# Google Consent Mode v2, explained without the jargon

What Consent Mode actually does, the signals it sends, the difference between Basic and Advanced, and the mistakes that quietly cost you conversions.

_The TagSentry team · September 22, 2026 · https://tagsentry.ai/blog/google-consent-mode-v2-explained_

> **The short answer:** Consent Mode is a set of on/off signals your site sends to Google's tags before they run. It doesn't show a banner and it doesn't make you follow any law. It tells Google's tags what the visitor agreed to, so they can behave accordingly. Get the defaults wrong and you either track people you shouldn't, or throw away data you were allowed to keep.

## What it is, in one paragraph

Consent Mode is Google's way for a website to tell its Google tags (Analytics, Ads, Floodlight) what a visitor has agreed to. Your cookie banner collects the answer. Consent Mode passes that answer to Google's tags as a handful of named signals, each either `granted` or `denied`. The tags read those signals and change what they store and send.

It is not a cookie banner. It is not a consent record. It only covers Google's own tags. A Meta Pixel or Hotjar script ignores it completely, so those need to be held some other way.

## The signals

Version 2 arrived in March 2024, when Google made two extra signals a requirement for measuring and advertising to people in the European Economic Area. These are the ones that matter:

| Signal | What it controls |
|---|---|
| `ad_storage` | Whether ad cookies can be read or written |
| `analytics_storage` | Whether analytics cookies can be read or written |
| `ad_user_data` | Whether data about the user can be sent to Google for advertising (new in v2) |
| `ad_personalization` | Whether that data can be used for personalised ads and remarketing (new in v2) |
| `functionality_storage` | Cookies the site needs for features like language |
| `security_storage` | Cookies for security, like fraud prevention |

Most consent tools set all six. Google's tags only act on the first four.

## Defaults and updates

Every page load has two moments.

1. **The default.** Before any Google tag runs, the page says what the signals are for someone who hasn't answered yet. In the EU, UK and similar places, that should be `denied`. In most US states, where the law lets people opt out instead of asking first, it is usually `granted`.
2. **The update.** When the visitor answers the banner, the page sends the new state. From then on, Google's tags follow the answer.

The single most common failure is order. If the default is set after a Google tag has already run, that tag fired with no instructions at all. One practitioner put it plainly on Reddit: everything works in staging because there's no banner, then in production the consent tool loads a split second after Tag Manager "and half the conversion events just never fire."

## Basic and Advanced, plainly

Google offers two ways to run Consent Mode, and the names don't help.

**Basic mode** holds Google's tags completely until the visitor agrees. Nothing from Google loads before consent. If someone never answers, or says no, Google hears nothing about that visit.

**Advanced mode** lets Google's tags load straight away, with no cookies. Until the visitor agrees, they send what Google calls cookieless pings: a request that says a page was viewed or a conversion happened, with the consent state attached and no identifiers stored. Google uses these to estimate the conversions it can't see directly.

| | Basic | Advanced |
|---|---|---|
| Google's tags before a choice | Don't load | Load, no cookies |
| Requests before a choice | None | Cookieless pings |
| Conversion modelling | Limited | Available, if you have enough traffic |
| Strictest reading of EU rules | Closer | Debated |

> **The modelling catch** Modelling only kicks in above a threshold. Google Analytics needs at least 1,000 events a day with analytics storage denied for seven days, plus at least 1,000 daily users who did consent. Google Ads conversion modelling needs 700 ad clicks over seven days per country. Most small sites never reach either, so they get the pings but not the recovered numbers.

Which one is right depends on your appetite for risk and where your visitors are. Many German sites choose Basic, because a 2025 German court decision treated loading Tag Manager before consent as something that itself needs consent. Many US-focused sites choose Advanced.

## What changed in June 2026

On 15 June 2026, Google changed how Analytics data reaches Google Ads. Since then, `ad_storage` alone decides whether ad data collected by Google Analytics is shared with Ads. Before, Google Signals also had a say.

The practical effect: a wrong `ad_storage` default now shows up directly as missing conversions in Google Ads. If your Ads numbers moved in late June, check that signal first.

## What goes wrong, most often

- **The default is set too late.** Google's tags run before the default arrives. Check the order in Tag Manager's preview, looking at the very first event on the page.
- **The strictest rules are applied to everyone.** A banner that denies everything for US visitors throws away data those visitors never asked you to drop. This is [the most common reason analytics falls](/blog/why-analytics-dropped-after-cookie-banner) after a banner goes up.
- **Tags have no consent settings.** In Tag Manager, a tag whose [consent settings are "Not set"](/blog/gtm-consent-settings-not-configured) doesn't wait for anything beyond Google's built-in checks. Non-Google tags in that state fire regardless.
- **The update never fires.** The banner records the answer but nothing tells Google's tags. Everything stays on the default forever.
- **The two new signals are missing.** A setup from before 2024 may only send `ad_storage` and `analytics_storage`. Without `ad_user_data` and `ad_personalization`, EEA audiences and some measurement features stop working.

## How to check yours in five minutes

1. Open your site in a private window, from the region you care about.
2. Open Tag Manager's preview mode, or your browser's network panel filtered to `google`.
3. Look at the first Google request. Find the `gcs` parameter. `G100` means both storage signals were denied; `G111` means both were granted.
4. Answer the banner, reload, and check that the value changed.
5. Repeat from a US connection. If you see `G100` there too, you are applying EU rules to American visitors.

For a fuller test, work through our [Consent Mode v2 checklist](/blog/check-consent-mode-v2-working).

## Where TagSentry fits

TagSentry [sets Consent Mode defaults](/docs/how-consent-works) from a single line that sits above your Tag Manager code, so they are in place before any Google tag runs. Every visitor starts `denied`, and visitors in opt-out regions switch to `granted` as soon as their region is known. Advanced is the default and Basic is one switch. Either way, you can see what each tag did.

## Sources

- [Google Tag Manager Help: Consent mode overview](https://support.google.com/tagmanager/answer/13695607?hl=en)
- [Google Analytics Help: Behavioral modeling for consent mode](https://support.google.com/analytics/answer/11161109?hl=en)
- [Google Ads Help: About consent mode conversion modeling](https://support.google.com/google-ads/answer/10548233?hl=en)
- [OneTrust: What Google's June 2026 Consent Mode changes mean for Google Ads](https://www.onetrust.com/blog/what-googles-june-2026-consent-mode-changes-mean-for-google-ads/)
- [Usercentrics: Google Signals and Consent Mode changes in 2026](https://usercentrics.com/knowledge-hub/google-signals-consent-mode-changes-2026/)
- [r/GoogleAnalytics: Consent Mode silently blocking events](https://www.reddit.com/r/GoogleAnalytics/comments/1weaz6m/_/p9he6xw/)
- [iubenda: Google Tag Manager and GDPR after the German court decision](https://www.iubenda.com/en/blog/google-tag-manager-and-gdpr-what-a-recent-german-court-decision-means/)
