What is Google Consent Mode?
Google Consent Mode is an API that allows your website to communicate user consent choices to Google services in real time. Rather than treating consent as a binary switch where Google either gets full tracking access or no access at all, Consent Mode creates a middle ground. It lets you tell Google exactly what each visitor has agreed to, and Google adjusts its behavior accordingly.
When a visitor lands on your website and your consent banner appears, Consent Mode sets a default state for all consent parameters — typically “denied” for everything until the user makes a choice. If the user accepts cookies, Consent Mode sends an update command to Google that switches the relevant parameters to “granted.” Google tags then operate normally, setting cookies, collecting analytics data, and tracking conversions just as they always have.
The real value of Consent Mode emerges when a user declines cookies. Without Consent Mode, declining cookies means Google receives zero data from that visitor. No analytics hit, no conversion event, no remarketing signal — nothing. With Consent Mode enabled, Google tags can still send cookieless pings to Google’s servers. These pings do not contain personally identifiable information and do not set cookies on the user’s device, but they do transmit basic information such as the timestamp of the page visit, the user agent, and whether a conversion event occurred. Google then uses machine learning models to estimate the full picture from this partial data, a process known as behavioral modeling or conversion modeling.
Google first introduced Consent Mode in September 2020 as a beta feature. The original version included two consent parameters: ad_storage and analytics_storage. In November 2023, Google announced Consent Mode v2, which added two new parameters: ad_user_data and ad_personalization. These additional signals were introduced to align with the European Union’s Digital Markets Act (DMA) and to give users more granular control over how their data is used for advertising purposes. Google made Consent Mode v2 mandatory for all advertisers serving ads to users in the EU and EEA starting in March 2024.
It is important to understand what Consent Mode is not. It is not a consent banner. It is not a cookie scanner. It does not collect consent from users or display any user-facing interface. Consent Mode is a behind-the-scenes integration layer that sits between your consent management platform (the banner your visitors see) and Google’s tracking tags. Your consent banner makes the decision about what the user has agreed to; Consent Mode communicates that decision to Google.
Why Google Consent Mode v2 Matters
The importance of Google Consent Mode v2 comes down to three things: regulatory compliance, data recovery, and continued access to Google’s advertising features.
Regulatory compliance
Google requires Consent Mode v2 for any business using Google Ads, Google Analytics 4, or Google Tag Manager that targets users in the European Union or the European Economic Area. This is not a recommendation or a best practice — it is a requirement. Google introduced this mandate in response to the EU’s Digital Markets Act, which designates Google as a “gatekeeper” platform and imposes specific obligations around user consent and data handling. If you run Google Ads campaigns targeting EU users and you have not implemented Consent Mode v2, Google may restrict your ability to measure conversions, build remarketing audiences, and use certain targeting features.
Data recovery
The average consent rate across European websites hovers between 40% and 70%, depending on the industry, the design of the consent banner, and the country. That means anywhere from 30% to 60% of your visitors are declining cookies. Without Consent Mode, every single one of those visitors becomes invisible to your analytics and advertising platforms. You cannot see what pages they visited, whether they completed a purchase, or how they found your site.
With Consent Mode v2 enabled in Advanced mode, Google’s behavioral modeling can recover an estimated 30% to 50% of otherwise lost conversion data. Google achieves this by analyzing the cookieless pings from non-consenting users alongside the full data from consenting users. The model identifies patterns — such as the correlation between specific traffic sources and conversion rates — and uses those patterns to estimate what the non-consenting users likely did. The result is modeled conversion data that appears in your Google Ads and GA4 reports, clearly labeled as modeled rather than observed.
For an e-commerce business spending $10,000 per month on Google Ads, losing 50% of conversion data means your reported return on ad spend (ROAS) is significantly understated. Your campaigns may actually be performing well, but your reports show otherwise because half of the conversions are invisible. This leads to poor optimization decisions: you might pause high-performing campaigns or reduce budgets on keywords that are actually driving revenue. Consent Mode helps close this gap by recovering a meaningful portion of that missing data.
Continued access to Google features
Without Consent Mode v2, Google has begun limiting access to several key features for EU-targeted campaigns. These include audience building for remarketing lists, enhanced conversions, and certain Smart Bidding strategies that rely on conversion data. Over time, Google has signaled that Consent Mode compliance will become increasingly important for accessing the full suite of advertising tools. Implementing it now ensures you are not caught off guard by future restrictions.
The bottom line: If you advertise to EU users through any Google platform, Consent Mode v2 is no longer optional. Without it, you lose conversion data, face advertising restrictions, and risk falling behind competitors who have already implemented it.
