Consent Mode v2: What Silently Breaks If You Skip It

You are spending real money to bring people to your site, and you assume Google is counting what happens next. For most advertisers running in or near Europe, that assumption now depends on a configuration most people set up once and never verified. Consent Mode v2 sits between your consent banner and every Google tag on your site. When it is wrong, nothing throws an error. Your conversions just quietly get thinner, your remarketing audiences stop refilling, and your reported cost per acquisition drifts away from reality.
The expensive part is that the failure is invisible. There is no red warning in Google Ads that says "we stopped receiving consent signals." Campaigns keep spending, dashboards keep showing numbers, and the numbers are simply lower or less trustworthy than they should be. This article explains what Consent Mode v2 actually does, the four signals it controls, and the specific ways a bad setup drains data, including from traffic that has nothing to do with Europe.
What Consent Mode v2 actually is
Consent Mode is not a consent banner. It is a communication layer between your consent management platform, often called a CMP, and Google's tags. Your CMP collects the user's choice. Consent Mode translates that choice into a set of signals that Google Analytics 4, Google Ads, and Google Tag Manager read before they decide how to behave.
Version 2 is the update Google rolled out to align with the EU Digital Markets Act. The practical requirement is this: if you advertise to users in the European Economic Area or the UK through Google Ads, you need to pass these consent signals to keep using personalized advertising features. That includes building and populating remarketing audiences and receiving conversion data that Google can attribute and, where allowed, model. Without the signals, Google restricts those features for the affected users. This is an operational requirement inside Google's own products, not legal advice about what your business must collect. Treat the compliance question as one for your legal counsel and the measurement question as the one this article covers.
The four signals and what each one controls
Consent Mode v2 works through four named parameters. Two existed in the original Consent Mode. Two are new in version 2 and are the ones most setups get wrong because they were bolted onto an older configuration.
| Signal | What it controls | What breaks when set to denied |
|---|---|---|
| ad_storage | Whether advertising cookies and identifiers can be read or written | Click identifiers and ad cookies are blocked, so direct conversion attribution to a specific ad degrades |
| analytics_storage | Whether analytics cookies like the GA4 client ID can be stored | GA4 cannot persist a stable client ID, so sessions fragment and user counts inflate |
| ad_user_data | Whether personal data may be sent to Google for advertising measurement | Google Ads loses consented user data for measurement, weakening Enhanced Conversions and reported conversions |
| ad_personalization | Whether personal data may be used for ad personalization | Remarketing and personalized audiences stop collecting the user, so audience lists shrink over time |
| Default state | The value assigned before the user chooses | If defaulted to denied and never updated, every downstream signal stays off |
| Granted update | The value after the user accepts | If your CMP never fires the update, consent is never recorded as given |
The two new signals, ad_user_data and ad_personalization, are explicit permissions rather than storage switches. You can grant ad_storage and still deny ad_personalization, and the two mean different things. Missing them is the most common version 2 defect: a site upgraded its banner text but never wired the two new parameters into the tag, so Google treats those permissions as absent.
Why Google made this required
Google's own attribution has depended on cookies and click identifiers for years. As browsers restrict third party cookies and privacy regulation tightens, the share of conversions Google can observe directly keeps falling. Consent Mode v2 is how Google decides what it is allowed to do with the data it can still collect, and it is the input that lets Google model the conversions it cannot see.
That modeling is the key mechanism. In advanced Consent Mode, when a user denies consent, Google's tags still send anonymous, cookieless pings. Google uses those pings, plus the behavior of consented users, to statistically estimate the conversions that happened without observable identifiers. If the consent signals never arrive, Google has less to model from, and modeled conversions either shrink or stop appearing. Advertisers who skip the setup often see a step down in reported conversions and assume their campaigns got worse, when the real change is that measurement got quieter.
Basic versus advanced, and the real tradeoff
There are two ways to implement Consent Mode, and the choice has a direct effect on how much data you recover.
In basic Consent Mode, Google tags are blocked from loading until the user grants consent. A user who declines is simply invisible. You send nothing, Google models nothing from that user, and your measurement reflects only the consenting subset.
In advanced Consent Mode, the tags load on every page in a restricted state. When consent is denied, they send cookieless pings that carry no personal identifiers. When consent is granted, they switch to full behavior. Because Google receives a signal even from users who decline, it has the raw material to model the unobserved conversions.
