Google Consent Mode v2
Google Consent Mode v2 is the API through which a website’s consent banner tells Google Analytics and Google Ads tags what a visitor chose, using four consent types. When consent is denied, the tags send nothing in basic mode or cookieless pings in advanced mode, and Google models part of what is missing.
Consent Mode is not a consent banner and not a legal basis. It is a signalling layer between the two: your consent management platform collects the choice, Consent Mode hands it to Google’s tags, and the tags adjust what they store and send. What happens to the visitors who refuse depends on the implementation, on how much traffic the site has and on which Google report you read.
What are the four consent parameters?
Google defines four consent types. Each is either granted or denied, and in advanced mode the defaults are typically set to denied until the visitor answers:
ad_storage— storage such as cookies or device identifiers related to advertising.analytics_storage— storage such as cookies or device identifiers related to analytics, for example visit duration.ad_user_data— whether user data may be sent to Google for online advertising.ad_personalization— whether consent was given for personalised advertising.
The first two are about what the tag may store on the device. The last two are what version 2 added, and they are about what Google may do with the data once it has it. That distinction is why a site can deny storage and still send a ping, and why a setup that handles analytics cookies correctly can still be missing the two advertising signals.
Basic mode vs advanced mode
The same four parameters produce two very different data flows depending on when Google’s tags are allowed to load:
| Basic mode | Advanced mode | |
|---|---|---|
| Before the visitor answers | Tags are blocked; nothing is sent | Tags load with consent denied |
| Visitor refuses | Nothing reaches Google, not even the consent state | Cookieless pings: timestamp, user agent, referrer, consent state, ad-click identifiers |
| Modelling available | A general conversion model | Advertiser-specific conversion modelling; GA4 behavioural modelling when eligible |
Advanced mode gives Google more to model with, and it also sends data while consent is denied, including before the visitor has answered. Which trade-off is acceptable is a question for your DPO, not for the tag configuration.
What is measured and what is modelled?
Measured: visitors who grant analytics_storage are observed as usual, with users, sessions, events, sources and conversions. For visitors who refuse, basic mode observes nothing. Advanced mode observes that a hit happened, but without a cookie there is no identifier to join one hit to the next, so the pings cannot be assembled into users and sessions the way consented hits are.
Modelled: GA4’s behavioural modelling estimates users, sessions and new users for visitors who declined, from the behaviour of similar visitors who accepted. It needs advanced mode on every page and a property with at least 1,000 events a day with analytics storage denied for 7 days, plus at least 1,000 daily users with it granted for 7 of the previous 28 days, and Google notes that meeting those prerequisites does not guarantee eligibility. The estimates appear under the Blended reporting identity and not under Observed. Google Ads models conversions separately, in its Conversions column, once an account reaches 700 ad clicks over seven days per country and domain grouping.
How to read the modelled share in your own property, metric by metric, is set out in Consent Mode: what GA4 measures and what it models.
Why Consent Mode v2 matters for Google Ads in the EEA
The Digital Markets Act regulates Google as a gatekeeper; what reaches an advertiser is Google’s EU user consent policy. When Google set out its Digital Markets Act changes in March 2024, it described upgrades to its advertising products to help advertisers communicate consent under that policy. Google’s Ads Help is explicit about the consequence: to keep using its tags for measurement, ad personalisation and remarketing with end users in the European Economic Area, an advertiser must collect consent and share consent signals with Google. Google’s page for verifying those signals lists the EEA, the United Kingdom and Switzerland as regions where consent is required.
In practice that makes Consent Mode v2 the price of keeping Google Ads measurement, personalisation and remarketing working for European traffic, not an optional analytics refinement. It says nothing about how much of that traffic your own analytics will see.
What Consent Mode v2 does not restore
- The source of each refused visit. Modelling estimates totals; it does not give an unconsented visit its own channel in your reports.
- Modelled data outside the interface. The BigQuery export and other data exports, audiences, user explorer, segments with sequences, retention reports and predictive metrics contain no modelled data.
- Anything below the threshold. A property that never meets the prerequisites gets no behavioural modelling, only the consented share.
- A lawful basis. Consent Mode transmits a choice; it does not make the processing behind it lawful. That assessment sits with GDPR analytics compliance and the ePrivacy Directive.
