MarketingLimits

Consent Mode: what initial consent states are and how to tell if your website declares them

Consent Mode is how Google tags behave depending on what each visitor has consented to. This finding is triggered when your page doesn’t declare initial consent states before loading those tags. Wakaris checks it on the URL you give it and tells you if they’re missing.

By Juan Ignacio FrancoUpdated: September 7, 20268 min read

In short

What’s checked

that the page declares an initial consent state before running any tag that sends tracking data.

Reference

Google’s documentation defines seven consent types and warns that, by default, no value is set.

Why it matters

without a prior declaration, what gets sent or stored depends on the order in which the page loads.

Severity in Wakaris

Important. On the pages where this check has run, 73% don’t declare any initial state.

Page loading sequence comparing the correct order, with the consent declaration before the tags, and the incorrect order
Order matters more than content: a correct declaration that arrives late is useless.

What this finding is and what it measures

When a page has Google tags (analytics, advertising, remarketing), those tags need to know what can be stored in the browser and what can be sent. Consent Mode is the mechanism through which the page tells them. Google’s documentation describes it as the way to control how tags and SDKs behave based on the visitor’s consent choices.

That mechanism distinguishes seven consent types, each with its own permission: ad_storage, analytics_storage, ad_user_data, ad_personalization, functionality_storage, personalization_storage and security_storage.

This finding doesn’t look at whether the visitor accepted or rejected: it looks at whether the page declares a starting point. The documentation is explicit that, by default, no consent value is set. If the page declares nothing, there’s no initial state for the tags to respect, and the finding is triggered.

How it’s detected

Wakaris analyzes the URL you give it, watches the page load and checks whether an initial consent state is declared before any tag that sends data runs. It tells you whether that declaration exists and the severity of the finding, without installing anything. It’s the direct way to know where you stand.

What it looks for is the command that sets the starting point, such as gtag('consent', 'default', {...}). Google’s documentation asks for it to be called on every page of the site before any command that sends tracking data, and warns that if the consent code is called in the wrong order, the default values don’t work.

It’s worth knowing what’s left out. The check is done on one page load, without anyone clicking the banner, so it describes the starting point and not what happens after accepting or rejecting. Nor does it judge whether the declared values are right for your case: it distinguishes between having declared and not having declared.

Inferred scope: the catalog doesn’t document whether detection requires the declaration to precede the tag or only that it exists.

Why it matters

Without a declared initial state, the behavior of your tags stops being a decision and becomes a loading accident. Google’s documentation describes two ways of working. In basic mode, tags don’t load until the visitor interacts with the banner, and no data is transmitted before that interaction. In advanced mode, tags load when the page opens with permissions usually denied, and while they’re denied they send cookieless measurements.

Both modes depend on a prior declaration existing. Without it, neither one is really running: you can end up with tags that run before knowing what they’re allowed to do, or with a banner that updates a state that was never set.

An important note, and this isn’t legal advice: declaring initial states is a technical tag setting, not proof that you collect consent in line with the law. They’re two different checks and Wakaris presents them separately.

Common causes

The most frequent cause isn’t lack of knowledge, but order. The cookie banner is installed after the analytics tags, or through a tag manager that loads later, and the initial declaration ends up below what it should govern. Google’s documentation lists that sequence as an error case: the visitor opens the page, the advertising tag fires and only then is the default consent set.

The second cause is the plugin that promises to solve everything. Many consent management platforms can issue the declaration, but only if the corresponding option is turned on in their settings; installing them doesn’t turn it on by itself.

The third is the half-finished migration: a new page, a different template or a redesign that carries over the tags and leaves behind the consent block, which usually lives in the header and not in the body of the template.

And the fourth is asynchrony: a consent platform that’s slow to resolve and a page that doesn’t give it time to respond.

How to fix it

First, find out whether it’s missing and on which page: Wakaris tells you in the report. From there, in order of effort versus result.

Start with your consent platform’s settings. If you already have one installed, it can usually issue the initial declaration and you just need to turn on the integration in its settings. It’s the cheapest fix and the one that touches the code least.

If it doesn’t issue it, declare the initial state by hand in the header of every page, above any tag snippet. Google’s documentation says to move the code that calls the default consent command higher up the page, above the tag snippets.

If your consent platform resolves asynchronously, give it time: the command accepts a wait parameter that holds the tags while the platform decides. The documentation’s example allows 500 milliseconds.

And if you have visitors from several territories, the declaration accepts a region parameter to set different starting points per area.

