Consent Mode v2 adds two new advertising signals, ad_user_data and ad_personalization, on top of the original ad_storage and analytics_storage parameters. If you run Google Ads or GA4 on a UK site, you need to implement or upgrade to v2 to keep full functionality for EEA and UK visitors, and to stay on the right side of PECR. The immediate job is simple: check your default consent state, wire up the update commands in gtag or Google Tag Manager, or confirm your consent tool already handles v2 for you.
TL;DR:
- Implementing or upgrading to Consent Mode v2 is essential for proper data collection and compliance on UK sites using Google Ads or GA4, especially for EEA and UK visitors.
- Using basic mode ensures full compliance but results in no data for visitors who decline or ignore consent banners, while advanced mode allows some data recovery through cookieless signals.
- Correct setup requires placing default consent commands before any tags load and updating consent after user decisions, with verification done via Tag Assistant’s Consent tab.
- UK law mandates specific, informed, and freely given consent for cookies, requiring banners to provide granular choices and the ability to withdraw consent easily, regardless of Consent Mode.
- Small businesses should prioritise proper implementation to avoid skewed reporting, reduced remarketing audiences, and ineffective ad campaigns caused by incomplete consent signals.
Table of Contents
- What changed between consent mode v1 and v2
- Basic mode versus advanced mode: which one fits your site
- Implementation checklist: gtag.js, Tag Manager and server-side
- How to verify your setup with Tag Assistant
- What UK law actually requires beyond the technical setup
- The practical checklist agencies actually run
- Staying compliant with GDPR beyond the UK
- How v1 compares with v2 and other consent frameworks
- Privacy and security considerations worth understanding
- Real-world benefits once it’s working properly
- What it means for your advertising numbers
- Why we think small UK businesses can’t afford to skip this
- How TTOY Digital handles this for small business sites
- Sources
- FAQ
What changed between consent mode v1 and v2
Consent Mode v2 is Google’s update to its consent signalling framework, and it adds two new parameters to the two that already existed. You now need to communicate all four: ad_storage, analytics_storage, ad_user_data and ad_personalization. The first two control whether cookies can be set for advertising and analytics. The two newer ones tell Google whether it can use personal data for ad targeting and whether that data can feed personalised advertising.

Miss the new pair and Google quietly scales back what it will do with your data, even if the visitor accepted cookies. Google Ads support pages are explicit that missing consent signals for EEA and UK traffic switch off personalisation and advertising features and limit conversion tracking. Google brought in v2 largely because European regulators wanted clearer, more granular signals than the original two-parameter version gave them. For a small business running Google Ads to England-based customers, the practical upshot is that your remarketing lists, conversion tracking and audience data all depend on getting these four signals right.
Basic mode versus advanced mode: which one fits your site
Once you know which parameters you need to send, the next decision is how. Google offers two implementation routes: basic and advanced.
Basic mode blocks Google tags entirely until a visitor makes a choice on your banner. Nothing fires, nothing pings, until consent is granted. It is the simplest to build and the safest from a compliance standpoint, but it comes at a measurement cost: anyone who never interacts with the banner, or who declines, leaves no data trail at all.
Advanced mode takes a different approach. Tags load straight away with denied defaults, then send cookieless pings to Google even when consent hasn’t been granted. Those pings feed statistical modelling that helps recover some of the conversion data you would otherwise lose.
- Basic mode: tags stay dormant until consent, so declined or ignored banners produce zero data for that visitor.
- Advanced mode: tags load immediately with signals denied, and cookieless pings support conversion modelling even without explicit consent.
- Modelling quality: advanced mode generally recovers more conversions because it has cookieless signals to model from, while basic mode relies on broader, less precise recovery.
For remarketing lists and demographic reporting specifically, advanced mode tends to hold up better because Google has more raw signal to work with, even when it can’t attribute a conversion to an individual. Basic mode is easier to implement correctly, which matters if you don’t have a developer on tap, but you should go in knowing your reporting will have bigger gaps.
Implementation checklist: gtag.js, Tag Manager and server-side
Whichever mode you choose, the sequence of steps is largely the same. Get this order wrong and the whole thing can fail silently, which is the single most common problem we see when auditing existing setups.
- Set default consent before anything else loads. Using gtag.js, place
gtag('consent', 'default', {...})for all four parameters (ad_storage, analytics_storage, ad_user_data, ad_personalization) as the very first script on the page, ahead of your Tag Manager container or any Google tag. - Fire the update command when a visitor makes a choice. When your banner registers a decision, call
gtag('consent', 'update', {...})with the relevant values. This is what tells Google the visitor’s actual preference, replacing your defaults. - In Google Tag Manager, use the built-in Consent Initialisation trigger so your default consent settings fire before any other tag, and make sure your community CMP template (if you use one) is mapping its consent categories to Google’s four tokens correctly.
- Place the Conversion Linker tag so it respects the same consent settings, since a misconfigured Conversion Linker is a frequent cause of broken attribution even when consent signals look fine elsewhere.
- For server-side tagging, relay consent from the web container to the server container. Google’s server-side documentation sets out how the GA4 client and Conversion Linker inside the server container need to read and respond to those same consent values, with region settings configured so behaviour differs correctly between UK and non-UK visitors.
