Google Consent Mode v2 Under GDPR: Basic vs Advanced
By Eli C., MarTech & Analytics Engineer
Published Updated
Quick answer: Google Consent Mode v2 passes a visitorâs consent choice to Google tags through four settings:
ad_storage,analytics_storage,ad_user_dataandad_personalization. In Basic mode, Google tags donât load until the visitor makes a choice, so Google receives nothing before consent. In Advanced mode, the tags load on every page and send cookieless pings while consent is denied. The EDPB treats JavaScript that makes the browser send data as covered by Article 5(3) of the ePrivacy Directive, so for EU visitors Basic is the lower-risk setup. Advanced gets you better conversion modeling in return.
What is Google Consent Mode v2?
Google Consent Mode is an API in Googleâs tags (the Google tag, GA4, Google Ads, Floodlight) that reads the consent state your banner sets and changes what those tags store and send. It doesnât ask for consent itself. A consent management platform (CMP) or your own banner does that, then calls the API.
Version 2 is Googleâs November 2023 update, which added ad_user_data and ad_personalization to the original two types. The update came after the European Commission designated Alphabet as a gatekeeper under the Digital Markets Act in September 2023. Google defines the four types like this in its consent mode overview:
| Consent type | Googleâs definition |
|---|---|
ad_storage | âEnables storage, such as cookies (web) or device identifiers (apps), related to advertising.â |
analytics_storage | âEnables storage, such as cookies (web) or device identifiers (apps), related to analytics, for example, visit duration.â |
ad_user_data | âSets consent for sending user data to Google for online advertising purposes.â |
ad_personalization | âSets consent for personalized advertising.â |
GTM also knows functionality_storage, personalization_storage and security_storage, which you can use to control your own tags.
Do you have to use Consent Mode v2?
For Googleâs ad products and visitors in the EEA, yes in practice. Googleâs Ads help says: âTo keep using applicable tags/SDKs for measurement, and for ad personalization, and remarketing features, you must collect consent⌠from end users based in the EEA and share consent signals with Google.â Consent Mode is one way to share those signals. A TCF consent string is the other, covered in the TCF post.
Two limits are often misstated:
- UK and Switzerland. Googleâs EU user consent policy help says: âwe do not have an expectation for advertisers to send a verified consent signal to Google for UK or Swiss trafficâ. Thatâs about the signal only. Where local law requires consent, you still need it.
- Certified CMPs. Google requires a Google-certified CMP only from publishers serving personalized ads through AdSense, Ad Manager or AdMob: in the EEA and UK since January 16, 2024, and in Switzerland since July 31, 2024. For everyone else, âGoogle does not require advertisers to use a CMP from the partner Program.â
Whatâs the difference between Basic and Advanced Consent Mode?
The difference is when Google tags load. Basic waits for the visitorâs choice, while Advanced loads straight away and adjusts to the consent state. Based on Googleâs overview:
| Basic | Advanced | |
|---|---|---|
| Tag loading | Blocked until the visitor interacts with the banner | Loads on every page with the consent defaults |
| Sent before a choice | Nothing, ânot even the default consent statusâ | Consent state and measurements without cookies |
| Sent after a refusal | Nothing | Cookieless pings when tags fire |
| Google Ads conversion modeling | A general model | An advertiser-specific model |
| GA4 behavioral modeling | Not available | Available once the property meets Googleâs thresholds |
GA4 behavioral modeling needs volume too: âat least 1,000 events per day with analytics_storage=âdeniedâ for at least 7 daysâ, plus 1,000 daily users who granted consent (Analytics Help). Many smaller sites never qualify, and Google doesnât put a number on how much modeling recovers. Its own caveat on Basic: âGoogle wonât be able to verify user consent choices and this may lead to loss in dataâ (Ads help).
Set a denied default yourself either way. Googleâs developer guide says âBy default, no consent mode values are setâ, while its Ads help says the system âdefaults to a consented state unless a specific choice has been madeâ.
What does Google receive before consent?
In Basic mode, nothing: no request goes to Google. In Advanced mode, Googleâs overview lists what a ping sent while consent is denied can contain:
- Functional information the browser adds by itself: timestamp, user agent and referrer.