The tradeoff is straightforward. Advanced recovers more measurement and generally produces fuller conversion data, but it requires the Google tags to be present before the consent decision, which some organizations resist for policy reasons. Basic is simpler and keeps tags fully dormant until acceptance, at the cost of the modeled conversions you would otherwise recover. For most advertisers whose goal is accurate measurement, advanced is the stronger choice, and it is what Google recommends for conversion modeling. The decision is worth making deliberately rather than inheriting whatever your CMP template shipped with.
How a bad default silently drops conversions everywhere
Here is the failure that catches advertisers who think this is only a European problem. Consent Mode runs for every visitor, not just EEA and UK ones. Your tags read the same default consent state regardless of where the user is. If your default is set to denied and your CMP only updates the signal to granted for European users behind a geo rule, then everyone outside that rule can be stuck at denied forever.
The result is that a business with mostly United States traffic and a single misapplied default can suppress its own conversion data across its entire audience. The tags fire, the site works, and Google records a fraction of what actually happened because the consent state never flips to granted. We see this most often when a CMP is installed with a global "deny by default" template and the "update to granted" call is scoped too narrowly or is missing entirely.
The related failure is a broken or missing update call. Consent Mode is built on a default state followed by an update after the user chooses. If the default fires but the update never does, because of a script ordering problem, a tag that loads after the consent event, or a CMP that was never fully connected, consent is technically never granted in Google's eyes. The banner looks fine to the visitor. The signal never moves. If your Google Ads conversions have quietly dropped, this is one of the first things worth ruling out, and it overlaps heavily with the broader causes covered in why Google Ads stops tracking conversions.
How to verify your signals are actually firing
You do not have to guess. The consent state is inspectable, and a few minutes of checking will tell you whether your setup is doing what you think.
Start with Google Tag Assistant. Load your site, open Tag Assistant, and look at the consent state it reports before you interact with the banner. That is your default state. Then accept consent and confirm the four signals, ad_storage, analytics_storage, ad_user_data, and ad_personalization, update to the values you expect. If any of the four are missing entirely, your version 2 wiring is incomplete.
Next, use GTM Preview mode and GA4 DebugView together. Preview mode lets you watch each tag fire and see the consent context it ran under. DebugView confirms that your GA4 events, including the purchase event, arrive with the right consent state attached. Watch specifically for the transition: the default should be present on the first pings, and granting consent should flip the relevant signals so subsequent events run in the fuller state.
Finally, test from a non European context. Set your default, then verify that a visitor outside the EEA gets the consent state you actually intend rather than a leftover deny. This single check catches the most expensive silent failure described above. A complete walkthrough of this kind of end to end verification lives in our conversion tracking audit guide, which covers the surrounding tags as well as the consent layer.
Find out what your tracking is hiding
Consent Mode v2 is one of those systems where "it looks like it is working" and "it is working" are completely different states, and the gap between them is money. If your conversions dipped after a banner change, if your remarketing audiences have been shrinking, or if you simply never confirmed the four signals fire correctly, the honest answer is that you do not yet know what your tracking is reporting. Our conversion tracking repair service audits your consent configuration alongside your full tagging setup, confirms the signals fire in every geography you serve, and fixes the defaults and update calls that quietly cost you data. You get a measurement stack you can actually trust before you spend another dollar against it.
FAQ
Is Consent Mode v2 required for everyone?
Google requires Consent Mode v2 signals for advertisers who serve European Economic Area and UK users through Google Ads if they want to keep using features like remarketing audiences and personalized conversion data. If you have zero EEA or UK traffic, Google does not force it on you, but the same tags run for every visitor. A misconfigured setup can still suppress data for your non European traffic if your defaults are wrong.
What is the difference between basic and advanced Consent Mode?
In basic Consent Mode, Google tags do not load at all until a user grants consent, so you get no signal from users who decline. In advanced Consent Mode, tags load in a restricted state and send cookieless pings when consent is denied, which lets Google model the conversions you cannot observe directly. Advanced generally recovers more measurement, but it requires the tags to be present on the page before the consent choice is made.
What are the four Consent Mode v2 signals?
The four signals are ad_storage, analytics_storage, ad_user_data, and ad_personalization. The first two control whether advertising and analytics cookies can be written. The last two, added in version 2, are explicit consent signals that tell Google whether it may use personal data for ad measurement and whether it may use it for personalization such as remarketing.
How do I check if Consent Mode is working?
Use Google Tag Assistant to inspect the consent state on your page and confirm the four signals appear with the values you expect before and after a user interacts with your banner. GA4 DebugView and GTM Preview mode let you watch events fire and confirm they carry the right consent context. The goal is to verify that your default state matches your intent and that granting consent flips the signals to granted.