your own template, use Tag Manager's setDefaultConsentState and updateConsentState APIs rather than gtag('consent', 'update', ...), because gtag commands are queued behind other data layer messages and may not be processed before the next event.
How do you check Consent Mode v2 in Tag Assistant?
Tag Assistant is Google's consent mode checker. It shows the default state the page set, the update after your banner click, and which tags fired or were blocked. Run it in Chrome with the Tag Assistant Companion extension installed for the best results.
Open tagassistant.google.com and enter your website URL. Your site opens in a new tab.
In the Summary, select the earliest Consent event. In the API Call section, confirm ad_storage, ad_personalization, ad_user_data and analytics_storage were all set. Or open your tag's Output, select the Consent tab and read the On-page Default column.
On your site, click Accept all (then repeat the session and click Reject all).
Back in Tag Assistant, select the most recent Consent event and confirm all four were updated, or read the On-page Update column.
Open the Tags tab and click each tag to see whether it behaved according to the consent state.
If you set regional defaults, set a different location in Chrome and repeat the session.
Tag Assistant names the common faults. An empty Consent tab means consent mode is not implemented. "Default consent set too late" means a tag read or wrote a cookie before the default ran, so move the default higher in the page. A consent state that does not update means your banner is not calling update.
Check your consent signals on every scan
Tag Assistant checks one session you drive. To have the default state checked in a real browser each time you scan, run the free scan. LaunchScaler's free scan needs only your URL and no account, and its compliance category includes "Google Consent Mode v2 signals not set to denied before consent", which flags Google tags that load with no default, or with ad_user_data and ad_personalization never set. The same run checks whether trackers fire before any consent action and whether they keep firing after a reject.
Once the signals pass, check two neighbours. Your privacy policy must name Google among the recipients of visitor data, as the guide to what a SaaS privacy policy must include explains. And if you denied analytics_storage for most visitors, your source reporting will change; the guide to tracking signups by source in GA4 covers how to read it.
Google requires advertisers who receive data from users in the European Economic Area to collect consent and pass consent signals to Google to keep using its tags for measurement, ad personalization and remarketing. Consent mode is how gtag.js and Tag Manager pass those signals.
03
What is the difference between basic and advanced consent mode?
In basic mode, Google tags are blocked until the visitor interacts with the banner, and nothing is sent before consent. In advanced mode, tags load with defaults set to denied and send cookieless pings while consent is denied, which Google uses for more detailed modeling.
04
Does consent mode replace a cookie banner?
No. Google's help says consent mode does not provide a consent banner or widget. You still need a banner that collects the choice; consent mode only passes that choice to Google tags.
05
How do I check that Consent Mode v2 is working?
Open tagassistant.google.com, enter your URL, and in the Summary select the earliest Consent event. The API Call section should show all four parameters set to denied, and the most recent Consent event should show them updated after you click the banner.