- Aggregate or non-identifying information: whether the current page or an earlier page in the visit had ad-click information in the URL (GCLID or DCLID), the consent state, and a random number generated on each page load. It also includes the consent platformâs developer ID.
The request comes from the visitorâs browser, so Google also receives the IP address. For EU users, GA4 uses it âsolely for geo-location data derivation before being immediately discardedâ (Analytics Help), and âAds products truncate IP addresses at collectionâ. While ad_storage is denied, ad tags still collect âFull page URLs⌠including ad-click information in URL parametersâ unless you turn on ads_data_redaction (below).
One change to watch: from August 2026, Googleâs policy help says it will use âthe IP Addresses it receives via customer tags⌠for ads measurement and ads personalizationâ in the EEA, UK and Switzerland, and that consent âwill apply, for example, to the use of IP addresses for ads personalization or ads measurementâ. As of October 2026, it doesnât say how that applies to IP addresses in pings sent while consent is denied, and I havenât found a Google statement that does.
You can see which mode a site runs in a minute:
- Open the site in a private window with DevTools, go to Network and tick Preserve log.
- Filter by
/googletagmanager|google-analytics|googleadservices|doubleclick/(DevTools accepts a regex between slashes) and donât touch the banner. - With Basic loaded as Google describes it, the list stays empty until you accept. With Advanced, requests to Google appear straight away: those are the pings. A lone
gtm.jsrequest means GTM loads before consent, the in-between setup described below.
Is Advanced Consent Mode GDPR-compliant?
I havenât found a court or regulator decision on Consent Mode by name (as of October 2026). But on the EDPBâs reading, Advanced pings need consent unless an exemption applies, and ad measurement is hard to fit into one. Most of the question sits in the ePrivacy Directive, not the GDPR.
Article 5(3) of the ePrivacy Directive requires consent for storing information on a userâs device or accessing information on it. The only exceptions are access strictly necessary to transmit a communication, or to provide a service âexplicitly requested by the subscriber or userâ. Four sources shape how it applies to pings:
- EDPB Guidelines 2/2023 (version 2.0, adopted October 7, 2024). Paragraph 33 covers âJavaScript code, where the accessing entity instructs the browser of the user to send asynchronous requests with the targeted information. Such access clearly falls within the scope of Article 5(3) ePD.â A cookieless ping is that kind of request. Falling within scope âdoes not systematically mean that consent needs to be collectedâ (paragraph 56). You still assess whether an exemption applies, and measuring ads isnât needed to deliver the page the visitor asked for.
- Planet49 (C-673/17, October 1, 2019). The CJEU held that Article 5(3) applies whether or not the information is personal data. âThe ping has no cookie and no identifierâ doesnât take it out of scope.
- EDPB Opinion 5/2019, paragraph 40. Where ePrivacy requires consent, âthe controller cannot rely on the full range of possible lawful grounds provided by article 6 of the GDPRâ. Legitimate interest canât stand in for it.
- VG Hannover, March 19, 2025 (10 A 5385/22). A German administrative court held that âDer Einsatz des Dienstes Google Tag Manager bedarf einer Einwilligungâ (using Google Tag Manager requires consent) under § 25 TTDSG and Article 6(1)(a) GDPR. Before any banner interaction, the site had sent the IP address, device configuration, country and referrer URL to Google, and the court found GTM ânicht technisch erforderlichâ (not technically necessary). Itâs a first-instance ruling in one German state, but itâs the closest published case to tags that talk to Google before a choice.
On the GDPR side, an IP address is personal data for a website operator that âhas the legal meansâ to identify the person with the internet providerâs help (Breyer, C-582/14, paragraph 49). The US transfer has a legal basis for now: Google LLC is certified under the EUâUS Data Privacy Framework, whose adequacy decision the General Court upheld on September 3, 2025 (Latombe, T-553/23). An appeal (C-703/25 P) is pending.
My reading: Advanced pings fall within Article 5(3), and neither exemption fits ad measurement well. If your DPO wants the conservative option for EU traffic, thatâs Basic. Thatâs an engineerâs reading of published guidance; the decision belongs with your DPO or counsel.
What changes for UK visitors?
Since February 5, 2026, UK law has an exception for analytics that EU law doesnât have. The Data (Use and Access) Act 2025 replaced regulation 6 of PECR and added Schedule A1. Its paragraph 5 lets you store or access information without consent when all of these hold:
- The sole purpose is statistical information about how your service is used, with a view to improving it.
