Basic Google Consent Mode blocks the relevant Google measurement tags until consent. Advanced Consent Mode loads them with consent defaults and can send measurements without cookies while storage consent is denied. Choose between them by deciding what data your site may send before consent and after rejection, then assessing the measurement consequences.
Both approaches support Consent Mode v2. Advanced mode is not a separate paid version or a requirement reserved for large websites. Neither approach, by itself, establishes that your consent collection or data processing is lawful. Google's basic and advanced comparison.
This guide concerns website implementations. App SDKs have different integration steps and platform requirements.
Basic vs advanced: the practical difference
| Decision point | Basic implementation | Advanced implementation |
|---|---|---|
| Before consent | Relevant measurement tags remain blocked | Tags can run with denied defaults |
| Visitor rejects | Blocked tags send no measurement or consent pings | Tags can send cookieless measurement and consent pings |
| Visitor grants a purpose | Release the relevant tags with the appropriate consent state | Update the corresponding state for running tags |
| Google Ads conversion modelling | General model | Advertiser-specific model, subject to eligibility |
| Main review question | Does any integration bypass the blocking rule? | What exactly is transmitted while consent is denied? |
Google distinguishes these implementations by tag behaviour and data transmission. The choice does not determine your banner layout, number of preference categories or ability to serve multiple domains. Consent Mode overview.
The blocking boundary matters. Keeping a measurement tag inactive inside a loaded Google Tag Manager container does not mean the browser made no connection to Google: downloading the container is itself a request. If your requirement is no Google connections before consent, assess the loader as well as the tags inside it.
What the four Consent Mode v2 signals control
Consent Mode communicates choices; it does not obtain them. Map your CMP categories and purposes deliberately to the Google parameters:
| Parameter | Purpose |
|---|---|
analytics_storage | Storage associated with analytics |
ad_storage | Storage associated with advertising |
ad_user_data | Sending user data to Google for advertising |
ad_personalization | Personalised advertising |
The values are the strings granted and denied. Keep the American spelling in the API key ad_personalization, even when the interface uses British English. Granting analytics must not automatically grant all advertising purposes. Google's Consent Mode reference.
For example, a visitor who accepts analytics and rejects advertising might produce this state:
{
"analytics_storage": "granted",
"ad_storage": "denied",
"ad_user_data": "denied",
"ad_personalization": "denied"
}
This is an illustrative mapping, not an installation snippet. Your notice, CMP purposes and actual processing must support it. Review the mapping whenever you add enhanced conversions, advertising destinations or a new analytics integration.
Cookieless pings still need a data review
A denied storage state is not a general instruction to stop network traffic. Google's documentation explains that cookieless requests can include browser information and an IP address in transmission, although Analytics does not log or store IP addresses. Configured fields such as user_id and custom dimensions can still be sent. Advertising requests can also contain page URLs and click information, depending on settings. Google's tag-behaviour reference.
Inspect the payload rather than assuming that the word “cookieless” means nothing identifying can leave the page. Useful review cases include:
- A confirmation page whose URL contains an email address or order reference.
- A signed-in page that populates a customer identifier before the CMP finishes loading.
- A custom event that contains a free-text form answer.
- A server endpoint that adds identifiers to an incoming event before forwarding it.
Document the purpose and destination of each field. Remove unnecessary fields at their source and repeat the check for denied and granted states. A clean cookie list cannot establish that these transfers are absent.
Separate Google policy from legal permission
Google's EU user consent policy applies to relevant products and users in the EEA, UK and Switzerland. It requires legally valid consent for cookies or local storage where legally required, and for personal-data collection, sharing and use for personalised advertising. It also requires consent records and instructions for withdrawal. These are vendor obligations, not a legal exemption for advanced mode. Google EU user consent policy.
The ePrivacy analysis extends beyond cookies. The EDPB's guidance addresses technologies including tracking pixels, URLs and some IP-based tracking. It explains that Article 5(3) protects information on terminal equipment even when the information is not personal data. Its guidance does not settle consent exemptions for every implementation. EDPB Guidelines 2/2023, final version.
Consequently, assess the actual access, storage, transmissions and purposes under the applicable national rules and data-protection requirements. Do not classify denied-state pings as “essential” solely because a vendor offers them. Equally, basic mode only addresses part of that assessment: notices, valid choices, withdrawal and other technologies still need review.
What modelling can and cannot provide
GA4 behavioural modelling estimates missing user and session information. It does not recreate a verified history for every person who declined analytics storage.
Google currently lists these prerequisites:
- Advanced Consent Mode across all relevant pages, with tags loading independently of consent.
- At least 1,000 events per day with
analytics_storage='denied'for at least seven days. - At least 1,000 daily users sending granted-state events on at least seven of the previous 28 days.
