Google Consent Mode v2 and Cookie Consent: A Setup Guide for Business Sites

How to set up Google Consent Mode v2 alongside a compliant cookie banner: ePrivacy and PECR consent rules, the GDPR consent standard, the four consent parameters, basic versus advanced mode, CMP requirements, WordPress and Shopify implementation, Tag Assistant testing and common mistakes.

Google Consent Mode v2 and Cookie Consent: A Setup Guide for Business Sites article cover image

Google Consent Mode v2 is the mechanism that tells Google tags whether a visitor has agreed to advertising and analytics storage, using four signals: ad_storage, analytics_storage, ad_user_data and ad_personalization. If you use Google Ads measurement, remarketing or personalisation for visitors in the EEA, Google requires you to collect consent and pass these signals. Consent Mode does not collect consent itself: you still need a cookie banner that meets EU and UK law, with tags set to "denied" by default until the visitor chooses.

This guide covers the legal rules behind the banner, how Consent Mode v2 works, how to implement it on WordPress, WooCommerce and Shopify with working code, how to test it, and the mistakes that most often break compliance or measurement.

This article is general information, not legal advice. Cookie rules are applied differently by national regulators, so check guidance in the countries where your visitors are.

In the EU, Article 5(3) of the ePrivacy Directive requires consent before storing or accessing information on a user's device, unless it is strictly necessary to provide the service the user requested. This covers cookies, local storage, pixels and similar technologies, not only cookies. Shopping cart cookies, login sessions and security tokens are generally exempt; advertising, remarketing and most analytics are not.

The UK applies the same principle through the Privacy and Electronic Communications Regulations (PECR). As of 2026, PECR has been amended by the Data (Use and Access) Act 2025, which introduced additional exceptions, including one for certain statistical (analytics) purposes, provided users receive clear information and a simple, free way to object. The ICO's guidance on storage and access technologies explains the conditions. Tracking and profiling for advertising still require consent in the UK. The EU has no equivalent analytics exception, so a site serving both markets usually keeps consent for analytics too.

Where consent is required, it must meet the GDPR definition in Article 4(11) and Article 7: freely given, specific, informed and unambiguous, given by a clear affirmative action, and as easy to withdraw as to give. For cookie banners that translates to:

  • no pre-ticked boxes (the Court of Justice confirmed this in Planet49, C-673/17, in 2019);
  • no tracking before the visitor acts, and scrolling or continuing to browse is not consent;
  • a "Reject" option as prominent and easy as "Accept", typically on the first layer;
  • separate choices for separate purposes (analytics, advertising);
  • clear information on who sets each cookie and why;
  • a persistent way to change or withdraw consent, such as a footer link.

Google's consent mode developer documentation defines the parameters:

ParameterControls
ad_storageStorage (such as cookies) related to advertising
analytics_storageStorage related to analytics, such as visit duration
ad_user_dataWhether user data can be sent to Google for advertising purposes
ad_personalizationWhether data can be used for personalised advertising, such as remarketing

The "v2" update added ad_user_data and ad_personalization. Each is set to "granted" or "denied". Your banner sets defaults when the page loads and sends an update when the visitor makes a choice.

Google describes two implementations in its consent mode overview:

  • Basic: Google tags do not load until the visitor interacts with the banner. No data goes to Google before consent. If the visitor declines, nothing is sent. Simple and conservative, but Google has less data for conversion modelling.
  • Advanced: Google tags load immediately with consent defaults. While consent is denied, tags do not set advertising or analytics cookies, but they send cookieless pings that Google uses for modelling. If the visitor accepts, full measurement resumes.

Which to choose is partly a legal judgement. Advanced mode sends limited data to Google before consent, and some EU regulators and advisers take a stricter view of that than others. Basic mode is the safer default if you are uncertain; advanced mode improves modelled conversions. Decide deliberately and document why.

What Google requires for EEA and UK traffic

Google's consent mode update for EEA traffic states that to keep using applicable tags for measurement, ad personalisation and remarketing features, you must collect consent for use of personal data from end users based in the EEA and share consent signals with Google. Google's EU user consent policy also covers users in the UK and Switzerland, so treat all three the same way.

Do you need a Google-certified CMP?

