All posts
MeasurementStep-by-step

Consent Mode v2 in Google Tag Manager: Setup Steps

Set up consent mode v2 in Google Tag Manager: add a CMP template, set defaults for four consent types and regions, then verify in Tag Assistant.

October 2, 2026·7 min read·by Olexander Cheberko
Table of contentstap to expand

To set up consent mode v2 in Google Tag Manager, add your consent management platform's template tag on the Consent Initialization trigger, give all four consent types a default, scope denied defaults to the regions where you show a banner, and leave Google tags on their built-in consent checks. Then confirm in Tag Assistant that the defaults load before any tag and update after a banner click, from every region you set.

Decide before you tag

Check 1: How much of your traffic comes from the EEA?

WhereGA4AdminData collection and modificationConsent settings
Do: Select your web data stream.
You should see: The share of traffic and conversions from the EEA at the top, when Google shows it, then the consent signals for that stream (GA4 consent settings). Google's EU user consent policy covers end users in the EEA, the UK and Switzerland, and to keep using Google tags for measurement, ad personalization and remarketing on EEA traffic you must collect consent and send the signals to Google.
If not: No visitors from those regions? The policy does not name US visitors, and Google advises scoping denied defaults to the regions where you show a banner so measurement elsewhere is kept (check 5). Whether a US state law requires a banner on your site is a question for your lawyer; this manual does not answer it.

Check 2: Basic or advanced consent mode?

Do: Pick one with whoever owns your privacy policy; Google says to check your company's guidelines.
You should see: Advanced, unless that policy forbids loading any Google tag before consent. In advanced mode tags load with your defaults, send cookieless pings while consent is denied, and Google Ads models conversions with an advertiser-specific model. In basic mode nothing is sent until the visitor grants consent, not even the consent state, and modeling falls back to a general model.
If not: Use basic. Google's basic setup sets the defaults in the page head, loads the banner outside Tag Manager and loads the container only after the visitor grants consent, so the banner does not go in the container the way check 3 describes.

Set it up in Tag Manager

Check 3: Add your CMP's template on Consent Initialization

WhereGoogle Tag ManagerTagsNewTag Configuration
Do: Open the Community Template Gallery, search for your CMP's tag, click Add to workspace and fill the fields as your CMP documents them. Under Triggering, select Consent Initialization - All Pages (Google's steps).
You should see: The CMP tag on that trigger. It fires before all other tags, Initialization triggers included. The template should set your defaults on load and update consent when the visitor makes a choice.
If not: No banner yet? Open your Google tag's Admin tab and, under Google tag management, the Set up consent mode section, which walks you through an integrated CMP partner and can add the banner to your container. Keeping your own banner? Build a template on setDefaultConsentState and updateConsentState.
Careful: Do not call gtag('consent', ...) from a Custom HTML tag. gtag commands are queued and may not be processed before the next event, so Google says to set consent from a template tag.

Check 4: Set a default for all four consent types

Do: In the template's default settings, give each of ad_storage, ad_user_data, ad_personalization and analytics_storage a value.
You should see: All four set. ad_storage and analytics_storage cover advertising and analytics cookies, ad_personalization covers personalized ads, and ad_user_data covers sending user data to Google for advertising, which Google calls required for measurement such as enhanced conversions and tag-based conversion tracking. The last two are the v2 additions from November 2023.
If not: A template that offers only ad_storage and analytics_storage lacks the v2 types, and Google says the tag must load defaults for at least these four: update it. If you cannot use a template, Google's fallback is this default command above the container snippet, and the order is vital:
<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}
  gtag('consent', 'default', {
    'ad_storage': 'denied',
    'ad_user_data': 'denied',
    'ad_personalization': 'denied',
    'analytics_storage': 'denied'
  });
</script>

Check 5: Scope the defaults by region

Do: If your template has region controls, add a default row for your banner regions, written as ISO 3166-2 codes, and a row with the region left blank for everyone else.
You should see: The blank row applies to every visitor no region row covers, and the most specific region wins: with US granted and US-CA denied, a California visitor gets denied.
If not: One denied row for all regions makes every US visitor start as denied too. Google's best practices say applying denied only to the appropriate regions avoids losing precise measurement everywhere else.

