Check whether your cookie consent and Consent Mode v2 work
Enter your site's address — we'll visit as a real user, click through consent, and show what it actually sends: cookie consent, Consent Mode v2 and trackers, with evidence from network traffic.
Seven signals of compliance and clean measurement
Consent platform (CMP)
Whether you have a consent mechanism and which one — everything else depends on it.
Consent Mode v2 default
Whether Google tags start from 'denied' (gcs=G100) before consent — the foundation of compliant measurement.
Trackers before consent
Whether advertising tags (e.g. Meta) politely wait for the user's click — the most common thing to improve.
Measurement after acceptance
Whether data actually starts after consent — full, reliable measurement begins right here.
Behavior after refusal
Whether refusal is respected — including on the next page view, which we check most carefully.
Cookies before a decision
Whether attribution cookies (e.g. _fbp) are set before any click.
Banner visibility
Whether the banner actually asks for a decision — covering the page or locking scroll — or is an easy-to-miss bottom bar.
Three scenarios in a real browser
New user
We open the site like a first-time visitor and listen to every request.
Acceptance
We click 'accept all' and check what fires and whether the consent signal flips to 'granted'.
Refusal
We click 'reject' and return for a second page view — that's where leaks invisible at first appear.
We don't check a single variable in the code — we actually click and listen to the network. That's the difference between 'looks fine' and 'works'.
Good consent works for your data and peace of mind
Correct consent means full measurement and stronger remarketing — algorithms learn on complete data and your budget works at its best.
GDPR and EDPB guidance call for genuine, freely given consent. A well-built banner means peace of mind in any audit.
Correct Consent Mode v2 unlocks the full set of advertising features and conversion modeling across the Google ecosystem.
We inspect your site's real network traffic
A consent-platform vendor's checker confirms you installed their tool. We do something different: we visit as a user, click, and listen to real network traffic across three scenarios. That's how we catch things a single code check won't see — like a pixel firing only on the next page view after refusal.
Consent Mode v2 — what you need to know
Consent Mode v2 is now a precondition for running Google ads in Europe — and not every setup that “looks done” actually sends the right signals. Here, in one place, is what it is, how it works, how to implement it, and how to check it really works.
What Consent Mode v2 is
Consent Mode is the layer where your site tells Google about the user's consent. It sets a default state before the decision and updates it after the click in the banner. Google tags — Google Ads, GA4, Floodlight — read this signal and adjust their behavior to it.
Version 2, required in the European Economic Area since March 2024, adds two new parameters to the familiar ad_storage and analytics_storage: ad_user_data and ad_personalization. Without them, from that date Google limits remarketing and audience lists for EEA and UK traffic.
Two new parameters: ad_user_data and ad_personalization
ad_user_data is consent to send user data to Google for advertising purposes. ad_personalization is consent to ad personalization and remarketing. Together with ad_storage (advertising cookies) and analytics_storage (GA4 measurement) they form four independent signals — each either granted or denied.
You can see these values in the network traffic: in Google requests as the gcs parameter (for example G100 on refusal, G111 after consent) and gcd, which encodes the state of all signals. These are exactly what we look at when checking whether consent actually flips from denied to granted after acceptance.
Basic vs Advanced Consent Mode
Consent Mode runs in two modes. In Basic mode Google tags don't load until the user consents — after refusal they send nothing. It's simpler to implement, but on refusal you're left with no data and no modeling.
In Advanced mode tags load right away, but before consent they send cookieless, anonymized pings. From these Google models the conversions and behavior of users who didn't consent — measurement is fuller, but the setup needs more care.
Which one? Advanced gives more data and better modeling at higher traffic volumes; Basic can be more convenient for simple setups and a cautious approach to privacy. In both modes the same thing matters: a correct default state and respecting refusal.
Where Consent Mode v2 comes from: DMA and GDPR
Consent Mode v2 is a response to two regulations. The Digital Markets Act (DMA) requires Google — as a gatekeeper — to obtain consent before using data for ad personalization. GDPR and the European Data Protection Board's guidance call for genuine, freely given consent, in which refusal is as easy as acceptance.
That's why v2 isn't a Google setting you can skip — it's a precondition that determines whether your EEA campaigns get a full set of data at all.
What you lose without a correct setup
A faulty setup doesn't block the site — it quietly trims the data your campaigns learn from:
- Remarketing and audience lists stop being fed by EEA traffic.
- Conversion modeling is off — some real conversions never reach the reports, and Smart Bidding loses its optimization signal.
- Ad personalization is limited, so the same budgets land less effectively.
The loss is gradual and hard to spot without measurement — which is why it's worth verifying, instead of assuming that if the banner is there, everything works.
