Google Consent Mode v2 For Shopify

Ildi Veliu

Written by Ildi Veliu

Google Consent Mode v2 For Shopify

Google Consent Mode tells Google what your Shopify store is allowed to do with a shopper's data. It's been required for EEA visitors since March 2024, and in June 2026 Google went further. For any Analytics property linked to a Google Ads account, Consent Mode is now the one control that decides whether ad data gets collected at all.

That signal now decides whether your ads can see conversions and build audiences. The rules change from one country to the next. A shopper in Germany, a shopper in California, and a shopper in Brazil each sit under different rules.

Here's what your setup needs to look like in each one.

What Consent Mode v2 sends to Google

Consent Mode and the cookie banner do different jobs. The banner collects the shopper's choice; Consent Mode passes that choice on to Google. It runs on four signals, each either "granted" or "denied" for a given shopper, and Google's tags change what they do based on them. You can see all four in Google's own Consent Mode docs.

Signal

What it controls

New in v2?

ad_storage

Storing ad cookies and IDs

No

analytics_storage

Storing analytics data (GA4)

No

ad_user_data

Sending user data to Google for ads

Yes

ad_personalization

Using that data for remarketing and personalized ads

Yes

The first two are old. The two new ones, ad_user_data and ad_personalization, are the ones European rules turn on. A banner that only sets the first two is running half a setup, even if it looks fine on the page.

Once these signals reach GA4, they change how your reports fill in. 

The rules change by region

One store, many countries, and the law is different in each one. The table below lays it out.

Region

Model

By default

What your store must do

EEA, UK

Ask first (opt-in)

Nothing tracks

Block non-essential tags. All four signals set to denied until the shopper agrees.

Switzerland

Ask first, in practice

Same as EEA for most stores

Group it with the EEA and UK.

United States

Opt out

Tracking runs

Give a clear opt-out. Honor the browser opt-out signal. Set the ad signals to denied when someone opts out.

Brazil

Ask first (opt-in)

Ask before tracking

Treat it like the EEA.

In the EEA and UK, ask before you track

The European Economic Area and the UK run on consent. No non-essential tag can fire until the shopper agrees. So all four signals start at denied and only turn to granted after a clear yes.

  • Consent means nothing fires until the shopper answers.

  • “Yes" and "no" both have to be equally easy to click. The reject button needs the same visibility as accept

  • The two new signals, ad_user_data and ad_personalization, are what keep remarketing and ad personalization working for these shoppers.

You have two ways to run it, and the choice affects how much data you keep.


Basic mode

Advanced mode

When tags load

Only after consent

On page load, set to denied

Shoppers who decline

Send nothing

Send a small signal, no cookies

Filled-in (modeled) conversions

Lost

Recovered

Setup effort

Lower

Higher

Best for

Small EEA traffic

Bigger EEA volume

Advanced mode lets Google fill the gaps for shoppers who say no, using its own estimates instead of their real data. For most stores with steady EEA sales, that is worth the extra work.

Get these two signals wrong and remarketing and personalization stop working for your EEA shoppers, with nothing in Google Ads or GA4 telling you why.

Your stores must adhere to the 7 principles of GDPR if it targets or collects data from individuals in the EU/EEA, regardless of your location.

Switzerland gets grouped with the EEA

Switzerland sits outside the EU, so it drops off a lot of setups, but its updated privacy law means it still belongs on your list. Swiss law differs from the EU's, but it's close enough that most stores run the same ask-first banner for Swiss shoppers. Shopify lets you group Switzerland with the EEA and UK, so covering it costs you nothing.

The United States runs on opt-out

The US works the other way, and this is where stores get caught out. Under California's CCPA and the wave of state laws behind it, tracking is allowed the moment a shopper lands. As of 2026, twenty US states have full privacy laws in effect, led by California. 

Your job is to give people a working way to opt out, and to honor it when they do.

Two things matter for your Google setup:

  • When a US shopper opts out, ad_user_data and ad_personalization should turn to denied. Same signals, different trigger.

