Google Consent Mode tells Google what your Shopify store is allowed to do with a shopper's data. It's been required for EEA visitors since March 2024, and in June 2026 Google went further. For any Analytics property linked to a Google Ads account, Consent Mode is now the one control that decides whether ad data gets collected at all.
That signal now decides whether your ads can see conversions and build audiences. The rules change from one country to the next. A shopper in Germany, a shopper in California, and a shopper in Brazil each sit under different rules.
Here's what your setup needs to look like in each one.
What Consent Mode v2 sends to Google

Consent Mode and the cookie banner do different jobs. The banner collects the shopper's choice; Consent Mode passes that choice on to Google. It runs on four signals, each either "granted" or "denied" for a given shopper, and Google's tags change what they do based on them. You can see all four in Google's own Consent Mode docs.
|
Signal |
What it controls |
New in v2? |
|
ad_storage |
Storing ad cookies and IDs |
No |
|
analytics_storage |
Storing analytics data (GA4) |
No |
|
ad_user_data |
Sending user data to Google for ads |
Yes |
|
ad_personalization |
Using that data for remarketing and personalized ads |
Yes |
The first two are old. The two new ones, ad_user_data and ad_personalization, are the ones European rules turn on. A banner that only sets the first two is running half a setup, even if it looks fine on the page.
Once these signals reach GA4, they change how your reports fill in.
The rules change by region

One store, many countries, and the law is different in each one. The table below lays it out.
|
Region |
Model |
By default |
What your store must do |
|
EEA, UK |
Ask first (opt-in) |
Nothing tracks |
Block non-essential tags. All four signals set to denied until the shopper agrees. |
|
Switzerland |
Ask first, in practice |
Same as EEA for most stores |
Group it with the EEA and UK. |
|
United States |
Opt out |
Tracking runs |
Give a clear opt-out. Honor the browser opt-out signal. Set the ad signals to denied when someone opts out. |
|
Brazil |
Ask first (opt-in) |
Ask before tracking |
Treat it like the EEA. |
In the EEA and UK, ask before you track
The European Economic Area and the UK run on consent. No non-essential tag can fire until the shopper agrees. So all four signals start at denied and only turn to granted after a clear yes.
-
Consent means nothing fires until the shopper answers.
-
“Yes" and "no" both have to be equally easy to click. The reject button needs the same visibility as accept
-
The two new signals, ad_user_data and ad_personalization, are what keep remarketing and ad personalization working for these shoppers.
You have two ways to run it, and the choice affects how much data you keep.
|
Basic mode |
Advanced mode |
|
|
When tags load |
Only after consent |
On page load, set to denied |
|
Shoppers who decline |
Send nothing |
Send a small signal, no cookies |
|
Filled-in (modeled) conversions |
Lost |
Recovered |
|
Setup effort |
Lower |
Higher |
|
Best for |
Small EEA traffic |
Bigger EEA volume |
Advanced mode lets Google fill the gaps for shoppers who say no, using its own estimates instead of their real data. For most stores with steady EEA sales, that is worth the extra work.
Get these two signals wrong and remarketing and personalization stop working for your EEA shoppers, with nothing in Google Ads or GA4 telling you why.

