Skip to content
Open workspace
Browse help topics
Google tags and tag gateway

Run every Google tag on the visitor’s choice.

Check which tags follow Consent Mode on their own, set the advertising options, and keep consent intact with Google tag gateway and server-side tagging.

5 min readReviewed 30 September 2026

Know which tags need extra settings

Google Analytics, Google Ads and Floodlight tags have built-in consent checks. They read the Consent Mode state that Velo sets and change their behaviour without further setup. Other tags in your container, including Custom HTML and most community templates, do not read it.

  1. In GTM, open Admin → Container Settings and, under Additional Settings, select Enable consent overview.
  2. Open Tags and click the Consent Overview icon. It lists tags whose consent is not configured.
  3. For each tag that is not a Google tag, open Advanced Settings → Consent Settings, choose Require additional consent for tag to fire and add the signals it depends on. Advertising tags need ad_storage, ad_user_data and ad_personalization. Analytics tags need analytics_storage.
  4. Publish the container and test again in a fresh session.

A tag held back by consent settings does not fire later on its own. If it has to run once the visitor accepts, also fire it on a Custom Event trigger for velo_consent_update, the data layer event Velo pushes whenever a choice takes effect.

Choose the advertising options

The Velo CMP template has two Google options under Advanced. Both are off by default.

Advanced options in the Velo CMP template
OptionWhat it does while advertising is refused
ads_data_redactionWhen ad_storage is denied, ad click identifiers are dropped from Google’s requests, and the requests are sent without cookies.
url_passthroughAd click, client and session identifiers are passed from page to page through link URLs, because they cannot be stored in cookies.

Choose them to match your organisation’s policy. With url_passthrough, test your forms and internal links, because extra parameters are added to the URLs. With a direct installation, set these options in your Google tag code by following Google’s consent setup instructions.

Check user-provided data

Features such as enhanced conversions send user-provided data, like a hashed email address, to Google for advertising. Google uses the ad_user_data signal to decide whether that data may be sent. Velo grants ad_user_data only when the visitor allows the Advertising category.

Test a conversion in two fresh sessions, one accepting advertising and one rejecting it. In Tag Assistant, check the consent state on the conversion event in each session.

Serve Google tags through tag gateway

Google tag gateway for advertisers loads your Google tag or GTM container from a path on your own domain, such as /metrics/, instead of from googletagmanager.com. Your CDN or load balancer forwards that path to Google.

The gateway changes where tags load from, not what consent they follow.

Keep the Velo CMP template on Consent Initialization – All Pages, and keep every tag’s consent settings. Velo’s own script still loads from Velo. That is expected.

If your website uses Cloudflare

  1. In GTM, open Admin → Google tag gateway.
  2. Review the measurement path. Use a path your website does not already use.
  3. Sign in to Cloudflare, authorise Google and select the domains to enable.

Any other CDN or load balancer

Follow Google’s tag gateway setup guide. You route the measurement path to your tag’s fps.goog address, forward the visitor’s location headers and change the src in your GTM or gtag snippet to the new path.

Check the gateway

Replace /metrics with your own path. Both addresses should show ok.

Health checks · use your own domain and path
https://www.example.com/metrics/healthy
https://www.example.com/metrics/?validate_geo=healthy

Serving tags from your own domain does not change your consent obligations. After switching, repeat the Tag Assistant test with accept, reject and partial choices.

Carry consent into server-side tagging

With a server container, Google tags in the browser add the visitor’s consent state to each request they send to your server. Google’s server-side tags, such as Google Analytics and Google Ads, read that state and adjust what they send. You only set up Consent Mode in the web container, which the Velo CMP template already does.

Server tags for other vendors, such as Meta Conversions API or TikTok Events API, do not follow Google’s consent state automatically. Configure each one to check consent before it sends data, following that template’s documentation, and test a rejected session in the server container’s preview.

See Google’s consent guide for server-side tagging.

Test after every change

  • Start each test in a fresh browser session on the published website.
  • In Tag Assistant, check that the Velo defaults appear before any Google tag fires.
  • Accept, reject and save a partial choice, then check the consent state on each tag.
  • With tag gateway, check that Google requests go to your measurement path.
  • Check that tags with additional consent settings stay blocked after a rejection.
  • Change a choice through the privacy button and check the update on the next page.

If something does not look right

A health check does not show “ok”.

Check that the path is forwarded to the correct fps.goog address and that no cache or redirect rule catches it first. If only the validate_geo check fails, the location headers are missing.

Tags still load from googletagmanager.com.

The snippet on the page was not updated to the new path, or an old copy of it is still installed. Search your theme and plugins for the original snippet.

A non-Google tag fires before the visitor chooses.

Its consent settings are missing or set to No additional consent required. Use the Consent Overview to find it, add the consent types it needs and publish again.