Skip to main content
Privacy Compliance

Google Consent Mode v2 Under GDPR: Basic vs Advanced

By , MarTech & Analytics Engineer

Published Updated

Quick answer: Google Consent Mode v2 passes a visitor’s consent choice to Google tags through four settings: ad_storage, analytics_storage, ad_user_data and ad_personalization. In Basic mode, Google tags don’t load until the visitor makes a choice, so Google receives nothing before consent. In Advanced mode, the tags load on every page and send cookieless pings while consent is denied. The EDPB treats JavaScript that makes the browser send data as covered by Article 5(3) of the ePrivacy Directive, so for EU visitors Basic is the lower-risk setup. Advanced gets you better conversion modeling in return.

Google Consent Mode is an API in Google’s tags (the Google tag, GA4, Google Ads, Floodlight) that reads the consent state your banner sets and changes what those tags store and send. It doesn’t ask for consent itself. A consent management platform (CMP) or your own banner does that, then calls the API.

Version 2 is Google’s November 2023 update, which added ad_user_data and ad_personalization to the original two types. The update came after the European Commission designated Alphabet as a gatekeeper under the Digital Markets Act in September 2023. Google defines the four types like this in its consent mode overview:

Consent typeGoogle’s definition
ad_storage”Enables storage, such as cookies (web) or device identifiers (apps), related to advertising.”
analytics_storage”Enables storage, such as cookies (web) or device identifiers (apps), related to analytics, for example, visit duration.”
ad_user_data”Sets consent for sending user data to Google for online advertising purposes.”
ad_personalization”Sets consent for personalized advertising.”

GTM also knows functionality_storage, personalization_storage and security_storage, which you can use to control your own tags.

For Google’s ad products and visitors in the EEA, yes in practice. Google’s Ads help says: “To keep using applicable tags/SDKs for measurement, and for ad personalization, and remarketing features, you must collect consent… from end users based in the EEA and share consent signals with Google.” Consent Mode is one way to share those signals. A TCF consent string is the other, covered in the TCF post.

Two limits are often misstated:

  • UK and Switzerland. Google’s EU user consent policy help says: “we do not have an expectation for advertisers to send a verified consent signal to Google for UK or Swiss traffic”. That’s about the signal only. Where local law requires consent, you still need it.
  • Certified CMPs. Google requires a Google-certified CMP only from publishers serving personalized ads through AdSense, Ad Manager or AdMob: in the EEA and UK since January 16, 2024, and in Switzerland since July 31, 2024. For everyone else, “Google does not require advertisers to use a CMP from the partner Program.”

The difference is when Google tags load. Basic waits for the visitor’s choice, while Advanced loads straight away and adjusts to the consent state. Based on Google’s overview:

BasicAdvanced
Tag loadingBlocked until the visitor interacts with the bannerLoads on every page with the consent defaults
Sent before a choiceNothing, “not even the default consent status”Consent state and measurements without cookies
Sent after a refusalNothingCookieless pings when tags fire
Google Ads conversion modelingA general modelAn advertiser-specific model
GA4 behavioral modelingNot availableAvailable once the property meets Google’s thresholds

GA4 behavioral modeling needs volume too: “at least 1,000 events per day with analytics_storage=‘denied’ for at least 7 days”, plus 1,000 daily users who granted consent (Analytics Help). Many smaller sites never qualify, and Google doesn’t put a number on how much modeling recovers. Its own caveat on Basic: “Google won’t be able to verify user consent choices and this may lead to loss in data” (Ads help).

Set a denied default yourself either way. Google’s developer guide says “By default, no consent mode values are set”, while its Ads help says the system “defaults to a consented state unless a specific choice has been made”.

In Basic mode, nothing: no request goes to Google. In Advanced mode, Google’s overview lists what a ping sent while consent is denied can contain:

  • Functional information the browser adds by itself: timestamp, user agent and referrer.
  • Aggregate or non-identifying information: whether the current page or an earlier page in the visit had ad-click information in the URL (GCLID or DCLID), the consent state, and a random number generated on each page load. It also includes the consent platform’s developer ID.

