[Cloud Nine Digital] Insights

Google Consent Mode is not the same as Dutch cookie compliance

Written by Eliza Badescu | Sep 28, 2026, 6:15:00 AM

If you're a Dutch marketing team checking whether your website meets consent requirements, you will often hear that it uses Google Consent Mode. Even though this is useful, it answers a narrower question, as Google is only one part of most measurement stacks. Google Consent Mode communicates a visitor’s consent choices to consent-aware tags. Dutch law asks something different: Is the information being stored on or read from the visitor’s device, and if so, is consent required for that activity?

What Google Consent Mode actually does

 Consent Mode is a signaling layer between a consent solution and Google’s tags. The CMP asks the visitor for a choice, while Consent Mode communicates that choice to Google. There is an important distinction between Basic and Advanced Consent Mode. With Basic Consent Mode, Google tags are blocked until the visitor grants consent. If the visitor does not consent, Google says it does not transfer any data to Google, not even the consent status. With Advanced Consent Mode, Google tags load with consent set to ‘denied’ unless configured otherwise. They do not use the corresponding cookies, but consent-aware tags can send measurements without cookies. The exact behavior depends on the Google product: Google Ads remarketing and Floodlight requests are blocked when ad_storage is denied. At the same time, Google Analytics and Google Ads conversion measurement can operate in a more limited, cookieless form 

 Google can use measurement gaps and observable data for conversion or behavioral modeling. Google additionally strengthened enforcement of its EU User Consent Policy in 2024. For applicable measurement, ad-personalization, and remarketing features, advertisers must collect the relevant consent from EEA users and share consent signals with Google. Consent Mode is Google’s mechanism for communicating those choices from websites. That product requirement should not be confused with the legal test itself.  

What happens server-side?

 In a server-side Google Tag Manager setup, the Google tag adds consent parameters to the HTTP request sent to the server container. Google’s product tags in that container are consent-aware and modify their behavior based on those parameters. Google therefore states that Consent Mode itself only needs to be configured in the web container for this architecture.  

 That does not, however, mean every tag in the server container is automatically covered. Custom tags and third-party templates must be configured and verified separately. Some third-party tags can use Tag Manager consent settings, but Google’s built-in consent checks do not automatically govern every custom or third-party request. The same applies in the browser. A tag manager can enforce consent checks for non-Google tags, but those checks still need to be configured correctly. The presence of a consent signal is not the same as enforcement of that signal.

Why Dutch law asks a different question

 Article 11.7a of the Telecommunicatiewet concerns storing information on, or gaining access to, information stored on a user’s device. The rule is technology-neutral and is not limited to Google, cookies, or personal data. Where personal data are processed, the GDPR applies alongside it 

 Article 11.7a (3) contains two main exemptions. The first covers storage or access whose sole purpose is carrying out communication over an electronic communications network. The second covers storage or access strictly necessary to provide a service requested by the user. It also covers obtaining information about the quality or effectiveness of a delivered service, if this has no or only limited consequences for the user’s privacy.  

 The last exemption is the basis for what is commonly called the Dutch analytics exemption. This exemption is not limited to first-party analytics. The legislative history explicitly chose a technology-neutral test rather than an exemption that specifically links to first-party analytics. A third-party analytics provider can, in principle, fall within the scope, but wider reuse of the data for profiling or other privacy-sensitive purposes can take implementation outside the exemption.  

This is where Consent Mode and Dutch law stop aligning. Google categories such as analytics_storage and ad_storage are technical consent signals, not legal classifications under Article 11.7a. A tag associated with analytics is therefore not automatically exempt under Dutch law. Equally, not every analytics implementation necessarily requires consent.

 The assessment is based on the purpose of the collection, the way information is stored or accessed, and the privacy consequences of that configuration. Advertising functionality, profiling, cross-service tracking, or reuse of analytics data for other purposes can materially change it.  

 There is also an important enforcement distinction. The Autoriteit Consument en Markt (ACM) is the competent Dutch regulator for Article 11.7a itself. Where cookies or similar technologies process personal data, the GDPR also applies, and the Autoriteit Persoonsgegevens (AP) supervises that layer. The two regulators cooperate on overlapping cookie issues.  

Enforcement is active

 The AP increased its scrutiny of cookie banners back in 2024. We can see this in the announcement from April 2025, when they started continuously scanning 10,000 Dutch websites, with around 500 organizations a year targeted for warnings.  The AP also states that where GDPR consent is used, withdrawing consent must be as easy as giving it.  

We can see this development in the Kruidvat case, with an important distinction. The six hundred thousand Euros fine published in July 2024 was a GDPR fine based on the finding that AS Watson, the operator of Kruidvat.nl, had processed personal data through tracking cookies without a lawful basis because valid consent had not been obtained. On objection, the AP reduced the fine to fifty thousand, while claiming that it was a GDPR violation. It cited the unnecessarily long duration of the process, AS Watson’s full admission of the violation, the relatively low seriousness of the infringement, and conformity with a comparable tracking cookie case. This final amount should not be understood as a standard price for a cookie violation, as it depends on its severity among other things.

Cookie banners are not disappearing yet.

The European Commission’s Digital Omnibus proposal included Article 88b, which would require online interfaces to support automated, machine-readable consent and refusal signals and later require larger browser providers to showcase the technical means. In the Council Presidency’s compromise text, Article 88b was struck out in full. That was a negotiating draft, not an adopted Council position. Negotiations are still ongoing, with a further compromise discussed this month. The current European Parliament procedure is labeled as ‘Awaiting committee decision’. For now, the current Dutch consent rules remain in force.

What this means for you

  1. Inventory every tag and request that it runs in the browser, not just within the GTM.
  2. Record what consent signal each tag checks and what happens when it is denied.
  3. Repeat the exercise from the server-side perspective to showcase custom tags, third-party tags and forwarding rules.
  4. For anything that runs without consent, document which Article 11.7a (3) exemption you can rely on and why the conditions are met.
  5. Test withdrawal as well as acceptance. Changing the visitor’s choice should change the technical behavior of the site as expected.

It is important to distinguish that Google Consent Mode is an important part of a modern consent implementation. It however, is not a compliance lawyer for the entire site.

FAQ

About the author

 Eliza Badescu is Lead Consultant Data Privacy & Compliance at Cloud Nine Digital. She joined the company to further strengthen and add value to its Privacy & Compliance pillar, helping organizations translate complex regulatory requirements into practical solutions.
She leads the development of Cloud Nine Digital’s privacy, compliance and governance expertise, with work spanning DPIAs, consent, privacy governance and the responsible and compliant use of AI.

Looking for support with AI governance, compliance or a DPIA for your AI use cases? Reach out to Cloud Nine Digital to see how Eliza and the team can support you.