Google Consent Mode v2: how it works and what to set up
Consent Mode v2 is how your consent banner tells Google tags what a visitor agreed to. This guide covers the four consent signals, the difference between basic and advanced mode, and the setup mistakes that quietly break measurement.
What Consent Mode v2 is
Consent Mode is a Google API that adjusts how Google tags (GA4, Google Ads, Floodlight) behave based on consent state. It does not show a banner or store consent. Your consent management platform (CMP) does that, then passes the result to Google through Consent Mode.
Google's developer documentation defines four consent types that matter for ads and analytics:
- ad_storage: storage such as cookies related to advertising.
- analytics_storage: storage related to analytics, such as visit duration.
- ad_user_data: consent for sending user data to Google for online advertising.
- ad_personalization: consent for personalised advertising, including remarketing.
Google announced the two new signals, ad_user_data and ad_personalization, in November 2023 and began requiring them for EEA traffic in March 2024, when the Digital Markets Act took effect. Advertisers who want measurement, ad personalisation and remarketing on traffic from the European Economic Area need them.
Basic vs advanced implementation
Google documents two ways to implement Consent Mode. The difference is what happens before the visitor makes a choice.
Basic mode blocks Google tags until the visitor interacts with the banner. Google's documentation says no data is sent before consent, not even the default consent status. If the visitor declines, Google gets nothing from that visit. Conversion modelling falls back to a general model.
Advanced mode loads Google tags immediately with consent set to denied. While consent is denied, tags send the consent state and cookieless measurement pings. Google uses those pings for an advertiser-specific model, which Google describes as more detailed than the basic model.
Our take: advanced mode recovers more conversion data, but it sends pings to Google before consent. Decide on that with whoever owns privacy in your business, not only with the ads team.
Who needs it
- You run Google Ads conversion tracking, remarketing or Floodlight on EEA or UK traffic: implement all four signals.
- GA4 is linked to Google Ads and you import conversions or build audiences: implement all four signals.
- You use GA4 for reporting only, with no ads link: analytics_storage is the signal that matters, though sending all four does no harm.
- You use no Google tags at all: Consent Mode is irrelevant. You still need a compliant consent banner for any other non-essential cookies.
How it works
Every page runs two commands. First, a default command sets the starting state for each consent type, usually denied for EEA visitors. Google's documentation requires this call on every page before any command that sends measurement data. Second, an update command runs when the visitor accepts or rejects, and again whenever they change their mind.
wait_for_update sits in the default command and gives the CMP a set number of milliseconds to send the update before tags fire. It matters for returning visitors whose choice is already stored.
Region-specific defaults let you apply denied defaults only where you need them. Google's documentation specifies ISO 3166-2 codes, so an EEA rule is a list of country codes such as DE, FR and IT, not a single EU value.
ads_data_redaction, when set to true while ad_storage is denied, redacts ad click identifiers in requests sent by Google Ads and Floodlight tags.
url_passthrough carries ad click and analytics parameters such as gclid, dclid and _gl in page URLs when cookie storage is denied, so a conversion later in the session can still be attributed.
Which reviewed CMPs support it
All three consent platforms in our dataset are recorded with Consent Mode v2 support. Confirm the current integration details in each vendor's documentation before you commit.
- Cookiebot: built-in Consent Mode v2 support plus automated cookie scanning. A common fit for e-commerce sites running Google Ads.
- Usercentrics: Consent Mode v2 support aimed at larger teams, with white-label options. No automated scanner in our dataset, so plan to maintain your cookie inventory yourself.
- iubenda: Consent Mode v2 support bundled with privacy policy and terms generators. Useful for small businesses that need both.
Common failures
- Defaults set after tags load. If the Google tag fires before the default command, the first hits go out with no consent state. In GTM, fire the default on the Consent Initialization - All Pages trigger, not the regular Initialization or Page View trigger.
- Missing update call. The banner records the choice but never sends an update, so every visitor stays denied and your conversion data collapses.
- Template mis-mapped. A GTM template maps the CMP's categories to only ad_storage and analytics_storage, leaving ad_user_data and ad_personalization at their defaults.
- Gaps hidden by test environments. GTM preview and server-side tagging can behave differently from the live site. Check production traffic from an EEA location with a clean browser.
Verify and implement
Run your setup through the Consent Mode v2 readiness checker to find missing signals and get a prioritised fix list. Then confirm in Google Tag Assistant that the default fires before any tag and that accept and reject both produce an update.
For the step-by-step Google Tag Manager setup, with code for defaults, updates and CMP connection, use the Consent Mode v2 setup playbook. The GTM template and test cases cover the wiring and the checks.
Frequently Asked Questions
- Does a CMP support Google Consent Mode v2 out of the box?
- Most established CMPs ship a Consent Mode v2 integration, but it is usually a setting you have to switch on and map. Cookiebot, Usercentrics and iubenda are all recorded with Consent Mode v2 support in our dataset. Support only helps if the integration sets all four consent types as denied before your Google tags load and sends an update when the visitor chooses. Check both in production after you enable it.
- Is Consent Mode v2 a GDPR requirement?
- No. Consent Mode v2 is a Google requirement for advertisers who want measurement, personalisation and remarketing on EEA traffic. The legal obligation to get consent before setting non-essential cookies comes from the ePrivacy rules and GDPR. Consent Mode is the mechanism that tells Google tags what the visitor decided in your consent banner. It does not collect consent itself.
- Should I use basic or advanced Consent Mode?
- Our take: start with basic if you have no one to validate the setup, because nothing reaches Google before consent. Move to advanced when you rely on Google Ads conversion data and can confirm, with your privacy lead, that sending cookieless pings before consent fits your own risk position. Advanced gives Google more data to model with, and that data is the trade-off.
- What does wait_for_update do?
- wait_for_update is set in the default command and is measured in milliseconds. It tells Google tags to hold off for that long so the CMP has time to send an update, for example for a returning visitor whose choice is already stored. Google's documentation uses 500 milliseconds as its example. If your CMP loads slowly, tags fire with the default state once the timer expires.
- Do I need Consent Mode v2 if I only use GA4?
- The two newer signals, ad_user_data and ad_personalization, matter most when GA4 is linked to Google Ads or when you use Google Ads directly. With GA4 alone, analytics_storage still decides whether GA4 sets cookies. Most CMP integrations send all four signals regardless, so you rarely need a separate GA4-only setup.
Related Resources
Consent Mode v2 Readiness Checker
Answer questions about your setup and get a prioritised fix list for missing signals.
PlaybookConsent Mode v2 Setup in GTM
Step-by-step Google Tag Manager implementation with code for defaults and updates.
DownloadConsent Mode GTM Template
Container template for wiring consent defaults and updates in GTM.
DownloadConsent Mode Test Cases
Test scenarios to confirm Consent Mode v2 behaves correctly in production.
GuideIAB TCF Guide
When ad-funded sites also need the Transparency and Consent Framework.
ComparisonCookiebot vs Usercentrics
Two CMPs with Consent Mode v2 and IAB TCF support, compared side by side.