  • In California, Colorado, Connecticut, and a growing list of other states, a browser that sends the Global Privacy Control signal counts as an opt-out on its own, with no click needed. You have to honor it.

Shopify handles more of this than most people expect, but only if you switch it on. When you turn on the data sale opt-out page for your US regions, Shopify reads the Global Privacy Control signal automatically and marks those shoppers as opted out of data selling. Plenty of stores never enable that page, so the signal arrives and nothing happens.

Brazil and the shift to opt-in

Brazil's privacy law (LGPD) is closer to Europe's approach than America's. It runs on consent, so the safe default for Brazilian shoppers is to ask before you track. The wider trend across Latin America, Canada, and parts of Asia points the same way, toward asking first. 

Build for consent now, and adding a new ask-first market later is just a settings change.

How about the rest of the world?

Google's own requirement is narrow. Consent Mode v2 is tied by law to the EEA and UK, through the DMA and GDPR. The US and Brazil rows are in the table because their own privacy laws change what your tags are allowed to do, not because Google requires it there. Outside these four rows, no law currently forces a Google-facing consent signal, so the default holds: tracking runs, and there is no Consent Mode setup to build yet.

That is shifting. Canada, several Latin American markets beyond Brazil, and a growing list of Asian markets are moving the same direction, toward asking first. If one of your markets gets there, group it with the EEA and UK banner the way you already treat Brazil.

What to do if you sell in more than one country

Most Shopify stores sell to several regions from one storefront. That puts you under more than one set of rules. If you have EEA visitors, GDPR applies, whatever your size.

US state laws usually start above a size threshold, but those thresholds are low, so most growing stores plan as if they apply. Each region's law applies on its own terms, regardless of the others.

There are two ways to handle that:

  • Strictest rule everywhere. Show the ask-first banner to everyone, including US shoppers. It is the simplest to set up and the safest. The cost is data: you block tracking by default for US shoppers you were allowed to track.

  • Right rule per region. Show an ask-first banner to EEA, UK, Swiss, and Brazilian shoppers, and an opt-out notice to US shoppers. More setup, but you keep the data each region lets you keep.

For most stores with decent US sales, we go with the second option. The extra setup keeps more of your US data.

Whichever you pick, a few things hold true in every region:

  • Detect location, then apply the rule. Your banner should check where the shopper is and behave the right way for that region. Shopify's region settings and your consent app do this together.

  • Keep a record of consent. Most laws expect you to show that a shopper agreed. Your consent app logs this for you, with a timestamp, per region.

  • Match the shopper's language. Consent only counts if the shopper can actually read the banner. If you run storefronts in more than one language, the banner should follow.

  • Run a single setup with region rules built in, rather than stacking banners that conflict with each other. It's cleaner and easier to check.

Is your Consent Mode set up wrong?

You will not get an error message if your consent mode is set up wrong. The tags still load, the banner still shows, and the data just stops arriving. Check your own store for these signs:

  • Your Google Ads remarketing audiences stopped growing, or shrank.

  • EEA conversions in GA4 dropped off on a set date and never came back.

  • Google Ads is showing a consent or EU user consent policy warning.

  • In Google Tag Assistant, ad_user_data or ad_personalization reads denied for visitors who accepted.

  • In an incognito window from an EU location, Google tags fire before you touch the banner.

When we audit Shopify stores, the same three problems come up again and again:

  • The banner sends the old two signals but never the two new ad signals, ad_user_data and ad_personalization, so ads data stops for EEA shoppers.

  • One consent setup is applied worldwide, so either US shoppers get blocked by default and you lose data, or EEA shoppers get tracked before they agree.

  • The US data sale opt-out page was never turned on, so opt-out signals arrive and nothing happens.

Set up consent mode correctly on Shopify

Shopify gives you the parts to run one setup that behaves right by region, so there's no need to rebuild it per country. For most stores, a consent app gets this done in an afternoon. Server-side tracking is the one bigger piece, and only if you spend a lot on ads.