Image pending · {IMG_2}

Table with the seven Consent Mode consent types and what each one controls

Brief to generate the image
Editorial illustration for a Wakaris technical guide.
Topic: Table with the seven Consent Mode consent types and what each one controls.
Style: white background with a soft lime→pale green wash (#F8F7D6 → #E2F2DC), green→lime gradient accent (#8ED390 → #DCD86F), near-black ink (#12150B), pill shapes and rounded corners, soft shadows, clean schematic look, no photography.
Format: 16:9, 1440 pixels wide.
No legible text: any label, code or figure is shown as gray placeholder bars. The caption carries the meaning, not the image.
No real logos or third-party brands. No recognizable people.
Tags: consent, mode, table, types, consent, controls
The seven consent types. The initial declaration sets a starting point for each one.
Table with the seven Consent Mode consent types and what each one controls
The seven consent types. The initial declaration sets a starting point for each one.

Ask your AI

If you want to dig into your specific case, copy one of these two prompts and paste it into the AI you use. Pick the one that fits your situation.

Prompt A

I already have the finding measured with Wakaris and want to fix it

Act as a professional, careful technical web analyst. Your goal is to help me understand a specific finding about my website and decide what to do about it, without making anything up.

Context: I got this finding from Wakaris, a tool that analyzes a website across 9 areas (performance, SEO, security, social, market, AI, user experience, accessibility and legal) and explains each problem so that every profile on a team can understand it. The finding is: Consent Mode. My page doesn’t declare initial consent states before loading Google tags, so those tags run without knowing what they’re allowed to store or send. Reference: the initial declaration must be called on every page before any command that sends tracking data, and it covers seven consent types.

Paste the Wakaris result here: what came up for this finding and on which analyzed page. If you don’t have it, tell me and I’ll explain how to get it before we continue.

Rules you must follow at all times:

1. Don’t assume anything about my website. Every piece of data you use must come from what I confirm or what Wakaris has measured. If you don’t know something, ask me before stating it.
2. Before giving me conclusions, ALWAYS ask me these questions, all together and in plain language, to find out whether this finding really affects me and where:
   a) What platform is your website on? (WordPress, Shopify, custom-built, other)
   b) Do you have a cookie banner or consent platform installed? Do you know which one?
   c) Which Google tags do you have: analytics, advertising, remarketing? Did you add them directly to the template or through a tag manager?
   d) Who installed the banner and who installed the tags? Was it the same person and at the same time?
   e) Have you changed template, theme or cookie platform in recent months?
   f) If the template header needs changing, would you do it yourself, an in-house technician or an agency?
3. Every statement or recommendation must be reasoned in relation to MY context, not in general. If you recommend something, explain why it applies to my case.
4. Always flag your level of certainty. If something is a hypothesis because you can’t measure it, say so: you can’t see my website, you’re reasoning about what I tell you.
5. Don’t suggest irreversible or risky technical changes (touching the template header, editing the tag manager, direct changes on the live site) without first warning me about the risk and that a backup or test environment is advisable.
6. Remember that declaring initial states is a technical tag setting and doesn’t amount to complying with privacy law: if I ask you about the latter, tell me it’s a legal matter and should be assessed by a professional.
7. If you need data that can only be obtained by measuring the website (confirming whether the declaration exists, or whether the fix worked), tell me and recommend that I run the page through Wakaris again: that gets checked, not guessed.
8. The final decision is mine, not yours. Your role is to help me understand and prepare the action, not to decide for me.
9. If the fix goes beyond what I can do myself, or a team will carry it out, help me get the problem ready to hand over: what it is, where it is, why it matters and what needs to be done, in an actionable format for that person.

Source for this finding: https://www.wakaris.com/en/guides/marketing/consent-mode
To check it or check it again: https://www.wakaris.com/

Start by briefly introducing yourself in your role and asking me the first set of questions.
Paste it into the AI you use.
Prompt B

I haven’t measured it yet and want to check if my website has this problem

Act as a professional, careful technical web analyst. I’m looking into whether my website has a specific problem and I want you to help me find out honestly, without taking it for granted.

Context: I came across this through Wakaris, a tool that analyzes a website across 9 areas (performance, SEO, security, social, market, AI, user experience, accessibility and legal) and explains each problem so that every profile on a team can understand it. The problem I want to look into is: Consent Mode. It means a page doesn’t declare initial consent states before loading Google tags, so those tags run without knowing what they’re allowed to store or send. Reference: the initial declaration must be called on every page before any command that sends tracking data. I DON’T know yet whether my website has it: I want to find out.