It depends on what you use Google for:

  • Publishers that show ads through AdSense, Ad Manager or AdMob to users in the EEA, UK or Switzerland must use a Google-certified consent management platform integrated with the IAB Transparency and Consent Framework.
  • Advertisers using Google Ads and Google Analytics are strongly recommended by Google to use a certified CMP, which updates consent signals automatically, but a correct custom implementation using the consent mode API is also possible.

For most small businesses a certified CMP is the lowest-maintenance route, because it keeps up with Google's changes and provides consent records.

Implementation on WordPress and WooCommerce

Option 1: A certified CMP plugin

Most WordPress sites should use a consent plugin from a Google-certified CMP. The typical settings path is:

  1. 1Install the CMP's WordPress plugin and connect your account.
  2. 2Run its cookie scan and categorise each cookie (necessary, preferences, statistics, marketing).
  3. 3Enable its Google Consent Mode v2 integration and choose basic or advanced mode.
  4. 4Configure the banner: "Accept all", "Reject all" and "Settings" on the first layer, equal visual weight.
  5. 5Set the region behaviour, for example opt-in consent for EEA, UK and Switzerland.
  6. 6Add a "Cookie settings" link in the footer.

If you use Site Kit by Google, its Consent Mode setting works with the WP Consent API and compatible consent plugins, so the plugin's choices reach Google tags without custom code. Avoid loading the Google tag twice (for example, once through Site Kit and once through a theme option or a WooCommerce analytics plugin); duplicate tags make consent behaviour unpredictable and inflate conversions.

Option 2: Custom gtag implementation

If you manage tags yourself, the consent default must run before the Google tag loads and before any config or event command. Place this as high as possible in the head:

`html

<script>

window.dataLayer = window.dataLayer || [];

function gtag(){dataLayer.push(arguments);}

// 1. Defaults: everything denied until the visitor chooses.

gtag('consent', 'default', {

'ad_storage': 'denied',

'ad_user_data': 'denied',

'ad_personalization': 'denied',

'analytics_storage': 'denied',

'wait_for_update': 500

});

// Optional: redact ad identifiers and pass click IDs in URLs while denied.

gtag('set', 'ads_data_redaction', true);

gtag('set', 'url_passthrough', true);

</script>

<!-- 2. The Google tag loads after the defaults. -->

<script async src="https://www.googletagmanager.com/gtag/js?id=G-XXXXXXXXXX"></script>

<script>

gtag('js', new Date());

gtag('config', 'G-XXXXXXXXXX');

</script>

`

Replace G-XXXXXXXXXX with your own measurement ID. Then, when the visitor chooses in your banner, call an update with their actual choices and store the decision so it can be re-applied on later page views:

`html

<script>

function applyConsent(choice) {

gtag('consent', 'update', {

'analytics_storage': choice.analytics ? 'granted' : 'denied',

'ad_storage': choice.marketing ? 'granted' : 'denied',

'ad_user_data': choice.marketing ? 'granted' : 'denied',

'ad_personalization': choice.marketing ? 'granted' : 'denied'

});

try { localStorage.setItem('consent', JSON.stringify(choice)); } catch (e) {}

}

// Re-apply a stored choice on every page view.

try {

var saved = JSON.parse(localStorage.getItem('consent'));

if (saved) applyConsent(saved);

} catch (e) {}

// Wire these to your banner buttons:

// Accept all: applyConsent({ analytics: true, marketing: true });

// Reject all: applyConsent({ analytics: false, marketing: false });

</script>

`

For the stored-choice update to take effect before tags fire, run it in the same early script block as the defaults. This is the basic pattern; a production banner also needs consent records, a settings panel and an accessible, keyboard-operable interface.

If you use Google Tag Manager, set defaults with a Consent Initialization trigger, enable consent overview in the container settings, and configure each non-Google tag (Meta, TikTok, Pinterest, Microsoft Ads) to require the relevant consent. Consent Mode only controls Google tags; third-party pixels must be blocked by your CMP or tag manager until consent.

