Guide
29 September 2026

Consent Mode v2: the step-by-step GTM setup

Cookie consent through Consent Mode v2 is deployed by connecting a Google-certified CMP to Tag Manager. You then configure the four consent signals before your tags fire. In advanced mode, Google sends anonymized pings as soon as the page loads and models the conversions lost after a refusal. Basic mode recovers nothing. Real validation happens through GA4's Consent tab and Google Ads diagnostics, never through the GTM preview alone. Without this setup in the European Economic Area, Google stops feeding your remarketing audiences.

liste de données analytic GA4 pour suivre son site internet
Consent Mode v2 is a Google mechanism that passes each visitor's consent state to your tags (GA4, Ads) through four signals, so they can adjust their behavior and model lost conversions.

4

consent signals to pass from a certified CMPGoogle Developers (Consent Mode)

2

new parameters added by v2: ad_user_data and ad_personalizationGoogle Developers (Consent Mode)

TCF v2.2

IAB framework required for Google partner CMPs in the EEAIAB Europe

Σ

Key takeaways

  • Consent Mode v2 adds 2 signals (ad_user_data, ad_personalization) to the 2 existing ones: all 4 must be passed to keep your Ads audiences.
  • Without a working Consent Mode v2, Google stops feeding remarketing audiences and conversion modeling in the EEA.
  • 'Advanced' mode lets anonymized tags fire before refusal and can recover a significant share of lost conversions, versus 0 in 'basic' mode.
  • A CMP must be Google-certified (IAB TCF v2.2 partner) for conversion modeling to actually turn on.
  • Verification happens through GA4's Consent tab and the Google Ads diagnostic report, not just the GTM preview.

Contents

Consent Mode v2 adds two signals to the two existing ones. All four must travel from your banner to the Google tags, no exceptions. Otherwise your ad audiences stop being fed.

The first version handled analytics storage and ad storage. The second one grafts on two parameters tied to user data for advertising. analyticsstorage lets GA4 place its measurement cookies. adstorage allows the advertising cookie, the one that links an ad to a purchase. aduserdata tells Google whether it can use the visitor's data for advertising. ad_personalization tells it whether it can use that data for remarketing. These last two are the newcomers in v2. Their absence alone is enough to empty your lists.

The stakes are not theoretical. According to Google's official documentation on Consent Mode, without passing ad_user_data and ad_personalization, remarketing lists stop filling up in the EEA. An online retailer that used to re-target abandoned carts watches that audience drain within a few weeks. It all happens silently, with no alert in the interface. This shift is part of the wider move driven by the Digital Markets Act (DMA), the European regulation that governs large digital platforms. The European Commission sets out the scope of the DMA and aims to regulate how gatekeepers use data. This regulatory pressure is also pushing the market toward a cookieless web, where measurement increasingly relies on modeling.

What exactly is Google's Consent Mode?

It's a mechanism that adjusts how your tags behave based on the response to the cookie banner. If the visitor refuses, the tags do not place cookies. They can send an anonymous signal, without any identifier. Google uses it to estimate missing conversions through statistical modeling.

Basic or advanced: which mode should a small business choose?

Basic mode is not right for a site that invests in Google Ads. The gain in legal safety is marginal, because the advanced ping stays anonymous. In return, you lose all data on every refusal.

In basic mode, no tag loads until the visitor clicks "accept". Refusals go straight to the bin. In advanced mode, an anonymized ping fires as soon as the page loads, even before the banner response. That gives Google the material to model lost conversions. For a small business that lives on paid acquisition, advanced mode is almost always the right call.

A field example makes the difference tangible. An e-commerce small business, around 900 monthly conversions, was running in basic mode with a refusal rate near 40%. In plain terms, nearly 360 conversions a month were no longer tied to their campaigns after refusal. After switching to advanced mode, modeling reattributed a large share of those lost conversions back to the Ads campaigns. The account regained enough data to optimize its bids, where it had previously been flying blind on truncated numbers.