The request comes from the visitor’s browser, so Google also receives the IP address. For EU users, GA4 uses it “solely for geo-location data derivation before being immediately discarded” (Analytics Help), and “Ads products truncate IP addresses at collection”. While ad_storage is denied, ad tags still collect “Full page URLs… including ad-click information in URL parameters” unless you turn on ads_data_redaction (below).

One change to watch: from August 2026, Google’s policy help says it will use “the IP Addresses it receives via customer tags… for ads measurement and ads personalization” in the EEA, UK and Switzerland, and that consent “will apply, for example, to the use of IP addresses for ads personalization or ads measurement”. As of October 2026, it doesn’t say how that applies to IP addresses in pings sent while consent is denied, and I haven’t found a Google statement that does.

You can see which mode a site runs in a minute:

  1. Open the site in a private window with DevTools, go to Network and tick Preserve log.
  2. Filter by /googletagmanager|google-analytics|googleadservices|doubleclick/ (DevTools accepts a regex between slashes) and don’t touch the banner.
  3. With Basic loaded as Google describes it, the list stays empty until you accept. With Advanced, requests to Google appear straight away: those are the pings. A lone gtm.js request means GTM loads before consent, the in-between setup described below.

I haven’t found a court or regulator decision on Consent Mode by name (as of October 2026). But on the EDPB’s reading, Advanced pings need consent unless an exemption applies, and ad measurement is hard to fit into one. Most of the question sits in the ePrivacy Directive, not the GDPR.

Article 5(3) of the ePrivacy Directive requires consent for storing information on a user’s device or accessing information on it. The only exceptions are access strictly necessary to transmit a communication, or to provide a service “explicitly requested by the subscriber or user”. Four sources shape how it applies to pings:

  • EDPB Guidelines 2/2023 (version 2.0, adopted October 7, 2024). Paragraph 33 covers “JavaScript code, where the accessing entity instructs the browser of the user to send asynchronous requests with the targeted information. Such access clearly falls within the scope of Article 5(3) ePD.” A cookieless ping is that kind of request. Falling within scope “does not systematically mean that consent needs to be collected” (paragraph 56). You still assess whether an exemption applies, and measuring ads isn’t needed to deliver the page the visitor asked for.
  • Planet49 (C-673/17, October 1, 2019). The CJEU held that Article 5(3) applies whether or not the information is personal data. “The ping has no cookie and no identifier” doesn’t take it out of scope.
  • EDPB Opinion 5/2019, paragraph 40. Where ePrivacy requires consent, “the controller cannot rely on the full range of possible lawful grounds provided by article 6 of the GDPR”. Legitimate interest can’t stand in for it.
  • VG Hannover, March 19, 2025 (10 A 5385/22). A German administrative court held that “Der Einsatz des Dienstes Google Tag Manager bedarf einer Einwilligung” (using Google Tag Manager requires consent) under § 25 TTDSG and Article 6(1)(a) GDPR. Before any banner interaction, the site had sent the IP address, device configuration, country and referrer URL to Google, and the court found GTM “nicht technisch erforderlich” (not technically necessary). It’s a first-instance ruling in one German state, but it’s the closest published case to tags that talk to Google before a choice.

On the GDPR side, an IP address is personal data for a website operator that “has the legal means” to identify the person with the internet provider’s help (Breyer, C-582/14, paragraph 49). The US transfer has a legal basis for now: Google LLC is certified under the EU–US Data Privacy Framework, whose adequacy decision the General Court upheld on September 3, 2025 (Latombe, T-553/23). An appeal (C-703/25 P) is pending.

My reading: Advanced pings fall within Article 5(3), and neither exemption fits ad measurement well. If your DPO wants the conservative option for EU traffic, that’s Basic. That’s an engineer’s reading of published guidance; the decision belongs with your DPO or counsel.

What changes for UK visitors?

Since February 5, 2026, UK law has an exception for analytics that EU law doesn’t have. The Data (Use and Access) Act 2025 replaced regulation 6 of PECR and added Schedule A1. Its paragraph 5 lets you store or access information without consent when all of these hold:

  • The sole purpose is statistical information about how your service is used, with a view to improving it.
  • The information isn’t shared except to help you make those improvements.
  • The user gets “clear and comprehensive information” about the purpose.
  • The user gets “a simple means of objecting, free of charge”, and doesn’t object.