Basic vs Advanced Mode
Google Consent Mode v2 can operate in two distinct modes: Basic and Advanced. Both modes communicate consent signals to Google, but they differ significantly in how much data you recover from users who decline cookies. Understanding the difference is critical for making the right implementation choice for your business.
Basic mode
In Basic mode, no Google tags fire at all until the user grants consent. When a visitor arrives on your site, the default consent state is set to “denied” for all parameters. The Google Analytics tag, the Google Ads tag, and any other Google tags are completely blocked from executing. They do not load, they do not send pings, and they do not set cookies. If the user then clicks “Accept” on your consent banner, the consent state updates to “granted,” the tags fire, and tracking proceeds normally for the remainder of the session.
The advantage of Basic mode is simplicity. No Google code runs before consent, which makes it the most conservative approach from a privacy perspective. Some Data Protection Authorities (DPAs) and legal advisors prefer this approach because it eliminates any possibility of data collection before consent is given. The disadvantage is equally clear: you receive absolutely zero data from users who decline cookies. No cookieless pings, no modeled data, no conversion estimates. Those visitors simply do not exist in your reports.
Advanced mode
In Advanced mode, Google tags load on every page visit, even before consent is granted. However, when the consent state is “denied,” these tags operate in a restricted fashion. They do not set cookies, they do not read cookies, and they do not collect personally identifiable information. Instead, they send cookieless pings to Google’s servers. These pings include limited information: the page URL, a timestamp, the user agent string, and whether a conversion event (such as a purchase) occurred. Crucially, they do not include any client-side identifiers that could be used to track the user across sessions.
When a user grants consent, the tags switch to full operation — setting cookies, collecting detailed analytics data, and tracking conversions with complete fidelity. When a user denies consent, the tags continue sending cookieless pings for the duration of the session. Google then uses these pings, combined with observed data from consenting users, to build behavioral models that estimate the conversion behavior of non-consenting users.
Advanced mode is the approach Google recommends for most businesses, and it is the mode that enables the 30–50% recovery of lost conversion data through modeling. The trade-off is that some code does execute before consent, which requires careful consideration of your legal obligations and the guidance from your relevant Data Protection Authority.
| Aspect | Basic Mode | Advanced Mode |
|---|---|---|
| Tags before consent | ✗ No tags load | ✓ Tags load in restricted mode |
| Cookieless pings | ✗ None sent | ✓ Sent without identifiers |
| Data from non-consenters | Zero — completely invisible | Modeled conversions via machine learning |
| Conversion recovery | 0% of declined users | Estimated 30–50% via modeling |
| Privacy posture | Most conservative | Privacy-respecting with cookieless pings |
| Google recommendation | Acceptable | Recommended for most businesses |
| Setup complexity | Simpler | Slightly more involved |
For most businesses, Advanced mode is the right choice. It respects user consent while recovering meaningful data that would otherwise be lost entirely. However, if your legal team or DPA requires that no Google code executes before consent, Basic mode satisfies that requirement while still communicating consent signals to Google when users do accept.
The Four Consent Parameters
Google Consent Mode v2 uses four consent parameters to control how Google services behave based on user consent. Each parameter corresponds to a specific category of data processing, and each can be independently set to either granted or denied. Understanding these parameters is essential for configuring Consent Mode correctly.
Advertising Cookies
ad_storage
Controls whether advertising cookies can be read and written on the user’s device. When set to granted, Google Ads and other advertising tags can set cookies for conversion tracking, remarketing audience building, and ad frequency capping. When set to denied, no advertising cookies are set, and existing advertising cookies are not read. This is the primary parameter that governs whether Google can track a user for advertising purposes across sessions.
Analytics Cookies
analytics_storage
Controls whether analytics cookies can be read and written on the user’s device. When set to granted, Google Analytics 4 can set its _ga and _ga_* cookies to identify unique users, track sessions, and measure engagement metrics across visits. When set to denied, GA4 operates without cookies. In Advanced mode, it still sends cookieless pings with basic page and event data, but it cannot identify returning visitors or track multi-session journeys.
Advertising User Data
ad_user_data
Controls whether user data can be sent to Google for advertising purposes. This parameter was introduced in Consent Mode v2 and is distinct from ad_storage. While ad_storage controls cookies on the device, ad_user_data controls whether data such as email addresses (used for enhanced conversions and Customer Match) can be transmitted to Google’s advertising platform. This parameter is required for compliance with the EU’s Digital Markets Act.
