Last updated: September 30, 2026
If you serve Google Ads, run Google Analytics, or use Google Tag Manager on a site that reaches visitors in the EEA, UK, or Switzerland, GDPR cookie consent rules already apply to you, and Google Consent Mode v2 is the specific mechanism Google requires on top of that. The enforcement window everyone talks about is not a future deadline anymore. Google's certified-CMP requirement took effect January 16, 2024 for the EEA and UK, and July 31, 2024 for Switzerland. Both dates have passed. If your consent setup still isn't sending the right signals, you're not early. You're behind.
This guide covers what actually changed in v2, which Google products require it, how the certified-CMP program really works (including what Google's certification does and doesn't check), and how to implement it correctly, whether you're doing it manually, through Google Tag Manager, or through a consent management platform (CMP).
What is Google Consent Mode v2?
Google Consent Mode is a framework that lets Google's tags, Google Ads, Analytics, Tag Manager, and Floodlight, adjust their own behavior based on the consent choices a visitor actually makes. Instead of an all-or-nothing block on tracking, the tags check a visitor's consent status first and then decide what data they're allowed to collect, the same underlying job a consent management platform handles for every other vendor tag on your site, not just Google's.
Version 2 added two new consent parameters on top of the original two. Here's the full set of four:
| Parameter | Introduced | What it controls |
|---|---|---|
| ad_storage | v1 | Whether cookies related to advertising can be set |
| analytics_storage | v1 | Whether cookies related to analytics measurement can be set |
| ad_user_data | v2 | Whether user data can be sent to Google for advertising purposes |
| ad_personalization | v2 | Whether data can be used for personalized advertising (remarketing, Similar Audiences) |
The two new parameters exist because the original two didn't say enough. ad_storage only ever covered whether a cookie gets set. It said nothing about whether the data itself could be sent to Google or used to personalize ads once collected another way. ad_user_data and ad_personalization close that gap, which is why Google now requires all four for any site using a certified CMP to serve personalized ads in the EEA, UK, or Switzerland.
The enforcement timeline: what's actually in effect right now
This is where a lot of blog content still gets it wrong, describing March 2024 as an approaching deadline. It isn't. Google's own EU User Consent Policy set two hard dates, both already in the past as of this writing:
- January 16, 2024: EEA and UK sites serving personalized ads through Google's ad products must use a Google-certified CMP integrated with Consent Mode v2.
- July 31, 2024: the same requirement extended to Switzerland.
"March 2024" is the rough, rounded version of this timeline that circulated widely when Consent Mode v2 launched. The actual enforcement dates, as stated in Google's own EU User Consent Policy documentation, are the two above. If your site has been serving personalized ads to EEA, UK, or Swiss visitors since mid-2024 without a certified CMP correctly configured, that's a compliance gap that already exists, not one on the horizon.
Which Google products does this affect?
Consent Mode v2 touches every major Google measurement and advertising product:
- Google Ads: for personalized ad serving and conversion tracking
- Google Analytics (GA4): for full visitor and event data collection
- Google Tag Manager: as the mechanism most sites use to deploy consent signals
- Floodlight / Campaign Manager 360: for advertiser-side conversion tracking
One nuance worth being precise about: Google's hardest, ad-serving-specific mandate (the certified-CMP-plus-IAB-TCF requirement) is scoped to products that serve personalized ads, primarily AdSense, Ad Manager, and AdMob. For GA4, Ads, and Tag Manager more broadly, Consent Mode v2 is how Google recommends and, in practice, requires you to preserve full measurement, since without it, EEA/UK/Swiss traffic simply won't be collected. Either way, the practical outcome for most sites is the same: implement all four parameters correctly, or lose data and ad functionality for regulated visitors.
Basic mode vs. Advanced mode
Consent Mode v2 offers two implementation modes, and the difference matters for what you get back when a visitor declines.
- Basic mode blocks Google tags from firing entirely until consent is granted. No data of any kind reaches Google before that point. This is the simpler, stricter option.
- Advanced mode lets tags fire even without consent, but strips identifying data and sends anonymous "consent pings" instead. Google then uses machine-learning-based conversion modeling to estimate the data it couldn't collect directly.
Choose Advanced mode if preserving conversion measurement matters more than implementation simplicity; choose Basic mode if you'd rather keep your setup minimal and don't rely heavily on Google's modeled conversion data. Most advertising-driven businesses choose Advanced mode specifically because conversion modeling recovers a meaningful share of the data that consent declines would otherwise erase.
How to implement Google Consent Mode v2
There are three practical paths, in increasing order of how much a CMP does for you.
