Skip to main content

Google Consent Mode v2

Google Consent Mode v2 is Google's API for passing visitor consent to Google tags (Analytics, Ads, Tag Manager, AdSense). Once the banner is installed, OptSens sets the consent types for you. No extra tagging is needed. For Google's own explanation, see Consent mode overview and Set up consent mode on websites.

What OptSens does on the wire​

OptSens calls gtag('consent', 'default', ...) before any Google tag loads, then gtag('consent', 'update', ...) after the visitor makes a choice. It also sets gtag_enable_tcf_support, which lets Google tags read the TC string when IAB TCF is active, and identifies itself to Google with its CMP developer ID.

The default asks Google tags to wait up to 500 ms (wait_for_update) while the banner loads. What the four Google types start as depends on the visitor's region, see Defaults per region.

TypeDefaultGranted when
ad_storageFrom the region's ruleAdvertising consent
ad_user_dataFrom the region's ruleAdvertising consent
ad_personalizationFrom the region's ruleAdvertising consent
analytics_storageFrom the region's ruleAnalytics consent
functionality_storagedeniedFunctional consent
personalization_storagedeniedPerformance consent
security_storagegrantedAlways granted

OptSens also sets ads_data_redaction, which removes ad identifiers from the requests Google tags still send while ad_storage is denied. url_passthrough stays off, because it changes the URLs of your pages.

On every consent update OptSens also pushes an OptSensConsentUpdate event to window.dataLayer with the active categories, for GTM triggers. See GTM dataLayer.

How to enable it​

Google Consent Mode v2 is on by default. To check or change it:

  1. Open the dashboard and select your domain.
  2. Go to Frameworks.
  3. Toggle Google Consent Mode v2.
  4. Save.

This toggle is marked Recommended for any site using Google products.

When Consent Mode is off, OptSens sends no Consent Mode commands and blocks Google tags until the visitor consents to the matching category, like any other tracker. The OptSensConsentUpdate event still fires.

Google describes two ways to run Consent Mode. OptSens supports both.

  • Advanced (the default). Google tags load right away under the default consent state. Before consent they send cookieless pings, which Google uses for modelling. After consent they work as usual.
  • Basic. Google tags stay blocked until the visitor consents to the matching category: Analytics for Google Analytics and Tag Manager, Advertising for Google Ads and Floodlight. Nothing is sent to Google before a choice.

To choose:

  1. Go to Frameworks.
  2. Under Google Consent Mode v2, set Consent Mode type to Advanced or Basic.
  3. Save.

The same choice is in the Frameworks step of onboarding.

Defaults per region​

Before a visitor chooses, Google receives the defaults of the geo rule that matches the visitor's country. The Default rule for other regions sets the global default. Every other rule sets a default for its own countries, and Google applies the most specific one.

Each rule starts from its consent mode:

  • Opt-in rules, for example GDPR regions: all four Google types start denied.
  • Opt-out, Notice only and Implied consent rules, for example CCPA regions: all four start granted.

To change them:

  1. Go to Geo-targeting Rules and open a rule.
  2. Under Google Consent Mode defaults, turn each type on (granted) or off (denied).
  3. Save.

In regions where the rule shows no opt-in banner, OptSens also sends these values as an update straight away, so Google tags do not wait on a choice the visitor is never asked to make.

With IAB TCF on, Google tags read the visitor's TC string. The option Let Google read ad consent from the TCF string (on by default) tells Google to take ad_storage, ad_user_data and ad_personalization from the TC string. Consent Mode still sends analytics_storage.

To change it:

  1. Go to Frameworks.
  2. Under IAB TCF, turn Let Google read ad consent from the TCF string on or off. The option shows when both IAB TCF and Google Consent Mode v2 are on.
  3. Save.

With the option off, Google takes the ad types from the Consent Mode signals instead.

Meet Google's banner requirements​

When a site uses Consent Mode without IAB TCF, Google asks that the banner:

  • explains what the data is used for,
  • links to Google's page on how it uses data, from inside the banner,
  • gives the visitor a way to accept.

The OptSens banner already describes each cookie category and offers Accept all. To add Google's link:

  1. Go to Frameworks.
  2. Under Google Consent Mode v2, turn on Show Google's privacy link in the banner.
  3. Save.

The banner then shows How Google uses data in the description of the Advertising category on its preferences screen, in every banner language. The link opens business.safety.google/privacy. The same option is in the Frameworks step of onboarding.

The option is marked Recommended while IAB TCF is off. With IAB TCF on, Google is listed as a vendor on the TCF consent screen, and the link is optional.

This option covers the banner part of Google's requirements. It does not by itself make a site meet any law. For Google's full rules, see the EU user consent policy.

In apps​

The Android and iOS SDKs pass the same consent to Firebase and follow the settings on this page: the switch, the Consent Mode type and the defaults per region.

  • Before a choice, Firebase starts with all four types denied. On Android the SDK adds this to your app. On iOS you add four keys to Info.plist, see Firebase and attribution partners.
  • Advanced: Firebase gets the four values and sends cookieless pings before consent.
  • Basic, or Consent Mode off: Firebase collects nothing until the visitor consents to analytics.

The SDK learns the Consent Mode type when its settings load. On a first launch that is after Firebase has started, so with Basic or with Consent Mode off, also turn Firebase collection off in your app. The SDK turns it on once the visitor consents to analytics.

Android, in AndroidManifest.xml:

<meta-data android:name="firebase_analytics_collection_enabled" android:value="false" />

iOS, in Info.plist:

<key>FIREBASE_ANALYTICS_COLLECTION_ENABLED</key><false/>

Leave it out with Advanced.

How to verify it​

Open your site, then run this in the browser console:

window.dataLayer.filter(function (e) {
return e[0] === 'consent';
});

You should see a default entry first, then an update entry after you accept or reject in the banner.

To confirm the dataLayer event fired:

window.dataLayer.filter(function (e) {
return e.event === 'OptSensConsentUpdate';
});

For an automated check that the defaults and updates fire in the right order, run the Consent Mode check from the Integration page in the dashboard. The Scanner page shows the same check for every page of your latest scan.