Checklist

Consent Mode v2 vs runtime cookie evidence: what still fires?

Start a free audit

Consent Mode signals do not prove tags and cookies stopped. Compare them with cookies and network rows on Fresh or Reject. This is not a setup guide.

In brief

Google Consent Mode, including v2-style defaults, is a signal path tags can read. A cookie audit asks whether marketing cookies, storage, and third-party requests still appeared when the signal said denied or the visitor chose Reject. Treat the signal and the banner text as claims. Falsify them with a clean visit and state-labeled screenshots. ConsentProbe can store that pack. This page is not a setup tutorial and not legal advice.

Not legal advice

This guide explains how to falsify, at runtime, whether tags and cookies still fire when Google Consent Mode signals denial or a limited state. It is not legal advice (非正式法律意见), not a Consent Mode setup tutorial, and not a GDPR, ePrivacy, or CPRA certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow.

Last updated September 24, 2026. The CMP claims guide owns the wider claims-versus-evidence method. The Reject leftovers guide owns a Reject All failure. The evidence pack guide owns the file fields. This page stays on Consent Mode signals versus cookies and network rows.

Short answer

Consent Mode signals are not proof that tags and cookies stopped. A denied or granted style default is a value tags or the CMP can expose. The audit asks a different question: did marketing cookies, storage, and third-party requests still appear under the state you care about?

Treat Consent Mode defaults and CMP text as claims. On a clean visit, record the state you believe is active, capture cookies and network rows, and keep screenshots labeled by that state. Fresh, Reject, and a claimed default-denied load are the usual labels. If default-denied or Reject still looks like Accept, the signal and the runtime disagree.

ConsentProbe can produce that state-labeled evidence pack, with each finding tied to a request, a cookie, or a screenshot. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not configure Consent Mode. This page is not a setup tutorial.

Signals versus evidence

Three layers get mixed in vendor write-ups. Separate them before you write the finding. Stay with signal and runtime disagree. Leave legal conclusions to counsel.

Consent Mode and CMP signals, runtime evidence, and banner screenshots.
LayerWhat it isWhat it does not prove alone
Consent Mode or CMP signalA value tags or the CMP expose, such as a denied or granted style defaultThat cookies and beacons stayed off
Runtime cookie and network evidenceWhat the browser actually set and requestedLegal permission, which stays with counsel
Policy or banner screenshotThe UI claim on screenThat the network matched the banner

Falsify the claim on a clean visit

These steps compare a claimed state with cookies and requests. They do not configure Consent Mode, Google Tag Manager, or a tag. Do not treat a parameter list as the test. The CMP claims guide, the Reject leftovers guide, and the evidence pack guide hold the neighboring methods.

  1. Use a clean profile. Note the state under test: Fresh with no click, Reject All, or a claimed default-denied load.
  2. Load the storefront once. Do not click Accept.
  3. Capture cookies and storage. Flag ads, analytics, and marketing IDs.
  4. Capture Network rows for marketing hosts and tagged requests.
  5. Screenshot the banner and the rows. Label both with the state. Write one finding sentence per mismatch.
  6. Optional: run Accept All as a positive control so you know what on looks like.

Mismatch patterns you can observe

The rows below are observations from a labeled visit. They are not a configuration recipe and they do not name a penalty.

Common Consent Mode assumptions and the runtime red flag.
Claim or assumptionWhat you hoped to seeRed flag
Consent Mode default deniedAds and analytics cookies and beacons stay off on FreshThe same fan-out as a visit that looks consented
Reject All with Consent Mode onMarketing stays off after Reject and the next navigationReject looks like Accept
The CMP supports Consent ModeStorefront runtime matches that support claimThe banner looks settled and the network is still hot

When hand-checking the states gets slow

Checking Consent Mode claims across templates by hand is slow. ConsentProbe runs on the URL and stores state-labeled findings tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not configure Consent Mode, does not install a CMP, and does not issue a certificate.

FAQ

Does Consent Mode v2 stop cookies by itself?

No. It is a signal path. Verify cookies and network rows under the state you care about.

Is a default-denied setting enough evidence?

No. Capture cookies, storage, and requests labeled for that state. The signal alone does not show the network stayed quiet.

Where do I learn CMP claims versus evidence?

The CMP claims guide covers the wider method. This page stays on Consent Mode signals versus runtime rows.

What if Reject All still tracks with Consent Mode on?

Treat it like any Reject failure. The Reject leftovers guide is the network check. Keep an evidence pack.

Will this page teach me to set up Consent Mode?

No. This page is a falsification check, not a Consent Mode setup tutorial. It does not list tag parameters or admin steps.

Is this legal advice?

No (非正式法律意见). These are technical observations. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This page tells you how to compare Consent Mode signals with cookies and network requests. It is not legal advice (非正式法律意见), not a Consent Mode setup tutorial, and not a certificate. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the CMP claims guide for the wider method, the Reject leftovers guide when Reject still tracks, and the evidence pack guide for the file fields.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Consent Mode vs runtime evidence | ConsentProbe