Ad Personalization
ad_personalization
Controls whether personalized advertising is allowed for the user. When set to granted, Google can use the user’s data to show them personalized ads, including remarketing ads based on their browsing behavior. When set to denied, the user is excluded from remarketing audiences and personalized ad targeting. They may still see ads, but those ads will not be tailored to their browsing history or interests. This parameter also affects dynamic remarketing and similar audience features.
In practice, most consent banners map their cookie categories to these four parameters. A typical mapping looks like this: when a user accepts “Marketing” or “Advertising” cookies, the parameters ad_storage, ad_user_data, and ad_personalization are all set to granted. When a user accepts “Analytics” or “Statistics” cookies, analytics_storage is set to granted. When a user declines a category, the corresponding parameters remain denied.
Here is what the default consent state looks like in code. This snippet should execute before any Google tags load, typically as the very first script in your page’s <head> section:
After the user interacts with the consent banner, your consent management platform sends an update command. The update only changes the parameters that the user has granted:
If the user only accepts analytics cookies but declines advertising, the update would set analytics_storage to granted while leaving the three advertising-related parameters as denied. This granularity is what makes Consent Mode v2 more nuanced than the original version — it allows for partial consent that accurately reflects what the user has actually agreed to.
Implementation with FixGDPR
If you are using FixGDPR as your consent management platform, the good news is that Google Consent Mode v2 is handled automatically. FixGDPR’s consent banner has built-in integration with Google’s consent API, which means you do not need to write any custom JavaScript or manually configure the gtag consent commands described above. The banner handles the entire lifecycle — from setting the default denied state to sending the update command when the user makes their choice.
Here is what happens behind the scenes when you use FixGDPR with Google Consent Mode v2:
- Default denied state set automatically. When the FixGDPR consent banner script loads, it immediately calls
gtag('consent', 'default', ...)with all four parameters set todenied. This happens before any Google tags fire, ensuring compliance from the very first millisecond of the page load. - Consent update sent on user action. When a visitor clicks “Accept All,” “Reject All,” or saves their individual preferences, FixGDPR sends the corresponding
gtag('consent', 'update', ...)command with the correct parameter values based on the categories the user has granted. - Works with GA4 out of the box. Google Analytics 4 automatically respects Consent Mode signals. When FixGDPR sends the consent state, GA4 adjusts its cookie behavior and data collection accordingly. No additional GA4 configuration is needed.
- Works with Google Ads out of the box. Google Ads conversion tracking and remarketing tags also respond to Consent Mode signals. Conversion events are recorded as modeled conversions when consent is denied, preserving your ability to optimize campaigns.
- Works with Google Tag Manager. If you use GTM to manage your tags, FixGDPR’s consent signals are available as built-in consent types within GTM’s consent configuration. Tags configured to require specific consent types will automatically fire or stay blocked based on the signals FixGDPR sends.
- No manual JavaScript coding needed. The entire integration is handled by the single FixGDPR script you already have on your site. There is no need to add additional code snippets, edit your Google tag configuration, or modify your GTM container.
Setup in practice: If you already have the FixGDPR consent banner installed on your site, Google Consent Mode v2 is already active. You can verify this using the steps in the next section. If you are new to FixGDPR, the consent banner script is a single line of JavaScript that you add to your site’s <head> tag. The Consent Mode integration is enabled by default — no dashboard toggle required.
FixGDPR supports both Basic and Advanced mode for Google Consent Mode v2. The mode is configurable from your FixGDPR dashboard under your site’s consent banner settings. Advanced mode is enabled by default because it provides the best balance of privacy compliance and data recovery. If your legal requirements demand that no Google tags execute before consent, you can switch to Basic mode with a single toggle in the dashboard. In Basic mode, FixGDPR prevents all Google tags from loading until the user grants consent, and then sends the appropriate consent signals once they do.
How to Verify Your Consent Mode Setup
Once Consent Mode v2 is in place — whether through FixGDPR or another consent management platform — you should verify that it is working correctly. An improperly configured Consent Mode setup can be worse than no setup at all, because it might give you false confidence that your data is being captured when it actually is not. Here are four methods to confirm everything is functioning as expected.
- Use Google Tag Assistant. Google Tag Assistant is a Chrome extension and a web-based debugging tool that shows you exactly what Google tags are firing on your page and what consent state they are receiving. Navigate to tagassistant.google.com, connect your website, and load a page. In the Tag Assistant interface, look for the “Consent” tab. You should see the default consent state (all parameters denied) on the initial page load, and then an updated consent state after you interact with the consent banner. If the consent state does not change after you click “Accept,” there is a problem with the integration between your consent banner and Google’s consent API.
