Performance Marketing
What is Google Consent Mode v2 and how do you set it up?

In short
Google Consent Mode v2 passes a visitor's cookie choices to Google tags so the tags behave accordingly. Version 2 requires two parameters, ad_user_data and ad_personalization, in addition to ad_storage and analytics_storage. Setting it up takes a consent banner, a default consent state on every page and an update when the visitor makes a choice.
Contents
- What is Google Consent Mode v2 and how do you set it up on an ecommerce site?
- What changed with Consent Mode v2?
- Does this apply outside Europe?
- What is the difference between basic and advanced Consent Mode?
- How do you set up Consent Mode v2 step by step?
- How do you verify the setup works?
- What changes in measurement after setup?
- What are common setup mistakes?
- Key takeaways
What is Google Consent Mode v2 and how do you set it up on an ecommerce site?
Google Consent Mode v2 is a mechanism that passes a visitor's cookie and data use choices to Google Analytics and Google Ads tags. The tags then write cookies or not, depending on that choice. Setting it up requires a consent banner (CMP), a default consent state on every page and a consent command that updates when the visitor chooses.
Consent Mode is not a consent banner and does not collect consent for you. Google's developer documentation is explicit: obtaining user consent is your responsibility; Consent Mode only communicates the decision to Google and makes the tags respect it.
What changed with Consent Mode v2?
Google updated Consent Mode in November 2023 and added two parameters. The consent types in use today are:
| Parameter | What it controls | New in v2? |
|---|---|---|
| ad_storage | Storage of advertising cookies | No |
| analytics_storage | Storage of analytics cookies | No |
| ad_user_data | Sending user data to Google for advertising | Yes |
| ad_personalization | Personalized advertising (remarketing) | Yes |
| functionality_storage, personalization_storage, security_storage | Site functionality, personalization and security | No |
Google states that Consent Mode users need to send these two new parameters in addition to ad_storage and analytics_storage. The update is part of Google strengthening enforcement of its EU user consent policy.
Does this apply outside Europe?
Google's EU user consent policy requires disclosures and consent for end users in the European Economic Area, the UK and Switzerland. A store that only sells domestically outside those regions does not trigger the policy directly. Two reasons still make Consent Mode necessary:
- International traffic: If you sell to or receive visitors from Europe, you cannot fully use Google's advertising features for those visitors without consent signals.
- Local privacy law: Many countries have their own cookie rules. In Turkey, for example, the Personal Data Protection Authority's (KVKK) cookie guide discusses when explicit consent is needed for processing personal data through cookies. When a visitor declines in your banner, Google tags must reflect it, and Consent Mode is the technical way to do that.
The KVKK guide cites, as an example of good practice, a cookie panel at entry that presents "accept", "reject" and "preferences" buttons equally in color, size and font. It stresses that cookies requiring explicit consent should be off by default, and states that consent for advertising cookies cannot be bundled into terms of use. Always get legal advice for your own situation.
What is the difference between basic and advanced Consent Mode?
Google defines two implementations:
| Attribute | Basic mode | Advanced mode |
|---|---|---|
| Tag loading | Blocked until the user interacts with the banner | Loads on page open, default usually denied |
| Data when denied | Nothing sent to Google, not even consent state | Cookieless pings (consent state and events) are sent |
| Conversion modeling | General model | Advertiser-specific, more detailed model |
| Setup effort | Simpler | More configuration |
According to Google, in advanced mode tags do not read or write cookies when consent is denied; instead they send cookieless measurement signals that enable conversion modeling in Google Ads and GA4. Which mode you choose depends on company policy and legal review. Advanced mode keeps more data for measurement, while basic mode sends nothing for users who decline.
How do you set up Consent Mode v2 step by step?
- Choose a consent management platform (CMP). Use a solution that works with your platform (Shopify, WooCommerce and so on) and can send Consent Mode v2 signals. If you build your own banner, you also need to add the code that passes consent state to Google.
- Set the default consent state. The default command must run on every page before the Google tag and any other commands. Google's documentation stresses that defaults will not work if the order is wrong.
- Use region-specific defaults. Google recommends scoping defaults to the regions where you show a consent banner. The region parameter sets defaults per region using ISO 3166-2 codes.
