Consent Mode v2: Basic vs Advanced, and why almost nobody knows which one they have
80.4% of the sites I’ve audited still send data after the user clicks “Reject.” It’s not a failure of whichever Consent Mode setting they picked. It’s that nobody checked what actually happens in Network.
The two modes, no filler
Basic: Google’s tags (GA4, Ads) don’t load at all until there’s a consent decision. Before that, zero requests. It’s the simplest option to reason about, but it means zero data — not even modeled — for any visitor who hasn’t responded to the banner yet.
Advanced: tags load always, from the first moment, but without using cookies until there’s consent — instead they send a cookieless signal (“ping”) indicating the consent state. Google uses that to statistically model the gaps, without identifying anyone individually without permission.
Neither one is “the correct one.” Both are compliant if implemented properly.
The real failure isn’t there
Here’s what almost nobody checks: having gtag('consent', 'default', {...}) properly set up in the <head> — which technically “activates” Consent Mode v2 — doesn’t automatically gate every individual tag inside GTM. Each tag (the Meta pixel, the Ads conversion, the server-side event) has its own “Additional consent checks” section, and if nobody explicitly checks it, that tag keeps firing no matter what happens in the banner — with Consent Mode “active” on the entire page.
It’s the difference between having the alarm installed and having the alarm wired to the door.
The 30-second test
- Open your site in an incognito window.
- F12 → Network tab → filter by “collect” or by the pixel’s domain you care about.
- Reject everything in the cookie banner.
- Browse or interact a bit.
- Check whether traffic to those domains still shows up.
If it does, it’s not a problem with the Basic or Advanced mode you have selected — it’s that some tags don’t have their consent check ticked, and you need to go tag by tag to fix it, not change the global config.
This is the same failure I documented in the PII leak finding I found auditing 154 tags — the cause repeats often enough that I now look for it first in every new audit. If you want me to review yours, here’s how I work.