Consent

Consent Mode v2 without throwing data away

Consent Mode v2 without throwing data away

Rhobin

July 30, 2026

7 min read

Consent Mode v2 is how a consent decision reaches Google, not a reason to measure less. What you keep after a refusal comes down to four configuration decisions: what happens on a denial, how your banner categories map onto Google's four consent types, which regions the denied defaults cover, and whether the consent state reaches your server container.

The symptom

Legal signs off on the banner text, the consent platform goes in, the warning in the client's Google Ads account disappears, and somebody ticks "Consent Mode v2" in the status report. Everyone moves on, because the flag is gone.

A few weeks later the conversion numbers read thinner than the business behind them, and the honest answer to "is that the banner" is that nobody knows. Two groups reviewed this project and neither reviewed the middle. Legal reviewed what the visitor is told and asked, the performance team reviewed the campaigns, and the part where a consent decision becomes tag behaviour went to whoever installed the plugin.

That middle is where the money is. A banner can be lawful and still discard measurement it never had to, and your reporting looks the same either way.

[IMAGE: three banner toggles beside Google's four consent types, mapping lines crossing wrongly]

Why it happens

Because Consent Mode v2 does two separate jobs, and only one of them fails loudly.

Job one is satisfying Google's policy. Google's EU user consent policy covers "end users in the European Economic Area, the UK and Switzerland", and Google Tag Manager's documentation adds that advertisers must collect that consent from EEA end users and share the signals with Google to keep using measurement, ad personalization and remarketing. This half is close to binary and it fails in public: Google Ads documentation states that since March 2024 a Customer Match list used in the EEA needs both consent fields granted, and that data from unconsented EEA users "will not be processed and cannot be used for ad personalization". Audience features stop, somebody notices, it gets fixed.

Job two is deciding what still gets measured when a visitor says no. Nothing stops, no warning appears. This half is four decisions, and in most setups a default made all four.

The four decisions nobody was asked to make

What happens on a denial. Google documents two modes. In basic mode "no data is sent before a user consents, not even the default consent status". In advanced mode tags load with defaults set to denied, and on a refusal "consent state and measurements without cookies are sent". Plenty of setups run basic because that is what the plugin does, not because anyone chose it. Modelling is meant to fill part of that gap, and it has conditions: Google Ads puts the requirement at "a daily ad click threshold of 700 ad clicks over a 7 day period, per country and domain grouping", and nothing in the interface says which markets clear it. Sizing the loss is a job of its own, covered in how much data a cookie banner throws away.

How your banner categories map onto Google's consent types. Consent Mode v2 works with four, and they mean different things: storage for advertising, sending user data to Google for advertising purposes, personalized advertising, and storage for analytics. Your banner has three toggles, probably necessary, statistics and marketing, so somebody mapped three onto four. When all four hang off the marketing toggle, a visitor who accepted statistics and refused marketing is recorded as refusing analytics too, and you lose a measurement they agreed to give you. Nothing errors and no report shows it.

Which regions the denied defaults cover. Defaults can be scoped. Google's setup documentation describes default consent states "that apply to visitors from particular areas" by specifying a region, and a default set without one covers everybody else. Google's obligation covers the EEA, the UK and Switzerland, so denied-by-default worldwide is a choice, and for a client selling in the United States it gates measurement in markets that obligation does not reach. It can still be the right choice, many clients want one global standard. It should be a choice someone made on purpose, with the cost named.

Whether the consent state travels. A yes collected in the browser has to reach the server container and the ad platforms with the event. Where that wiring is missing, traffic that did consent gets handled downstream as though it had not. The most expensive of the four, because it discards consent you earned.

[IMAGE: two-column comparison, what a refusal costs beside what a default chose, second column marked recoverable]

And Consent Mode v2 is not the law

Worth being exact, because the two get conflated constantly. Consent Mode v2 is Google's mechanism for receiving a decision. The obligation itself is Article 5(3) of the ePrivacy Directive, which allows storing or accessing information on a user's device only where that user "has given his or her consent, having been provided with clear and comprehensive information", exempting what is "strictly necessary" to provide a service the user explicitly requested. It is a Directive, so what binds your client is their own member state's implementation, and regulators read that exemption differently. France's CNIL publishes an exemption for audience measurement on conditions, then says "most large audience measurement offerings do not fall within the scope of the exemption, regardless of their configuration". The exemption is real and it is not a plan.

What good looks like

The goal is not a higher consent rate. Nudging visitors toward accept is how an agency ends up explaining itself to a regulator, and it is the one move here with real downside. The goal is duller: a refusal should cost what a refusal costs, and a yes should not be quietly downgraded on the way through.

Start by reading the current state instead of rebuilding. One question per decision above.

  • Which mode does the banner run in, so what leaves the browser before anyone clicks?

  • Do the categories map onto the four consent types, and does a statistics-only visitor still get counted?

  • Which regions do the denied defaults cover, and does that match where the obligation applies?

  • Does a consented event still carry its consent state at the server container?

Then repair only what was never required, and write down what the setup does. That record is what legal actually needs and what almost nobody produces, and it decides whether the next review takes an hour or a week. This is the work Archon Consent does: a lightweight banner with Consent Mode v2 configured so compliance and measurement stop competing.

Be straight with the client about what will not change. A refusal is permanent. Ad blockers strip 30 to 40% of events before the browser sends anything, networks fail, people close tabs. A typical account carries 15 to 30% of its conversions uncaptured for reasons unrelated to the banner, covered in why conversions never reach GA4. Roughly 95% of events is the realistic ceiling, and it is a ceiling rather than a promise. The gain from fixing consent is the measurement you were allowed to keep and were throwing away.

FAQ

Our consent platform says we are Consent Mode v2 compliant. Is that not the whole job?

It records the click and passes the signals, which is job one. It does not know which of your tags need which consent type, which regions your defaults should cover, or whether your server container ever receives the consent state. Google's own documentation treats it as one option among several, saying you can implement a banner or a custom solution, or use a consent management platform. The banner is a component, the configuration around it is the job.

Will loosening the defaults put our client at risk?

Not if they come down to what the law asks and no further. The useful question is what produced the current settings, a legal position or nervousness in a meeting, because only one is worth the measurement it costs. Ask it with a written description of the setup, since nobody can rule on a configuration nobody has described. We implement the technical side, sign-off on policy stays with the client and their counsel.

Can we rely on modelling to fill the gap?

Partly, conditionally, and per country rather than per account. Google's threshold is 700 ad clicks over a 7 day period per country and domain grouping, and it notes modelling is most accurate when a denial still sends a cookieless ping. A large single-market client is usually fine, a client spread across five small markets often is not, and the account-level view hides that.

Does any of this recover data from visitors who refused?

No, and anything sold to you on that basis is a compliance problem rather than a measurement one. A refusal is a refusal. What is recoverable is the other category: measurement lost after a yes, and measurement discarded by defaults stricter than the obligation. That is the half worth scoping, and usually the larger of the two.

If you want to know which half your clients' banners are losing, request a free tracking audit and we will check all four decisions per account.

© 2026 Archon LabsPrivacyTermsBuilt on unsampled data.