Short answer
Google Consent Mode v2 is a tagging API that passes a visitor's cookie choice to Google Ads, GA4 and other Google tags using four signals: ad_storage, analytics_storage, ad_user_data and ad_personalization. Google requires these signals for traffic from the EEA to keep using measurement and ad personalization. Consent Mode does not make you GDPR-compliant by itself; your banner and consent records still have to meet the law.
Key takeaways
- Consent Mode v2 adds ad_user_data and ad_personalization to the original ad_storage and analytics_storage signals.
- Google's EU user consent policy covers end users in the EEA, the UK and Switzerland; for EEA traffic, consent choices must be passed to Google.
- Basic mode sends nothing to Google when a visitor declines; advanced mode sends cookieless pings that enable an advertiser-specific conversion model.
- Google Ads conversion modeling needs 700 ad clicks over 7 days per country and domain grouping; GA4 behavioral modeling needs 1,000 denied events and 1,000 consented users a day.
- Your real loss is usually smaller than your reject rate, because Google says consented users are typically 2-5x more likely to convert.
Contents
What is Consent Mode v2 and what changed from v1?
Consent Mode v2 is the way your cookie banner tells Google tags what a visitor agreed to. Version 2 added two signals, ad_user_data and ad_personalization, on top of the original ad_storage and analytics_storage.
It helps to separate the two pieces. Your banner, usually a consent management platform (CMP), collects the choice. Consent Mode translates that choice into instructions Google Ads, GA4 and Floodlight tags understand. A banner without Consent Mode leaves Google guessing; Consent Mode without a proper banner has nothing legitimate to pass on.
| Signal | What it controls | If denied |
|---|---|---|
ad_storage | Advertising cookies and similar storage | No ad cookies are written, so click IDs are not stored in cookies |
analytics_storage | Analytics cookies, such as visit duration | GA4 runs without cookies (advanced mode) or not at all (basic mode) |
ad_user_data | Sending user data to Google for advertising | User-provided data features, such as enhanced conversions, are restricted |
ad_personalization | Personalized ads, including remarketing | The visitor is not added to remarketing audiences |
The two v2 signals matter more than their names suggest. ad_user_data decides whether the data that feeds your Smart Bidding can be used for advertising at all, and ad_personalization decides whether your remarketing lists keep growing. A CMP that still sends only the two v1 signals leaves both effectively unset.
Is Consent Mode v2 mandatory for GDPR and UK traffic?
For visitors in the European Economic Area, yes in practice: Google says you need to pass end-user consent choices to Google to keep using its measurement and ad personalization features. Google's EU user consent policy itself applies to end users in the EEA, the UK and Switzerland.
There are two different layers here, and mixing them up causes most of the confusion:
- Google's contract. Under its EU user consent policy, you must get valid consent for cookies where legally required and for using personal data to personalize ads, keep records of that consent, and tell users how to withdraw it. Consent Mode v2 is how Google expects EEA consent to reach its tags.
- The law. In the EU, the ePrivacy rules and GDPR govern cookies and personal data; in the UK, it is PECR and UK GDPR. Consent Mode is not a legal basis. It only carries the decision your banner already collected.
The UK has one 2025 wrinkle worth knowing. Following the Data (Use and Access) Act 2025, the ICO's guidance describes a "statistical purposes" exception: storage used solely to collect statistics about how your service is used, with a view to improving it, can run without consent if you give clear information and a simple, free way to object. The ICO is explicit that the exception does not cover online advertising, and it does not cover sharing data with a third party for that party's own purposes. Your Google Ads tags still need consent; whether a particular analytics setup fits the exception is a question for your privacy counsel.
If you sell only in the US, Google's EEA requirement does not apply to that traffic, but several US state privacy laws give opt-out rights for targeted advertising. Many stores simply set region-specific defaults: denied for EEA, UK and Swiss visitors, and a different default elsewhere, which Consent Mode supports natively.
Basic vs advanced Consent Mode: which should you choose?
In basic mode, Google tags stay blocked until the visitor makes a choice, and nothing reaches Google if they decline. In advanced mode, tags load immediately with consent set to denied and send cookieless pings until consent is granted.
Basic mode
- Google tags do not load before the banner interaction.
- If the visitor declines, no data is sent to Google.
