The short answer
Google Consent Mode v2 tells Google tags what a visitor agreed to, using four parameters: ad_storage, analytics_storage, ad_user_data and ad_personalization. You implement it by setting all four to denied before any tag runs, then updating them the moment the visitor answers your banner.
DataCops is a tool whose first-party consent manager, built on IAB TCF v2.2, is served from your own domain so blockers are less likely to stop it, and which sits in one script with first-party analytics, a bot verdict on every visit, server-side conversions that skip web events marked as declined, and a log of every send.
How DataCops does it:
- Consent, memory and proof. A TCF 2.2 consent banner from your domain with Google Consent Mode v2 on by default, a server-set cookie up to 400 days where enabled, and a delivery log row for every send, counted once against the pixel.
- First-party collection, no extra tool. One script and one DNS record put collection on your own subdomain; with your DNS on Cloudflare, the free Worker reads the click at the edge before the page loads. Click IDs are kept on the server for up to 90 days.
- Real people only. Every visit gets a bot verdict against 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default. Every form email is checked for disposable providers, domains with no mail server and an email risk score.
- The sale after the form. HighLevel natively (lead, booked, showed, won with value, paid), any CRM by webhook, Shopify through the DataCops Shopify app, all matched to the click by click ID or hashed email and phone, and sent to Meta, Google Ads, TikTok and LinkedIn.
- Ads Warmup. Upload your existing customers (up to 20,000 rows), see a 0 to 10 match score per person, and send them to Meta, Google Ads and TikTok so new campaigns start warm.
Best for: advertisers with EU, UK or Swiss traffic who want a consent banner that loads reliably, and consent, analytics and ad conversions in one script.
- Default first: a consent default command, before GA4 or Google Ads loads.
- Update on click: your CMP sends the choice the instant it is made.
- All four parameters: setups with only the old two are not v2.
- Check it live: Tag Assistant, before and after clicking.
The banner that said yes to nobody
Picture this. A clinic in Dublin installs a cookie banner, ticks the Consent Mode box in the plugin, and moves on. Six weeks later, Google Ads conversions from Irish traffic have fallen by half. Nobody changed the campaigns.
The banner works. Visitors click accept. But the update command fires after the Google Ads tag has already run with everything denied. The tag never looks again. Every accept is thrown away.
Nothing errors. Nothing turns red. The dashboard just gets quieter.
Consent Mode rarely breaks loudly. It fails politely, one missing conversion at a time.
The real cost of a cheap tool
Most consent tools are cheap, often free to start. That is the invoice, not the cost. Cheap tracking that is handled badly costs far more, because the bill arrives in what your ads learn.
- Bots forwarded as buyers. A forwarder sends what reaches it. Junk conversions teach the platform to find more junk.
- The sale that never gets sent. A booked call, a phone order or a won deal happens outside the store or the page. Most tools never see it.
- The limit you hit on your busiest day. Hosts and apps cap requests, events or orders, and sending can pause or stop over the limit.
- The build and the upkeep. Containers, plugins and automations need someone to build them and fix them when a platform changes.
The tracking is 0.17 percent of your spend. If one in five of the conversions your ads learn from is a bot or a fake lead, a fifth of the learning signal points at the wrong people, across the other 99.83 percent of the budget.
Cheap tracking is the cheapest line on the bill and the most expensive one to get wrong.
Tools for Consent Mode
| Tool | Best for |
|---|---|
| DataCops | Ad-funded teams who want clean conversions from one script |
| A standalone consent platform | Consent banners and records, nothing else |
| Google Tag Manager | Browser tags you manage yourself |
When not to use DataCops
- You need a legal opinion. DataCops gives you a consent banner and a record. It is not legal advice, and you still decide your own consent basis.
- You only need a banner and no ads. A basic consent banner is enough if you run no ads and no conversions.
Ads Warmup: tell the ads who pays
Google Consent Mode v2 records the consent choice. It does not tell the ad platforms who your customers are, so new campaigns learn from scratch. Ads Warmup sends customers you already have, from a list you choose to upload, after you have checked your own consent basis for that list.
