检查清单
Do Google Tag Manager tags fire before Accept?
A loaded GTM container is not proof that tags consented. Check cookies and network on Fresh and after Reject. Not a GTM setup guide.
In brief
Google Tag Manager tags can fire before Accept, or they can stay gated while the container script loads. Check cookies, storage, and network requests on a Fresh visit, then again after Reject. A loaded container and a Consent Mode denial signal are claims. Runtime rows are what you verify. ConsentProbe can store Fresh and Reject packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a GTM setup guide and not legal advice.
Not legal advice
This guide explains how to observe Google Tag Manager web container tags relative to Accept and Reject. It is not legal advice, not a GTM setup or Consent Mode configuration tutorial, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow.
Last updated September 24, 2026. The before-Accept audit owns the general first-load method. The pre-consent checklist owns the pass order. The Consent Mode versus runtime page owns signal-versus-cookie falsification. The Reject leftovers guide owns a Reject failure. This page stays on container load versus tags that fired.
Short answer
Google Tag Manager tags often fire before Accept when nothing gates them. The container script can also load on that first visit while marketing tags inside it stay quiet. Those are different rows. A cookie consent audit asks which cookies, storage entries, and network requests appeared before a choice, including hosts that GTM commonly injects.
Treat banner text that says marketing is off, and a Consent Mode default denied state, as claims. Falsify them on a clean visit. Capture googletagmanager and gtm rows, plus downstream marketing hosts, on Fresh. Repeat after Reject. Note any fan-out that continues. Host names here are examples of where a browser test can look. This page does not tell you which host to block, and it does not list triggers or Consent Mode parameters.
Consent Mode signals are not proof the tags stayed off. Runtime cookies and requests are the check. The Consent Mode versus runtime guide holds that comparison. ConsentProbe can produce Fresh and Reject packs with request, cookie, and screenshot links. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not configure GTM or Consent Mode. This page is not a GTM setup guide and not legal advice.
Container, tags, and Consent Mode
Three layers get mixed when someone says GTM is consented because the container loaded. Separate them before you write the finding. Stay with tag request before Accept. Leave legal permission with counsel.
| Layer | What you can observe in a browser test | What it does not prove alone |
|---|---|---|
| GTM container script | googletagmanager.com or gtm.js present on Fresh | That marketing tags inside the container stayed off |
| Downstream tags and pixels | Cookies, storage, and Network rows to ads or analytics hosts | Legal permission, which stays with counsel |
| Consent Mode or CMP UI claim | A screenshot, or a console signal state you recorded | That Fresh and Reject runtime matched the claim |
Fresh and Reject on the storefront
These steps compare a claimed wait-for-Accept state with cookies and requests. They do not install a container, write a trigger, or set a Consent Mode parameter. The before-Accept audit, the pre-consent checklist, the Consent Mode page, and the Reject leftovers guide hold the neighboring methods.
- Use a clean profile. Load the storefront once. Do not click Accept.
- Capture cookies, storage, and Network for GTM hosts and for marketing or analytics hosts the container may inject.
- Screenshot the banner state. Label the pack Fresh.
- Open a new clean profile, or clear storage. Click Reject All. Navigate once more.
- Recapture cookies and Network. Label the pack Reject. Compare it with Fresh and, if you ran one, with an Accept control.
- Write one finding sentence per mismatch, such as an ads pixel via GTM on Fresh, or the same host after Reject.
Mismatch patterns you can observe
The rows below are observations from a labeled visit. They are not a trigger cookbook and they do not name a penalty. When the claimed gate is Consent Mode, open the Consent Mode versus runtime guide instead of inventing a parameter list here.
| Claim | What you hoped to see | Red flag |
|---|---|---|
| GTM only loads, and tags wait for Accept | Downstream marketing hosts stay quiet on Fresh | Ads or attribution IDs before a choice |
| Consent Mode default denied | Marketing tags stay off until Accept | The same fan-out on Fresh as on an Accept visit |
| Reject All stops GTM marketing tags | Marketing stays off after Reject and the next navigation | Reject looks like Accept in Network |
When sorting GTM hosts gets slow
Sorting GTM hosts across templates by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install or configure GTM or Consent Mode, does not install a CMP, and does not issue a certificate.
FAQ
Do Google Tag Manager tags fire before Accept?
They often do when the tag is ungated. Verify Network and cookies on a Fresh visit. Container presence alone does not answer the question.
Does loading the GTM container mean tags consented?
No. A loaded container and consented tags are different checks. Look at downstream hosts.
Does Consent Mode default denied prove tags stayed off?
No. The signal is a claim. Cookies and network rows are the check. The Consent Mode versus runtime guide is that comparison.
What if Reject All still shows GTM marketing hosts?
Treat it as a Reject failure. The Reject leftovers guide is the network check. Keep the evidence pack.
Will this page teach GTM or Consent Mode setup?
No. This page is a Fresh and Reject check, not a GTM or Consent Mode setup guide.
Is this legal advice?
No. These are technical observations. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This page tells you how to separate a loaded GTM container from tags that fired before Accept, and how to repeat the check after Reject. It is not legal advice, not a GTM setup guide, and not a certificate. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the before-Accept audit for the general first load, the pre-consent checklist for the pass order, the Consent Mode page when that signal is the claimed gate, and the Reject leftovers guide when Reject still tracks.
- Pre-Consent Cookie Audit: A Storefront Checklist
- Pre-consent audit checklist: what to verify before Accept
- Consent Mode v2 vs runtime cookie evidence: what still fires?
- Reject All Still Tracking: What to Check After You Say No
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- What belongs in a cookie consent audit evidence pack?
- Which cookie consent test should you run first?
- Meta Pixel and CAPI before Accept: what to check
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。