Skip to main content
Promotional banner for the pentest readiness checklist
Category: Google Consent Mode

Consent Mode Modeling

Also known as: Behavioural Modeling for Consent Mode, Consent Mode Behavioral Modeling
Simply put

Consent Mode Modeling is a Google feature that uses machine learning to estimate what website visitors who decline cookies might have done, filling gaps in analytics and advertising data that arise when consent is withheld. When a visitor refuses cookies, Google's tags do not read or write those cookies, so the modeling produces statistical estimates rather than measurements based on actual observed behavior. It is one part of Google's broader Consent Mode system, which adjusts how tags behave according to each visitor's consent choices.

Formal definition

Consent Mode Modeling refers to the machine-learning (described by Google as 'Google AI') component of Google Consent Mode that estimates conversions and user behavior for sessions in which advertising or analytics consent has not been granted. Under Consent Mode, Google tags adjust their behavior based on the visitor's consent status: where consent is absent, the tags are configured not to read or write cookies for advertising or analytics purposes, and in that state the tags may transmit consent-signal data (in Advanced Consent Mode, cookieless 'pings') that feed the modeling. The modeling then produces estimated metrics to compensate for gaps in campaign performance and analytics data caused by declined consent. Consent Mode operates in Basic and Advanced (Advanced/Consent Mode V2) configurations, which differ in whether and how data is collected before consent is obtained; the modeling capability is typically associated with the Advanced configuration. Consent Mode is a signaling and measurement mechanism operated by Google and does not itself collect consent from users, determine the legal validity of that consent, or replace a CMP or the underlying obligations under the ePrivacy Directive (for placing or accessing cookies) or the GDPR (for processing any resulting personal data). The precise modeling methodology, its accuracy, and its interaction with specific jurisdictional consent requirements are not detailed in the evidence provided and fall outside the scope of this definition.

Why it matters

When visitors decline consent for advertising or analytics cookies, the corresponding Google tags do not read or write those cookies, which leaves gaps in campaign performance and analytics data. Consent Mode Modeling matters because it is Google's attempt to address those gaps by using machine learning to estimate the behavior of non-consenting visitors, allowing organizations to continue deriving aggregate insights without relying on data drawn from users who refused. For privacy and marketing compliance teams, this makes the feature attractive as a way to preserve measurement value while still respecting a visitor's consent choice.

At the same time, the feature raises important questions that compliance professionals should not overlook. Because the modeled figures are statistical estimates rather than measurements of actual observed behavior, they should be understood as approximations whose accuracy is not detailed in the evidence available here. More significantly, Consent Mode is a signaling and measurement mechanism operated by Google; it does not itself collect consent, determine whether that consent is legally valid, or replace a consent management platform. Deploying it does not by itself satisfy the underlying obligations under the ePrivacy Directive for placing or accessing information on a device, or under the GDPR for processing any resulting personal data.

Organizations therefore need to treat Consent Mode Modeling as one component within a broader compliance framework rather than as a compliance solution in its own right. In particular, the way modeling interacts with specific jurisdictional consent requirements is not something that can be assumed to be uniform, and requirements differ between the EU, the UK, and individual US states. Legal judgment about the validity of the consent being signaled, and about the lawfulness of any data transmitted before consent is obtained, remains essential.