Rules you must follow at all times:

1. First and most important: this is checked by looking at how the page loads, and you can’t load my website from this conversation. Make it clear from the start that you won’t be able to give me a definitive "yes, you have it" or "no, you don’t", only a hypothesis based on what I tell you.
2. Don’t assume anything. Before giving me any assessment, ALWAYS ask me these questions, all together and in plain language, to estimate whether I’m likely to have the problem:
   a) Do you have any Google tags on your website: analytics, advertising, remarketing? If you have none, tell me, because then the problem doesn’t apply to you.
   b) Do you have a cookie banner or notice? Did you add it with a plugin, an external service or by hand?
   c) Do you know whether that banner’s settings include an option related to Google tags or to analytics and advertising consent? Is it turned on?
   d) Were the banner and the tags installed at the same time and by the same person, or at different times?
   e) Have you changed template, theme or cookie platform since you added the tags?
3. Based on my answers, give me a clear estimate of whether it’s LIKELY or UNLIKELY that I have it, reasoned from what I’ve told you and explicitly marked as a hypothesis, not a diagnosis.
4. Tell me plainly that the only way to know for sure is to check it, and that I can do it for free and without creating an account by running my website through Wakaris, which will tell me whether the declaration exists and the status of the other areas too.
5. If I ask you how to check it by hand, don’t hide it from me, but remind me that Wakaris does it faster, on the real page and with additional information I don’t get by hand.
6. Don’t tell me that declaring initial states amounts to complying with privacy law: they’re different things, and the legal side should be assessed by a professional.
7. If checking shows that I do have it, tell me the next step is to understand how it affects me and how to fix it in my specific case.
8. The conclusion and the decision are mine, not yours. You help me find my bearings.

Source for this finding: https://www.wakaris.com/en/guides/marketing/consent-mode
To check it: https://www.wakaris.com/

Start by briefly introducing yourself in your role, making point 1 clear, and asking me the set of questions.
Paste it into the AI you use.

Frequently asked questions

What are initial consent states? +

They’re the starting point a page declares for each type of consent before its tags start working. Google defines seven types, including advertising storage and analytics storage, and warns that by default no value is set.

If I have a cookie banner, is it already sorted? +

Not necessarily. Many consent management platforms can issue the initial declaration, but only when that option is turned on in their settings. Installing the banner doesn’t turn it on by itself, nor does it guarantee the declaration arrives before the tags.

Does declaring initial states mean I comply with the law? +

No. It’s a technical setting for how tags behave, not proof of legal compliance. You can declare them and have a poorly designed cookie notice, or the other way round. They’re two separate checks, and the legal side should be assessed by a professional.

Why does it fail if the code is in place? +

Almost always because of order. The declaration has to run before any tag that sends data, and Google’s documentation warns that if the code is called in the wrong order, the default values don’t work. Being on the page isn’t enough.

Sources cited

  • developers.google.comConsent mode overview, Google for Developers: the definition of Consent Mode, the seven consent types and the difference between basic and advanced mode.
  • developers.google.comSet up consent mode on websites, Google for Developers: the requirement to call the default declaration on every page before any command that sends data, that by default no values are set, the wait parameter with its 500-millisecond example and the region parameter.
  • developers.google.comTroubleshoot consent mode, Google for Developers: the error sequence in which the tag fires before the declaration, and the instruction to move that code above the tag snippets.
Portrait of Juan Ignacio Franco

Juan Ignacio FrancoData analyst · Bitanube

Juan Ignacio Franco is a data analyst at Bitanube. He sets up and measures campaigns, analyzes performance metrics and KPIs, and reviews the technical quality of websites and projects before delivery. The findings in these guides are the ones that come up in that work.

Updated: September 7, 2026.

This article is part of Wakaris, which analyzes your website across 9 areas and explains each finding so that every profile on your team can understand it.

Share this guide
Get started

Your website has a lot
to tell you, and
And you’ll finally understand it

135 checksNo account or cardResults in ~30 seconds
PerformanceHow fast your website loads. If it’s slow, you lose visits and sales before anyone sees you.SEOWhether Google understands your website and shows you when someone searches for what you offer.SecurityWhether your website is protected. A flaw here scares off customers and Google alike.Online presenceHow you show up on Google, social media and maps. It’s the first impression you make before anyone contacts you.MarketingHow you look to someone comparing before deciding, and where your competitors get ahead of you.AI visibilityWhether ChatGPT, Gemini and other AIs recommend you when someone asks about what you do.User experienceThe user experience (UX): whether it’s clear at first glance and people get where they want. A confusing website gets abandoned even if it loads fast.AccessibilityWhether anyone can use your website without barriers and whether you follow the WCAG 2.2 guidelines. A wider audience that understands you.LegalWhether you comply with cookie and data protection rules. Avoid penalties and fines that hurt.