Check 6: Leave Google tags on their built-in checks

WhereGoogle Tag ManagerTagsTag ConfigurationAdvanced SettingsConsent Settings
Do: Open each Google Analytics, Google Ads, Floodlight and Conversion Linker tag. To review every tag on one screen, go to Admin > Container Settings and, under Additional Settings, select Enable consent overview.
You should see: Built-In Consent Checks listed and Additional Consent Checks at Not set or No additional consent required.
If not: Reset Additional Consent Checks on Google tags and remove their consent-based exception triggers: Google says additional checks on these tags do not work properly, and a blocked tag sends nothing. Non-Google tags do not react to consent mode, so give them Require additional consent for tag to fire with the types they need.

Verify it

Check 7: Does the page set the defaults first?

WhereGoogle Tag ManagerWorkspacePreview
Do: Click Preview to open Tag Assistant, enter your site's URL, then on the site open the banner and accept all.
You should see: In the Summary, the earliest Consent event lists all four types under API Call. On the Consent tab, the On-page Default column reads Denied for a visitor in a denied region (Google: verify consent mode).
If not: An empty Consent tab means consent mode is not on the page. A default set too late means a tag fired first: put the consent tag on Consent Initialization - All Pages (troubleshooting). More on reading a session in checking conversion tags with Tag Assistant.

Check 8: Does a banner click update consent?

WhereGoogle Tag ManagerWorkspacePreview
Do: In the Summary, select the most recent Consent event.
You should see: All four types updated under API Call and On-page Update at Granted. On the Tags tab, each tag behaved as its consent settings say.
If not: The template sets defaults but sends no update. Check your CMP's docs; a visitor must be able to update each type to both granted and denied.

Check 9: Does each region get its own default?

WhereGoogle Tag ManagerWorkspacePreview
Do: Repeat checks 7 and 8 with your browser's simulated location set to each region you set a row for, as Google's verification steps say to do for region-specific defaults.
You should see: On-page Default matches that region's row.
If not: Check the region codes in the template, and remember that the more specific region wins.
Careful: A check run from inside the EU sees the EU defaults and tells you nothing about US visitors. Verify the region defaults from a US location too.

Check 10: Does Google Ads report consent mode?

WhereGoogle AdsGoalsConversionsSummary
Do: Click a Google Ads website conversion action and open the Diagnostics tab.
You should see: Consent mode is implemented or Consent mode is implemented and modeling is active (consent mode status).
If not: If checks 7 to 9 pass, the gap is Google's delay: the status can take 48 hours, up to 2 weeks in some cases. Modeling also needs 700 ad clicks over 7 days for a domain and country grouping, so a small account can stay at the first status.

Consent mode controls what Google tags store and send: when visitors decline, tags send cookieless pings and Google fills the gaps with modeling. How I measure conversions when most visitors reject tracking is in measuring conversions under consent. If you want the banner, the defaults and these checks set up and verified on your site, that is my consent-safe measurement work.

Tags

consent-mode-v2-google-tag-managergoogle-consent-mode-v2-setupconsent-modegoogle-tag-managertag-assistantconsent-management-platform

Frequently asked questions

Do I need consent mode v2 if all my traffic is from the US?

Google's EU user consent policy covers end users in the European Economic Area, the UK and Switzerland, and Google's consent mode requirements for measurement and ad personalization are written for EEA traffic. Google advises scoping denied defaults to the regions where you show a banner, so measurement is not lost where no banner applies. Whether a US state law requires a banner on your site is a question for your lawyer.

What changed from consent mode v1 to v2?

Google added two parameters in November 2023: ad_user_data, consent for sending user data to Google for advertising, and ad_personalization, consent for personalized ads. They sit next to ad_storage and analytics_storage, and Google's Tag Assistant verification steps check that all four are set.

Does advanced consent mode send data before the visitor clicks accept?

Yes. Google tags load with your defaults and, while consent is denied, send cookieless pings that can include the consent state, a timestamp, the user agent, the referrer, whether the URL carried ad-click information and a random number. Basic mode sends nothing, not even the consent state, until the visitor grants consent.

How long until Google Ads shows consent mode as active?

Google says the status can take 48 hours and in some cases up to 2 weeks. "Consent mode is implemented and modeling is active" also needs 700 ad clicks over 7 days for a domain and country grouping, so a small account can stay at "Consent mode is implemented".

Related posts