Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Google Consent Mode

ad_storage

Also known as: ad storage consent signal
Simply put

ad_storage is one of the consent signals used in Google's Consent Mode to indicate whether advertising-related information may be stored on or accessed from a user's device, such as cookies used for ads. When it is set to 'denied', tags are instructed not to store this advertising data, and certain ad identifiers may be redacted from network requests. It is a technical signal that reflects a user's consent decision, but on its own it does not determine whether your overall setup meets legal requirements.

Formal definition

ad_storage is a Google Consent Mode parameter that governs whether advertising-related storage (for example, cookies used for advertising) may be read from or written to the user's device. Its value is typically 'granted' or 'denied'; when denied, Google Ads and Floodlight tags adjust behavior, and where ads_data_redaction is set to true alongside a denied ad_storage state, ad click identifiers in network requests are redacted. Within Consent Mode v2, ad_storage is distinct from related signals such as ad_user_data (which concerns transmission of user data to Google) and ad_personalization (which concerns personalized advertising); ad_storage specifically addresses device storage rather than data transmission or personalization. The signal is intended to be driven by an upstream consent decision, commonly relayed via a CMP or tag manager, and misconfiguration (for example, the consent signal not reaching the tags) can leave ad_storage denied even after a user accepts. Note that the storage of and access to information on a device is governed in most EU jurisdictions by the ePrivacy Directive as implemented nationally, while any subsequent processing of personal data engages the GDPR; setting ad_storage correctly supports but does not by itself establish compliance with either regime, and the precise internal scope of each Consent Mode signal is defined by Google and may evolve. Similar considerations apply to non-cookie technologies (pixels, local storage, SDKs) that fall within the same legal rules.

Why it matters

For teams running Google advertising tags, ad_storage is often the practical bridge between a user's consent decision and how advertising cookies actually behave on a device. Because the storage of and access to information on a user's device is governed in most EU jurisdictions by the ePrivacy Directive as implemented nationally, correctly reflecting a denial of consent in the ad_storage signal is an important part of respecting that decision. When ad_storage is set to 'denied', Google Ads and Floodlight tags adjust their behavior, and where ads_data_redaction is also set to true, ad click identifiers in network requests are redacted.

The signal matters just as much when it is misconfigured. A common failure mode is that the consent signal never actually reaches the tags, so ad_storage remains denied even after a user has accepted. This can quietly undercut measurement and advertising performance while giving the false impression that consent handling is working as intended. Conversely, an incorrectly granted state can result in advertising storage occurring against a user's wishes, which raises compliance concerns under the applicable ePrivacy rules and, for any resulting processing of personal data, under the GDPR.

Who it's relevant to

Web developers and tag managers
Those implementing Consent Mode need to ensure the consent decision from a CMP or tag manager actually reaches the tags, since a common cause of ad_storage remaining denied after acceptance is that the consent signal is not being relayed to the tags. They also configure related settings such as ads_data_redaction, which affects redaction of ad click identifiers when ad_storage is denied.
Marketing and advertising compliance teams
Because ad_storage controls whether advertising cookies may be stored on a device, its state directly influences both advertising measurement and how the platform behaves under a user's consent choice. These teams should understand that ad_storage is distinct from ad_user_data and ad_personalization, so relying on one signal alone does not address transmission or personalization concerns.
Privacy officers and legal counsel
Advisors need to recognize that setting ad_storage correctly supports but does not by itself establish compliance. In most EU jurisdictions the storage of and access to device information is governed by the ePrivacy Directive as implemented nationally, while any subsequent processing of personal data engages the GDPR. Similar considerations apply to non-cookie technologies such as pixels, local storage, and SDKs that fall within the same rules, and the internal scope of each Consent Mode signal is defined by Google and may change over time.

Inside ad_storage

Consent state parameter
ad_storage is one of the consent types used in Google's Consent Mode, representing whether storage related to advertising (such as cookies used for ad targeting and measurement) is permitted. It typically holds a value of 'granted' or 'denied' based on the user's choices.
Scope of storage governed
It relates to the setting and reading of information on a user's device for advertising purposes, including advertising cookies and similar identifiers. In the EU, placing or accessing such information is generally governed by the ePrivacy Directive's national implementations, with any resulting processing of personal data governed by the GDPR.
Behavior when denied
When ad_storage is set to 'denied', advertising-related tags are generally expected to refrain from writing or reading advertising cookies. Depending on configuration, some tools may still send limited, typically non-identifying signals, though the exact behavior depends on the specific implementation and vendor design.
Relationship to a CMP
The ad_storage value is commonly driven by the choices a user makes through a consent management platform (CMP). The CMP captures the consent decision and communicates it so that tags condition their storage behavior accordingly.
Distinction from other consent types
ad_storage is generally treated separately from consent types covering analytics or functional storage (such as analytics_storage), reflecting that advertising cookies typically require prior consent under EU law while other categories may be handled under their own conditions.

Common questions

Answers to the questions practitioners most commonly ask about ad_storage.

