Skip to main content
Promotional banner for the pentest readiness checklist
Category: Google Consent Mode

Consent Mode v2

Also known as: Google Consent Mode v2, Google Consent Mode V2
Simply put

Consent Mode v2 is a Google mechanism that adjusts how Google's advertising and analytics tools behave depending on whether a website visitor has consented to cookies and data collection. When a user declines or has not yet made a choice, it can limit the data Google collects while still allowing certain measurement through modeled estimates rather than directly observed data. It is a technical tool that reflects consent choices captured elsewhere on the site; it does not itself obtain consent or guarantee legal compliance.

Formal definition

Consent Mode v2 is Google's framework for communicating a user's consent state to Google Tags (such as Google Analytics and Google Ads tags), which then read and adjust their behavior based on defined consent signals. According to the evidence, it works by relaying consent preferences that determine whether tags fire in a full or restricted manner, and it employs conversion modeling to estimate measurement outcomes for users who did not grant consent for the collection of their personal data or browser identifiers. In practice, the consent signals it consumes are typically set by a separate consent management platform (CMP) or equivalent consent-capture layer; Consent Mode v2 governs downstream Google tag behavior rather than serving as the consent-collection interface itself. The evidence describes its mechanics and purpose but does not establish that its use, on its own, satisfies consent obligations under the ePrivacy Directive, the GDPR, or non-EU frameworks, the underlying validity of consent and the lawfulness of any data processing remain matters of separate legal assessment. Details such as specific consent parameters, default versus updated states, and jurisdiction-specific configuration are out of scope for this definition and are not covered by the cited evidence.

Why it matters

Consent Mode v2 has become a practical focal point for organizations that rely on Google's advertising and analytics tools while trying to respect user consent choices. Because it adjusts how Google Tags behave depending on whether a visitor has consented, it sits at the intersection of technical implementation and compliance operations: the consent decisions captured by a site's consent layer must be accurately reflected in downstream tag behavior, or the technical configuration may diverge from what users were actually told and asked. For privacy officers and developers, this makes correct integration a recurring point of attention rather than a one-time setup task.

A central reason Consent Mode v2 draws scrutiny is its use of conversion modeling, which estimates measurement outcomes for users who did not grant consent for the collection of their personal data or browser identifiers. This lets organizations retain some measurement capability while limiting direct data collection from non-consenting users, but it also raises questions that the tool itself does not resolve, chiefly, whether the underlying consent is valid and whether any associated processing is lawful under the applicable regime. Consent Mode v2 is a mechanism for relaying and acting on consent signals; it is not a substitute for legally valid consent.

Who it's relevant to

Privacy officers and data protection professionals
Consent Mode v2 reflects consent choices but does not itself establish that consent is valid or that downstream processing is lawful. Privacy teams generally need to assess whether the consent captured meets the applicable standard, for example, the freely given, specific, informed, and unambiguous standard associated with the GDPR in the EU, and whether the placing of and access to information on the device is addressed separately under the ePrivacy Directive and its national implementations. Requirements and enforcement positions differ across the EU, the UK, and individual US states, so configuration should be reviewed against the relevant jurisdiction rather than assumed to be universal.
Web developers and analytics implementers
Developers are typically responsible for ensuring that consent signals set by the site's consent layer are accurately relayed to Google Tags, so that tag behavior matches the choices users actually made. Because Consent Mode v2 governs how tags fire in full or restricted modes and can invoke conversion modeling for non-consenting users, implementation errors can cause a mismatch between stated consent behavior and actual data collection. Testing and verification against the intended configuration are important, as the tool does not validate consent on its own.
Marketing and measurement teams
Teams that depend on Google Ads and Analytics measurement have an interest in Consent Mode v2 because it can preserve some measurement capability, through modeled estimates, when users decline direct data collection. It is important to understand that these figures are estimates rather than directly observed data, and that retaining measurement does not by itself resolve the legal questions around consent. Any reliance on modeled outputs should be weighed alongside the compliance assessment carried out with legal and privacy colleagues.
Legal counsel and compliance advisers
Counsel may be asked whether use of Consent Mode v2 satisfies consent obligations. The evidence describes the tool's mechanics but does not establish that its use, on its own, meets requirements under the ePrivacy Directive, the GDPR, or non-EU frameworks. The validity of the underlying consent and the lawfulness of any resulting processing remain matters for separate legal assessment, and guidance from data protection authorities on such technologies continues to evolve.

