• About
  • Services
  • Partners
  • Case Studies
  • Pricing
  • Blog
  • Get In Touch
  • Consent Mode v2 - compliant without compromising data.

    GDPR compliance and accurate measurement are not mutually exclusive - but only if Consent Mode is implemented correctly. Most implementations we audit have at least one critical issue that either creates a compliance risk or unnecessarily destroys measurement quality.

    Consent Mode v2 Basic & Advanced OneTrust GDPR CCPA

    Signs your consent implementation has problems.

    Consent Mode issues are usually invisible - the site appears to work, the data appears to flow, but underneath there are compliance risks and data quality problems that only emerge under scrutiny.

    Tags firing before consent is given

    One of the most common issues - analytics and ad platform tags firing on page load before the user has interacted with the consent banner. This is a GDPR violation regardless of whether the user eventually accepts or declines.

    ✓ Correct consent initialisation prevents pre-consent firing

    The consent race condition

    The Google tag fires on Consent Initialisation - All Pages at the same moment OneTrust updates the consent state. This means the tag evaluates consent before it has been set - causing both a compliance issue and _gl URL pollution in GA4 reports that makes path analysis unusable.

    ✓ analytics_storage consent check on Google tag fixes this

    _gl parameters polluting your URLs

    When the Google tag fires for non-consenting users, GA4 appends _gl parameters to browser URLs - creating duplicate URL variants in GA4 reports. /page and /page?_gl=xxxxx appear as separate pages, making content analysis and path reporting completely unreliable.

    ✓ Fixing the race condition eliminates _gl pollution at source

    Server-side tags not respecting consent

    A common oversight - implementing Consent Mode correctly on client-side tags but forgetting that server-side tags also need to receive and respect the same consent signals. Server-side tags that ignore consent create the same compliance risk as client-side tags.

    ✓ Consent signals propagated correctly to server container

    Consent Mode v2 - Basic and Advanced.

    We implement both Consent Mode v2 Basic and Advanced depending on your market, regulatory requirements, and measurement needs. Basic blocks all tags until consent is given - the strictest approach, appropriate for healthcare and other highly regulated sectors. Advanced allows tags to fire in cookieless mode before consent, enabling GA4 behavioural modelling for non-consenting users - appropriate for most EU-facing businesses where consent rates vary significantly.

    • CMP integration - OneTrust, Cookiebot, Usercentrics, or any consent platform
    • Consent Mode v2 Basic or Advanced - based on your market and regulatory requirements
    • Correct consent initialisation timing - preventing pre-consent tag firing
    • Consent race condition fix - analytics_storage check on Google tag
    • _gl URL pollution prevention - clean URLs for all non-consenting users
    • Tag-level consent checks - every tag validated across all consent states
    • Server-side consent signal propagation - server tags respecting the same consent state
    • Validation across all consent states - pre-consent, granted, and denied
    What You Get
    • Fully compliant Consent Mode v2 implementation
    • CMP integration tested and validated
    • Consent race condition fixed
    • Clean URLs - no _gl pollution
    • Validation report across all consent states
    • Documentation of consent architecture
    • 30-day post-launch support

    How we implement Consent Mode v2.

    01

    Consent Audit

    We test your current implementation across all consent states - pre-consent, granted, and denied - identifying every tag that fires incorrectly and every compliance risk in your current setup.

    02

    Implementation & Configuration

    CMP integration, correct consent initialisation, tag-level consent checks, race condition fix, and server-side consent propagation - all configured in staging before touching production.

    03

    Validation Across All States

    Every tag tested in every consent state. _gl URL pollution verified eliminated. Server-side consent signals confirmed. Full validation report produced before sign-off.

    Common questions about Consent Mode v2.

    What is the difference between Basic and Advanced Consent Mode?

    Basic Consent Mode blocks all tags until the user grants consent - no data is collected for non-consenting users. Advanced Consent Mode allows tags to fire in a cookieless, limited mode before consent is given, sending anonymised pings that GA4 uses for behavioural modelling. The right choice depends on your regulatory environment and how much measurement quality matters for non-consenting users.

    What is the consent race condition and why does it matter?

    The race condition occurs when the Google tag is configured to fire on Consent Initialisation - All Pages, at the same moment the CMP is updating the consent state. The tag evaluates consent before the CMP has finished setting it - meaning it fires regardless of what the user has chosen. The fix is adding an explicit analytics_storage consent check directly on the Google tag, so it only fires after the consent state has been confirmed.

    We work with clients in the EU - which consent mode do we need?

    For EU-facing businesses under GDPR, both Basic and Advanced are valid approaches - the choice depends on your sector and risk appetite. Healthcare and highly regulated sectors typically use Basic. Most other EU businesses use Advanced to preserve measurement quality through GA4 behavioural modelling. We will recommend the right approach for your situation during the scoping call.

    Does Consent Mode work with all CMPs?

    Yes - we work with OneTrust, Cookiebot, Usercentrics, Didomi, TrustArc, and custom CMP implementations. The integration approach varies slightly between platforms but the outcome is the same: correct consent signals passed to GTM at the right time, in the right format, across all consent states.

    Up Next

    dataLayer Architecture

    Explore another service →