Google Consent Mode v2 Validation
Last updated: October 4, 2026
Use this page to verify Google Consent Mode v2 implementation quality before release.
1. Required Consent Signals
Section titled “1. Required Consent Signals”Verify all four keys are set and updated:
ad_storageanalytics_storagead_user_dataad_personalization
2. Required Ordering
Section titled “2. Required Ordering”Baseline expectation:
- Consent
defaultis set before Google tags evaluate. - In banner regions, user choice triggers consent
update. - Validated no-banner regional policy produces the configured granted update. Initial denied defaults remain safe while configuration loads; a delivery error is not a no-banner grant.
- No conflicting consent commands are pushed by other scripts.
For GTM, use Consent Initialization - All Pages trigger.
For full GTM implementation steps, see Google Tag Manager (GTM) Template Guide.
3. Recommended Google-ready banner
Section titled “3. Recommended Google-ready banner”When enabling Consent Mode without IAB TCF for a web property, start with the CYBEXO Google-ready banner in the dashboard. It is designed to make these points prominent before the affirmative choice:
- data is used for personalised advertising and analytics;
- the visitor can open Google’s Business Data Responsibility information;
- the visitor has an affirmative Accept All action, alongside the configured reject and preference controls.
Set a real privacy-policy URL for the property before publishing. The template is a technical implementation aid, not legal advice or a determination that a particular consent design meets every obligation that applies to the customer.
The Google-ready template’s required purpose explanation and Google disclosure currently use English and are marked lang="en"; configured title/intro and controls use their existing locale. This does not claim a fully localized Google-ready template. Verify the delivered language with your audience. Its category-only decisions are not TCF decisions and must not be described as TCF consent receipts.
4. Choose a Consent Mode implementation
Section titled “4. Choose a Consent Mode implementation”Google describes two implementation models. Select one deliberately and test the result on the production domain. Direct-script customers should follow the complete Web installation and mode-switching instructions. New properties enable Consent Mode by default; an explicit saved off choice is preserved.
Basic implementation
Section titled “Basic implementation”Use basic mode when the customer wants Google tags blocked until the visitor makes a choice.
- Keep Consent Mode enabled. Configure the publisher’s Google tags and their triggers/consent checks so they do not load before the required positive consent choice and stop further collection after withdrawal.
- For GTM installations, use the native CYBEXO template on Consent Initialization - All Pages. For direct installations, implement and verify the publisher’s blocking integration. The complete GA4 Basic/full-off example covers one direct GA4 destination with Web CMP 1.5.30 or later; the CMP toggle does not itself block other scripts.
- In a fresh browser session, confirm no Google tag request is sent before acceptance; then confirm the intended tags can run after acceptance. Test withdrawal separately: stop later manual events immediately, account for any in-flight/consent-transition request from a previously loaded tag, and confirm no Google load on the following denied page.
For the separate option to disable CYBEXO Google default/update commands entirely, publish Consent Mode off and replace the direct snippet with the off installation in the Web guide. Remove the old inline defaults and any separate advertiser-TCF override. Do not describe a mode toggle as automatic tag blocking.
Advanced implementation
Section titled “Advanced implementation”Use advanced mode when Google tags load with CYBEXO Consent Mode defaults and receive a consent update after the visitor’s action.
- Use the direct Web bootstrap before measurement scripts, or the CYBEXO native GTM tag on Consent Initialization - All Pages, according to your chosen integration.
- Keep the four-key default state region-appropriate; banner flows begin with the denied state and send an update after the visitor chooses.
- Verify in Tag Assistant that the default precedes Google tag execution and that the update reflects the visitor’s choice.
For the operational difference and Google’s current definitions, see Google Analytics: consent mode basic and advanced. Consent Mode configuration does not itself settle the customer’s legal or regulatory obligations.
5. Browser Console Checks
Section titled “5. Browser Console Checks”(window.dataLayer || []) .map(e => Array.isArray(e) ? e : Object.prototype.toString.call(e) === '[object Arguments]' ? Array.from(e) : null) .filter(e => e && e[0] === 'consent')In advanced mode, expect defaults before initialization and updates as policy/choices resolve. Full-off mode should have no CYBEXO Google defaults or updates. This log shows queued commands only; use Tag Assistant to verify effective state and tag behavior.
6. Tag Assistant Checklist
Section titled “6. Tag Assistant Checklist”- Open Tag Assistant preview.
- Test an EEA/UK session and reload with a fresh session.
- Confirm consent defaults are present before Ads/Analytics tag execution.
- Interact with banner and confirm consent update values change according to choice.
- Test a non-banner region session and confirm the validated regional policy grants the expected state when no banner is intentionally shown.
7. GTM Best Practices
Section titled “7. GTM Best Practices”- Keep CMP tag in Consent Initialization, not regular Page View.
- Avoid duplicate consent default commands from multiple templates.
- Keep region overrides documented in container notes.
- Direct Web starts with four denied defaults while configuration loads. Verify subsequent regional updates; do not replace this safe startup with an unconditional grant.
- If a Google tag is delivered through Google tag gateway, follow the Google tag gateway load-order and remediation guide before changing the CMP or tag sequence.
8. Common Failures
Section titled “8. Common Failures”- Consent defaults pushed too late.
- Tags fire before consent defaults.
- Missing one or more v2 keys in default or update calls.
- Another plugin overwrites consent state.
- A verified no-banner regional policy never reaches its expected update, or a dependency error is mistaken for a no-banner grant.
9. Evidence to Store for Audits
Section titled “9. Evidence to Store for Audits”- Tag Assistant screenshots with event timeline (EEA banner flow + non-banner regional flow).
- Browser console export of consent events.
- CMP debug report from production domain.