Inside Consent Mode v2

Consent signal parameters
Consent Mode v2 introduces parameters through which a website communicates a user's consent status to certain Google services. The core parameters typically include analytics_storage and ad_storage, which govern whether storage may be used for analytics and advertising purposes respectively.
ad_user_data parameter
A parameter added in version 2 that signals whether the user has consented to the sending of personal data related to advertising to the relevant service. It reflects consent for the use of data for advertising purposes as distinct from storage alone.
ad_personalization parameter
A parameter added in version 2 that signals whether the user has consented to the use of their data for personalized advertising, such as remarketing. It is treated separately from the general advertising storage signal.
Basic and advanced implementation modes
Consent Mode v2 can generally be deployed in a basic mode, where tags are blocked until consent is granted, or an advanced mode, where tags load and adjust their behavior based on the consent signals, sometimes sending pinged, non-identifying signals prior to consent. The exact behavior depends on configuration and should be assessed against applicable legal requirements.
Interaction with a CMP
In practice the consent signals are typically populated by a consent management platform that captures the user's choices. Consent Mode v2 is the mechanism that relays those choices to Google services; it does not itself collect consent or generate a compliant consent interface.
Scope and applicability
Consent Mode v2 is a Google-specific technical framework relevant to those using Google advertising and measurement products. It is designed with EU and UK requirements in mind and is generally most relevant where the ePrivacy rules and the GDPR apply, though the underlying consent obligations derive from law, not from the tool.

Common questions

Answers to the questions practitioners most commonly ask about Consent Mode v2.

Does implementing Consent Mode v2 mean my site is compliant with EU cookie consent requirements?
No. Consent Mode v2 is a technical mechanism that adjusts how Google tags behave based on the consent signals it receives; it does not, by itself, obtain valid consent or make a site compliant. Under the ePrivacy Directive as implemented in EU member states, prior consent is generally required before non-essential cookies or similar technologies are placed, and under the GDPR any resulting personal data processing must rest on a valid legal basis. Consent Mode v2 relies on consent being collected elsewhere, typically through a consent management platform (CMP), and it is that consent-gathering layer, together with your overall legal analysis, that determines compliance. The tool supports compliance but does not replace legal judgment.
Does Consent Mode v2 stop all cookies or data collection when a user declines consent?
Not necessarily in the way many assume. When consent is denied, Consent Mode v2 typically prevents Google tags from writing certain identifiers or cookies and instead may send pinged signals that can include aggregated or cookieless information, depending on the configuration you deploy. There are generally different implementation options that behave differently in terms of what tags load and what is transmitted. Whether a particular configuration is consistent with the consent requirements in your jurisdiction depends on the facts of your setup, and this is an area where interpretations and data protection authority positions can differ. You should assess your specific configuration rather than assume denial results in zero data flow.
What consent signals does Consent Mode v2 expect a CMP to provide?
Consent Mode v2 works with defined consent parameters that your consent management platform sets based on the choices a user makes. These generally cover categories such as analytics and advertising storage, along with additional signals introduced in the v2 iteration relating to advertising personalization and user data. Your CMP typically needs to be configured to map the consent categories presented to users onto these parameters. The precise parameter names and expected values are defined in Google's own documentation, which you should consult directly, as this definition does not reproduce those technical specifications.
How does Consent Mode v2 relate to a consent management platform and the IAB TCF?
Consent Mode v2 is distinct from, but often used alongside, a CMP and frameworks such as the IAB Transparency and Consent Framework (TCF). The CMP is generally responsible for presenting the consent interface, recording the user's choices, and maintaining consent logs, while Consent Mode v2 consumes the resulting signals to govern Google tag behavior. Some CMPs offer integrations that translate TCF outputs or their own consent states into the parameters Consent Mode expects. These are separate layers, and correct integration between them is a configuration and testing task rather than something Consent Mode v2 handles automatically.
Should I use the basic or advanced approach to deploying Consent Mode v2?
Deployments generally differ in whether Google tags are blocked entirely until consent is granted or whether they load and adjust their behavior based on consent signals, and each approach has different implications for what is transmitted before a choice is made. The appropriate choice depends on your risk tolerance, the guidance applicable in your jurisdiction, and how your CMP is configured. Because approaches that allow any transmission prior to consent can raise questions under EU rules governing access to and storage on a user's device, this is a decision to make in consultation with legal advisors and to document, rather than a purely technical preference. This definition does not endorse a specific approach as lawful everywhere.
How can I verify that Consent Mode v2 is working as intended after implementation?
Verification typically involves testing the different consent states, such as granted and denied, and observing whether tags behave and transmit as expected in each case, often using browser developer tools, tag debugging tools, and any diagnostics provided within your analytics or tag management environment. You should also confirm that your CMP correctly sets the expected consent parameters and that changes in user choices propagate to tag behavior. Separately, record-keeping and consent logging obligations are generally handled by the CMP rather than by Consent Mode itself, so verify those independently. Testing confirms technical behavior but does not by itself establish legal compliance, which requires a broader assessment.