- Conversion modeling relies on a general model.
- Simpler to implement and to explain to a legal team.
- The blind spot grows with your reject rate.
Advanced mode
- Tags load on page open, with defaults set to
denied. - Declined visits still send cookieless pings.
- Pings carry a timestamp, user agent, referrer, the consent state, a random per-page number and whether an ad-click parameter was in the URL.
- Enables an advertiser-specific conversion model, which Google says is more accurate.
- Needs its own legal assessment in your markets.
A workable decision rule: if your counsel is not comfortable with pings firing before consent, start with basic mode, measure the gap and close part of it with better consent rates and enhanced conversions. If counsel signs off, advanced mode surfaces more conversions, especially on accounts with enough click volume to qualify for modeling. GA4 behavioral modeling is only available with the advanced implementation.
How many conversions do you lose without consent?
In basic mode without modeling, every purchase by a visitor who declined is missing from Google Ads and GA4. The share of lost revenue is usually lower than your reject rate, because Google notes that consented users are typically 2-5x more likely to convert.
Here is a hypothetical store to make that concrete. It buys 20,000 ad clicks a month at $0.80 each ($16,000 spend), has an $80 average order value and a 60% consent rate. Assume consented visitors convert at 2.5% and declined visitors at 1%, a 2.5x gap within Google's range:
- Real orders 12,000 consented clicks × 2.5% = 300, plus 8,000 declined clicks × 1% = 80, for 380 orders and $30,400 revenue.
- Measured orders (basic mode) Only the 300 consented orders, worth $24,000.
- Invisible share 80 of 380 orders, about 21% of revenue, even though 40% of visitors declined.
- Effect on bidding Reported ROAS is 1.5 instead of the real 1.9, so a target ROAS strategy learns from understated data and may throttle campaigns that are actually profitable.
Your numbers will differ, so measure them. Compare the acceptance rate in your CMP report with the gap between orders in Shopify (or your store backend) and conversions in Google Ads for the same period. Not all of that gap is consent: attribution windows, time zones and duplicate tags also play a part, which we unpack in why Shopify, Meta and GA4 numbers don't match. When you recalculate targets, the ROAS guide shows how to work from store revenue rather than platform-reported revenue.
What thresholds does conversion modeling need?
Google Ads needs 700 ad clicks over a 7-day period, per country and domain grouping, before consent mode conversion modeling kicks in. GA4 behavioral modeling needs at least 1,000 events a day with analytics_storage denied and 1,000 daily consented users.
Modeled conversions in Google Ads do not get their own column. They appear in the Conversions column and in every report that uses it. Google adds that modeling is most accurate when cookieless pings fire, which is the main measurement argument for advanced mode.
Watch the "per country" part. The example store gets roughly 4,600 clicks a week, comfortably over 700 if it sells in one country. Split the same traffic across the UK, Germany, France and the Netherlands and some markets can fall below the line. In GA4, hitting the thresholds is not a guarantee either: Google also weighs factors such as the ratio of new to returning users, and you only see modeled data with the Blended reporting identity selected.
Do enhanced conversions and server-side tagging fix consent loss?
No. Both improve the quality of the data you are allowed to collect, but neither makes it lawful to measure a visitor who declined. Consent signals must be respected in the server container too.
Enhanced conversions hash first-party data from the checkout, such as email address or phone number, with SHA256 before sending it to Google, so a conversion can be tied back to an ad click even when the cookie is missing. Because this is user data sent for advertising, it depends on ad_user_data being granted. Its real value is on consented visitors whose cookies were lost to browser limits or cleared storage. Make sure the purchase event and the customer fields in your data layer are clean first; the GA4 ecommerce setup guide has a checklist.
Server-side tagging routes browser hits to a container you control before they go to Google, Meta or TikTok. Google's documentation stresses that only you have access to that data until you forward it, and recommends running the container on your own first-party domain, with Cloud Run as the recommended hosting. Practical benefits:
- Less third-party JavaScript in the browser, which can help page speed.
- You can strip or hash fields such as IP address or email before forwarding them.
- A first-party domain is less affected by ad blockers and browser restrictions.
- The same container can feed server-to-server integrations such as the Meta Conversions API.