- The information isnât shared except to help you make those improvements.
- The user gets âclear and comprehensive informationâ about the purpose.
- The user gets âa simple means of objecting, free of chargeâ, and doesnât object.
The ICOâs guidance (last updated April 29, 2026) sets the limits: âThe statistical purposes exception does not apply to purposes related to online advertising.â A third-party analytics provider is allowed only if it acts on your behalf and âmust be a processor, not a joint controllerâ.
For Consent Mode on UK traffic, that means:
- Google Ads and Floodlight pings serve advertising, so they still need consent, and Advanced mode for ad tags raises the same question as in the EU.
- GA4 fits the exception only if Google processes the data solely on your behalf, the data stays out of advertising, and visitors have a working way to object. Check your GA4 data-sharing settings and Googleâs terms against the ICOâs conditions rather than assuming it fits.
That Google doesnât expect a consent signal for UK traffic is Googleâs policy. It doesnât tell you what PECR allows.
How do you set up Basic Consent Mode with GTM?
Load the CMP directly in the page, and load the GTM container only after the visitor accepts. Googleâs setup guide says: âDonât load the consent banner through your Tag Manager container, since you are blocking it until a user grants consent⌠Load the Tag Manager container when the user grants consent.â
Hereâs a version for Cookiebot, which fires a CookiebotOnConsentReady event âwhen the userâs consent state is ready, either from being submitted or loaded from an existing cookieâ. Other CMPs have an equivalent callback. It replaces the standard GTM snippet in the <head>. Replace GTM-XXXXXXX and the data-cbid with your own IDs:
<script>
window.dataLayer = window.dataLayer || []
function gtag() {
dataLayer.push(arguments)
}
;(function () {
var gtmLoaded = false
function consentState() {
var ads = Cookiebot.consent.marketing ? 'granted' : 'denied'
return {
analytics_storage: Cookiebot.consent.statistics ? 'granted' : 'denied',
ad_storage: ads,
ad_user_data: ads,
ad_personalization: ads
}
}
function loadGtm(state) {
gtag('consent', 'default', {
analytics_storage: 'denied',
ad_storage: 'denied',
ad_user_data: 'denied',
ad_personalization: 'denied'
})
gtag('consent', 'update', state)
dataLayer.push({ 'gtm.start': new Date().getTime(), event: 'gtm.js' })
var script = document.createElement('script')
script.async = true
script.src = 'https://www.googletagmanager.com/gtm.js?id=GTM-XXXXXXX'
document.head.appendChild(script)
gtmLoaded = true
}
window.addEventListener('CookiebotOnConsentReady', function () {
var state = consentState()
if (gtmLoaded) {
gtag('consent', 'update', state)
} else if (Cookiebot.consent.statistics || Cookiebot.consent.marketing) {
loadGtm(state)
}
})
})()
</script>
<script
id="Cookiebot"
src="https://consent.cookiebot.com/uc.js"
data-cbid="00000000-0000-0000-0000-000000000000"
data-consentmode="disabled"
></script>
A visitor who rejects everything never loads GTM. On acceptance, the snippet sends the default and then the update, the order Google describes for Basic, before gtm.js so the first tags already see the granted state. Later changes become update calls. data-consentmode="disabled" turns off Cookiebotâs own Consent Mode integration, which is on unless you disable it, so the signals arenât sent twice.
Everything else in the container, such as a Meta or LinkedIn tag, now waits for consent too, which is usually what you want for EU traffic. Anything that really must run for every visitor has to live outside GTM.
The common alternative: load GTM, hold the tags. Many sites load GTM on every page and block Google tags inside the container. That works only with the right setting (see Googleâs consent settings help):
- Built-in consent checks donât block. Google tags have them, and Google describes them as logic that âchanges the tagâs execution behavior based on the userâs consent stateâ. The tags still fire while consent is denied and adapt, which is Advanced behavior.