Consent Mode v2 in an online store
In e-commerce the stakes are highest, because there's the most to capture: product views, add-to-carts, checkouts and purchases with real values. These feed dynamic remarketing, Enhanced Conversions and revenue-based optimization — and all of them pass through the consent layer.
Popular platforms — Shopify, WooCommerce, PrestaShop or Shoper — have Consent Mode v2 integrations, but the default configuration is rarely complete. What's usually missing is a correct default state, consistent passing of transaction values, or consent for non-Google pixels. The result: the store collects less data than it thinks, and campaigns optimize on an incomplete picture.
How to implement Consent Mode v2
In short, implementation comes down to five steps:
- Connect a Google-certified consent management platform (CMP) — it collects the user's decision.
- Set the default state to denied for all four signals before the user clicks.
- Update the signals after the decision — granted or denied according to the choice.
- Wire it all through Google Tag Manager and mind the order: the CMP loads before the tags.
- Consider server-side GTM for durable measurement and control over your data, plus a clean GA4 configuration.
And most importantly: installing a CMP doesn't mean the setup works. Configurations drift, tags end up wired outside the consent mechanism, and leaks like to hide until the second page view.
The most common implementation mistakes
Setups tend to break in a few recurring places:
- The default state isn't set to denied — tags start with full consent before the user clicks anything.
- The CMP loads after the tags, so the first requests go out before consent even takes effect.
- The Meta pixel or other trackers are wired outside the consent mechanism — Consent Mode covers Google tags, the rest has to be handled separately.
- Consent is respected on the first page view, but the leak only appears on the second visit.
- After refusal the signal doesn't flip to denied, or the tag sends data anyway.
Most of these look correct in the code and only surface in real traffic — which is why looking at the configuration alone isn't enough.
How to check whether Consent Mode v2 works
Manually: open your browser's developer tools, the Network tab, and filter by “collect” or “google”. Before clicking the banner, check that Google starts from gcs=G100 and that advertising trackers (for example Meta /tr) aren't firing yet. After acceptance the signal should flip to gcs=G111. After refusal no tag should send data — including on the next page view.
It works, but it's tedious and easy to miss a request that only fires on the second visit. That's why we built this test: enter your site's address at the top and we'll visit as a real user, click “accept” and “reject” across three scenarios, and show a report with evidence from the network traffic — no email required.
Frequently asked questions
What is Consent Mode v2?+
It's how a site tells Google whether the user consented to cookies. It sets a default state (usually 'denied') and updates it after the decision — so Google tags behave according to the user's choice.
Do I need Consent Mode v2?+
If you use Google remarketing and audience lists in the EU — practically yes. Without it Google limits ad features. Consent Mode is the Google layer; separately you need a consent mechanism (CMP).
What does gcs=G100 mean?+
It's a signal in Google requests indicating consent is set to 'denied' (before the user's decision). G111 means 'granted' — after acceptance. We see these values in the traffic and show them as evidence.
Must 'Reject' be in the first layer?+
EDPB guidance says refusal should be as easy as consent. Hiding 'Reject' under 'Settings' is a common market practice and an intermediate solution — we flag it neutrally, not as a critical error.
Does the test change anything on my site?+
No. We only visit the site like an ordinary user and observe what it sends. We don't write anything to your systems or modify the site.
Why does the result after refusal matter?+
Because it's the hardest scenario — the user refuses, yet a tag can still fire, often only on the next page view. That's exactly why we check this case most carefully.
How does Consent Mode v2 differ from v1?+
Version 2 adds two new consent signals: ad_user_data and ad_personalization, alongside v1's ad_storage and analytics_storage. These determine whether Google can use data for ads and remarketing in the European Economic Area.
Is Consent Mode v2 mandatory?+
It isn't a legal requirement in itself, but without it Google has, since March 2024, limited remarketing and audience lists for EEA and UK traffic. In practice, if you run Google ads in Europe, it's necessary.
Does Consent Mode cover the Meta pixel?+
No. Consent Mode is a Google mechanism and applies to Google tags. Consent for the Meta pixel and other trackers is enforced separately by your consent platform (CMP) and tag manager — which is why we check them independently.
Do I need a certified CMP?+
To use Google's advertising features and audience lists you need a consent platform from its list of certified CMPs. A plain 'I accept' banner without Consent Mode integration isn't enough.
What of this does Zest fix?+
All of the above: correct Consent Mode v2, tags that respect consent, server-side tracking and measurement you can rely on. Leave your contact — we'll show a fix plan.
See where your store loses customers — we walk the mobile purchase path and show the fixes.
Run a free UX audit →Leave your contact — we'll fix it
Send a brief or drop your contact — we'll reply within 24h.
Write to us