GTM & Google consent signals

Consent Mode & GTM Technical Audit

Consent Mode is only useful when the website, CMP and Google tags agree on the same consent state. PlainPrivacy checks the implementation in the browser instead of assuming the configuration is correct because a tag is present.

Technical assessment and implementation support. PlainPrivacy does not provide legal advice.

Audit method
01

Observe the live implementation

02

Compare consent states

03

Document evidence and priorities

04

Implement and retest when requested

Scope

What we inspect in GTM and Consent Mode

The goal is to establish exactly which consent signals are set, when they change, which tags depend on them and whether the resulting browser behavior matches the intended configuration.

01

Consent initialization

Review the default consent state and the order in which the CMP, consent logic and Google tags initialize.

02

Consent updates

Verify that accept, reject and granular choices produce the expected consent-state changes.

03

GTM triggers

Check triggers, consent requirements and tag sequencing for analytics and advertising tags.

04

GA4 & Google Ads

Observe requests and storage behavior before and after consent, including duplicate or unexpected implementations.

05

Duplicate tracking

Identify multiple containers, duplicate GA4 configuration or repeated conversion events that can distort measurement.

06

Browser verification

Validate the result through DevTools, network requests, storage and observable consent state rather than configuration screenshots alone.

Evidence

What the review is based on

Findings are grounded in observable website behavior and the configuration available within the agreed scope.

  • Consent state before interaction
  • Consent state after accept/reject
  • GTM tag and trigger review
  • GA4/Ads network request inspection
  • Cookie and browser-storage changes
  • Before/after remediation retest

Deliverables

What you receive

The output is designed to be usable by business owners, developers, agencies and privacy advisers.

  • Technical implementation findings
  • Consent-state evidence
  • Tag/trigger issues and priorities
  • Duplicate tracking findings
  • Recommended fixes
  • Optional implementation and verification

How it works

Investigate first. Change only what the evidence supports.

The initial review establishes the current behavior. Recommended changes are then scoped, implemented only when agreed, and retested afterward.

1

Review

Confirm the platforms, regions, consent system and tracking stack that need to be tested.

2

Test

Run controlled browser journeys and inspect consent, storage, requests and tracking behavior.

3

Prioritize

Separate working controls from technical issues and identify the fixes that matter most.

4

Fix & verify

When implementation support is requested, apply agreed changes and repeat the relevant tests.

Request a technical review

Need evidence of what your website is actually doing?

Tell us about the website, platform, consent setup and current concern. We will suggest an appropriate technical scope.

Request Your Technical Audit