1. Turn on the banner and the opt-out page. In your admin, go to Settings > Customer Privacy. Set up the cookie banner and, for your US regions, the data sale opt-out page. Shopify's region settings let you pick which regions see the banner and how it acts, so EEA shoppers get an ask-first banner and US shoppers get an opt-out notice. With the opt-out page on, Shopify honors the Global Privacy Control signal automatically in those regions.

2. Connect a certified consent app. Shopify's Customer Privacy API tracks the shopper's consent choices, but the native banner does not pass them to Google on its own. That is what a consent app is for. Pick one that:

  • is on Google's list of certified consent platforms,

  • connects to the Customer Privacy API,

  • blocks trackers before consent for EEA shoppers,

  • handles the US opt-out page and the Global Privacy Control signal,

  • logs consent per region for your records.

One app that does all five is worth more than three that each do part of the job. Here’s a few to consider.

App

Covers your five checks

Pricing

Rating

Pandectes GDPR Compliance

All five, plus TCF v2.3 and Hydrogen support

Free; paid from $9/mo

2,750+ reviews

Consentmo GDPR Compliance

All five, plus multi-pixel scanning

Free; paid from $9/mo

1,800+ reviews

Avada GDPR Cookies Consent

All five, plus GPC and wide law coverage (LGPD, PIPEDA, APPI)

Free; paid roughly $9 to $34/mo

850+ reviews


3. Add server-side tracking if you spend a lot on ads. Consent Mode handles what fires in the browser, and browser tags still fail on their own from ad blockers and script clashes. Server-side tracking makes sure the data you do have permission to collect actually reaches Google.

Image taken from our recent guide on how to set up server side tracking

4. Test it before you rely on it. Open your store in a fresh incognito window, run Google Tag Assistant, and check the consent state before and after you click the banner. In Google Tag Manager (GTM), the consent overview shows whether each tag has the right setting. Do this per region if you can. A banner that works in the EEA can still be wrong for US traffic.

Get your consent and tracking set up right

Consent Mode v2 is one piece of a tracking setup that has to hold up across every country you sell in. We build and check analytics and consent setups for Shopify stores, so the data reaching Google is both clean and allowed. 

If your remarketing has gone quiet or your GA4 numbers stopped adding up, talk to us about your analytics setup.

FAQs about Google Consent Mode v2 

Do I need to recheck my sites consent after a theme update?

Yes. A theme update can silently disable the app embed your consent app depends on. If your consent app stops firing after a theme change, that is usually why. Re-enable the embed and retest with Tag Assistant before you trust the numbers again.

Is the setup different for a headless (Hydrogen) storefront?

Yes. The cookie banner method most stores use does not fully integrate with Shopify Analytics on Hydrogen. If you're running a headless storefront, use the Hydrogen Analytics package instead, and check that your consent app explicitly lists Hydrogen support before you install it

Will turning on Consent Mode now change my past GA4 reports?

No. Consent Mode only affects data collected going forward. Your historical reports stay exactly as they are; nothing gets rewritten or reprocessed once you turn the signals on.

Does my consent choice cover Shopify's own use of my data, or just Google?

Both, but through different channels. Consent Mode is Google's own protocol, it only talks to Google's tags. Separately, the same consent choice, captured through Shopify's Customer Privacy API, also decides whether Shopify Network Intelligence can use that shopper's activity for its own advertising purposes. One choice, two systems reading it.

Does Consent Mode also cover my Meta or TikTok pixels?

No. Consent Mode is Google's own signal set, it only talks to Google's tags. Meta and TikTok each run their own separate consent systems, so getting the four Google signals right does not automatically cover those pixels too. Many apps like Elevar, handle all three, but check that scope explicitly rather than assuming one setup covers your whole stack.

Ildi Veliu

Ildi is a Technical SEO Specialist at Shero Commerce on a mission to help websites unlock their full organic potential. With a background in Informatics-Economics, he bridges the gap between technical web development and search engine algorithms, specializing in technical audits and search performance strategy. He is always looking for new ways to outsmart the algorithms and drive high-intent organic traffic.