Common misconceptions

Implementing Consent Mode v2 makes a website compliant with cookie consent law.
Consent Mode v2 is a technical mechanism for transmitting consent signals to Google services; it does not by itself establish valid consent or guarantee compliance. Consent must still be freely given, specific, informed, and unambiguous under the GDPR, and the placing of cookies and similar technologies must satisfy the applicable ePrivacy rules. The tool supports compliance but does not replace legal judgment or a properly configured consent interface.
Consent Mode v2 replaces the need for a consent management platform (CMP).
Consent Mode v2 generally relies on a separate mechanism, typically a CMP, to capture the user's choices, which are then relayed through its parameters. The two components serve different functions: the CMP obtains and records consent, while Consent Mode conveys the resulting signals to Google services.
The advanced mode's pre-consent signals mean no consent is needed before any data is sent.
Advanced implementations may transmit certain non-identifying signals before consent, but whether this practice is lawful depends on the facts and on evolving guidance from data protection authorities in the relevant jurisdictions. This is a contested area, and practitioners should not assume that any pre-consent transmission is automatically permissible under the ePrivacy rules or the GDPR.

Best practices

Treat Consent Mode v2 as a delivery mechanism for consent signals, and pair it with a properly configured consent management platform that obtains consent meeting the GDPR standard of freely given, specific, informed, and unambiguous, backed by a clear affirmative action.
Map each Consent Mode parameter (such as analytics_storage, ad_storage, ad_user_data, and ad_personalization) to the corresponding consent categories presented to users, so that signals accurately reflect the choices actually made.
Assess whether a basic or advanced implementation is appropriate for your risk posture, and where advanced mode transmits any pre-consent signals, obtain legal review given the unresolved regulatory questions around such transmissions in the EU and UK.
Confirm that strictly necessary cookies and consent-requiring technologies are handled consistently, remembering that pixels, SDKs, local storage, and similar technologies fall within the same consent rules even though they are not literally cookies.
Maintain records of consent and of your Consent Mode configuration to support consent-logging and accountability obligations, and be able to demonstrate how signals correspond to user choices.
Scope your implementation to the jurisdictions you serve, recognizing that requirements differ between the EU, the UK, and individual US states, and revisit the configuration as data protection authority guidance and enforcement positions evolve.
Promotional banner for the Penetration Report Template Kit