- Confirm your CMP actually supports v2 before you assume it does. Many older CMP installs still only send the original two parameters, so check the vendor’s own documentation and map its consent categories explicitly to all four Google tokens, then test what the defaults look like for a UK visitor versus an EEA one.
Pro Tip: Test your default consent code in an incognito window with the network tab open before you touch the CMP mapping. If the four parameters aren’t in the very first tag request, nothing downstream will behave correctly.
If you’re on WordPress, a GDPR cookie compliance plugin can handle much of this, but you still need to confirm it maps to v2’s four parameters rather than the older pair.
How to verify your setup with Tag Assistant
Once it’s live, don’t assume it works. Google’s own debugging guide points to Tag Assistant’s Consent tab as the first port of call.
- Open Tag Assistant, load your site, and check for the On-page Default event, which should appear before any other Google tag fires.
- Look for the On-page Update event once you interact with the consent banner, confirming your update command actually ran.
- Inspect the API Call output for both events and confirm all four parameters, ad_storage, analytics_storage, ad_user_data and ad_personalization, are present, not just the original two.
- If the default event fires late, after other tags have already loaded, that’s usually a script-ordering problem, not a code error, and moving the default snippet higher in the page fixes most of these.
- If update events never fire, check your banner’s event listeners are actually calling the gtag update command rather than just hiding the banner.
- If a CMP is installed but only sending two parameters, go back to its category-mapping settings, since most vendors have added v2 support but don’t always enable it by default.
What UK law actually requires beyond the technical setup
Consent Mode is a signalling mechanism, not a legal shortcut. The ICO is direct on this point: legitimate interests cannot replace consent for most cookies and similar technologies under PECR, and the regulator has separately debunked the idea that any clever legal basis lets you skip asking. Valid consent under PECR has to be specific, informed and given through a positive action, so a pre-ticked box or a banner that only offers “accept” doesn’t count.
Practically, that means your banner needs to give “reject” the same visual weight as “accept”, offer granular choices where you use cookies for more than one purpose, and let visitors withdraw consent as easily as they gave it. Keep a record of what was chosen and when, since you may need to show it. The ICO’s practical guidance also points to refreshing consent periodically, and six months is a reasonable working guideline for many sites. For a plain-English primer on what cookies actually do before you get into consent mechanics, our cookie basics guide covers the fundamentals.
The practical checklist agencies actually run
We work through this in a fairly fixed order when we take on a client’s consent setup, whether that’s a full rebuild or a quick health check on an existing site.
- Audit first: check what GA4, Ads and the CMP are currently sending, and whether server-side containers are even in the mix.
- Plan the mode: weigh basic against advanced based on how much you rely on remarketing versus how cautious the business wants to be.
- Execute the code: get default and update commands placed correctly, GTM workspace checked, server container configured if you’re running one.
- Verify and monitor: run the Tag Assistant checks, then keep an eye on regional consent behaviour for the following weeks and log any changes.
Staying compliant with GDPR beyond the UK
If your site draws any traffic from EU countries, whether through Ads targeting, organic reach or a supplier relationship, GDPR applies alongside PECR, and the two frameworks broadly align on consent standards. The same principles of specific, informed, freely given consent apply across the EU, though enforcement and guidance detail can vary slightly by member state’s data protection authority.
Consent Mode v2 itself doesn’t distinguish between UK and EU visitors in how it’s coded. What changes is the region setting inside your Tag Manager or server-side configuration, which lets you apply different default behaviours if your legal advice differs between markets. Many small UK businesses selling to EU customers, or running Ads campaigns targeting EU cities, treat the whole EEA and UK block as one consent standard rather than maintaining separate rules, which tends to be simpler to build and easier to defend if questioned. If you trade with EU customers regularly, it’s worth having your consent wording checked against both PECR and the GDPR requirements of any specific member state you target heavily, since local guidance occasionally adds detail the ICO doesn’t cover.

How v1 compares with v2 and other consent frameworks
The original Consent Mode covered two signals, ad_storage and analytics_storage, and that was enough to tell Google whether cookies could be set. It said nothing about how personal data could be used once collected, which is the gap v2 closes with ad_user_data and ad_personalization.
Outside Google’s own framework, most consent management platforms build on the IAB’s Transparency and Consent Framework (TCF), which standardises how vendors declare their purposes and how consent choices get passed between them. Consent Mode v2 doesn’t replace TCF. It sits alongside it: your CMP handles the TCF-side consent collection and legal record-keeping, then maps those choices onto Google’s four parameters so Ads and GA4 know what they’re allowed to do. Sites still running v1 will find their tags increasingly restricted, since Google’s own guidance ties full functionality to the newer signal set, so treating this as optional is no longer realistic for anyone serious about ad performance.
Privacy and security considerations worth understanding
Consent Mode v2 is a signalling layer, not a data vault. It tells Google what it can and cannot do with data your site already has permission to collect, but it doesn’t encrypt anything, anonymise anything on its own, or stop a poorly configured tag from firing when it shouldn’t.