Basic or advanced: which mode should a small business choose?

Criterion Basic mode Advanced mode
Tags before response Blocked Loaded (anonymized)
Conversions after refusal No recovery Modeled
Setup complexity Low Medium
Recommended for Brochure site, low Ads traffic E-commerce, active remarketing

According to Statista, which tracks search engine market share, Google remains largely dominant in Europe. Neglecting its signals therefore means cutting off most of your measured visibility.

Prerequisites before touching GTM

Three building blocks must be in place before you open Tag Manager: a Google-certified CMP, GTM installed correctly, and GA4 linked to Google Ads. Skipping this check means spending an hour configuring a setup that will never activate.

The CMP (Consent Management Platform, the tool that displays and manages your cookie banner) is the critical point. It must appear among Google's certified partners and comply with the IAB Europe TCF v2.2 framework. Without certification, conversion modeling does not activate. That holds true even if your banner works visually.

Is cookie consent mandatory?

Yes, for any cookie that isn't strictly necessary for the site to function. The CNIL requires free, informed and unambiguous consent before any measurement or advertising tracker is placed. Refusing must be as easy as accepting. A banner without a "reject all" button at the first level is unlawful. Fines have already been handed down against major players.

Which CMP to choose, and why it must be Google-certified?

Choose a CMP from Google's list of certified partners, otherwise modeling stays off. Three solutions cover most small business needs: Axeptio (French, affordable pricing), Cookiebot (by Usercentrics, very widespread), OneTrust (robust, but oversized for a very small business).

Which CMP to choose, and why it must be certified…

CMPOriginGoogle-certifiedBest fit
AxeptioFranceYesFrench small businesses
CookiebotDenmarkYesSMBs, mid-size catalogs
OneTrustUnited StatesYesMulti-site organizations

Before finalizing your choice, check that the CMP actually writes the consent commands into the GTM data layer. This is the point that breaks most often, well before the tags are set up. If you're starting from scratch on the measurement ecosystem, it's better to first get to grips with GA4 step by step before adding the consent layer.

Step 1: enable the CMP and consent settings in GTM

First, enable the additional consent settings in your GTM container settings. Without this, your tags will never listen to the signals. It's a hidden switch, forgotten in most installs I open up.

Go to the GTM workspace, click Admin, then Container Settings. Tick the box Enable consent overview in tag settings. This adds a "Consent" tab to each of your tags. There you declare the signals it waits for before firing.

Then install your CMP. Certified CMPs offer a template in the GTM template gallery. Search for the name of your tool (Axeptio, Cookiebot) under Tag Templates, import it, then trigger it on Consent Initialization - All Pages. This special trigger loads before everything else.

Where do you enable the additional consent settings?

In the Consent tab of each Google tag (GA4, Google Ads). Open the tag, expand Advanced consent settings, and declare the required consents. A GA4 tag waits for analytics_storage. An Ads conversion tag waits for ad_storage, ad_user_data and ad_personalization. If you leave it on "No additional consent required", the tag ignores the refusal and fires anyway. This mistake is probably the most common one.

Step 2: configure default consent and its update

The default state must deny all storage before the visitor responds. Then an update command applies their actual choice. Order matters. The "default" fires first, when the page opens. The "update" follows as soon as the banner is clicked. Reversing that order produces data Google cannot use.

The consent default command sets all signals to "denied" as soon as the page loads. This is the setting that makes the install compliant: nothing leaves with an identifier before consent. When the visitor clicks "accept", the CMP sends consent update, which switches the accepted signals to "granted". Certified CMPs handle both commands automatically once the template is in place.

1st ping

A bad default setting, where a signal stays on "granted" before any response, sends an identifying cookie before consent. This is the most common and most punishable form of non-compliance, because it contradicts the obligation to collect consent beforehand.

