Introduction

Hands busy arranging technical components on a work surface.

Google Consent Mode v2 sends four consent parameters to all Google products — analytics_storage, ad_storage, ad_user_data and ad_personalization — and directly determines access to advertising and measurement features for traffic from the European Economic Area. Since March 2024, any site using Google Ads or Google Analytics 4 (GA4) with EEA traffic must send these four signals to retain full access to conversion reporting, remarketing audiences and modeling. The priority action is simple: check that your consent management platform (CMP) correctly maps its categories to the four API parameters, and initialize all these parameters to denied for the EEA before loading any Google tag.

Three points to keep in mind before going further:

  • Consent Mode v2 is a technical signaling channel, not a CMP. It does not collect consent and does not replace the legal evidence you must retain.
  • Responsibility for compliance remains entirely with the publisher under the GDPR and the ePrivacy Directive — Consent Mode does not automatically make you compliant.
  • Immediate deliverables to prepare: inventory of active tags, CMP → API mapping plan, and technical acceptance testing protocol.

Pro tip: Before any change, export a snapshot of your Google Ads conversions and GA4 reports for the last 30 days. This baseline will be essential for measuring the impact after deployment.

Key takeaways

Consent Mode v2 requires sending the four consent parameters (analytics_storage, ad_storage, ad_user_data, ad_personalization) before loading any Google tag, initialized to denied for the EEA — this is the minimum condition for remaining compliant and preserving conversion modeling.

PointDetails
Four mandatory parametersad_user_data and ad_personalization are new in v2 and essential for Enhanced Conversions and Google Signals.
Initialization before tagsgtag('consent','default') must precede any GTM or gtag.js loading, with all parameters set to denied for the EEA.
Basic vs advancedBasic blocks tags (legally safer); advanced sends cookieless pings and enables advertiser-specific modeling.
Compliance is not automaticConsent Mode does not replace the CMP or evidence of consent: responsibility remains with the publisher under the GDPR and CNIL requirements.
Pharelia auditPharelia covers the 10 technical, legal and business checkpoints with a report, GTM playbook and test plan.

Table of contents

The Consent API relies on two distinct gtag calls, whose execution order is non-negotiable according to Google's official documentation:

  1. gtag('consent', 'default', {...}): initializes consent states before loading any Google tag. For the EEA, all parameters must default to denied.
  2. gtag('consent', 'update', {...}): updates the states after the user interacts with the banner.

If default is called after a Google Tag Manager tag or gtag.js loads, the parameters are ignored for that session. This is the most common production error.

Basic mode vs advanced mode

Google distinguishes two behaviors depending on the mode chosen:

  • Basic mode: Google tags are completely blocked until user interaction. No ping is sent if consent is refused. Conversion modeling is not available. This mode is the most legally conservative.
  • Advanced mode: tags load in a restricted state as soon as the page opens. If consent is refused, cookieless pings are sent to Google. These pings contain functional information (timestamp, user-agent, network access point) but do not identify the user. They feed advertiser-specific conversion modeling, which is more precise than generic modeling.

Google products incorporating Consent Mode checks include GA4, Google Ads, Floodlight, Conversion Linker and Google Tag. In server-side tagging (sGTM), the consent signal must be explicitly propagated to the server container: it is not automatically transmitted from the browser.

Pro tip: In advanced mode, check in the network console that cookieless pings are sent with all four consent parameters in the payload. A ping without `ad_user_data` indicates incomplete CMP mapping.

  1. JavaScript initialization: place the gtag('consent', 'default', { ad_storage: 'denied', analytics_storage: 'denied', ad_user_data: 'denied', ad_personalization: 'denied', wait_for_update: 500 }) call in the <head>, before any Google Tag Manager or gtag.js snippet. Consult the TagQueries implementation guide for recommended code snippets.

Pro tip: The most common errors according to field audits are a CMP loading too late (after GTM), incomplete mapping that omits `ad_user_data`, and failure to send the signal to the sGTM container. Check these three points first during acceptance testing.

Consent Mode v2 is a signal transmission channel, not a standalone compliance system. This confusion underlies most legal risks observed in production.

  • It does not collect consent: the banner, storage of choices and timestamped evidence remain the responsibility of your CMP and organization.
  • It does not replace GDPR documentation: the processing register, privacy policy, legal notices and evidence of consent are separate obligations.
  • It does not protect against premature storage: if a tag loads before the default call, Consent Mode does not intervene.