Your stores must adhere to the 7 principles of GDPR if it targets or collects data from individuals in the EU/EEA, regardless of your location.
Switzerland gets grouped with the EEA
Switzerland sits outside the EU, so it drops off a lot of setups, but its updated privacy law means it still belongs on your list. Swiss law differs from the EU's, but it's close enough that most stores run the same ask-first banner for Swiss shoppers. Shopify lets you group Switzerland with the EEA and UK, so covering it costs you nothing.
The United States runs on opt-out
The US works the other way, and this is where stores get caught out. Under California's CCPA and the wave of state laws behind it, tracking is allowed the moment a shopper lands. As of 2026, twenty US states have full privacy laws in effect, led by California.
Your job is to give people a working way to opt out, and to honor it when they do.
Two things matter for your Google setup:
-
When a US shopper opts out, ad_user_data and ad_personalization should turn to denied. Same signals, different trigger.
-
In California, Colorado, Connecticut, and a growing list of other states, a browser that sends the Global Privacy Control signal counts as an opt-out on its own, with no click needed. You have to honor it.
Shopify handles more of this than most people expect, but only if you switch it on. When you turn on the data sale opt-out page for your US regions, Shopify reads the Global Privacy Control signal automatically and marks those shoppers as opted out of data selling. Plenty of stores never enable that page, so the signal arrives and nothing happens.
Brazil and the shift to opt-in
Brazil's privacy law (LGPD) is closer to Europe's approach than America's. It runs on consent, so the safe default for Brazilian shoppers is to ask before you track. The wider trend across Latin America, Canada, and parts of Asia points the same way, toward asking first.
Build for consent now, and adding a new ask-first market later is just a settings change.
How about the rest of the world?
Google's own requirement is narrow. Consent Mode v2 is tied by law to the EEA and UK, through the DMA and GDPR. The US and Brazil rows are in the table because their own privacy laws change what your tags are allowed to do, not because Google requires it there. Outside these four rows, no law currently forces a Google-facing consent signal, so the default holds: tracking runs, and there is no Consent Mode setup to build yet.
That is shifting. Canada, several Latin American markets beyond Brazil, and a growing list of Asian markets are moving the same direction, toward asking first. If one of your markets gets there, group it with the EEA and UK banner the way you already treat Brazil.
What to do if you sell in more than one country
Most Shopify stores sell to several regions from one storefront. That puts you under more than one set of rules. If you have EEA visitors, GDPR applies, whatever your size.
US state laws usually start above a size threshold, but those thresholds are low, so most growing stores plan as if they apply. Each region's law applies on its own terms, regardless of the others.
There are two ways to handle that:
-
Strictest rule everywhere. Show the ask-first banner to everyone, including US shoppers. It is the simplest to set up and the safest. The cost is data: you block tracking by default for US shoppers you were allowed to track.
-
Right rule per region. Show an ask-first banner to EEA, UK, Swiss, and Brazilian shoppers, and an opt-out notice to US shoppers. More setup, but you keep the data each region lets you keep.
For most stores with decent US sales, we go with the second option. The extra setup keeps more of your US data.
Whichever you pick, a few things hold true in every region:
-
Detect location, then apply the rule. Your banner should check where the shopper is and behave the right way for that region. Shopify's region settings and your consent app do this together.
-
Keep a record of consent. Most laws expect you to show that a shopper agreed. Your consent app logs this for you, with a timestamp, per region.
-
Match the shopper's language. Consent only counts if the shopper can actually read the banner. If you run storefronts in more than one language, the banner should follow.
-
Run a single setup with region rules built in, rather than stacking banners that conflict with each other. It's cleaner and easier to check.
Is your Consent Mode set up wrong?
You will not get an error message if your consent mode is set up wrong. The tags still load, the banner still shows, and the data just stops arriving. Check your own store for these signs:
-
Your Google Ads remarketing audiences stopped growing, or shrank.
-
EEA conversions in GA4 dropped off on a set date and never came back.
-
Google Ads is showing a consent or EU user consent policy warning.
-
In Google Tag Assistant, ad_user_data or ad_personalization reads denied for visitors who accepted.
-
In an incognito window from an EU location, Google tags fire before you touch the banner.
When we audit Shopify stores, the same three problems come up again and again:
-
The banner sends the old two signals but never the two new ad signals, ad_user_data and ad_personalization, so ads data stops for EEA shoppers.
-
One consent setup is applied worldwide, so either US shoppers get blocked by default and you lose data, or EEA shoppers get tracked before they agree.
-
The US data sale opt-out page was never turned on, so opt-out signals arrive and nothing happens.
Set up consent mode correctly on Shopify
Shopify gives you the parts to run one setup that behaves right by region, so there's no need to rebuild it per country. For most stores, a consent app gets this done in an afternoon. Server-side tracking is the one bigger piece, and only if you spend a lot on ads.
1. Turn on the banner and the opt-out page. In your admin, go to Settings > Customer Privacy. Set up the cookie banner and, for your US regions, the data sale opt-out page. Shopify's region settings let you pick which regions see the banner and how it acts, so EEA shoppers get an ask-first banner and US shoppers get an opt-out notice. With the opt-out page on, Shopify honors the Global Privacy Control signal automatically in those regions.


2. Connect a certified consent app. Shopify's Customer Privacy API tracks the shopper's consent choices, but the native banner does not pass them to Google on its own. That is what a consent app is for. Pick one that:
-
is on Google's list of certified consent platforms,
-
connects to the Customer Privacy API,
-
blocks trackers before consent for EEA shoppers,
-
handles the US opt-out page and the Global Privacy Control signal,
-
logs consent per region for your records.
One app that does all five is worth more than three that each do part of the job. Here’s a few to consider.
|
App |
Covers your five checks |
Pricing |
Rating |
|
All five, plus TCF v2.3 and Hydrogen support |
Free; paid from $9/mo |
2,750+ reviews |
|
|
All five, plus multi-pixel scanning |
Free; paid from $9/mo |
1,800+ reviews |
|
|
All five, plus GPC and wide law coverage (LGPD, PIPEDA, APPI) |
Free; paid roughly $9 to $34/mo |
850+ reviews |
3. Add server-side tracking if you spend a lot on ads. Consent Mode handles what fires in the browser, and browser tags still fail on their own from ad blockers and script clashes. Server-side tracking makes sure the data you do have permission to collect actually reaches Google.

Image taken from our recent guide on how to set up server side tracking
4. Test it before you rely on it. Open your store in a fresh incognito window, run Google Tag Assistant, and check the consent state before and after you click the banner. In Google Tag Manager (GTM), the consent overview shows whether each tag has the right setting. Do this per region if you can. A banner that works in the EEA can still be wrong for US traffic.

Get your consent and tracking set up right
Consent Mode v2 is one piece of a tracking setup that has to hold up across every country you sell in. We build and check analytics and consent setups for Shopify stores, so the data reaching Google is both clean and allowed.
If your remarketing has gone quiet or your GA4 numbers stopped adding up, talk to us about your analytics setup.