Who it's relevant to

Privacy officers and data protection professionals
These readers need to understand that Consent Mode Modeling does not collect consent, validate its legal sufficiency, or replace a CMP. They should assess how any pre-consent pings and modeled data fit within the organization's obligations under the ePrivacy Directive for placing or accessing information on a device, and under the GDPR for processing any resulting personal data, recognizing that requirements differ across the EU, the UK, and US state regimes.
Marketing and analytics compliance teams
These teams often rely on Consent Mode Modeling to address gaps in campaign performance and analytics measurement caused by declined consent. They should treat the resulting figures as machine-learning estimates rather than observed measurements, and coordinate with legal and privacy colleagues before drawing conclusions from modeled data, particularly given that the modeling's accuracy is not detailed here.
Web developers and tag managers
Those implementing Google tags need to understand the difference between Basic and Advanced (Consent Mode V2) configurations, including whether and how data is collected before consent is obtained and how the tags behave when consent is absent. Correct configuration determines what signal data is transmitted and whether the modeling capability, typically associated with the Advanced configuration, is available.
Legal counsel advising on tracking technologies
Counsel should be aware that Consent Mode is a Google-operated signaling and measurement mechanism that does not determine the legal validity of consent. Its interaction with specific jurisdictional consent requirements is not settled by the feature itself and depends on facts outside this definition, so legal judgment remains necessary when advising on deployment across differing frameworks.

Inside Consent Mode Modeling

Consent Mode
A mechanism, associated primarily with certain analytics and advertising tag providers, that adjusts how tags behave based on the consent choices a user has made. When a user declines consent for a given purpose, the relevant tags are intended to operate in a restricted manner rather than setting or reading cookies as they otherwise would.
Consent signals
The parameters passed to tags indicating whether the user has granted or denied consent for particular purposes, such as analytics storage or advertising storage. These signals are typically driven by the choices captured through a consent management platform (CMP) or equivalent banner.
Modeling
A statistical estimation approach used to approximate certain measurement outcomes for users who have not granted consent, based on patterns observed among users who have. Because no cookies or identifiers are set for non-consenting users in restricted operation, the associated data is estimated rather than directly observed.
Cookieless pings
Signals that some consent mode configurations may send without setting or reading information on the user's device when consent is declined. Whether such pings involve access to or storage of information on the device, and whether they process personal data, is fact-specific and relevant to both ePrivacy and GDPR analysis.
Restricted (denied) versus granted states
The two broad operating conditions consent mode distinguishes: a granted state where tags may set and read cookies subject to the user's choices, and a denied state where tag behavior is limited. The precise behavior in each state depends on the specific implementation and configuration.

Common questions

Answers to the questions practitioners most commonly ask about Consent Mode Modeling.