CNIL

Take a seasonal online retailer with heavy volume in the last quarter. If its default is misconfigured and an Ads tag fires before the update, two problems arise. There's the legal risk. There's also the distorted data. Google receives conversions in an inconsistent consent state, which degrades the modeling. This kind of drift ties into the logic of a proper audit, like spotting the GA4 mistakes that distort data in small businesses.

Getting the configuration right comes down to a few things, but every detail counts. Here are the four settings to validate in this order, without skipping one:

  • consent default set to "denied" for all signals when the page loads
  • CMP template triggered on Consent Initialization - All Pages, before any other tag
  • consent update handled by the CMP when the banner is clicked
  • Each Google tag with its required signals declared in the Consent tab

The sequence looks simple on paper. In practice, it's the third point that goes wrong most often. The CMP sends the update, but the tag isn't listening. The Consent tab was left on "none required". The result: everything seems to work in the GTM preview, and nothing actually works on the modeling side.

How do you check that modeling really works?

The GTM preview proves nothing. The only reliable validation goes through GA4's Consent tab and Google Ads diagnostics. Seeing tags fire in Preview mode confirms the code runs, not that Google has turned on modeling.

In GA4, open Admin, then Data settings, then Data collection. The dedicated tab shows the transmission status of the signals. In Google Ads, the conversion tracking diagnostic flags whether Consent Mode is detected and active. These two dashboards are your only real proof. If I could only look at one indicator after an install, it would be the modeling status in Google Ads.

How do you check that modeling really works?

CheckpointWhat it validatesReliability
GTM previewCode firingPartial
GA4 Consent tabSignal transmissionHigh
Google Ads diagnosticModeling activeHigh
Network tags (DevTools)Anonymous ping sentTechnical

A cross-check between GA4 and Google Ads takes about thirty minutes by hand after every banner change. You can also run it continuously if you automate the monitoring of your conversion reporting. It's the kind of check people forget to redo three months later, when a developer touches the site theme. There's a quick browser-side test. Open the developer tools, Network tab, filter on google and reload the page without responding to the banner. You should see a ping go out with the parameter gcs=G100. This code (gcs stands for "Google consent status") means everything is denied by default. If you see gcs=G111 before any response, a signal is already granted and your default is misconfigured.

The mistakes that break your tracking (and how to avoid them)

Six mistakes come up again and again on Consent Mode v2 installs. They all share the same visible symptom. Conversions go missing, or audiences drain, with no alert in the interface. The first four take less than an hour to fix once spotted.

1

Basic mode enabled by default.

The CMP often sets it because it looks safer on the GDPR side, but it throws away all conversions after refusal. Switch to advanced if you invest in Ads.

2

CMP not Google-certified.

Without IAB TCF v2.2 certification, modeling never turns on, even with a perfect banner. Check the partner list before paying for a subscription.

3

Tags with no consent settings.

A Consent tab left on "none required" makes the tag fire despite the refusal. Declare the expected signals on each Google tag.

4

Misconfigured default.

A signal left on "granted" before any response sends an identifier without consent. Check gcs=G100 on the first ping.

The last two are more insidious. They don't show up in the GTM dashboard and generate no visible error. A reversed default/update order gives Google an inconsistent consent state. The certified CMP template handles that order automatically, so never code it by hand. Validation limited to the GTM preview alone creates false confidence. You think you're compliant while modeling is dormant. Always check in GA4 and Ads, not just in GTM.

These settings on the Google tags become all the more critical as the market slides toward a cookieless model. According to IAB Europe, in its work on how the ad market is evolving, the gradual disappearance of third-party identifiers increases the weight of modeling. In other words, clean consent data becomes your main measurement lever.

What are the 3 types of cookies to distinguish?