- âRequire additional consent for tag to fireâ does block. Itâs under Advanced settings â Consent settings, with, for example,
analytics_storagefor GA4, orad_storageandad_user_datafor Google Ads. The tag then âwill only fire if the status of all specified consent types are âgrantedâ when the tag is triggeredâ. A Page View trigger that ran before the visitor chose wonât run again, so also fire the tag on your CMPâs consent event, without firing twice for visitors who had already consented. - Consent defaults go on the Consent Initialization - All Pages trigger, which âwill always fire before all other tags, including any Initialization triggersâ.
- Consent Overview (Admin â Container Settings â Enable consent overview) lists which tags have consent settings and which donât.
This setup still loads gtm.js from googletagmanager.com before the visitor chooses. Thatâs what the Hannover court objected to, and it isnât what Google describes as Basic. Treat it as a middle ground.
How do you set up Advanced Consent Mode with less data?
If you run Advanced, for traffic outside the EU and UK or after your DPO has signed off, send as little as you can. Set the defaults before the GTM snippet:
<script>
window.dataLayer = window.dataLayer || []
function gtag() {
dataLayer.push(arguments)
}
gtag('consent', 'default', {
analytics_storage: 'denied',
ad_storage: 'denied',
ad_user_data: 'denied',
ad_personalization: 'denied',
wait_for_update: 500
})
gtag('set', 'ads_data_redaction', true)
</script>
<!-- the standard GTM snippet goes after this -->
The settings that matter, all from Googleâs setup guide:
wait_for_updateis how long, in milliseconds, tags wait for your CMP to callgtag('consent', 'update', âŚ)before they send data. It matters when the banner loads asynchronously.ads_data_redaction: when itâs true andad_storageis denied, âad click identifiers⌠will be redactedâ and requests go âthrough a domain without third-party cookiesâ. It âwill have no effect when ad_storage is grantedâ.url_passthroughstays off unless you set it totrue. When itâs on, Google tags appendgclid,dclid,gclsrc,_glandwbraidto links as visitors move through your site. Leave it off if youâre minimizing data.regionlimits a default to ISO 3166-2 codes (for example['ES', 'US-AK']), and the most specific match wins. It only changes defaults: the tags still load everywhere, so this is still Advanced.- Server-side GTM can drop parameters before they reach Google with transformations, but only the ones you configure. The ping still leaves the visitorâs browser first, so the Article 5(3) question doesnât change.
The same Article 5(3) reasoning applies to analytics tools sold as cookieless, which the cookieless post covers. If you want a second opinion on which mode fits your traffic, or a check of what your tags actually send before consent, thatâs part of my consent mode work.
Frequently asked questions
Does Google Consent Mode replace a cookie banner?
No. Consent Mode only passes the visitor's choice to Google tags. You still need a banner or consent management platform (CMP) to ask for consent and record it. Advertisers don't have to use a Google-certified CMP; that requirement applies to AdSense, Ad Manager and AdMob publishers.
Is Basic Consent Mode GDPR-compliant?
Basic keeps Google tags from sending anything before the visitor chooses, so those tags no longer raise the pre-consent question. Whether the site as a whole complies still depends on the banner, on your other tags, and on whether the GTM container itself loads before consent.
What happens when ad_user_data or ad_personalization is denied?
With ad_user_data denied, Google doesn't use personal data for advertising, which affects enhanced conversions and tag-based conversion tracking. With ad_personalization denied, remarketing gets no data. Google needs both granted for personalized advertising.
Can I run Basic in the EU and Advanced everywhere else?
Yes, but the region setting alone won't do it: region only changes the default consent state, and the tags still load everywhere. You have to decide before the tags load whether the visitor is in the EU, for example from a country header your CDN adds, and load GTM only after consent for those visitors.
Sources
- Consent mode overview (Google Tag Platform)
- Set up consent mode on websites (Google Tag Platform)
- Consent management in Tag Manager (Tag Manager Help)
- EU user consent policy help (Google)
- Consent mode reference (Google Ads Help)
- Behavioral modeling for consent mode (Analytics Help)
- EDPB Guidelines 2/2023 on the technical scope of Art. 5(3) ePrivacy Directive, version 2.0
- EDPB Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR
- CJEU, Planet49 (C-673/17), press release
- VG Hannover, judgment of 19 March 2025, 10 A 5385/22
- PECR Schedule A1: exceptions to the storage and access rule (legislation.gov.uk)
- Guidance on the use of storage and access technologies (ICO)