- Add a wait time if the banner loads slowly. The wait_for_update parameter gives tags a number of milliseconds for the CMP to send an update.
- Update based on the user's choice. When the user accepts or declines, update the relevant parameters to granted or denied. Send the update on the same page, before any page transition.
- Connect other tags. In Google Tag Manager, add consent requirements under Advanced > Consent Settings for tags without built-in consent checks. Make sure third-party tags such as the Meta pixel follow the same choice.
- Test. In preview mode, decline and accept in the banner and confirm the consent state changes correctly and advertising cookies are not written when declined.
A simple gtag example for the default state:
gtag('consent', 'default', {
'ad_storage': 'denied',
'ad_user_data': 'denied',
'ad_personalization': 'denied',
'analytics_storage': 'denied',
'wait_for_update': 500
});
When the user grants everything, the same parameters are updated to granted with gtag('consent', 'update', ...).
How do you verify the setup works?
Open Google Tag Manager preview mode (Tag Assistant) and visit the site in a private window. Check that on the first event, before the banner is answered, all advertising and analytics consent shows as denied, and that it switches to granted on events after you accept. Repeat the test by declining and confirm in your browser's developer tools that no advertising cookies are created. Finally, place a test order and note how the purchase event behaves in both scenarios.
What changes in measurement after setup?
When consent is denied, some data is inevitably lost. According to Google, when ad personalization is denied, personalized advertising features such as remarketing receive no data for that user. When ad_user_data is denied, hashed first-party data for enhanced conversions is not sent. In advanced mode, cookieless pings fill part of the gap through modeling.
In practice, observed conversion counts in GA4 and ad dashboards may shift after setup. Note a one-week baseline before going live so you can tell whether changes come from campaign performance or from the measurement change. It makes sense to pair Consent Mode with server-side tracking to reduce losses from browser restrictions, but server-side tracking must respect the user's consent choice too.
What are common setup mistakes?
- Running the default after the tag. If the order is wrong, the first page view can write cookies without consent.
- Sending only v1 parameters. Without ad_user_data and ad_personalization, the setup is not v2.
- Hiding the reject button. It goes against good practice guidance such as KVKK's and erodes user trust.
- Forgetting third-party tags. If Google tags respect consent but the Meta or TikTok pixel fires regardless, the setup is incomplete.
- Going live untested. Use the checks in our GA4 ecommerce tracking guide to confirm purchase events fire fully when consent is granted.
Key takeaways
- Consent Mode v2 passes the user's consent choice to Google tags; collecting consent is your job.
- Version 2 added the ad_user_data and ad_personalization parameters.
- Google's EU policy covers users in the EEA, UK and Switzerland; local cookie rules apply on top.
- Advanced mode enables more detailed modeling through cookieless pings; basic mode sends nothing for users who decline.
- The default command must run before everything else, and the setup must be tested.
If you want to check that your consent banner, Consent Mode and conversion tracking work together correctly, the Performetic team can review your measurement stack in a free growth analysis.
Frequently asked questions
Is Consent Mode v2 mandatory?
Google's EU user consent policy requires consent for users in the European Economic Area, the UK and Switzerland, and Consent Mode v2 is how you pass that consent to Google. If you do not serve those regions, the policy is not triggered directly, but you still need a way to make Google tags respect consent choices under local privacy law.
Is Consent Mode a cookie banner?
No. Consent Mode is a technical mechanism that passes the user's decision to Google tags. You need a separate consent banner or consent management platform (CMP) to collect consent. Google clearly states that obtaining user consent is the site owner's responsibility.
Should I choose basic or advanced mode?
Advanced mode sends cookieless pings when consent is denied, enabling advertiser-specific conversion modeling. Basic mode blocks tags completely until the user interacts with the banner and sends no data for users who decline. The choice depends on your legal review and company policy.
Why did my conversions drop after setting up Consent Mode?
For users who decline, advertising and analytics cookies are not written, so observed conversions can fall. In advanced mode modeling fills part of the gap. Compare data before and after setup; if the drop is larger than expected, check the order of the default command and that updates fire correctly.