Gerris home
Gerris

Chris Abraham: technical consulting, AI tools, and technical SEO

Home › Guides › GA4 Consent Mode

Google Consent Mode v2 for GA4: a practical setup guide

Consent Mode is how Google's tags learn whether a visitor agreed to cookies, and how they behave when the answer is no. Set up well, it keeps analytics honest and the site compliant. Set up badly, it either drops most of your data or quietly ignores the visitor's choice.

The four signals

SignalControls
analytics_storageCookies for analytics, such as GA4's visitor identifier
ad_storageCookies for advertising, such as conversion and remarketing cookies
ad_user_dataWhether visitor data may be sent to Google for advertising
ad_personalizationWhether that data may be used for personalized ads and remarketing

Version 2 added the last two in late 2023. Since March 2024 Google has required them for advertisers who want to use audience and conversion features with traffic from the European Economic Area, under the EU's Digital Markets Act.

Basic and advanced mode

Advanced mode lets GA4 estimate the behavior of visitors who declined, through behavioral modeling, once a property has enough traffic. Google's documented minimum is roughly a thousand daily events from visitors with analytics denied, and a thousand daily users with analytics granted, sustained for a week or more. Smaller sites never reach it, and for them the choice between modes makes little difference to the reports.

Setting the defaults

The default state must be set before any Google tag loads. With the gtag snippet, that means a consent default command above the config line. Defaults can differ by region, using ISO country codes:

gtag('consent', 'default', {
  ad_storage: 'denied', ad_user_data: 'denied',
  ad_personalization: 'denied', analytics_storage: 'denied',
  region: ['AT','BE','BG','CH','CY','CZ','DE','DK','EE','ES','FI','FR','GB',
           'GR','HR','HU','IE','IS','IT','LI','LT','LU','LV','MT','NL','NO',
           'PL','PT','RO','SE','SI','SK']
});
gtag('consent', 'default', {
  ad_storage: 'denied', ad_user_data: 'denied',
  ad_personalization: 'denied', analytics_storage: 'granted'
});

That's the pattern this site uses: advertising signals denied everywhere, because the site runs no ads, and analytics denied by default in the EEA, the UK, and Switzerland, where the law requires prior consent, and granted elsewhere. The most specific matching region wins. When a visitor accepts or declines, the banner sends a consent update command with the new values.

In Google Tag Manager, set defaults with a tag on the Consent Initialization trigger, which fires before every other trigger. Most consent platforms certified by Google ship a Tag Manager template that does this for you.

Choosing a consent platform

Publishers who show Google ads to visitors in the EEA, the UK, or Switzerland must use a consent platform from Google's certified list. For everyone else it's still the safer choice, because certified platforms send Consent Mode signals correctly by default. Check that the platform supports regional rules, so visitors in places that don't require a banner aren't shown one.

Checking that it works

Mistakes I find most often

What to expect in the reports

After a consent banner goes live in Europe, GA4's European sessions usually fall, sometimes sharply, because declined visitors are no longer counted as users. That's the system working. Search Console doesn't use cookies, so its click counts are unaffected, and comparing the two separates a consent effect from a real traffic loss.

References