Does obtaining consent for ad_storage automatically satisfy all my cookie compliance obligations?
No. ad_storage is a consent category used within Google's Consent Mode to govern storage related to advertising, but managing it is not the same as meeting your full legal obligations. In most EU jurisdictions, the placing of and access to information on a user's device is governed by the ePrivacy Directive as implemented nationally, while any subsequent processing of personal data is governed by the GDPR. Setting ad_storage to granted or denied is a technical signal; it does not by itself demonstrate that you collected valid consent, provided adequate information, or maintained the records that authorities may expect. The category is a tool that supports compliance rather than a substitute for legal judgment.
Is ad_storage the same thing as an advertising cookie?
Not exactly. ad_storage is a consent category or parameter that governs whether storage used for advertising purposes is permitted, rather than a specific cookie itself. It can apply to cookies as well as to similar technologies used for advertising, such as identifiers held in local storage or values set via pixels or SDKs, which generally fall within the same consent rules under EU law even though they are not literally cookies. Treating ad_storage as a single cookie can lead you to overlook other advertising technologies that its state is meant to control.
Should ad_storage default to granted or denied before a user makes a choice?
In most EU jurisdictions, advertising-related storage typically requires prior consent through a clear affirmative action, so a default of denied before the user interacts is generally the more defensible position there. Under some US state frameworks that rely on an opt-out rather than opt-in model, the expectation may differ. Because these obligations vary by jurisdiction, you should configure defaults according to the legal scope of your audience and confirm the position for each region you serve rather than applying a single global default.
How does ad_storage relate to a consent management platform (CMP)?
A CMP is typically the component that collects the user's choice and then communicates it, which can include updating the ad_storage state so that downstream advertising tags behave accordingly. In this arrangement, the CMP handles the user-facing consent interaction and record-keeping, while ad_storage reflects the resulting instruction for advertising storage. The two work together, but neither the CMP nor the ad_storage signal alone guarantees compliance; they support decisions that still depend on how you have configured and documented them.
What should I do about advertising tags before a user has interacted with the ad_storage setting?
Where advertising storage requires prior consent, as is generally the case in most EU jurisdictions, the common approach is to withhold advertising storage until the user provides a clear affirmative indication, meaning ad_storage remains denied in the interim. What behavior occurs while consent is pending, and whether any signals are sent at all, depends on your specific configuration and the technologies involved. You should verify this against the requirements applicable to your users' jurisdictions.
Do I need to keep records of the consent that drives the ad_storage state?
Consent record-keeping is generally treated as important under EU frameworks, so being able to demonstrate that a user's advertising storage choice was captured is typically advisable. The ad_storage state itself is an operational signal and is not necessarily a complete consent record. Maintaining logs of when and how consent was obtained is usually handled by your CMP or related systems rather than inferred from the ad_storage value alone. The precise record-keeping expectations can vary by jurisdiction and by the guidance of the relevant data protection authority.

Common misconceptions

Setting ad_storage to 'denied' by itself makes an implementation compliant.
ad_storage is a technical signal that conditions tag behavior; it does not, on its own, establish valid consent or compliance. In most EU jurisdictions, advertising storage generally requires prior consent that is freely given, specific, informed, and unambiguous, and the legal assessment depends on how consent is obtained, recorded, and honored. The parameter supports compliance efforts but does not replace legal judgment.
ad_storage only concerns cookies.
While the name references storage, the underlying obligations generally extend to other technologies used for advertising, such as pixels, local storage, SDKs, or device identifiers. Under EU rules, the placing of or access to information on a user's device is governed similarly regardless of whether a literal cookie is used, so limiting attention to cookies alone can leave gaps.
The same ad_storage configuration is appropriate everywhere.
Consent obligations differ across jurisdictions. Many EU jurisdictions rely on an opt-in model requiring prior consent before advertising storage, whereas several US state frameworks (such as those in California) often rely on an opt-out approach. A single default value or configuration may not reflect the differing legal requirements across regions.

Best practices

Default ad_storage to 'denied' before any user interaction in jurisdictions where prior consent is generally required, and update it only after a clear affirmative action, rather than relying on pre-ticked boxes or continued browsing as consent.
Drive the ad_storage value from your consent management platform so the signal consistently reflects the user's recorded choices, and keep the CMP configuration and tag conditions aligned.
Apply the appropriate consent model per region, recognizing that EU jurisdictions typically expect opt-in for advertising storage while some US state laws rely on opt-out signals, and configure defaults accordingly.
Verify that advertising tags actually refrain from writing or reading advertising storage when ad_storage is 'denied', since real-world behavior depends on the specific tags and implementation and should be tested rather than assumed.
Extend your consent conditioning beyond cookies to cover pixels, local storage, SDKs, and similar identifiers used for advertising, so that consent gating is not circumvented by non-cookie technologies.
Maintain records of consent decisions and configuration to support accountability, and treat the technical setup as a support for, not a substitute for, legal review by qualified privacy counsel.
Promotional banner for the Penetration Report Template Kit