Server containers cost money to host and need maintenance, so a small store is usually better off getting Consent Mode and enhanced conversions right first. If you are also sending Meta events from a server, the Meta Conversions API setup guide covers how to keep those events consistent with the browser pixel.
How do you check that Consent Mode v2 is working?
Check three places: Tag Assistant for the default and updated consent states, the Consent settings page in GA4 Admin, and the Diagnostics tab of your Google Ads conversion actions. If all three agree, your setup is probably correct.
- Check the default Load the page in Tag Assistant without touching the banner and confirm all four signals start as
deniedfor EEA and UK visitors. - Test accept Click Accept and confirm the signals update to
grantedand GA4 and Google Ads tags fire with full data. - Test reject In a fresh private window, click Reject. In basic mode no Google requests should appear; in advanced mode only cookieless pings should.
- Check GA4 Go to Admin > Data collection and modification > Consent settings and confirm the advertising and behavior analytics consent signals show as active.
- Check Google Ads Go to Goals > Conversions > Summary, open a conversion action and review its consent mode status in the Diagnostics tab.
Common mistakes: the banner script loads after the Google tag, so the default command arrives too late (it has to run before any Google tag fires); the CMP still sends only the two v1 signals; the Reject button is hidden in a second layer; and a different banner, or none, runs on the cart or checkout. If your CMP loads asynchronously, the wait_for_update parameter lets tags wait briefly for the choice. Menu labels here are as of September 2026 and Google does rename things, so trust the signal values over the screen names.
What should you do next?
- Run Tag Assistant on your home, product and checkout pages and confirm all four v2 signals are sent, with
deniedas the EEA and UK default. - If you use a CMP, confirm it is on Google's certified list and that its Consent Mode v2 integration is switched on.
- Ask your privacy counsel to decide between basic and advanced mode, and to review banner wording and consent records.
- Record your last 30 days' consent rate and the gap between store orders and Google Ads conversions; that is your baseline.
- Turn on enhanced conversions and recheck the Diagnostics tab after 7 days.
- Revisit ROAS and CPA targets with the measurement gap in mind; the ad performance KPI guide explains which metrics to trust most.
To see store orders next to what Google Ads, Meta and GA4 report after consent loss, Marpany's conversion analysis screen puts them side by side in one table.
Frequently asked questions
Is Consent Mode v2 mandatory?
For traffic from the European Economic Area, Google says you need to pass end-user consent choices to Google to keep using its measurement and ad personalization features, and Consent Mode v2 is how you do that. Google's EU user consent policy also covers the UK and Switzerland. Outside those regions it is optional, though many stores use it everywhere with region-specific defaults.
Does Consent Mode v2 make my website GDPR compliant?
No. Consent Mode only passes the visitor's choice to Google tags. Your banner design, privacy notice, consent records and the legal basis for each cookie still have to meet GDPR, the ePrivacy rules or UK PECR, so have a privacy professional review them.
What is the difference between basic and advanced Consent Mode?
In basic mode Google tags are blocked until the visitor makes a choice, and nothing is sent to Google if they decline. In advanced mode tags load straight away with consent denied and send cookieless pings, which allows an advertiser-specific conversion model and GA4 behavioral modeling.
What happens if I don't implement Consent Mode v2?
For EEA traffic, Google treats consent signals as the condition for using its measurement and ad personalization features, so remarketing lists and conversion data from those visitors can shrink. You also lose conversion modeling, which is what fills part of the gap left by visitors who decline cookies.
Where do modeled conversions show up in Google Ads?
They are included in the regular Conversions column and every report that uses it, not in a separate column. To qualify, an account needs 700 ad clicks over 7 days per country and domain grouping.
Does server-side tagging remove the need for cookie consent?
No. Server-side tagging gives you more control over what data is forwarded and to whom, but it does not make processing lawful without consent. Consent Mode signals should be respected in the server container as well.
Sources
- Google Ads Help: About consent mode (basic and advanced implementation) support.google.com
- Google Tag Manager Help: Updates to consent mode for traffic in the European Economic Area support.google.com
- Google Ads Help: About consent mode conversion modeling support.google.com
- Google Analytics Help: Behavioral modeling for consent mode support.google.com
- Google: EU user consent policy google.com
- ICO: Guidance on storage and access technologies, exceptions (statistical purposes) ico.org.uk

Turkish
English
Spanish
Arabic
Russian