The ICO’s guidance (last updated April 29, 2026) sets the limits: “The statistical purposes exception does not apply to purposes related to online advertising.” A third-party analytics provider is allowed only if it acts on your behalf and “must be a processor, not a joint controller”.

For Consent Mode on UK traffic, that means:

  • Google Ads and Floodlight pings serve advertising, so they still need consent, and Advanced mode for ad tags raises the same question as in the EU.
  • GA4 fits the exception only if Google processes the data solely on your behalf, the data stays out of advertising, and visitors have a working way to object. Check your GA4 data-sharing settings and Google’s terms against the ICO’s conditions rather than assuming it fits.

That Google doesn’t expect a consent signal for UK traffic is Google’s policy. It doesn’t tell you what PECR allows.

Load the CMP directly in the page, and load the GTM container only after the visitor accepts. Google’s setup guide says: “Don’t load the consent banner through your Tag Manager container, since you are blocking it until a user grants consent… Load the Tag Manager container when the user grants consent.”

Here’s a version for Cookiebot, which fires a CookiebotOnConsentReady event “when the user’s consent state is ready, either from being submitted or loaded from an existing cookie”. Other CMPs have an equivalent callback. It replaces the standard GTM snippet in the <head>. Replace GTM-XXXXXXX and the data-cbid with your own IDs:

<script>
	window.dataLayer = window.dataLayer || []
	function gtag() {
		dataLayer.push(arguments)
	}

	;(function () {
		var gtmLoaded = false

		function consentState() {
			var ads = Cookiebot.consent.marketing ? 'granted' : 'denied'
			return {
				analytics_storage: Cookiebot.consent.statistics ? 'granted' : 'denied',
				ad_storage: ads,
				ad_user_data: ads,
				ad_personalization: ads
			}
		}

		function loadGtm(state) {
			gtag('consent', 'default', {
				analytics_storage: 'denied',
				ad_storage: 'denied',
				ad_user_data: 'denied',
				ad_personalization: 'denied'
			})
			gtag('consent', 'update', state)
			dataLayer.push({ 'gtm.start': new Date().getTime(), event: 'gtm.js' })
			var script = document.createElement('script')
			script.async = true
			script.src = 'https://www.googletagmanager.com/gtm.js?id=GTM-XXXXXXX'
			document.head.appendChild(script)
			gtmLoaded = true
		}

		window.addEventListener('CookiebotOnConsentReady', function () {
			var state = consentState()
			if (gtmLoaded) {
				gtag('consent', 'update', state)
			} else if (Cookiebot.consent.statistics || Cookiebot.consent.marketing) {
				loadGtm(state)
			}
		})
	})()
</script>
<script
	id="Cookiebot"
	src="https://consent.cookiebot.com/uc.js"
	data-cbid="00000000-0000-0000-0000-000000000000"
	data-consentmode="disabled"
></script>

A visitor who rejects everything never loads GTM. On acceptance, the snippet sends the default and then the update, the order Google describes for Basic, before gtm.js so the first tags already see the granted state. Later changes become update calls. data-consentmode="disabled" turns off Cookiebot’s own Consent Mode integration, which is on unless you disable it, so the signals aren’t sent twice.

Everything else in the container, such as a Meta or LinkedIn tag, now waits for consent too, which is usually what you want for EU traffic. Anything that really must run for every visitor has to live outside GTM.

The common alternative: load GTM, hold the tags. Many sites load GTM on every page and block Google tags inside the container. That works only with the right setting (see Google’s consent settings help):

  • Built-in consent checks don’t block. Google tags have them, and Google describes them as logic that “changes the tag’s execution behavior based on the user’s consent state”. The tags still fire while consent is denied and adapt, which is Advanced behavior.
  • “Require additional consent for tag to fire” does block. It’s under Advanced settings → Consent settings, with, for example, analytics_storage for GA4, or ad_storage and ad_user_data for Google Ads. The tag then “will only fire if the status of all specified consent types are ‘granted’ when the tag is triggered”. A Page View trigger that ran before the visitor chose won’t run again, so also fire the tag on your CMP’s consent event, without firing twice for visitors who had already consented.
  • Consent defaults go on the Consent Initialization - All Pages trigger, which “will always fire before all other tags, including any Initialization triggers”.
  • Consent Overview (Admin → Container Settings → Enable consent overview) lists which tags have consent settings and which don’t.