Three families structure any compliant banner. Strictly necessary cookies run the site (cart, session, security) and require no consent. Audience measurement cookies feed GA4 and require consent, except under the CNIL's strict exemption conditions. Advertising cookies power targeting and remarketing. They always require explicit consent. Consent Mode v2 ties the last two families to its signals, with the first one falling outside the scope. This distinction directly guides how you configure your CMP.

This tracking hygiene shapes every media buying decision. Without reliable conversion data, it's hard to judge whether Google Ads is profitable or not for your small business. The cost-per-acquisition calculation rests entirely on this reporting. Getting consent configured right also feeds into reading your website traffic statistics to track correctly. A high refusal rate mechanically underestimates your measured traffic.

Make your post-consent tracking reliable and monitored with Lysible

At this stage, your Consent Mode v2 is set up and validated once. The real risk begins afterward. A theme change, a CMP update, a developer touching GTM, and your signals drop without warning. Nobody reopens the GA4 Consent tab every week by hand.

Regular monitoring of the consent rate and conversion reporting catches the drift before it distorts weeks of data. That's exactly the check we've built into Lysible. A conversion that stays invisible for a quarter costs more than a monitoring subscription. The verification time, not the data itself, is the real cost center for an organization without a dedicated data analyst.

Want tracking that holds up over time? Lysible monitors your consent signals

You've set up Consent Mode v2, checked GA4 and the Ads diagnostic. What's left is the hard part: keeping the setup reliable after every theme or CMP update. Lysible tracks the consent rate and your conversion reporting, and alerts you the moment a signal drops. To manage your tags cleanly without code, a clear Google Tag Manager guide for business owners covers the basic logic.

Frequently asked questions

What's the difference between Consent Mode v1 and v2?

Version 2 adds two signals to the two existing ones. v1 handled analytics_storage (measurement) and ad_storage (advertising cookie). v2 adds ad_user_data, which authorizes using the visitor's data for advertising, and ad_personalization, which authorizes remarketing. These two new signals have been mandatory since March 2024 in the EEA. Without them, remarketing audiences stop filling up. The default/update logic and the basic/advanced modes stay identical between the two versions.

What happens if I don't implement Consent Mode v2?

Google stops feeding your remarketing audiences and cuts off conversion modeling in the EEA. Your targeting lists drain. Your re-engagement campaigns lose their fuel. You'll still see traffic in GA4, but the advertising side goes blind. For an online retailer that lives on remarketing, the impact is measured in missed revenue. The absence of Consent Mode v2 doesn't cause a sudden shutdown, but a silent erosion, harder to diagnose than an outright failure.

Do you need a certified CMP for Consent Mode v2?

Yes, if you want conversion modeling to actually turn on. A non-certified CMP can display a compliant banner and pass signals. But Google only engages advanced modeling with a certified partner that complies with the IAB TCF v2.2 framework. Axeptio, Cookiebot and OneTrust are among the certified solutions suited to small businesses. Check the official list before any subscription. Switching CMP later forces you to reconfigure all your GTM triggers.

Is advanced mode compatible with the GDPR?

Yes, as long as the ping sent before the response is genuinely anonymous, with no persistent identifier. In advanced mode, the tag loads as soon as the page opens but only sends an aggregated signal, with no cookie until consent is granted. The CNIL penalizes placing identifying trackers before consent, not sending an anonymous signal. The point to watch is the default setting: all signals must start on "denied". A misconfigured default makes the install non-compliant, regardless of the mode chosen.

How long does it take to install Consent Mode v2?

Plan for half a day for a clean install if your GTM and GA4 are already in place. Enabling the settings in GTM takes a few minutes. Setting up the CMP template and configuring the signals takes one to two hours. The longest part is verification. Modeling takes several days to appear in Google Ads, and the cross-check requires coming back to the account after that delay. So plan the install over a calendar week, even if the actual working time stays limited.

Consent Mode v2: the step-by-step GTM setup

Isaac SIKORSKI

With Lysible, I want to give businesses back control of their online presence. A website you actually understand is one that brings in real opportunities.