Meeting the thresholds does not guarantee eligibility. Google applies additional quality criteria. Eligible properties can include estimated data using the Blended reporting identity, but behavioural modelled data is not available in every feature, including audiences and BigQuery export. GA4 behavioural modelling requirements.
For a low-traffic site, assess the realistic benefit before adopting advanced mode for modelling alone. For a larger site, decide which reports actually need estimated data and whether stakeholders can distinguish estimates from observations. Do not promise that changing modes will restore a particular percentage of conversions or improve campaign results.
Choose a mode with a documented decision
Use these questions in your privacy and measurement review:
- What must remain blocked? Define the requirements for first visits, rejection and withdrawal, including script downloads and server forwarding.
- Which purposes can proceed in each state? Assess analytics, conversion measurement, advertising data and personalisation separately.
- Is there a supported basis for the proposed denied-state processing? Record the actual fields and recipients considered, rather than approving a product label.
- Is modelling useful and realistically available? Check property traffic, eligibility and reporting needs.
- Can the implementation be tested and maintained? Assign responsibility for CMP changes, new tags, regional rules and regression checks.
Illustrative basic-mode decision: a lead-generation site requires Google measurement to wait for a visitor's choice. It blocks the relevant loaders and tags, then releases analytics only after analytics consent. It also checks embedded tools and backend events for routes around that control.
Illustrative advanced-mode decision: an online retailer has reviewed and approved a defined set of denied-state transmissions. It documents permitted payloads, applies consent updates and compares actual requests against that specification. If a later integration adds customer identifiers, the previous approval does not automatically cover the change.
Implementation details that change the outcome
Set explicit defaults before measurement commands. Do not assume installing a banner creates the correct initial state. For a direct gtag.js implementation, Google's setup guide places the consent default before commands such as config and event.
For GTM consent templates, use the consent APIs setDefaultConsentState and updateConsentState. Google warns that queued gtag updates may be processed too late when used instead of the template APIs. Consent Mode does not persist the choice itself; the consent solution must restore it on later pages.
wait_for_update gives an asynchronous CMP a bounded time to respond. It is not an indefinite block until the visitor chooses. Record updates before navigation and test withdrawal as well as acceptance. Google's website implementation guide.
Treat third-party pixels, custom HTML tags and server integrations as separate items in the inventory. A Google consent signal only controls a destination when the integration actually interprets and enforces it.
Test before release
Use Tag Assistant to inspect default and updated consent states and compare their order with tag events. Google's diagnostics help identify missing or late defaults and unexpected updates. Troubleshoot Consent Mode with Tag Assistant.
Then test the behaviour independently in browser developer tools and, where relevant, server logs:
| Test case | Evidence to capture |
|---|---|
| Fresh visitor, no interaction | Loaded scripts, request destinations, cookies and initial consent values |
| Reject all | Requests after rejection and after the next page load |
| Analytics only | Analytics grant, advertising denials and purpose-specific payloads |
| Accept all | Expected events without duplicate installations or duplicate conversions |
| Withdraw after accepting | Immediate state change, future requests and saved preferences |
| CMP unavailable or slow | Behaviour before defaults and after any waiting period |
| Returning visitor | Correct restoration without a temporary unintended grant |
| Checkout or single-page navigation | State continuity and consent updates before new events |
Keep expected results for each mode alongside the observations. Repeat the relevant cases after changing the CMP, tag container, checkout or server forwarding. A successful Tag Assistant check alone cannot prove legal compliance or cover tools outside its scope.
FAQ
Is basic Consent Mode the same as Consent Mode v1?
No. Basic and advanced describe deployment approaches. Version 2 added advertising user-data and personalisation signals; both approaches can use those signals.
Does advanced Consent Mode require a different banner?
No. The defining difference is what tags do before consent and after rejection. The banner must accurately explain and implement the choices available on that site.
Does a denied consent state stop every Google request?
No. In advanced mode, storage denial can still permit cookieless measurements. If your requirement is no requests, implement and test blocking of the relevant loaders, measurement tags and forwarding paths.
Does basic mode guarantee GDPR compliance?
No. Blocking relevant measurement before consent is one control. The validity of consent, transparency, withdrawal, other tools and the wider processing still require assessment.
Can we change from basic to advanced later?
Yes, but review the newly introduced transmissions before release. Update the documented decision, configuration and notices where needed, then retest rejection, withdrawal and returning visits.
For a reproducible fault, use our Google Consent Mode v2 troubleshooting guide to trace missing defaults, failed updates and unexpected tag behaviour.
Related reading
- Google Consent Mode, GPC and GPP implementation for coordinating different privacy signals.
- Global Privacy Control and universal opt-out for browser opt-out signals and their scope.
- GDPR cookie consent for consent and device-access requirements.
- Google Consent Mode and GTM services for implementation support.
To inspect your current setup, run a free consent audit.
