Attribution Lab
  • in the demo
  • GA4
  • GTM
  • sGTM
  • Google Ads

Cookie consent when your company is in the EU or UK: comply with the law and lose less

Updated 21 September 2026
Go to the demo

This page is for a business with a company, branch or office in the EU or the UK. If all you have in Europe is visitors, the main page of this case is for you, with the focus on Google's requirements.

What is wrong

Under EU and UK rules, no cookie (a marker in the browser that lets the site recognize a visitor and tie their purchase to an ad) may be set and no data sent to Google before the visitor consents. So the site shows a cookie consent banner. Some click "Decline", some click nothing and move on – and the easier the banner is to miss, the more people ignore it.

For everyone who did not accept right away, your ads lose data:

  1. Audiences. The visitor does not enter remarketing lists (lists of visitors for repeat ads) and does not get personalized ads. This is Google's rule since March 2024 (Consent Mode v2).
  2. Conversions. The purchase is not tied to the ad. Google decides who to show ads to based on the purchases it sees, and it learns without this one. In the reports this looks like a drop in conversions, and nobody can say whether demand fell or tracking broke.
  3. The first touch. If the visitor accepts only on the third page, the source they came from is already gone by then.
  4. The journey between domains. If you have several domains, say the site and a separate booking platform, without consent the visitor's journey breaks at the hand-off, and the booking on the second domain has no source. More in the case "The ad source is lost between domains".

You can estimate your loss: the share of visitors who do not click "Accept". Your consent banner service usually shows it.

The opposite mistake is to treat everyone as consenting: setting cookies before consent, filing ad cookies under "strictly necessary" (those need no consent), or telling Google by default that consent was given. The numbers in the reports stay, but companies get fined for this. It also breaks Google's rules for advertisers, and Google may restrict or suspend the ad account.

What is mandatory

The law. Companies in the EU or the UK get fined for breaking the cookie consent rules. In short, the rules require you to:

  1. set no cookies before consent except those the site needs to work, and send no visitor data to Google;
  2. make refusing as easy as accepting: a "Decline" button on the first screen of the banner, next to "Accept";
  3. ask for consent separately for each purpose – analytics, ads; banners usually do this with a "Customize" button;
  4. keep a record of when and to what the visitor consented;
  5. on request, show the visitor what is stored about them, and delete it.

Fines are issued by the regulator of the country where the company operates: on a complaint, and for large sites also in spot checks. The exact requirements differ between countries. This page is not legal advice – assess your own situation with a lawyer.

Google. The same requirements as for everyone: a consent signal for visitors from the EU, the UK and Switzerland. A consent signal is a flag that Google tags (the ads and analytics code on the page) send with every event: whether the visitor agreed to ads and analytics. The consent banner sets it; ask whoever set up your site whether Consent Mode v2 is on and what goes to Google after "Decline".

Visitors from other countries. The rules of your country may apply to every visitor of the site, wherever they come from. A lighter flow for visitors outside Europe (step 4) is a decision to make together with a lawyer.

How to comply and lose less

Steps in order: first what the law allows without caveats, then what needs a decision with a lawyer.

1) Write nothing to the browser before a decision, keep the source in page memory

The usual consent flow (Basic consent mode): before the visitor decides, Google tags do not load and nothing is written to the browser. This meets point 1 of the rules: nothing that needs consent happens before the decision. A visitor who accepts is counted as usual, in conversions and in audiences.

On top of the standard flow the demo does two things. The source of the visit waits in page memory and is saved as soon as the visitor clicks "Accept". On decline, your own server keeps an anonymous visit count: where they came from, no cookie, no visitor identifier.

Cons: page memory lasts only while that page is open; if the visitor moves to another page without deciding, the source is lost. Google does not fill in the missing conversions (step 5 does that).

In the demo.

2) A "what we know about you" page

The visitor sees their journey, how the site recognizes them, the consent history and every key the site wrote to their browser, and can export the record and delete it. For the record on your server this covers points 4 and 5 of the rules: the consent history is kept, and the answer and the deletion come from one record. Data already sent to Google, to the booking system or to a CRM is deleted there separately.

What it takes: a single journey record per visitor on your own server – all their visits, sources and consents in one place.

In the demo.

3) Ask for the decision before the visitor moves on

Links and buttons on the page do nothing until the visitor chooses: accept or refuse, both buttons equally easy. This cuts the number of people who do not mind but never click. And the decision happens on the first page, while the source is still in memory.

Conditions: refusing is as easy as accepting, and the site stays open to those who refused. Requirements for a banner that covers the page until a decision differ between countries – check with a lawyer. In the demo the banner does not block.

Description only.