The most common operational risks, documented by field audits:

  • Incorrect CMP → parameter mapping (an ‘Advertising’ category that does not populate ad_user_data).
  • Tags firing before the consent signal (CMP loaded too late in the DOM).
  • Server-side container without explicit consent transmission.
  • No initialization logs usable in the event of a CNIL inspection.
‘Using technical consent management solutions does not exempt the controller from its obligation to demonstrate that consent has been validly obtained.’ This position, consistently stated in EDPB guidelines, applies directly to Consent Mode.

Consequences of a faulty implementation may include CNIL formal notices, fines for placing trackers without valid consent, and an obligation to demonstrate compliance over a retrospective period. Involve your DPO in acceptance testing, retain initialization logs and document every version of the CMP mapping.

This article provides general information and does not constitute legal advice. Consult your DPO or specialist counsel to validate compliance for your specific situation.

What the technical implementation reveals about your measurement health

A poorly executed Consent Mode v2 deployment does more than break compliance: it silently distorts Google Ads automated bidding, which relies on conversion signals to optimize campaigns. When input data is corrupted by incorrect mapping or a faulty call sequence, the bidding algorithm makes decisions on a biased basis. Marketing teams then see CPA deteriorate without identifying the cause, because the problem is invisible in standard reports.

What I observe on audit projects is that most problems do not stem from a lack of Consent Mode knowledge, but from silos between teams. Marketing configures the CMP without consulting the CIO about script loading order. The CIO deploys GTM without validating the mapping with the DPO. The result: an implementation that is technically present but functionally faulty, passing superficial checks and failing in production.

The right approach is a joint project, with documented acceptance testing and post-deployment monitoring for at least 14 days. Clients following this method with Pharelia, such as those documented in our Applewood client cases and M2A, were able to stabilize measurement and resume optimization decisions based on reliable data. Data continuity is not a technical detail: it is the condition for any credible marketing decision.

What the technical implementation reveals about your measurement health — overview diagram
Pharelia

Faulty CMP mapping or incomplete acceptance testing can cost weeks of corrupted data and Google Ads campaigns optimized on bad signals. Pharelia handles the complete audit of your Consent Mode v2 implementation: tag inventory, call-order verification, CMP mapping to the four parameters, multi-scenario GTM acceptance testing and post-deployment monitoring.

The project starts with a free audit, then continues as monthly support or a one-off project depending on your needs. You leave with an audit report, an implementation playbook and a secured GTM container. For teams also managing visibility in generative engines, our resources on AI search visibility naturally complement this measurement work.

Contact us.

Official sources and useful reading

The resources below are arranged in recommended reading order: Google technical documentation first, legal texts next, practical guides last.

Google technical documentation

European legal texts

French practical guides

ResourceTypePriority
developers.google.com/consentTechnical documentation1st read
support.google.com/analyticsProduct support1st read
EUR-Lex ePrivacyLegal text2nd read
EDPB Guidelines 2023Guidelines2nd read
TagQueries / eegeekFrench practical guides3rd read
Official sources and useful reading — overview diagram

Frequently asked questions

Is Consent Mode v2 mandatory for French sites?

Yes, since March 2024, any site using Google Ads or GA4 with traffic from the EEA must implement Consent Mode v2 to retain full access to measurement and conversion features.

What is the difference between basic mode and advanced mode?

Basic mode completely blocks Google tags before consent; advanced mode loads them in a restricted state and sends cookieless pings to feed conversion modeling, at the cost of greater technical complexity.

Does Consent Mode v2 replace my CMP (Didomi, OneTrust, Cookiebot)?

No. Consent Mode is a technical signaling channel that transmits consent states to Google. Collection, storage and evidence of consent remain the responsibility of your CMP and organization.

How long does it take to see the impact on conversions?

The first effects on conversion reports are generally visible after 7 days, but a monitoring period of at least 14 days is recommended to distinguish Consent Mode's impact from natural traffic variation.

What happens if ad_user_data is not sent?

Enhanced Conversions and advertising audience lists do not work properly. Google cannot associate conversion data with users, degrading the quality of automated bidding signals in Google Ads.

Recommendation