Does Google Tag Manager Need Cookie Consent?

“Does Google Tag Manager need cookie consent?” is a fair question, because GTM is an odd beast. It is not an analytics tool or an ad pixel; it is a container that loads other tags. Google is right that the container itself does very little. But the answer that matters for a small business is about what the container loads, and that answer is yes.

Does Google Tag Manager set cookies?

Google’s Tag Manager data privacy page says Tag Manager may collect aggregated data about tag firing for monitoring and diagnostics, that this data does not include IP addresses or measurement identifiers tied to an individual, and that, apart from that and standard HTTP request logs deleted within 14 days, it does not collect, retain or share information about visitors. Google does not list cookies for the container itself.

So when you open DevTools on a site with GTM and find _ga, _gcl_ cookies or _fbp, GTM is the messenger: Google Analytics, the Google Ads conversion linker and the Meta Pixel set them, because GTM fired those tags.

Two practical consequences:

  1. The consent question moves to the tags. A container full of analytics and ad tags is, in effect, an analytics and ad deployment.
  2. The container still contacts Google. Loading gtm.js from googletagmanager.com is a request from your visitor’s browser, carrying their IP address, to Google. Light, but not nothing.

Article 5(3) of the ePrivacy Directive is the rule: storing information on the visitor’s device, or reading it back, requires prior consent unless it is strictly necessary for the service the visitor asked for. Analytics cookies and ad identifiers are not. The container does not change the analysis; it only changes who fires the tag.

  1. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing.

— ePrivacy Directive, Article 5(3)

Google’s answer for GTM sites is Consent Mode, which comes in two flavours:

Basic consent modeAdvanced consent mode
Before the visitor choosesGoogle tags do not loadGoogle tags load, consent “denied” by default
If consent is deniedNothing is sent to Google, not even the consent statusCookieless pings are sent (timestamp, user agent, referrer, consent state, a random number per page)
After consent is grantedTags load and send full measurementTags send full measurement
Conversion modellingGeneral modelAdvertiser-specific model

Advanced mode recovers more modelled data; basic mode sends nothing before consent. Which one fits you is a judgement call, but understand what you are choosing: in advanced mode, Google’s tags run on the device of a visitor who has not consented, and the EDPB’s Guidelines 2/2023 read Article 5(3) as covering more than cookies. For a small site without a legal team, basic mode is the defensible default.

Consent Mode also only governs Google tags. A Meta, TikTok or Hotjar tag fired by GTM ignores it unless you configure a consent check on each tag.

Our free cookie consent banner (CCB) treats Google Tag Manager as a marketing service, with the signature [./]googletagmanager\.com(?![\w-]). What that means on your site:

  1. Consent Mode defaults first. Before any tag can run, the banner declares all seven Consent Mode v2 signals: ad_storage, ad_user_data, ad_personalization, analytics_storage, functionality_storage and personalization_storage set to “denied”, and security_storage set to “granted”.
  2. GTM is held until consent. Requests to googletagmanager.com are blocked until the visitor accepts the marketing category. This is basic consent mode, applied to every tag in the container, Google or not.
  3. One exception by design. A direct Google Analytics 4 tag (googletagmanager.com/gtag/js?id=G-...) is recognised first as analytics, so a GA4-only site loads with analytics consent alone.
  4. After the choice, the banner sends a Consent Mode update matching it, so the tags GTM then fires see the visitor’s real decision.

What if your container only holds analytics tags? Then waiting for marketing consent is stricter than you need. You can declare the category yourself by replacing GTM’s loader with a neutralised tag and keeping the dataLayer initialisation inline:

<script>
  window.dataLayer = window.dataLayer || [];
  window.dataLayer.push({'gtm.start': new Date().getTime(), event: 'gtm.js'});
</script>
<script type="text/plain"
        data-wl-src="https://www.googletagmanager.com/gtm.js?id=GTM-XXXXXXX"
        data-wl-category="analytics"></script>

Only do this if the container truly holds nothing but analytics: the category you declare is the consent the whole container will run under.

The mistake that cancels everything

Never load your consent banner through GTM. A banner injected by a tag manager arrives after GTM and after the page has started loading, so it can only block what has not been requested yet, which by then is very little. Ours goes first in the <head>, without defer or async, and warns in the browser console when it detects that it was loaded late.

And remember what no client-side banner sees: server-side GTM and other server-to-server tracking never pass through the visitor’s browser. Gate them on the consent cookie on your server.

Check your site

Open your site in a fresh browser profile with DevTools open and do nothing. In Network, filter on googletagmanager: with the WebLegal banner, nothing should load until the visitor accepts. In Application > Cookies, no _ga, _gcl_ cookie or _fbp should exist yet. Our free GDPR compliance checker runs the same test for you and lists every tracker that fires before consent. For the full Consent Mode setup, see our Google Consent Mode v2 guide.

Declare what the container loads

Your cookie policy must list the tags GTM fires, not “Google Tag Manager” alone. Every WebLegal pack includes a cookie policy, from the Essential pack at €19.90. The most common tags behind GTM have their own guides: the Meta Pixel, Microsoft Clarity, and the complete list in the 37 trackers your cookie banner must block.