4) A lighter flow for visitors outside Europe

Consent in advance for the EU, the UK and Switzerland, a notice with a way to opt out for everyone else. Visitors from other countries are counted at once and do not wait for a decision.

Cons: for a company in Europe this is a decision with a lawyer – the rules of your country may apply to these visitors too. The country is guessed from the connection address (IP), approximately.

In the demo: the Auto regime by the visitor's country.

5) Advanced consent mode: fill in part of the conversions with statistics

Before consent, Google tags load anyway and send anonymous signals – no cookie, no visitor identifier. From them Google estimates the missing conversions, and part of the losses comes back into the reports as an estimate.

Cons: for a company in Europe this is a decision with a lawyer – regulators view these signals differently, and one reading says even they may not be sent before consent. The estimate appears only at large volumes: GA4 (Google Analytics), for example, starts filling in from a thousand consenting visitors a day, and a small site never gets there. The demo does not use this mode: it shows the most cautious flow.

Description only.

What the demo does

In the opt-in regime (consent in advance) nothing loads and nothing is written to the browser before the visitor decides: no cookie, no identifier, no journey record. The source the visitor came from waits in page memory. After "Accept" it is saved to the journey, the server sets the cookie, the tags load. After "Decline" only an anonymous visit count remains on the server. Moving to the second site without consent passes no identifier, and the page says why. Permission for analytics and permission for advertising are stored separately: remarketing audiences depend on the second one. In the opt-out regime (a notice with a way to opt out) the journey is created at once, with a notice strip and an opt-out link. The Auto regime picks the flow by the visitor's country. The "what we know about you" page shows the visitor everything stored about them, with export and deletion: that is how a site answers "what do you keep about me".

Open the demo

The demo opens already set up for this case: server-side transport, and by default the visit counts as a Google Ads click with a demo click id. Start with "Force EU – opt-in": that is where consent is visible. Use a private window for a clean run, because the regime and the transport stick in the browser.

Consent regime
Open the demoLink the demo opens withhttps://alpha.nexusnode.ru/?utm_source=GAds&utm_medium=CPC&utm_campaign=case_consent&demo_click_id=GADS-11111&al_case=consent-regimes-eu-company&al_lang=en&al_transport=server&al_regime=auto

What you will see in the opt-in regime:

  1. The consent banner: "Nothing is stored yet." Click "Show what was recorded" to open the panel: no journey created, the source google / cpc waiting, only an anonymous visit count on the server, no Google tags loaded.
  2. Click "Continue to the regional site" before deciding. The page answers that no hand-off token was issued because consent was not given. Site B opens with no link to the first site and names the same reason.
  3. Click "Decline". "Nothing stored. Reload keeps you anonymous." No cookie, no identifier, no journey.
  4. Or "Accept". The tags get permission, the server sets the cookie, the journey is created with the source google / cpc saved from the wait. The Consent tab lists the consent commands issued, in order.
  5. Open "What we know about you" from the panel. Your path, how the site recognizes you, the consent history, a table of every key stored in your browser with who set it, and export and delete for the whole record.

In the opt-out regime the journey is created at once, the strip says "Analytics is on. You can opt out.", and the opt-out link opens the Consent tab.

Frames

Opt-in regime: nothing stored before the decision
Opt-in regime before the decision: the source waits in page memory, no cookie, no identifier, no Google tag.
What we know about you
The "what we know about you" page: path, recognition, consent history, storage, export and delete from one record.

What the demo does not prove

  • That this is the right setup for your market. Jurisdiction, purposes and platform requirements are checked for the actual business. This is not legal advice.
  • What Advanced consent mode would recover. It is not in the demo: the demo shows the most cautious flow.
  • The full banner. This one has two buttons. A three-action banner with a Customize step, Global Privacy Control (the browser's "do not sell my data" signal) and a "Your Privacy Choices" link are planned.
  • That an anonymous visit count is enough for your reporting. It keeps source and channel, and nothing that ties to a person.
  • What the ad platform forgets. The "what we know about you" page deletes our record. What a platform does with data it already received is up to the platform.

Who built this

Anton Kozhanov – marketing data and attribution engineer. Own server-side Tag Manager on own infrastructure, a first-party loader and cookies, a journey vault with export and deletion. Four years on a theatre's measurement (revenue ×2.3 on his watch, ad spend held near 7% of revenue) and a call-tracking → CRM → ads feedback pipeline for a manufacturer (cost per lead −25%, a 2.5-year low).

Book a call

Bring your site, your consent banner if you have one, and the drop you cannot explain. We check what your setup stores and sends to Google before the visitor decides, after "Accept" and after "Decline", and decide what is worth fixing first. If you walked through the demo, I open your journey record on the call: what was held, what was saved, what was refused.