Audit the current state
Whether Consent Mode is installed at all, and if so, whether the signals are mapped correctly.
The damage doesn't show up as an error message. It shows up as EEA traffic that quietly stopped existing in your reporting.
Without Consent Mode wired up, a visitor who declines cookies disappears from conversion reporting entirely, not just from remarketing lists.
A default implementation guesses at how your CMP's categories map to Google's signals, and that guess is wrong more often than accounts realise.
Two different consent configurations drifting apart over time means GA4 and Ads eventually disagree about the very same visitor.
A handful of consent signals, mapped correctly between your CMP and Google's tags, then verified — not just switched on and assumed to be right.
ad_storage, analytics_storage, ad_user_data and ad_personalization, all four wired in properly instead of a partial implementation that only covers analytics.
Deliverable: CMP & consent auditMatched to how your consent platform's categories actually work, not the default guess most implementations ship with and never revisit.
Deliverable: Consent Mode v2 configuredWhichever your CMP actually supports, chosen deliberately rather than defaulted to whatever a plugin happened to install first.
Deliverable: Implementation chosen & verifiedChecked that declined-consent traffic is actually populating modeled conversions, not just assumed to be working because the tag fired.
Deliverable: Modeling verifiedGA4's own consent settings aligned to the same signal set as Ads, instead of drifting apart as two separately configured systems.
Deliverable: GA4 alignment checkedVerified through Google's own consent diagnostics tooling before we call it done, not left as a setting nobody ever confirmed was working.
Deliverable: Compliance documentationWhether Consent Mode is installed at all, and if so, whether the signals are mapped correctly.
Your CMP's categories connected to Google's consent parameters, matched to what they actually mean.
Checked that declined-consent traffic is being modeled, not just dropped from reporting.
A written record for your own compliance file, not just a setting nobody can explain later.
We'd turned on Consent Mode ourselves using the plugin defaults and EEA traffic basically vanished from reporting overnight. Mapping it into the account properly recovered most of that volume within the modelled numbers.
Our consent signals had been mapped to the wrong categories since the CMP was installed two years ago. Nobody had ever checked, because the banner itself looked fine to every visitor.
GA4 and Google Ads had been configured with two completely separate consent setups for years. Aligning them to one signal set closed a gap our finance team had been quietly working around.
We only had basic Consent Mode installed and had no idea advanced modeling existed. Switching to it recovered a meaningful share of the EEA conversions we'd been missing for over a year.
Our legal team flagged that we needed Consent Mode v2 and we had no idea where to start. Having someone document exactly what was configured and why made our compliance review painless.
We'd assumed our developer had already handled Consent Mode when the new banner launched. An actual check found the signals were only partially wired up, and analytics_storage had been ignored the whole time.
We switched CMPs last year and nobody remapped the consent signals to the new platform's categories. Six months of EEA data had been quietly wrong before anyone noticed the drop.
We assumed our developer had wired up Consent Mode when the banner shipped two years ago. An actual check found it had never been connected to anything — the banner just sat there doing nothing.
Consent rates on our banner looked healthy, so we assumed the downstream setup was fine too. The gap wasn't the banner at all — it was what happened, or didn't happen, after someone clicked it.
Google's requirement applies to any EEA traffic your account serves, even if it's a small share. It's worth configuring even for a small percentage.
Any CMP that supports the Google Consent Mode API — that covers most major platforms, including Cookiebot, OneTrust and Complianz.
No — we configure the technical implementation correctly. Whether your consent banner itself meets your specific legal obligations is a question for your legal counsel.
The signal mapping needs to be redone against the new CMP's categories — usually a short piece of work rather than a full rebuild.
Send us access and we will come back with a written audit: what is tracked, what is double-counted, what is missing, and what we would change first.
No pitch deck · No lock-in · Findings are yours either way