1. Manual implementation with gtag.js
You can set default and updated consent states directly in code before your tags load:
gtag('consent', 'default', {
'ad_storage': 'denied',
'analytics_storage': 'denied',
'ad_user_data': 'denied',
'ad_personalization': 'denied'
});
// After the visitor makes a choice:
gtag('consent', 'update', {
'ad_storage': 'granted',
'analytics_storage': 'granted',
'ad_user_data': 'granted',
'ad_personalization': 'granted'
});This works, but it means you're maintaining the consent logic, the banner, the storage of user choices, and the regulatory record-keeping yourself.
2. Through Google Tag Manager
GTM has a built-in Consent Mode configuration that lets you set default consent states per region and update them through triggers tied to your banner. This is less code than a pure gtag.js setup, but you still need something in front of it collecting and storing actual user consent choices.
3. Through a Google-certified CMP
A CMP handles the banner, the consent logic, the record-keeping, and the signal-passing to Google in one system. If you're still comparing providers, a current CMP comparison is worth checking before you build around any single vendor's specifics. To be certified, a CMP provider has to support Consent Mode two ways: a gtag.js add-on integration and a published GTM consent-mode template. Certification itself is scoped narrowly. Google checks that a CMP correctly integrates with its own systems and the IAB Transparency & Consent Framework (TCF); it does not certify that a CMP makes your site fully compliant with GDPR or other privacy laws. That distinction matters. A Google-certified CMP is a required piece of the puzzle for ad personalization in the EEA/UK/Switzerland, not a substitute for your own legal compliance review.
Secure Privacy is a Google-certified CMP partner (Gold Tier, per Google's CMP Partner Program) and supports Consent Mode v2 through both the gtag.js and GTM integration paths described above, alongside IAB TCF compliance. As with any CMP, certification confirms the technical integration works as Google requires; it's not a claim of blanket legal compliance, and you should still confirm your own configuration matches your specific regulatory obligations.
What implementation actually gets you
Conversion modeling recovers data that consent declines would otherwise erase entirely. When a visitor in Basic mode declines, or a visitor in Advanced mode grants only partial consent, Google fills gaps in ad performance and conversion data using machine-learning estimates, so your reporting doesn't just have holes in it. This is the single biggest practical reason advertisers implement Consent Mode v2 at all, beyond the compliance requirement itself.
Beyond conversion recovery, a correct implementation gets you:
- Continued Google Ads and GA4 functionality for consented and non-consented visitors alike, instead of losing all data from anyone who declines
- A defensible compliance record showing what consent was actually collected and when
- Continued eligibility to serve personalized ads to EEA, UK, and Swiss traffic through AdSense, Ad Manager, or AdMob
Frequently asked questions
Is Google Consent Mode v2 mandatory?
Yes, for sites serving personalized ads to visitors in the EEA, UK, or Switzerland through Google's ad-serving products. The certified-CMP requirement has been in effect since January 16, 2024 (EEA/UK) and July 31, 2024 (Switzerland). For GA4 and other measurement products, it's less a hard legal mandate than the mechanism Google requires for full data collection from regulated regions.
What's the difference between Consent Mode v1 and v2?
V1 covered ad_storage and analytics_storage, whether ad and analytics cookies could be set. V2 added ad_user_data and ad_personalization, which govern whether user data can be sent to Google at all and whether it can be used for ad personalization, closing gaps the original two parameters left open.
Does using a certified CMP guarantee GDPR compliance?
No. Google's certification confirms a CMP correctly integrates with Consent Mode and the IAB TCF. It does not certify full GDPR, ePrivacy, or other regional privacy-law compliance, which depends on how the CMP is configured and how your organization handles consent and data beyond Google's own systems.
Should I use Basic mode or Advanced mode?
Use Advanced mode if recovering conversion data through modeling matters to your advertising performance, which is true for most businesses running paid campaigns. Use Basic mode if you want the simplest possible setup and don't rely on Google's modeled conversion estimates.
What happens if I don't implement Consent Mode v2?
Sites without a certified CMP correctly sending all four consent signals risk losing the ability to serve personalized ads to EEA, UK, and Swiss visitors through Google's ad products, along with the conversion data and modeling that Consent Mode v2 would otherwise recover.
The bottom line
Google Consent Mode v2 is no longer a future compliance project. The enforcement dates passed in 2024, and any gap between what your site currently sends and what Google requires is an active gap, not a scheduled one. The fastest path to closing it is a Google-certified CMP that already handles the gtag.js and GTM integration, the IAB TCF signal-passing, and the consent record-keeping, so your team isn't rebuilding that logic from scratch. Whatever path you choose, verify your implementation against Google's own Consent Mode documentation directly rather than relying solely on secondary summaries, since the underlying requirements are Google's to set and can change.


