Google Tag Manager Consent Mode: Implement and Verify It

Google Tag Manager Consent Mode lets Google tags adjust their behaviour according to consent states supplied by a consent management solution. It does not collect consent, create a compliant banner or decide which defaults are lawful for your organisation.

Dennis Westphal
Dennis WestphalFounder, Growth Junction
Google Tag Manager Consent Mode: Implement and Verify It

Google Tag Manager Consent Mode lets Google tags adjust their behaviour according to consent states supplied by a consent management solution. It does not collect consent, create a compliant banner or decide which defaults are lawful for your organisation.

A correct setup needs an agreed policy, a working consent interface, early default states, timely updates and technical validation of each user choice.

Quick answer: Configure a consent management platform, set default consent states before dependent Google tags run, update those states immediately when the user confirms or changes a choice, and test the resulting tag and network behaviour. Consent Mode v2 includes ad_storage, analytics_storage, ad_user_data and ad_personalization signals.

A cookie banner or consent management platform asks for and stores user choices. Consent Mode communicates applicable states to Google tags. The two must be integrated, but they are not the same product.

Responsibilities normally include:

  • legal or privacy owner defines the policy and categories;
  • consent platform presents choices and persists them;
  • website loads the consent solution in the correct order;
  • GTM or the Google tag receives default and updated states;
  • each tag declares or respects its consent requirements;
  • analytics owner validates data and documents limitations.

Do not infer that a familiar banner configuration is correct for every business. Consent requirements and permitted defaults need qualified advice based on the organisation’s situation.

Consent Mode v2 uses four prominent signals for analytics and advertising:

Signal What it communicates
analytics_storage Consent for storage related to analytics measurement
ad_storage Consent for storage related to advertising
ad_user_data Consent for sending user data to Google for advertising purposes
ad_personalization Consent for personalised advertising

Each can be set to values such as granted or denied according to the implementation. Other settings and behaviours may apply, so use the current Google documentation and consent platform guide.

These signals do not replace the organisation’s own consent categories. Map the banner’s choices to Google’s signals explicitly. A vague “marketing” toggle may need to update more than one state.

3. Set defaults before measurement depends on them

The order is critical. Default consent states should be established before Google tags that depend on those states execute. If defaults arrive late, tags may act under an unintended state or early events may be difficult to interpret.

In GTM, consent templates commonly use the Consent Initialization – All Pages trigger so they run before standard initialization and page-view tags. When a supported consent platform provides a vetted community template, follow the provider’s current setup instructions and review the template permissions.

Avoid implementing GTM consent updates through a generic Custom HTML tag when the Tag Manager consent APIs or a proper template are available. Google’s current guidance favours consent-aware template methods.

If the consent solution loads asynchronously, account for timing intentionally. A delay is not a substitute for a correct default state.

4. Update the state when the user chooses

When the user accepts, rejects or customises choices, the consent platform should send an update on the page where the interaction occurs. Persist the choice so the correct state can be established on later pages.

Test these journeys:

  • first visit before interaction;
  • accept all;
  • reject all;
  • analytics only;
  • advertising choices where offered;
  • reopening settings;
  • changing granted to denied;
  • changing denied to granted;
  • navigating immediately after selection;
  • returning in a new session.

Do not rely solely on a page reload after choice. Current Google guidance notes that updates should occur when the state changes; reloading too quickly can interrupt measurement requests and lose context.

The banner must remain usable with keyboard and mobile interaction. A technically correct update that people cannot understand or control is not a sound consent experience.

Google tags include built-in consent checks for relevant signals. Third-party or custom tags may need explicit consent requirements configured in GTM.

For each tag, document:

  • purpose;
  • vendor and destination;
  • data sent;
  • built-in consent behaviour;
  • additional consent requirements;
  • trigger order;
  • owner;
  • validation result.

Avoid applying “No additional consent required” mechanically. That setting means no extra GTM check is configured beyond any built-in behaviour; it is not a legal assessment.

Review templates and Custom HTML carefully. A third-party script can set cookies or send data independently of Google Consent Mode. The consent platform and tag inventory must cover all vendors, not only Google tags.

6. Validate with Tag Assistant and network inspection

Open Tag Assistant through GTM Preview and inspect the Consent tab or relevant event details. Confirm default states at Consent Initialization and updated states after interaction.

Use this test table:

Test Expected evidence
Initial page load Default states exist before dependent tags
Accept choice Correct signals update to granted
Reject choice Correct signals remain or update to denied
Custom choice Each mapped signal reflects the category
Revocation State updates promptly and persists
Navigation Next page starts with stored choice
Tag firing Tags act according to built-in and extra checks
Network requests Request behaviour matches consent mode and policy design

Also inspect browser storage and network requests. A GTM tag marked “did not fire” is only one layer; hard-coded scripts, CMS plugins or duplicate containers may still send requests.

Test production after publishing. Consent behaviour can differ when preview parameters and debug tools are absent.

Consent choices affect what can be collected and reported. Changes to banner design, defaults, CMP version or tag order can create sudden shifts in sessions, key events, attribution and (not set) values.

Monitor:

  • consent-state distribution where appropriately available;
  • tag and CMP errors;
  • GA4 session and page-view changes;
  • key-event changes by device and browser;
  • ad conversion diagnostics;
  • unassigned and direct traffic changes;
  • container and banner releases;
  • discrepancies between operational outcomes and analytics.

Annotate consent releases. Do not interpret a measurement drop as a demand drop until implementation and user-choice changes are ruled out.

If Google Tag Manager cookie consent is difficult to verify across the banner, GTM, GA4 and Google Ads, Growthjunction’s analytics and tracking service can map and test the technical flow alongside the organisation’s approved consent policy.

Frequently asked questions

Find the leak before you scale the channel.

Growth Junction connects demand, landing pages, tracking and sales feedback so the next fix is based on evidence, not guesswork.

Find the leak in my account
A short qualification flow keeps the Calendly booking step hidden until there is enough context.
Two quick questionsCheck whether the Lead-Leak Analysis is likely to be useful for your company.

Use USD or your local equivalent. Your answers stay in your browser and only determine whether the booking calendar appears.