Can you still build remarketing audiences if visitors reject cookies

No, not from the visitors who rejected. Denied advertising consent means no advertising identifier is stored, so those visitors never enter a remarketing list, and modelled conversions cannot backfill them. In the EEA even Customer Match needs those signals granted. What still works is contextual and broad targeting, and the channels you own outright.
What actually happens at the moment someone rejects
Three signals decide this, and it is worth separating them because setups often get one right and the others wrong. ad_storage governs whether an advertising identifier may be stored on the device at all. ad_user_data governs whether user data may be sent to Google for advertising purposes. ad_personalization governs whether that data may be used for personalised advertising. A visitor needs them granted before they can enter a personalised remarketing audience, and a setup that asks only for analytics consent quietly stops list growth.
When either is denied, Google's tags do not stop communicating. They send a cookieless ping instead: an aggregated signal carrying no identifier for that person. It is enough to tell Google that something happened. It is not enough to add anyone to anything, because there is no stable thing to add. Your remarketing lists therefore stop growing from denied traffic at the moment the denial is recorded, and they keep growing normally from everyone who accepted.
The practical consequence catches teams out more than the mechanism does. Nothing appears broken. The tags fire, the reports still populate, and the audience simply grows more slowly than the traffic would suggest.
Why modelling does not rescue this
This is the most common misunderstanding we meet, and it is an understandable one, because the same feature does genuinely rescue the neighbouring problem. Conversion modelling estimates the conversions you lost, so your reporting stops understating performance. It works in aggregate and it produces an estimate, never a person.
Modelled results also stay where they are produced. They are excluded from the data export, from audiences, from user explorer and cohort explorations, and from predictive metrics, which is the same boundary we walked through in what happens to GA4 data when users reject cookies. So measurement partly recovers and targeting does not recover at all. If you take one thing from this page, take that asymmetry.
The hole is smaller than the skew
The obvious worry is size. Across Amplio Data client implementations we measure consent choices hiding around 34% of sessions, which is a measured range across those implementations and not a guarantee, and your own figure will sit somewhere else depending on your market and how the banner is built.
The more useful worry is shape. The visitors who accept are not a random sample of the visitors who do not, so an audience built only on consenters is not a scale model of your traffic. It leans toward the people most comfortable accepting, which in most markets means it leans away from exactly the segments a campaign was often trying to reach. Treat a shrinking list as a change in composition rather than only a change in volume, and the reporting stops surprising you.
What still works, cheapest first
Everything below is real and none of it involves recovering a rejected visitor, because that cannot be done. Work down the list.
Earn more consent before you replace anything
This is the only lever that grows the audience itself rather than working around it, and it is usually the cheapest. A banner that is clear, quick and genuinely balanced converts better than one that is not, without resorting to anything manipulative, which we covered in raising accept rates without dark patterns.
Use the customer data you already hold, knowing its limit
Customer lists you upload reach people you have a direct relationship with, and they do not depend on a visitor being cookied on your site. Do not treat them as a way around consent, though, because they are not one: Google states that data from unconsented EEA users will not be processed and cannot be used for ad personalisation through Customer Match. Outside the EEA the list is unaffected. Inside it, the same consent signals still govern.
Build audiences from consented visitors deliberately
A smaller list of people who did consent is still a real audience, and it behaves better than a large stale one. Define it on purpose rather than accepting whatever accumulates by default.
Move spend toward targeting that needs no identifier
Contextual placements, broad reach and creative work do not depend on knowing who somebody is. When the addressable pool shrinks, the returns on the parts of advertising that never needed an identifier go up.
Invest in the channels where you own the relationship
Email, on site personalisation and your own logged in experience are unaffected by any of this. They are the only audiences no consent signal can take away from you.
What to stop asking for
No configuration turns a denied visitor into a list member. If a tool or an agency implies otherwise, what is really on offer is one of three things: modelling, which is measurement and not targeting; first party data you already had; or a consent setup that is not honouring the choice, which is the expensive one to discover later.
The honest position is that this trade is the point rather than a bug. A visitor said no to being followed, and the system did what they asked. The work worth doing is making the yes easier to give and making the data you already own do more. Velo is built for the first half of that: one snippet sets the consent state before your tags initialise, the choice is recorded with its categories and notice version, and the signals your advertising platforms read match what the visitor actually chose. The mechanism is on the product page.
Common questions
What people ask about this topic.
Can you still build remarketing audiences if visitors reject cookies?
Not from the visitors who rejected. When the advertising consent signals are denied, Google's tags store no advertising identifier for that visitor, so there is nothing for a remarketing list to be built on and no configuration recovers it. Your lists keep growing from consented visitors only. Customer lists you upload are a separate route, but not a way around consent: in the EEA those same signals must be granted before the data can be used for ad personalisation.
Does conversion modelling add rejected visitors to remarketing lists?
No. Modelling estimates conversions in aggregate to fill a reporting gap, and it never produces an identifier for an individual. Modelled results also stay inside the reporting interface: they are excluded from the data export, from audiences, from user explorer and cohort explorations, and from predictive metrics. Measurement recovers, targeting does not.
Which consent signal controls remarketing?
Three of them. Storing the advertising identifier is governed by ad_storage, sending user data to Google for advertising is governed by ad_user_data, and using that data for personalised advertising is governed by ad_personalization. A visitor needs them granted to enter a personalised remarketing audience, which is why a setup that only asks for analytics consent quietly stops list growth.
How much of your remarketing audience do you actually lose?
It depends on your consent rate and your market, so treat any single number as a starting point rather than a forecast. Across Amplio Data client implementations we measure around 34% of sessions hidden by consent choices, which is a measured range and not a guarantee. The more useful point is that the visitors you keep are not a random sample of the ones you lose.
Your banner, your consent,
your data — all in one place.