Incapto, a Shopify store running GA4 with Consent Mode, is a measured example of the gap. Rosa Tomàs, its B2C Acquisition Manager, put it this way: “Consent Mode left us with a structural blind spot: we knew there was traffic we were not seeing, but we had no way to size it.” When the team ran Sealmetrics next to GA4 for 48 days, GA4 did not record 29% of visits. In a later ten-day window, 14% of GA4 visits had no usable origin, against 0.3% in Sealmetrics. The details are in the Incapto case study, and the wider picture in data loss in analytics.
How cookieless measurement differs
Consent Mode exists because Google’s tags depend on cookies and identifiers. Cookieless analytics removes that dependency instead of modelling around it. Sealmetrics does not use Consent Mode: it sets no cookies and stores nothing on the visitor’s device, so there is no storage for a consent type to grant or deny. It reads the source of each landing page from its UTM parameters or referrer, so the visits it records carry their channel rather than an estimate, and the same figures appear in the dashboard, the API and the export. The architecture is explained in complete data.
The limits run the other way. Sealmetrics identifies no one, so there are no user-level retention reports, cohorts or cross-session journeys. It does not send conversions to Google Ads, so it does not replace Consent Mode for bidding. Ad blockers can still stop the tracker unless it is served from a subdomain of your own domain. And whether a cookieless deployment is exempt from consent depends on its configuration and on your national authority’s criteria. If that assessment concludes it is, the common mistake is in Google Tag Manager: a Sealmetrics tag left behind a consent gate reports only the visitors who accept, which the Sealmetrics documentation lists as the most common cause of missing data.
Questions about Consent Mode v2
What is the difference between Consent Mode v1 and v2?
Version 2 adds two consent types, ad_user_data and ad_personalization, to the original ad_storage and analytics_storage. Google introduced them for traffic from the European Economic Area as part of stronger enforcement of its EU user consent policy: the two new signals say whether a visitor agreed to their data being sent to Google for advertising and to personalised ads.
Is Consent Mode v2 mandatory?
Not as a law in itself. It is Google's requirement: to keep using Google tags for measurement, ad personalisation and remarketing with visitors in the EEA, advertisers must collect consent and send consent signals to Google, and Google's verification page also lists the United Kingdom and Switzerland. Consent Mode is Google's mechanism for sending them. A site that runs no Google tags has nothing to send.
Does Consent Mode v2 recover the data lost to cookie rejection?
Partly, and as an estimate. Advanced mode sends cookieless pings when consent is denied, GA4 models users, sessions and new users once a property meets Google's thresholds, and Google Ads models conversions above 700 ad clicks over seven days per country and domain grouping. None of that turns a refused visit back into an observed session with its own traffic source.
Does modelled Consent Mode data reach BigQuery?
No. Google lists data export, including the BigQuery export, among the features without modelled data, together with audiences, user explorer, segments with sequences, retention reports and predictive metrics. A warehouse built on the export shows observed data only, so it will usually show fewer users than GA4's Blended reports.
Does Consent Mode v2 make analytics GDPR compliant?
Not on its own. Consent Mode carries the choice a visitor made in your consent banner to Google's tags; it does not decide whether you have a lawful basis or whether a banner is needed. Advanced mode also sends pings while consent is denied, including before the visitor answers, which is worth reviewing with your DPO against your national authority's criteria.
Does Sealmetrics use Consent Mode v2?
No. Sealmetrics sets no cookies and stores nothing on the visitor's device, so there is no storage for a consent type to switch on or off. If you run Google Ads, Google's own tags still need Consent Mode; Sealmetrics runs alongside them and does not send conversions to ad platforms. Whether a cookieless deployment is exempt from consent depends on its configuration and on your national authority's criteria.
Related concepts
- Consent Management Platform (CMP)Software that displays cookie consent banners and manages user preferences. Required under GDPR for websites using cookies or collecting personal data. What consent costs analytics varies by site: in our experience with clients, between 40% and 60% of traffic doesn't accept cookies.
- GDPR Analytics ComplianceMeeting GDPR requirements for web analytics: lawful basis for processing, data minimization, purpose limitation, and — if using cookies — valid consent collection before tracking.
- Data Loss in AnalyticsThe gap between actual website traffic and what analytics tools report. Caused by consent rejection, ad blockers, browser restrictions, and data sampling. How much depends on the store and the channel; at Incapto, GA4 missed 29% of visits over 48 days.
- Cookieless AnalyticsWeb analytics that captures visitor data without using browser cookies, enabling traffic measurement that doesn't depend on consent status or cookie restrictions.