This setup still loads gtm.js from googletagmanager.com before the visitor chooses. That’s what the Hannover court objected to, and it isn’t what Google describes as Basic. Treat it as a middle ground.

If you run Advanced, for traffic outside the EU and UK or after your DPO has signed off, send as little as you can. Set the defaults before the GTM snippet:

<script>
	window.dataLayer = window.dataLayer || []
	function gtag() {
		dataLayer.push(arguments)
	}
	gtag('consent', 'default', {
		analytics_storage: 'denied',
		ad_storage: 'denied',
		ad_user_data: 'denied',
		ad_personalization: 'denied',
		wait_for_update: 500
	})
	gtag('set', 'ads_data_redaction', true)
</script>
<!-- the standard GTM snippet goes after this -->

The settings that matter, all from Google’s setup guide:

  • wait_for_update is how long, in milliseconds, tags wait for your CMP to call gtag('consent', 'update', …) before they send data. It matters when the banner loads asynchronously.
  • ads_data_redaction: when it’s true and ad_storage is denied, “ad click identifiers… will be redacted” and requests go “through a domain without third-party cookies”. It “will have no effect when ad_storage is granted”.
  • url_passthrough stays off unless you set it to true. When it’s on, Google tags append gclid, dclid, gclsrc, _gl and wbraid to links as visitors move through your site. Leave it off if you’re minimizing data.
  • region limits a default to ISO 3166-2 codes (for example ['ES', 'US-AK']), and the most specific match wins. It only changes defaults: the tags still load everywhere, so this is still Advanced.
  • Server-side GTM can drop parameters before they reach Google with transformations, but only the ones you configure. The ping still leaves the visitor’s browser first, so the Article 5(3) question doesn’t change.

The same Article 5(3) reasoning applies to analytics tools sold as cookieless, which the cookieless post covers. If you want a second opinion on which mode fits your traffic, or a check of what your tags actually send before consent, that’s part of my consent mode work.

Frequently asked questions

Does Google Consent Mode replace a cookie banner?

No. Consent Mode only passes the visitor's choice to Google tags. You still need a banner or consent management platform (CMP) to ask for consent and record it. Advertisers don't have to use a Google-certified CMP; that requirement applies to AdSense, Ad Manager and AdMob publishers.

Is Basic Consent Mode GDPR-compliant?

Basic keeps Google tags from sending anything before the visitor chooses, so those tags no longer raise the pre-consent question. Whether the site as a whole complies still depends on the banner, on your other tags, and on whether the GTM container itself loads before consent.

What happens when ad_user_data or ad_personalization is denied?

With ad_user_data denied, Google doesn't use personal data for advertising, which affects enhanced conversions and tag-based conversion tracking. With ad_personalization denied, remarketing gets no data. Google needs both granted for personalized advertising.

Can I run Basic in the EU and Advanced everywhere else?

Yes, but the region setting alone won't do it: region only changes the default consent state, and the tags still load everywhere. You have to decide before the tags load whether the visitor is in the EU, for example from a country header your CDN adds, and load GTM only after consent for those visitors.

Sources

  1. Consent mode overview (Google Tag Platform)
  2. Set up consent mode on websites (Google Tag Platform)
  3. Consent management in Tag Manager (Tag Manager Help)
  4. EU user consent policy help (Google)
  5. Consent mode reference (Google Ads Help)
  6. Behavioral modeling for consent mode (Analytics Help)
  7. EDPB Guidelines 2/2023 on the technical scope of Art. 5(3) ePrivacy Directive, version 2.0
  8. EDPB Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR
  9. CJEU, Planet49 (C-673/17), press release
  10. VG Hannover, judgment of 19 March 2025, 10 A 5385/22
  11. PECR Schedule A1: exceptions to the storage and access rule (legislation.gov.uk)
  12. Guidance on the use of storage and access technologies (ICO)