Google Consent Mode: what to actually do
Since March 2024, Google has required advertisers using Google Ads and its advertising features on visitors from the European Economic Area and the UK to pass consent choices to it via Consent Mode v2. That’s a requirement set by Google for its own products, separate from the legal obligation to collect consent, which comes from GDPR and falls under the CNIL’s remit in France.
What I see most often
- A Google Ads notice flagging missing consent signals for European Economic Area visitors
- A custom consent banner that collects the visitor’s choice correctly but sends nothing to Google
- Confusion between "collecting consent" (a GDPR obligation overseen by the CNIL) and "passing consent to Google" (a Google Ads-specific requirement)
- Remarketing or conversion modelling that seems to have weakened since a consent banner went live
- A third-party CMP to choose from without knowing whether it handles consent mode automatically
How the mechanism works
Consent Mode v2 relies on four signals sent to the Google tag: analytics_storage for analytics storage and ad_storage for advertising storage, both already in v1, to which v2 adds ad_user_data (permission to send user data to Google for advertising purposes) and ad_personalization (permission to personalise advertising, remarketing included). Those last two are what make it v2: an implementation that only sends ad_storage and analytics_storage is still on v1, and that is the most common case I find on custom banners.
All four are sent a first time by default, before the visitor has responded to the banner, then updated once they make a choice.
There are two ways to implement this. A Consent Management Platform (CMP) certified by Google integrates it automatically: it sends the right signals at the right time with no extra code to write. A custom-built banner has to implement these calls by hand via the gtag('consent', ...) function, once for the default state, once more for the update when the visitor decides.
What I check and set up
-
Does this apply to me?
I check whether the site uses Google Ads or Google advertising features (remarketing, Customer Match, conversion modelling) on visitors located in the EEA or the UK: that’s the exact scope of Google’s requirement.
-
State of the existing banner
I check whether the consent banner in place is a Google-certified CMP (automatic implementation) or a custom solution (manual implementation to verify or build).
-
Default state before the decision
I make sure a default consent state (usually denied) is sent before the visitor has even responded to the banner, a condition the mechanism needs to work correctly.
-
Update on decision
I check that the visitor’s actual choice (accepted or refused, by category) triggers an update call sent to Google the moment they click.
-
Checking the signals
Using Google Tag Manager’s preview mode or a debugging extension, I confirm consent signals appear correctly attached to the relevant Google Ads and GA4 tags.
gtag('consent', 'default', {
'ad_storage': 'denied',
'ad_user_data': 'denied',
'ad_personalization': 'denied',
'analytics_storage': 'denied'
});
// après la décision du visiteur sur la bannière
gtag('consent', 'update', {
'ad_storage': 'granted',
'ad_user_data': 'granted',
'ad_personalization': 'granted',
'analytics_storage': 'granted'
});
Related pages
-
Audience measurement without a consent banner
What the CNIL actually allows, and why GA4 doesn’t meet the exemption criteria in its standard configuration.
-
Conversions aren’t coming through
Consent refusal is one of the causes to check before questioning the setup itself.
-
Privacy policy
This site’s page describing what’s done with visitor data.
-
Cookie policy
The trackers this site places, and how to manage your choice.
-
ChatGPT Ads conversion tracking
OpenAI pixel, Conversions API, oppref and consent: the same pixel-plus-server logic, applied to ChatGPT ads.
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.