Cookie Compliance

Google Consent Mode v2 and OneTrust: What Marketers Need to Know

Consent Mode v2 with OneTrust: map categories to ad_storage, analytics_storage, ad_user_data, and ad_personalization, set defaults before tags, and verify in Tag Assistant.

Working summary: Google Consent Mode v2 tells Google tags how to behave after a user chooses. OneTrust can map banner categories to ad_storage, analytics_storage, ad_user_data, and ad_personalization, then push defaults and updates. Marketers still own the banner UX, tag order, and region defaults. Wrong wiring looks like “Consent Mode is on” while ads cookies still fire.

  • v2 extras: Besides storage signals, Google added ad_user_data and ad_personalization (November 2023 update) for EEA-related advertising consent signalling.
  • OneTrust path: Enable Google Consent Mode on the geolocation rule, map Performance to analytics and Targeting to the three ad signals (defaults OneTrust documents), publish CDN, or use the GTM OneTrust CMP template.
  • Order matters: Defaults before Google tags configure; updates on Accept, Reject, and Preference Center changes.
  • Not a legal shield: Consent Mode is a technical bridge. You still need a lawful banner and blocking (see articles 3, 5, 2).

This is article 8 of the Cookie Compliance series. Article 2 covers the OneTrust install. Article 7 compares CMP vs manual. Here the focus is what marketers need so GA4 and Google Ads respect the banner instead of ignoring it.

Consent Mode is Google’s API for adjusting tag behaviour from user consent choices. You obtain consent with a banner or CMP. You communicate the state to Google. Consent-aware Google tags (Google tag, GA4, Google Ads, Floodlight, Conversion Linker) then adapt storage and data use.

Google’s overview lists the job as three steps: collect the choice, send the state, and make tags honour it. Consent Mode is step two and three for Google products. It does not invent lawful consent for you.

Google’s November 2023 Consent Mode update (often called v2) requires two extra parameters alongside the older storage flags when you use Consent Mode for EEA-related advertising features:

  • ad_storage: advertising cookies / device identifiers.
  • analytics_storage: analytics cookies / identifiers (for example visit duration).
  • ad_user_data: consent to send user data to Google for online advertising.
  • ad_personalization: consent for personalised advertising.

Google’s setup guide says if you already used Consent Mode, upgrade so those two new parameters are sent. OneTrust’s Cookie Consent Integration with Google Consent Mode notes DMA gatekeeper context for Google and that script version 202311.1.0 or newer is required for the new parameters.

Other Consent Mode types exist (functionality_storage, personalization_storage, security_storage). Most marketing stacks start with the four above.

Basic vs advanced (why your reports look different)

Google documents two implementation styles:

  • Basic: Google tags stay blocked until the user interacts with the banner. No Google data before that interaction, including no default consent ping if tags never load. Modelling leans on a more general model.
  • Advanced: Tags can load with defaults (often denied). While denied, tags may send cookieless pings; after grant, full measurement resumes. Google describes richer advertiser-specific modelling than basic.

Pick the style with counsel and privacy ops, not only with the media agency. Advanced is not a licence to skip a Reject control or to set defaults to granted in consent regions.

Geolocation rule mapping

OneTrust’s product docs describe enabling Google Consent Mode on the geolocation rule and mapping Cookie Consent categories to Google consent types. By default, OneTrust associates:

  • Performance with analytics_storage
  • Targeting with ad_storage, ad_user_data, and ad_personalization

You can change those associations per rule, then save and republish. Wrong maps (for example parking ads under Performance) send the wrong signal even when the banner looks fine.

GTM OneTrust CMP template

Google Tag Manager Help documents installing the Community Template Gallery OneTrust CMP tag, toggling Google Consent Mode to Yes, and adding GCM categories with global and region-specific defaults (ISO country codes). The advantage OneTrust calls out for the CMP-GCM template is that consent defaults can live in the template so you do not always hard-code gtag('consent','default',...) on the page.

Without the template (gtag / OptanonWrapper)

OneTrust developer docs also show setting defaults, loading the OneTrust stub, then calling gtag('consent','update',...) from OptanonWrapper when active groups include the Performance or Targeting category IDs (for example C0002 / C0004; confirm IDs in your tenant under Categorization). Match the IDs in your tenant, not sample IDs from a blog post.

Marketer checklist before you trust the dashboard

  1. Banner first: Equal Reject, optional categories off by default, Preference Center reopen (article 5).
  2. Inventory clean: Unknown cookies resolved; optional tags gated (article 6).
  3. Script order: Consent defaults before Google config / GTM fires. Google warns out-of-order defaults fail silently.
  4. All four v2 keys: Defaults and updates include ad_user_data and ad_personalization where you rely on Consent Mode for ads.
  5. Region defaults: Deny in EEA/UK consent regions; do not copy one global granted default everywhere.
  6. Withdrawal: Preference changes must issue a new update (including deny). Google notes updates on the same page before navigation so events are not lost.
  7. Verify in Tag Assistant: Confirm consent states on Accept, Reject, and reopen. Do not ship on a single happy-path Accept test.

What happens when the user denies

When storage is denied, consent-aware Google tags avoid writing or reading the relevant advertising or analytics cookies. Google may still receive limited cookieless pings used for modelling, depending on basic vs advanced and product rules. ad_personalization denied disables personalised advertising features. ad_user_data denied blocks sending user data for online advertising (including paths that feed enhanced conversions style first-party data use). Optional flags such as url_passthrough and ads_data_redaction further change click-ID and ads-data handling; set them deliberately with eng, not as silent theme defaults.

Common marketing failure modes

  • Consent Mode “enabled” in OneTrust while GTM still fires Ads tags on All Pages with no consent check.
  • Only ad_storage / analytics_storage updated; v2 ad user data and personalization left unset.
  • Defaults set after gtag('config').
  • Testing only from an office IP outside the EEA while production traffic is mostly EU.
  • Assuming Consent Mode replaces Auto-Blocking or GTM consent triggers for non-Google pixels.
  • Treating modelled conversions as identical to observed conversions in board reporting.

FAQ

No. Consent Mode does not show a banner or store Preference Center choices. OneTrust (or another CMP / custom UI) collects the choice; Consent Mode tells Google tags what to do next.

Google documents CMP partners and custom banners. For ordinary advertiser sites, a correct custom implementation can send the signals. Publisher products with personalised ads in EEA/UK/CH may require a Google-certified CMP / TCF path; confirm current Google publisher policy for your stack (article 7).

Volumes usually drop versus an unconstrained baseline. Google offers modelling under eligibility thresholds. Plan media and finance reporting for a consent-aware baseline, not for 2022 unconstrained numbers.

Sources and further reading

Next in this series

Up next: Cookie Consent Records: Why They Matter and How OneTrust Helps. Consent Mode moves tags. Records prove what the user was shown and chose when someone asks.

Disclaimer

This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, privacy policies, or other privacy and data-protection controls. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.

Last updated on 9 September 2026

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *