The short answer
In Tag Manager, each tag has a consent setting under Advanced Settings. "Not set" means Tag Manager won't hold the tag for any consent beyond what the tag checks by itself. Google's own tags check Consent Mode on their own. Everyone else's tags don't, so a Meta or TikTok tag on "Not set" fires whatever the visitor chose.
Where the setting lives
Open any tag in Tag Manager, then Advanced Settings, then Consent Settings. You'll see three options:
- Not set: the default for most tags.
- No additional consent required: you've decided this tag doesn't need any.
- Require additional consent for tag to fire: pick which consent types (like
ad_storage) must be granted first.
Above that, some tags show Built-in consent checks. That's a read-only list of what the tag already respects by itself.
Built-in versus additional consent
This is the distinction that trips people up.
Built-in checks exist only on tags whose code understands Consent Mode. Google's own tags (the Google tag, GA4 events, Google Ads, Floodlight) have them. They'll adjust what they do based on ad_storage, analytics_storage and the rest without you configuring anything, as long as Consent Mode defaults are set early on the page.
Additional checks are Tag Manager holding a tag until a consent type is granted. This is how you control tags that know nothing about Consent Mode: Meta Pixel, TikTok, LinkedIn, Hotjar, most custom HTML.
| Tag type | Built-in checks | What to set |
|---|---|---|
| Google tag, GA4, Google Ads | Yes | Usually leave as is; Consent Mode handles them |
| Meta, TikTok, LinkedIn, Pinterest (template or custom HTML) | Usually no | Require additional consent, typically ad_storage |
| Hotjar, Clarity, session recording | No | Require analytics_storage |
| Chat widgets, A/B testing | Varies | Decide per tool, then set it explicitly |
| Strictly necessary (fraud, load balancing) | n/a | "No additional consent required", deliberately |
Why "Not set" is a problem
"Not set" isn't a decision. It's the absence of one. For a Google tag it's mostly fine, because the tag checks by itself. For a Meta Pixel it means the tag fires on every page for every visitor, whatever they clicked.
It also makes audits hard. When every tag says "Not set", you can't tell which ones someone thought about.
The 20-minute audit
- Turn on the consent overview. In the container, go to Admin, Container Settings, and tick "Enable consent overview". A shield icon appears on the Tags list.
- Open the consent overview. It groups tags into "Consent not configured" and "Consent configured". Start with the first group.
- For each tag, decide. Is it Google's (built-in checks)? Is it necessary? Or does it need
ad_storageoranalytics_storagefirst? Set it explicitly, even if the answer is "No additional consent required". - Check the order of defaults. Your Consent Mode defaults must be set before any tag runs. Either from a script above the Tag Manager snippet, or a tag on the "Consent Initialization" trigger. A default set on "All Pages" is too late.
- Look for blocking triggers on Google tags. If someone added "only fire when consent is granted" triggers to your GA4 or Google tag, you're probably losing page views you didn't need to lose. Let Consent Mode handle those.
- Test in preview, in two regions. Check the Consent tab on the first event: the default state should be there before any tag fires. Then accept, and check it updated.
- Write down what you decided. A short list of tag, purpose and consent type. It'll save the next person hours.
The ordering problem, again
A surprising number of "consent isn't working" threads come down to order. One Tag Manager user described it well: "the consent mode loads at the end of the events chain… it should activate before the page loads." If your consent tool runs as a tag in the container, check which trigger it uses. Consent Initialization exists for exactly this.
Keeping it right
The audit gets stale the day someone adds a new tag. One practitioner on r/gdpr pointed out that many consent tools only rescan weekly or monthly, "so a new script or tag can slip through undetected for weeks." Put a recurring reminder on the calendar, or use something that checks continuously.
How TagSentry helps
With Tag Manager connected, TagSentry reads every tag in your container, sorts each one by purpose, and shows you the consent settings it would change. Nothing changes in Tag Manager until you approve it, and every change is a new version there, naming the one it replaced. Trackers outside the container are found by a scan of your live site.