- Check the consent state in browser DevTools. Open your browser’s Developer Tools (F12 or right-click and “Inspect”), go to the Console tab, and type
dataLayerfollowed by Enter. This will display the contents of Google’s data layer, which is the JavaScript array that stores all tag-related events. Look for entries with the event typeconsent. You should see aconsent defaultentry with all four parameters set todenied, and after granting consent, aconsent updateentry with the appropriate parameters changed togranted. You can also filter the data layer entries by typingdataLayer.filter(e => e[0] === 'consent')to see only consent-related events. - Verify in GA4 consent reports. In your Google Analytics 4 property, navigate to Admin > Data Collection and Modification > Data Streams, select your web stream, and check the “Consent settings” section. GA4 will indicate whether it is receiving consent signals and whether behavioral modeling is active for your property. Additionally, in your GA4 reports, look for the “Consent overview” card, which shows the percentage of traffic with consent granted vs. denied. If this card shows 100% granted or is not visible at all, Consent Mode may not be configured correctly.
- Check Google Ads conversion modeling. In your Google Ads account, navigate to Tools & Settings > Conversions. Click on a specific conversion action and look for the “Modeled conversions” column. If Consent Mode is working correctly in Advanced mode, you should see modeled conversion data appearing alongside your observed conversions. Google requires a minimum volume of traffic and conversions before modeling kicks in (typically at least 100 conversions per month and a minimum consent rate threshold), so new or low-traffic sites may need to wait before modeled data appears. The presence of any modeled data, even a small amount, confirms that Consent Mode is communicating successfully with Google Ads.
If any of these checks reveal issues, the most common causes are: the consent default command executing after Google tags instead of before them, the consent update command not firing when the user interacts with the banner, or a mismatch between the consent categories in your banner and the four Google consent parameters. FixGDPR handles all of these automatically, but if you are using a custom implementation, double-check the execution order and the parameter mapping.
Frequently Asked Questions
Is Google Consent Mode v2 required?
Yes, for any business using Google Ads, Google Analytics 4, or Google Tag Manager that targets users in the European Union or the European Economic Area. Google made this a requirement in March 2024 in response to the EU’s Digital Markets Act. Without Consent Mode v2, you may lose access to conversion measurement, audience building, and certain bidding strategies for EU-targeted campaigns. If you only target users outside the EU and EEA, Consent Mode is not currently required, but implementing it is still recommended as a forward-looking privacy practice.
Does Consent Mode replace a cookie banner?
No. Google Consent Mode is not a user-facing tool and does not replace your cookie consent banner. It is an integration layer that communicates the consent decisions your banner collects to Google’s services. You still need a consent management platform — such as FixGDPR — to display a cookie banner, collect user consent, and store consent records. Consent Mode sits between your banner and Google’s tags, translating human consent choices into technical signals that Google’s code can understand and respect.
Will I lose data without Consent Mode?
Yes. Without Consent Mode, you will lose all conversion data, analytics data, and remarketing signals from EU users who decline cookies. Depending on your consent rate and the proportion of your traffic from EU countries, this can represent 30% to 60% of your total conversions. Your Google Ads ROAS will appear lower than it actually is, and your GA4 reports will undercount users, sessions, and engagement. Consent Mode’s behavioral modeling cannot recover 100% of this lost data, but it can typically recover 30–50%, which is a significant improvement over zero.
Does FixGDPR support both Basic and Advanced mode?
Yes. FixGDPR supports both Basic and Advanced mode for Google Consent Mode v2, and the choice is configurable in your FixGDPR dashboard. Advanced mode is enabled by default because it provides the best data recovery while still respecting user consent. If your legal counsel or Data Protection Authority requires that no Google code execute before consent is granted, you can switch to Basic mode with a single toggle. Both modes correctly implement all four v2 consent parameters and send the appropriate default and update commands.
How long does it take for modeled conversions to appear?
Google requires a minimum volume of data before behavioral modeling activates. For Google Ads, you typically need at least 100 observed conversions in a 30-day period and a sufficient volume of cookieless pings from non-consenting users. For GA4, behavioral modeling requires at least 1,000 daily events with consent granted and 1,000 daily events with consent denied over a sustained period. Once these thresholds are met, modeled data usually begins appearing within a few days. Lower-traffic sites may need to wait longer or may not reach the modeling threshold at all, in which case only observed data will appear in reports.