Implementation on Shopify

Shopify provides a native cookie banner (Settings, then Customer privacy) and the Customer Privacy API, which records visitor consent for analytics, marketing, preferences and sale of data. Shopify's own apps and customer event pixels read those settings. If you use a certified CMP app instead, it should write choices to the Customer Privacy API so Shopify and apps stay in sync.

If you add Google tags through theme code rather than an app, map Shopify's consent to Consent Mode. This snippet, placed in the theme after the gtag defaults shown above, listens for Shopify consent and updates Google:

`html

<script>

function syncShopifyConsent() {

var cp = window.Shopify && window.Shopify.customerPrivacy;

if (!cp) return;

var analytics = cp.analyticsProcessingAllowed();

var marketing = cp.marketingAllowed();

gtag('consent', 'update', {

'analytics_storage': analytics ? 'granted' : 'denied',

'ad_storage': marketing ? 'granted' : 'denied',

'ad_user_data': marketing ? 'granted' : 'denied',

'ad_personalization': marketing ? 'granted' : 'denied'

});

}

window.Shopify.loadFeatures(

[{ name: 'consent-tracking-api', version: '0.1' }],

function (error) {

if (error) return;

syncShopifyConsent();

}

);

document.addEventListener('visitorConsentCollected', syncShopifyConsent);

</script>

`

Before adding code, check whether your Google channel app or CMP app already sends Consent Mode signals. Two sources updating consent can conflict, and a second copy of the Google tag duplicates conversions. For a broader setup sequence, see the Shopify store setup checklist.

  1. 1Open Tag Assistant, add your site URL and connect. Use a private window so no earlier choice is stored.
  2. 2Before touching the banner, select the first event in the Tag Assistant timeline and open the Consent tab. All four parameters should show "denied" as the on-page default.
  3. 3Check that no advertising or analytics cookies (for example, _ga or _gcl_au) appear in the browser's DevTools under Application, then Cookies, before consent.
  4. 4Click "Reject all". Confirm the update keeps everything denied and that marketing pixels from other vendors do not fire in the Network tab.
  5. 5Clear the site data, reload and click "Accept all". The Consent tab should show an on-page update with all four parameters granted.
  6. 6Navigate to another page and confirm the stored choice is re-applied without the banner reappearing.
  7. 7In Google Analytics, open Admin and, under Data collection and modification, select Consent settings to confirm Analytics is receiving consent signals for measurement and personalisation. In Google Ads, check the consent diagnostics shown for your conversion actions.

Validate your events and revenue data after the change, because consent affects what gets recorded. The GA4 e-commerce analytics guide covers event validation, and the SEO reporting dashboard guide explains how to annotate reporting when measurement changes.

Common Mistakes

MistakeWhy it is a problemFix
Tags fire before consentBreaches ePrivacy or PECR regardless of Consent ModeSet defaults before the Google tag; block non-Google pixels until consent
Defaults set after the Google tagEarly hits go out without consent stateMove the default command above gtag.js or use Consent Initialization in GTM
Pre-ticked boxes or "legitimate interest" toggles switched onNot valid consent under GDPRAll non-essential categories off by default
Reject harder than AcceptRegulators treat this as invalid consentEqual "Accept all" and "Reject all" on the first layer
Only ad_storage and analytics_storage setMissing v2 parameters; Google treats ads data as not consentedSend all four parameters in default and update
Consent Mode but no bannerConsent Mode signals nothing without a real choiceUse a CMP or banner that records choices
Third-party pixels ignoredConsent Mode controls only Google tagsGate Meta, TikTok and other pixels through the CMP
No way to change choicesWithdrawal must be as easy as giving consentAdd a persistent "Cookie settings" link
Banner not accessibleKeyboard and screen reader users cannot chooseFocusable buttons, visible focus, proper labels

A compliant banner and a correct Consent Mode setup protect you legally and keep Google's measurement working for EEA and UK visitors. The pattern is always the same: deny by default, ask clearly, make rejecting as easy as accepting, update Google with the real choice and test it. If you want this set up or audited on your WordPress, WooCommerce, Shopify or Next.js site, see Cookie Consent & Privacy Compliance Setup or contact us.

Related posts

Author

Anushka Dahanayake

Anushka Dahanayake builds SEO-focused websites, e-commerce platforms, dashboards, and automation systems for businesses worldwide.