The short answer
Open your site in a private window with Google's Tag Assistant running. The first consent event should show all four signals already set, denied in places that ask first. Click Accept and they should change to granted; click Reject and they should stay denied. Repeat from a US connection, then check the consent mode status in Google Ads.
This is a checklist, not an explainer. For what Consent Mode is and why it matters, read Google Consent Mode v2, explained without the jargon and come back.
You need three things: a private browser window, Tag Assistant (Google's free debugging tool, which is the same thing as Tag Manager's Preview mode), and about ten minutes.
The four signals you're checking
Consent Mode sends Google's tags a set of on/off switches. Four of them matter for this test:
| Signal | In plain words |
|---|---|
ad_storage | Can ad cookies be stored? |
analytics_storage | Can analytics cookies be stored? |
ad_user_data | Can data about this visitor be sent to Google for ads? |
ad_personalization | Can it be used for remarketing and personalised ads? |
A "default" is what the switches say before the visitor answers your banner. An "update" is what they say after. You are checking both.
Check 1: the defaults are set before any tag
Start Tag Assistant, enter your site's address, and let it open your site in a new tab. Don't touch the banner yet.
Back in Tag Assistant, pick the earliest Consent event in the left-hand list and open the Consent tab. The "On-page Default" column should list all four signals. If you're in a place where the law asks first, like the EU or the UK, each should say Denied.
What you're really checking is order. Google's guidance is that the default command must run before anything that sends measurement data, and that "if your consent code is called out of order, consent defaults won't work." In Tag Manager, that means the consent tag sits on the Consent Initialization trigger, which fires before every other trigger.
Tag Assistant helps here. If an ad tag read or wrote a cookie before the default arrived, it flags that as an error. An empty Consent tab means Consent Mode isn't set up at all.
Check 2: the update after Accept, and after Reject
Now click Accept all on your banner. In Tag Assistant, pick the most recent Consent event. The "On-page Update" column should show all four signals as Granted.
Then clear the site's cookies (or open a fresh private window), start again, and click Reject all. The update should keep all four Denied.
Finally, open the Tags tab and click a few tags to see which fired and which were held. A Meta or Hotjar tag that fired after you rejected is a separate problem: those tags ignore Consent Mode, so Tag Manager has to hold them with its own consent settings. Tag Manager's "consent settings not configured" warning covers that.
Check 3: read gcs and gcd in the network panel
Tag Assistant shows what your page told Google. The network panel shows what actually went out. Open your browser's developer tools (F12, or Cmd+Option+I on a Mac), go to the Network tab, reload, and type gcs= in the filter box.
Click any matching request and look at its query string for two values. Google describes gcs as carrying ad_storage and analytics_storage, and gcd as encoding the full consent detail for all the signals. Google doesn't publish a decoding table, but practitioners have worked it out.
gcs, the short one. It always starts G1. The third character is ads, the fourth is analytics. 1 means granted, 0 means denied.
| gcs value | ad_storage | analytics_storage | Where you'd expect it |
|---|---|---|---|
G100 | denied | denied | Ask-first region before Accept, or after Reject |
G110 | granted | denied | Visitor allowed ads but not analytics |
G101 | denied | granted | Visitor allowed analytics but not ads |
G111 | granted | granted | After Accept, or an opt-out region by default |
gcd, the long one. It looks like 13r3r3r3r5. Reading Simo Ahava's breakdown, the letters after each 3 (or 1) are, in order, ad_storage, analytics_storage, ad_user_data and ad_personalization. The letters most useful to know:
| Letter | Meaning |
|---|---|
l | Signal never set |
p | Denied by default, no update yet |
q | Denied by default, still denied after update |
r | Denied by default, granted after update |
t | Granted by default, no update yet |
v | Granted by default, still granted after update |
u | Granted by default, denied after update |
An l in the third or fourth position means ad_user_data or ad_personalization was never set. These are Google's internal parameters and can change, so treat Tag Assistant as the final word.
Check 4: test from two regions
A banner can pass every check above in London and still be wrong in Texas. So run the test twice, using a VPN or a colleague in another country.
- An ask-first place, like Germany, France or the UK. Defaults should be denied,
gcsshould readG100until you click Accept. - An opt-out US state without a privacy-signal law, like Florida. If your setup follows US rules there, defaults are usually granted and
gcsreadsG111straight away.
If both regions behave identically, your banner is probably applying one set of rules to everyone. That is the usual reason analytics drops after a banner goes up.
Turn off any privacy extension for this test, and check your browser isn't sending the Global Privacy Control signal (a browser setting that tells sites "don't sell or share my data") unless that's what you mean to test.
Check 5: the status in Google Ads
In Google Ads, go to Goals, then Conversions, then Summary, and look at the diagnostics. Google lists two healthy statuses, each with a green tick:
- "Consent mode is implemented": it works, but you haven't reached the threshold for conversion modelling (Google's estimate of conversions it couldn't see). That threshold is 700 ad clicks over 7 days for a domain and country.
- "Consent mode is implemented and modeling is active": modelling is running.
Google says the status can take 48 hours to appear, and up to two weeks in some cases. If you see neither after that (the "not detected" case), go back to Check 1. Ads reports what your tags sent; Tag Assistant shows you why.
The usual failures, and what they look like
| What you see | Likely cause | Fix |
|---|---|---|
| Consent tab empty | Consent Mode isn't set up | Add defaults through your banner or a consent tag |
| "Default consent set too late" error | Banner script loads after Tag Manager, or its tag fires on All Pages | Put the defaults above the Tag Manager snippet, or on Consent Initialization |
| Defaults right, update never appears | Banner saves the choice but never sends the update | Ask your banner provider; the update must fire on every click |
| Same result from every region | Region settings missing or wrong | Use ISO codes like DE or US-CA; there's no single code for the EU, so list each country |
l in the last two gcd positions | ad_user_data or ad_personalization missing | Add both to the default and the update; personalised ads need both granted |
On the region point: Google's setup guide says regions use ISO 3166-2 codes, and when a country and one of its states both have a default, the more specific one wins. A typo like US-California simply doesn't match, so that visitor falls back to whatever default has no region.
For which rules each region should get, see how consent works. And remember that Tag Assistant checks one visit that you start. It won't tell you if something breaks next week, which is the gap our comparison with GTM Preview covers.
Where TagSentry fits
TagSentry is one line of code above Google Tag Manager. It sets Google Consent Mode v2 before any tag runs: denied by default, and granted where visitors can opt out, unless they already have. That covers Check 1 and Check 4. To see where you stand now, the free scan checks whether your site has a banner and whether it stops trackers.
Sources
- Google for Developers: Troubleshoot consent mode with Tag Assistant
- Google for Developers: Set up consent mode on websites
- Google for Developers: Consent mode overview (gcs and gcd parameters)
- Google Ads Help: Verify consent mode implementation
- Tag Manager Help: Consent mode reference
- Tag Manager Help: Consent settings and the Consent Initialization trigger
- Simo Ahava: Consent Mode V2 for Google tags (gcs and gcd decoding)