Ads Warmup, DataCops' flagship feature, sends them to your ad platforms before a campaign spends:
- Upload a customer list. A CSV of past buyers, old leads or booked calls. DataCops reads your columns; only email is required.
- See a match score for every person. An estimate from 0 to 10 from email, phone, name, location, click ID and customer ID, before anything is sent.
- Pick the event. Purchase, Lead, Complete registration, Add to cart or Schedule.
- Send server-side. Up to 20,000 people per upload to Meta, Google Ads and TikTok, with a sent, skipped or failed result per person. Google Ads credits only people who clicked a Google ad.
Each row is dated when you press send, not with the old sale date, so it gives a new campaign real customers to learn from on day one. Preview is free; sending needs a paid plan.
What else a consent platform never does
- Capture at the edge. With DNS on Cloudflare, the free, optional DataCops Cloudflare Worker reads click IDs and UTMs off the first request, before the page or any script runs. It captures; it does not block.
- Keep the click on the server. gclid, wbraid, gbraid, fbclid, ttclid and li_fat_id are stored for up to 90 days, so a deal that closes weeks later still finds its click. A signed server-set cookie lasts up to 400 days where enabled.
- Check the lead's email. Fixed rules, not guesses: disposable providers, domains with no mail server and an email risk score. With LeadCops (Business and up), a lead that fails is held and never billed.
- Install on Shopify. The DataCops Shopify app adds a web pixel and a theme app embed, so every paid order reaches your ads, express checkouts included. See Shopify Conversions API.
- Hand evidence to Google. On the Organization plan, the fraud refund report exports bot-flagged Google Ads clicks in the format Google's Click Quality form asks for. You attach it; Google decides.
What is Google Consent Mode v2?
Consent Mode v2 is a signal between your consent banner and Google's tags. It does not ask for consent. It passes on the answer your banner got.
Since March 2024, Google's EU user consent policy expects these signals for visitors in the EEA. Without them, measurement and remarketing for that traffic stop working properly.
| Parameter | What it controls | New in v2? |
|---|---|---|
| ad_storage | Advertising cookies, like the ones Google Ads uses for conversions | No |
| analytics_storage | Analytics cookies, like GA4's client ID | No |
| ad_user_data | Whether user data can be sent to Google for advertising | Yes |
| ad_personalization | Whether data can be used for remarketing and personalised ads | Yes |
If your setup was built before 2024 and never touched, check it. Many still send only the first two. They look fine in the banner. They are not v2.
Basic or advanced consent mode?
Pick advanced if you want Google to model the conversions it cannot see. Pick basic if you want Google tags silent until someone says yes.
Basic
Google tags are blocked until the visitor consents. No data at all from people who decline. Simple to explain to a lawyer. Google models from far less.
Advanced
Tags load with consent denied and send cookieless pings: no cookies, no identifiers. Google uses them for conversion modelling. Check with your legal team first.
How to implement Consent Mode v2, step by step
This is the order Google's own documentation asks for. The order is the whole trick.
- Set the default before anything else. In code:
gtag('consent', 'default', {...})with all four parameters set todenied, placed above your Google tag. In GTM, fire your CMP template on the Consent Initialization - All Pages trigger, not All Pages. - Add wait_for_update. Something like
wait_for_update: 500gives an async banner half a second to report a stored choice before tags fire. - Scope by region if you need to. The
regionfield takes country codes, so denied-by-default can apply to the EEA and UK only. - Send the update on click. When the visitor answers, your CMP must call
gtag('consent', 'update', {...})with the new values. Returning visitors need it on page load too, from the stored choice. - Decide on the extras.
ads_data_redactionstrips ad click identifiers when ad_storage is denied.url_passthroughcarries gclid through your URLs so a conversion can still be tied to a click. - Turn on consent overview in GTM. Container settings, Enable consent overview. Then every tag shows which consent it needs, and gaps are visible at a glance.