The main privacy benefit is that, done properly, it stops your site quietly sending personal data to Google when a visitor has said no. The main risk, if done badly, is the opposite: a misconfigured default that grants consent rather than denies it by mistake, or a CMP mapping error that sends the wrong signal. Advanced mode’s cookieless pings are designed to avoid transmitting identifiable data even before consent is given, but that protection only holds if the implementation matches Google’s specification. Security-wise, the bigger exposure for most small sites is usually the CMP plugin itself: an outdated cookie consent plugin is as much a risk as getting the consent signals wrong, so keeping it patched matters as much as the mapping.
Real-world benefits once it’s working properly
The clearest case for getting this right is a small retailer running Google Ads to drive footfall or online sales across Derbyshire and South Yorkshire. Without correct consent signals, a meaningful chunk of visitors who decline cookies simply vanish from reporting, making campaigns look worse than they are and skewing bidding decisions that rely on conversion data.
With advanced mode correctly implemented, that same retailer keeps enough modelled conversion data to let Google’s bidding algorithms keep optimising sensibly, even for visitors who didn’t consent. A service business relying on remarketing lists to bring back people who browsed but didn’t book sees a similar effect: without the newer parameters, those lists thin out over time as more browsers are excluded from tracking. Getting the setup right doesn’t create new data out of nothing, but it stops you losing visibility you’re otherwise entitled to have.
What it means for your advertising numbers
The parameters you send directly shape what Google Ads can do with your traffic. Correct signals for ad_user_data and ad_personalization determine whether Google can use a visitor’s data for personalised ads at all, which affects remarketing list size, lookalike or similar-audience targeting, and how much of your conversion data survives for bid optimisation.
Google’s own advertiser guidance is blunt that failing to send correct signals for EEA and UK traffic limits conversion tracking and switches off personalisation features outright, not just partially. For a small business with a modest ad budget, that’s the difference between a campaign that can learn and improve and one flying blind on incomplete data. Preserving that measurement isn’t just a technical tidiness exercise, it’s what keeps your ad spend efficient, and it’s the same argument BabyLoveGrowth make about analytics generally: decisions built on solid data tend to outperform decisions made on guesswork.
Why we think small UK businesses can’t afford to skip this
Ad spend without reliable conversion data is money spent on hope. For a small business, every pound needs to earn its keep, and Consent Mode v2 is what keeps that data honest. If you’ve got a developer and half a day, do it yourself. If you don’t, it’s worth paying someone who does this weekly rather than losing a weekend to it. Start with the default consent code, then the update commands, then verify.
— Chris
How TTOY Digital handles this for small business sites
We integrate consent handling into web design and CRM work for small businesses, ensuring it is a built-in feature rather than an afterthought. Getting this wrong quietly costs you ad performance and conversion data you’ll never get back, which is exactly the kind of problem we like solving.
- Audit: existing GA4, Ads and CMP setups are checked against the four required parameters.
- Implement: the default and update code is placed correctly, whether using gtag.js, GTM, or a server-side container.
- Verify: Tag Assistant checks are run to confirm correct implementation.
- Monitor: we keep an eye on regional consent behaviour after launch as part of our ongoing web design support, and where your setup needs CRM-linked conversion data, our CRM services cover the server-side mapping too.
If your site is on WordPress and you’d rather have someone else keep the plugins and consent tooling patched, our WordPress Maintenance plan folds that in alongside hosting. Get in touch and we’ll tell you honestly whether your current setup needs a rebuild or just a few fixes.
Sources
FAQ
What are the new cookie rules in the UK?
UK cookie rules still sit under PECR, enforced by the ICO, which requires prior, specific and freely given consent before setting most non-essential cookies. There’s no separate “new” UK cookie law beyond this, but the ICO has recently reinforced that legitimate interests cannot be used as a workaround, as set out in its guidance on storage and access technologies.
Is Google consent mode mandatory?
Consent Mode itself isn’t a legal requirement, but sending correct consent signals is effectively necessary if you want full Google Ads and Analytics functionality for UK and EEA traffic. Google is explicit that missing signals switch off personalisation and limit conversion tracking, which makes it a practical necessity rather than an optional extra.
What does consent mode do in Google Tag Manager?
In Google Tag Manager, Consent Mode controls whether tags fire based on a visitor’s consent choices, using a Consent Initialisation trigger to set defaults before any other tag loads. It then adjusts tag behaviour dynamically when the update command runs, as described in Google’s Tag Manager documentation.
Is a cookie banner mandatory in the UK?
A cookie banner isn’t explicitly named as mandatory in PECR’s wording, but in practice it’s the standard way sites obtain the valid, informed consent the ICO requires for non-exempt cookies. Without some mechanism to capture a positive consent action, most UK sites using analytics or advertising cookies would fail to meet that standard.
Recommended
- Working in Minutes: SSL Certificate Setup for UK Small Businesses
- Cloudflare for small business: practical setup guide
- Zero downtime for small business sites: Move your site to a new host
- Microsoft Defender for Business setup: a practical UK guide
Related reading: WordPress maintenance plans for small businesses · Cloudflare for small business: practical setup guide · Local SEO checklist for small businesses




