# Google and Microsoft

Consent Mode v2 and Microsoft UET consent, with no changes to your tags.

Google requires sites in Europe to tell it about consent before its tags run. We do this with Consent Mode v2: the banner sets default signals before your tags load and sends an update as soon as a visitor chooses. Google Analytics, Google Ads and Tag Manager need no changes.

Microsoft Advertising works the same way (UET consent), and it is on by default.

Consent Mode passes the visitor's choice to Google's tags. It doesn't decide what the law asks of your site; the banner's rules for each country do that.

Google's own guides: [Consent Mode for developers](https://developers.google.com/tag-platform/security/guides/consent) and [About Consent Mode](https://support.google.com/google-ads/answer/10000067).

## What the banner sends

- Before your Google tags run, `ad_storage`, `analytics_storage`, `ad_user_data` and `ad_personalization` start as denied.
- When a visitor accepts or rejects, the banner sends an update. Rejecting everything sends all four as denied; accepting everything sends all four as granted. Advertising sets the three ad signals, analytics sets `analytics_storage`.
- Where your rules show no banner (for example most US states), the banner sends granted, so your measurement there carries on.
- On later pages the defaults stay the same and the banner sends the visitor's saved choice as an update.

It is on for every new site. To turn it off, switch off **Tell Google Ads and Analytics about each choice (Consent Mode)** in the Banner tab's Advanced settings.

## Basic and advanced

Google describes two ways to run Consent Mode.

- **Basic (our default).** Google gets nothing until a visitor says yes. The banner holds Google's tag (`gtag.js`) until the visitor agrees to analytics, and holds the cookieless "no consent" requests of Google tags loaded through Tag Manager, including requests sent through your own address.
- **Advanced.** Google's tags load straight away. While consent is denied they send cookieless requests, which Google uses to estimate ("model") conversions. Turn on **Let Google's tags send cookieless data before visitors agree (Advanced)** in the Banner tab's Advanced settings. Switch it off to go back to basic.

Where the law asks first, regulators haven't settled whether advanced mode is allowed.

## What this means for your reports

- After consent, Google's tags work normally.
- If your site has enough traffic, Google can model some of the missing conversions. For Ads that takes about 700 ad clicks a week per country, and for Analytics about 1,000 daily visitors. Smaller sites see only the data that was observed. We mention this because the idea that modelling will recover lost data is often overpromised.

## Tag Manager

Our script must run before the Tag Manager snippet, so put it above the snippet in your page's `<head>`. The install check confirms this ("Google tags wait for consent"). If you load Meta, TikTok or other pixels through Tag Manager, either gate them on the consent state with a trigger or let our automatic blocking hold them. It does this for known pixel hosts.

## Checking your setup

- **Install check.** Press **Check my site** on the Install tab. It loads your homepage and tells you whether Google tags wait for consent or a Google tag loads first. The monthly email repeats the result.
- **Tag Assistant.** Open [Google Tag Assistant](https://tagassistant.google.com/), connect your site, and open the Consent tab on the first event. The defaults should be denied before any tag fires, and an update should follow when you choose in the banner.

If a Google tag loads first, move our script line above it. If it still loads first, check whether the tag comes through Google tag gateway (below).

## Google tag gateway

[Google tag gateway for advertisers](https://developers.google.com/tag-platform/tag-manager/gateway) serves Google's tag from your own domain, through your CDN (such as Cloudflare), load balancer or web server. When it is switched on with one click at the CDN, the CDN adds the tag to your pages itself, so you can no longer choose whether it loads before or after our script. Consent then arrives late.

**How to tell if a tag uses it:**
- In Google Ads, Analytics or Tag Manager, open the Google tag's settings and then **Google tag gateway**. A domain marked **Active** or **First-party** uses it.
- In your browser's developer tools, open the Network tab and reload. A gateway tag loads from a path on your own domain instead of `googletagmanager.com`.
- In Cloudflare, look for Google tag gateway under your domain's settings.

**If the install check says a Google tag loads first and the tag uses the gateway**, do one of these:
- Use advanced mode (above). Google recommends it for gateway tags, because advanced mode works when the tag loads before the consent signal. Review the consent defaults and data controls in your Google tag's settings to match what you need.
- Move your Google tags into a Tag Manager container and serve that container through the gateway, with our script above it.
- Set up the gateway by hand ([Google's setup guide](https://developers.google.com/tag-platform/tag-manager/gateway/setup-guide)) so you control the order of scripts on the page.

## Server-side tagging

Consent Mode signals only reach Google tags. Server-side integrations for Meta and TikTok need their own consent check, which can read the visitor's choice from the JavaScript API or the `cmp:consent` event.

## Getting help

If Google's tags aren't getting consent signals, email us first at hello@flatconsent.com, not Google support. The signals come from our banner, and Google's support asks you to check with your consent provider before contacting them.