How do you know Consent Mode v2 works?
Test it like a stranger would, in a clean browser, before and after clicking.
- Open Tag Assistant on your site in a private window. Do not touch the banner.
- Open the Consent tab on the first event. All four parameters should show On-page Default: Denied (inside your region).
- Click accept. The next event should show On-page Update: Granted for all four.
- Reload. The stored choice should arrive as an update before your first Google tag fires, not after.
- Check GA4 after a day or two. The consent settings panel on your data stream shows whether ad_user_data and ad_personalization are being received.
If you only tested after clicking accept, you have not tested consent mode. You have tested accept.
Five mistakes that pass every test
These are the ones that look healthy in a demo and cost you in production.
| Mistake | What you see | Fix |
|---|---|---|
| Default fires after tags | Early events carry no consent state | Consent Initialization trigger, default above the tag |
| Only two parameters | Remarketing lists stop growing in the EEA | Add ad_user_data and ad_personalization |
| No update on page load | Returning visitors look denied | CMP re-sends the stored choice |
| Banner blocked | No banner, no choice, everything denied | Serve the CMP from your own domain |
| Server ignores consent | Browser is clean, server still sends | Server sending reads the same choice |
The fourth one deserves a second look. Most banners load from the vendor's domain. Ad blockers and privacy browsers know those domains. When the banner never loads, the visitor never answers, and your defaults decide everything. Tag Assistant cannot show you a banner that never arrived.
What about server-side conversions?
Consent Mode is read by Google tags in the browser. If you also send conversions from a server, to Google Ads or Meta, those sends have to follow the same choice. Otherwise the banner is decoration.
This is where a lot of careful setups quietly leak. The browser respects denied. A webhook or a Zapier step three systems later does not know the banner exists.
DataCops is the tracking solution for ad-funded businesses: it keeps bots out of what your ads learn from and sends the sale that happens after the form to Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X.
Its first-party consent manager is a first-party IAB TCF v2.2 CMP served from your own domain, so fewer blockers strip it. It feeds Consent Mode v2 through TCF, and the same choice controls the server-side sending. Bots do not count as consent either. If you are comparing banners, see our Cookiebot and OneTrust comparisons.
A consent choice that stops at the browser is half a consent choice.
FAQ
Can I warm up a new campaign with my existing customers?
Yes, with DataCops Ads Warmup. Upload a CSV of customers (only email is required, up to 20,000 rows), see a 0 to 10 match score for each person, and send them to Meta, Google Ads and TikTok, dated when you send. Google Ads credits only people who clicked a Google ad.
What are the four Google Consent Mode v2 parameters?
ad_storage, analytics_storage, ad_user_data and ad_personalization. The first two control cookies. The two added in v2 control whether user data can be sent to Google for ads and whether it can be used for personalised ads and remarketing.
Is Google Consent Mode v2 required?
If you use Google Ads or GA4 for visitors in the EEA, yes in practice. Google's EU user consent policy expects consent signals for those users, and without them measurement, remarketing and audience building for that traffic break down.
Should I use basic or advanced consent mode?
Advanced if your legal team is comfortable with cookieless pings before consent, because it gives Google data for conversion modelling. Basic if you want no Google tag to load at all until the visitor says yes.
Does Consent Mode v2 replace my cookie banner?
No. Consent Mode only passes the choice to Google tags. You still need a consent banner (a CMP) to ask the question and record the answer.
Why does Tag Assistant show consent as denied after I click accept?
Usually the update command never fires, or it fires after the tags already ran. Check that your CMP sends a consent update on click and that tags wait for it.
Does Consent Mode apply to server-side conversions?
Google tags read it in the browser. Anything you send from a server, like offline or CAPI-style conversions, has to carry the same choice. A server that ignores the banner is not a consent setup.
Can ad blockers stop my consent banner from loading?
Yes, when the banner loads from a third-party domain that blocklists know. A banner served from your own domain is much less likely to be stripped.