Does Consent Mode modeling mean I can track users who have refused consent?
No. When a user declines consent, Consent Mode is designed to prevent the setting of the relevant cookies and to send only limited, non-identifying signals (often called cookieless pings) rather than to track that individual. Modeling does not recover or reconstruct data about the specific user who refused; instead it uses aggregate, statistical techniques to estimate conversions and other metrics for the declining population as a whole. Because the modeled figures are estimates rather than observations of identified individuals, they should not be treated as a way to circumvent a user's refusal. Whether the underlying cookieless signals themselves involve any processing of personal data, and how that is characterized, can depend on the facts and remains a matter for case-by-case assessment.
Does enabling Consent Mode make my cookie setup compliant on its own?
No. Consent Mode is a technical mechanism that adjusts how tags behave based on consent states it receives; it does not obtain consent, and it does not by itself satisfy the legal requirements of the ePrivacy rules or the GDPR in EU jurisdictions. You still need a valid consent mechanism (typically a consent management platform) that collects freely given, specific, informed, and unambiguous consent through a clear affirmative action before non-exempt cookies are placed, and you still need appropriate information, records, and a lawful basis for any personal data processing. Consent Mode can support an overall compliance approach by helping ensure tags respect the signals it is given, but it does not replace legal judgment or the underlying consent infrastructure, and no tool can guarantee compliance.
How does Consent Mode receive consent signals from a consent management platform?
In a typical implementation, the consent management platform captures the user's choices and communicates the resulting consent states to Consent Mode, which then determines whether the affected tags operate in their full or restricted state. The exact integration depends on the CMP and the tag management setup you use, and many CMPs offer built-in support or templates for this purpose. Because the reliability of the whole arrangement depends on the CMP correctly reflecting the user's actual choices, you should verify that the signals passed to Consent Mode accurately match what the user selected, and confirm this behavior across the consent categories relevant to your site.
What should I test before relying on Consent Mode in production?
At a minimum, verify that no non-exempt cookies are set before consent is given, that tags move to their restricted state when a user declines, and that they operate fully only after a valid affirmative action. It is also useful to confirm the behavior on first page load, after a user changes or withdraws consent, and across the different consent categories your site distinguishes. Testing should cover the geographic scope you operate in, since consent obligations differ between the EU, the UK, and individual US states, and the appropriate default behavior may differ accordingly. Technical testing verifies that tags respect the signals they receive, but it does not by itself establish that your consent collection meets the applicable legal standard.
How should Consent Mode interact with record-keeping and consent logging obligations?
Consent Mode governs how tags respond to consent states, but it is generally the consent management platform, rather than Consent Mode itself, that is responsible for capturing and storing records of the consent choices users have made. Where record-keeping is expected, you should ensure your CMP maintains logs that reflect what a user was shown and what they chose, and confirm that the states passed to Consent Mode are consistent with those records. The precise scope of any logging expectation depends on the applicable framework and the guidance of the relevant data protection authority, so treat the retention and content of consent records as a legal question rather than something the tag configuration alone resolves.
Does Consent Mode cover technologies other than cookies, such as pixels, SDKs, or local storage?
Consent Mode primarily adjusts the behavior of the tags and technologies it is configured to control, which can extend beyond classic cookies to include mechanisms such as pixels and other tracking calls implemented through the same tag setup. It is important to remember that similar technologies, including tracking pixels, local storage, mobile SDKs, and fingerprinting, generally fall within the same consent rules as cookies in the EU even though they are not literally cookies. Whether a given technology is actually brought under Consent Mode's control depends on how it is deployed and configured, so you should map all in-scope technologies separately and not assume that enabling Consent Mode automatically governs every tracking method present on your properties.

Common misconceptions

Enabling consent mode means you no longer need a consent banner or a CMP.
Consent mode responds to consent signals; it does not itself collect valid consent. In most EU jurisdictions a compliant mechanism for obtaining freely given, specific, informed, and unambiguous consent, typically through a CMP or banner, is still required, and consent mode does not replace that.
Modeled data means personal data is processed without consent in a way that is inherently compliant.
Modeling estimates outcomes for non-consenting users rather than tracking them individually, but whether any signals sent in a denied state involve access to or storage of information on the device (an ePrivacy question) or the processing of personal data (a GDPR question) is fact-specific. Consent mode does not by itself resolve these questions or guarantee compliance.
If consent mode is configured correctly, cookie compliance is achieved everywhere.
Cookie and consent obligations differ across the EU, the UK, and individual US states, which may rely on opt-out rather than opt-in. Consent mode is a technical feature that supports a chosen consent approach; it does not substitute for legal judgment about the applicable regime, and its correct behavior still depends on accurate configuration.

Best practices

Ensure consent mode is driven by a properly implemented consent mechanism, such as a CMP, that captures consent meeting the applicable standard (for example, a clear affirmative action in EU jurisdictions) before treating any signal as granted.
Verify through testing that in the denied state tags actually operate in the restricted manner intended and do not set or read cookies contrary to the user's choice.
Assess whether any signals sent in the denied state involve access to or storage of information on the device or the processing of personal data, and evaluate them under both ePrivacy and GDPR analyses rather than assuming they are exempt.
Document the configuration and the consent signals passed to tags as part of consent record-keeping, so that the behavior can be evidenced if questioned.
Configure and interpret consent mode according to the specific regime that applies to your users, distinguishing opt-in expectations in the EU and UK from opt-out approaches under US state laws.
Treat consent mode as a tool that supports compliance and involve legal or data protection judgment for contested or fact-specific questions rather than relying on the feature to guarantee a lawful outcome.
Application Security Isn’t Optional Anymore.