Skip to content

Google tag gateway (GTG) and consent timing

Last updated: October 3, 20267 min readAdvancedBrandDeveloper

Google Consent Mode only works as intended when the consent default is set before any Google tag runs. Google tag gateway changes where your Google tags load from, and some ways of setting it up also change when they load. This page explains what Google tag gateway is, how to check whether a tag uses it, and what to do when a tag is flagged as running before the consent default (a "late" consent signal).

What Google tag gateway is

Google tag gateway for advertisers serves your Google tags from your own website's domain instead of from Google's domains. Google describes it as a way to "deploy a Google tag using your own first-party infrastructure, hosted on your website's domain", using the content delivery network (CDN), load balancer or web server you already have. Instead of loading www.googletagmanager.com/gtag/js, the page loads the tag from a path on your own domain that you choose, called the measurement path (for example /metrics/). Measurement requests go to that path and are forwarded to Google.

How it affects consent

Google asks you to set the consent default "on every page of your site before any commands that send measurement data". On most sites that means the Arqam360 script, or the Arqam360 tag in Google Tag Manager, has to run before any Google tag. Google tag gateway doesn't change that rule, but some setups take the order out of your hands. With a one-click CDN setup, such as the Cloudflare integration in the Google tag, automated script set up can insert or rewrite Google tags in your HTML at the CDN. The tag can then end up above your consent script, and you can't move it from your site's code. Google's own setup guide says: "If you use consent mode, you must turn off automated script set up."

What a late consent signal means

A consent signal is late when a Google tag runs, or sends a request, before the consent default has been set. A tag that starts before the default doesn't know the visitor's consent state yet. Google Tag Assistant shows this, and so does any check that compares the position of the consent default with the first Google tag on the page.

Step 1: first check whether the late tag uses Google tag gateway

Do this by hand for each Google tag on the page. Don't rely only on an automatic check.

1

View the page source

Open the page in your browser and choose View Page Source. Search for gtag/js, gtm.js or your tag ID (G-, AW- or GTM-). If the script loads from www.googletagmanager.com, the tag doesn't use Google tag gateway. If it loads from a path on your own domain, such as /metrics/?id=G-XXXXXXX, it does. With a CDN setup the browser shows the source as the CDN delivered it, even if the files on your server still point to googletagmanager.com.

2

Check the Network tab

Open your browser's developer tools, go to the Network tab and reload the page. Filter by your tag ID. Requests to your own domain mean the tag goes through Google tag gateway. Requests to googletagmanager.com or google-analytics.com mean it loads from Google directly.

3

Check in Tag Assistant

Connect Google Tag Assistant to your site and browse a few pages. In Summary > Output > Hits Sent, hits that go through Google tag gateway are routed to your measurement path.

4

Check your Google tag settings

In the Google tag gateway settings of your Google tag, each domain where it runs shows an Active status.

If no Google tag on the page uses Google tag gateway, go to Step 2. If the late tag does, go to Step 3.

Step 2: the tag doesn't use Google tag gateway: fix the load order

1

Set the default before any Google tag

The consent default has to run before gtag.js, gtm.js or any other Google tag. The Arqam360 script sets the default as the first thing it does, so what matters is where the script sits on the page.

2

Put the Arqam360 script first in <head>

If you added the script yourself, make it the first script in <head>, above the Google Tag Manager or gtag.js snippet, and don't add async or defer to it.

3

In Google Tag Manager, use Consent Initialization

If your Google tags run in Google Tag Manager, use the Arqam360 tag template on the Consent Initialization - All Pages trigger. Google designed this trigger to make sure "all consent settings are honored before any other triggers fire".

4

Remove duplicate Google tags

If a Google tag is pasted into your theme and also set up in Tag Manager, one of them can run outside the order you set. Keep each Google tag in one place.

5

Check again

Reload the page with Tag Assistant connected. The earliest Consent event should show the default, with ad_storage Denied, before your Google tags fire.

Step 3: the tag uses Google tag gateway

For tags served through Google tag gateway, advanced consent mode is the recommended setup, because it is compatible with a manual Google tag gateway setup: the tags load with consent denied and adjust when the visitor chooses, instead of depending on a script that blocks them and may load after them. Arqam360 uses advanced consent mode by default. Then choose one of these, depending on what you need:

  • Keep advanced consent mode and use the Google tag's own settings. Turn on data transmission controls to limit what your tags send while consent is denied, for example Transmit limited advertising data only, or Prevent transmission of behavioral analytics data. Set global consent defaults with the Set consent mode override setting: it sets the default to denied for the regions you choose, even if the code on your page sets a different default. Google notes that it helps when your website builder or platform doesn't let you control the order scripts load in. It needs Manage default consent settings set to "No. Do not automatically mark this data as consented", and it applies only to the tag you configure, so set it on each Google tag.
  • Move all your Google tags into one Google Tag Manager container. Add the Arqam360 tag template on the Consent Initialization - All Pages trigger, and serve the container itself through Google tag gateway. The consent default then runs inside the container before any of its tags, wherever the container loads from.
  • Set up Google tag gateway manually, so you control the order of scripts. Turn off automated script set up, place the Arqam360 script first in <head>, then your Google tag with its src pointing to your measurement path.

Notes by platform

  • Shopify: Arqam360 loads through its app embed, which Shopify places in your theme's <head>. Turn it on in Online Store > Themes > Customize > App embeds. Shopify decides where the embed sits relative to your theme code and other apps, so a Google tag pasted into theme.liquid or added by another app can run first. Move those tags into a Google Tag Manager container with the Arqam360 template, or keep advanced consent mode and use the Google tag settings in Step 3.
  • Salla and Zid: the app adds the banner through the platform's app snippets. Google tags you connect through your store's own marketing settings are placed by the platform, and you can't change their order from your theme. Keep advanced consent mode (the default), and set data transmission controls and consent defaults in each Google tag's settings, as in Step 3.
  • WordPress: the Arqam360 plugin prints its script as the first script in <head>, without async. The exception is a Google tag hardcoded into your theme's header.php above wp_head(): it runs before anything WordPress adds. Move it below wp_head(), or add it through Google Tag Manager.
  • Google Tag Manager: use the Arqam360 tag template on the Consent Initialization - All Pages trigger, and install Arqam360 only once.
  • Any other site: place the Arqam360 script tag first in <head>, before the Google Tag Manager or gtag.js snippet.

How basic and advanced consent mode differ, and how to set each one in Arqam360: Consent Mode: basic vs advanced.

Step-by-step setup of the tag template: Install Arqam360 with Google Tag Manager.

Google documentation

Was this article helpful?