Analytics and Tracking

Consent Settings

Also called Additional consent checks

Per-tag rules stating which consent types must be granted before a tag is allowed to fire.

Quick facts: Consent Settings

Category
Analytics and Tracking
Also called
Additional consent checks
Level
Advanced
Affects
Compliance work, reported conversions, data completeness
Where to see it
Google Tag Manager (tag consent settings), preview mode, your consent platform
In this article4
  1. How consent settings work
  2. Why consent settings matter
  3. Where consent settings go wrong
  4. How to act on it

Every tag in a container carries a consent configuration. Google’s own tags declare their requirements themselves — an advertising conversion tag knows it depends on ad storage — and for any other tag you state the requirement yourself under the additional consent checks. When the trigger fires, Tag Manager compares the tag’s requirement against the current consent state. If a required type has not been granted, the tag is held back instead of firing.

The consent state does not come from these settings. It arrives from a banner or a consent management platform, which updates it as the visitor chooses. The settings only decide what each tag does with that state, and a tag with no requirement declared fires regardless of what the visitor said.

They are what turns a banner from decoration into a control. A site can display a perfectly worded cookie notice and still fire every marketing tag the moment the page loads, which is what I find on a great many sites I audit. Consent settings are the point where the promise on the banner becomes something the container actually enforces.

They also keep behaviour predictable in a container several people edit. Once a requirement is declared on a tag it travels with that tag, rather than depending on someone remembering to attach an exception trigger every time.

The first failure is a banner with nothing behind it. Nothing on screen gives this away: the notice appears, the visitor declines, and the tags fire anyway. Only preview mode or a tag inspection tool exposes it.

The second is the opposite — requirements drawn so broadly that basic first-party reporting is blocked alongside the advertising tags. The reporting gap that follows usually gets blamed on the analytics setup rather than on the consent configuration that caused it.

The third is assuming the settings satisfy a legal obligation. They are a technical control and nothing more. What consent you must collect, and how, depends on where your visitors are, and that is a question for a legal adviser rather than for a configuration screen.

How to act on it

Go through every tag in the container and decide what each genuinely requires; a tag whose requirement nobody can articulate probably should not be there at all. Then test both paths in preview, consent granted and consent declined, and confirm the blocked tags really are blocked. A declared requirement that was never tested is only an intention.

If you sell to visitors in the EU or the UK, build consent into the tracking setup from the start rather than bolting it on at the end, and expect reported conversions to sit lower than an unconsented setup showed. If you do not know what your container currently does when someone declines, a tracking audit settles it in an afternoon.

Do and do not

Do

  • Declare a consent requirement on every tag
  • Test both the granted and declined paths
  • Record the date enforcement went live

Do not

  • Assume a banner blocks tags by itself
  • Block basic reporting alongside advertising tags
  • Treat these settings as legal advice

Questions people ask about this

Do consent settings replace a cookie banner?

No. The banner asks the visitor and records the answer; consent settings decide what each tag does with that answer. A container full of correct settings and no banner never receives a decision to act on, and a banner with no settings behind it collects a decision that nothing enforces. Both halves are needed.

Will my conversion numbers drop after enabling this?

Reported conversions usually fall, because tags that previously fired for everyone now fire only for visitors who agreed. The underlying sales have not changed, only the measurement has. Expect a step down on the day the change goes live, record that date, and compare later periods against each other rather than against the unconsented history.

Which tags should require consent?

Anything that stores or reads identifiers for advertising or measurement, which covers ad platform pixels, remarketing tags and most analytics. Tags that simply make the site work, such as a chat window the visitor opened themselves, are usually treated differently. The exact line depends on the law where your visitors live, so take advice rather than copying another site.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.