Consent Mode v2 and cookie consent on a dental website
Last reviewed against the regulators’ own text, linked in the sources below.
This is general information, not legal advice.
Consent Mode v2 on a dental website is Google's way of telling its tags what each visitor agreed to in your cookie banner, so Google Analytics and Google Ads behave accordingly. It doesn't make a site compliant on its own. The law decides what needs consent; Consent Mode only passes the visitor's answer to Google, and it only works if the banner and the tags are wired in the right order.
A common failure is simple: tags fire before the visitor has answered, or keep firing after they said no. The legal position comes first, then what Consent Mode does, how to test for that failure yourself, and what it does to the numbers behind tracking ads to booked treatment. The full method, stage by stage, is in measuring marketing against booked revenue.
What the law requires
Cookie rules in the UK sit in PECR, the Privacy and Electronic Communications Regulations. They cover any technology that stores or reads information on a visitor's device, not only cookies, which is why the ICO now calls its guidance "storage and access technologies". The ICO last updated that guidance on 29 April 20261. Where the information collected is personal data, UK GDPR applies as well.
The starting point is consent, with a short list of exceptions in Schedule A1 to PECR, which the Data (Use and Access) Act 2025 inserted with effect from 5 February 20262. The ICO lists five: communication, strictly necessary, statistical purposes, appearance, and emergency assistance3.
| Purpose on a practice site | Consent needed? | Source |
|---|---|---|
| Keeping the site secure, remembering a booking in progress | No, if strictly necessary for the service the visitor asked for | ICO exceptions3 |
| Analytics used only to improve the site | Possibly not, under the statistical purposes exception, if its conditions are met | ICO exceptions3 |
| Google Ads conversion tracking, remarketing, Meta pixel | Yes. No exception applies to advertising | ICO exceptions3 |
The statistical purposes exception is narrow. The sole purpose must be collecting statistics about how the site is used, to improve it. Visitors must get clear and comprehensive information and a simple, free way to object, and the data may be shared only with someone helping you make those improvements3. A third-party tool can qualify, but the ICO says the provider must act as your processor, not a joint controller, and must not link the data with other information. An analytics setup that also feeds advertising audiences or ad conversions is being used for advertising, and needs consent.
On a dental site, a page address such as an implants or dentures page can say something about a visitor's health. The exception covers only aggregate statistics, so profiles of individual visitors by treatment page fall outside it. If you set out to infer anything about a person's health, UK GDPR treats that as special category data, which needs an Article 9 condition4.
On advertising the ICO is blunt: "If your service uses storage or access technologies for the purposes of online advertising, you must get consent. You cannot rely on any of the exceptions."3
Google adds its own requirement. Its EU user consent policy says disclosures must be given to, and consents obtained from, end users in the European Economic Area, the UK and Switzerland5.
Consent for emails and texts to patients is a different set of rules, covered in emailing and texting patients under PECR.
What Consent Mode does
Consent Mode is a set of signals your banner sends to Google tags. "v2" is the common name for the version with four parameters6:
| Parameter | Controls |
|---|---|
ad_storage | Storage such as cookies related to advertising |
analytics_storage | Storage related to analytics |
ad_user_data | Whether user data can be sent to Google for advertising |
ad_personalization | Whether data can be used for personalised advertising, such as remarketing |
Google describes two implementations6:
- Basic: Google tags are blocked until the visitor interacts with the banner. Nothing is sent before consent. Google applies general modelling to fill gaps.
- Advanced: tags load straight away with consent set to denied. While denied, they send cookieless pings: measurements without cookies, carrying details such as a timestamp and user agent. Google uses these for modelling specific to your account.
Two points matter for a practice. Consent Mode governs Google tags only; a Meta pixel or a call-tracking script needs its own consent rule in your banner tool or tag manager. And whether advanced mode's cookieless pings are acceptable before consent is a PECR question, because the rules cover reading information from a device, not only setting cookies. I put that one to the practice's data protection adviser rather than deciding it myself.
Testing your site
Google's own troubleshooting guide says the site must set the default consent state before any tags or other code use or update consent7. That is the thing to test, and you don't need a developer to do it.
| Step | What to do | Pass | Fail |
|---|---|---|---|
| 1 | Open the site in a private window. Do not touch the banner | Banner shows | No banner, or it shows after other scripts load |
| 2 | Open browser developer tools, Application tab, cookies | Only strictly necessary cookies, plus analytics cookies if you rely on the statistical purposes exception and the banner explains them with an off switch | Ad cookies already set, or analytics cookies set with no notice and no way to object |
| 3 | Run Google Tag Assistant and select the earliest Consent event7 | Defaults show as denied | Defaults missing, or granted |
| 4 | Click reject, browse two pages | No new ad or analytics cookies; non-Google pixels silent | Meta pixel or other tags still firing |
| 5 | Clear cookies, reload, click accept | Consent updates to granted; tags fire | Tags do not fire, so you lose consented data too |
| 6 | Repeat on the booking and contact pages | Same results | Booking widget sets its own tracking cookies before consent |
Step 4 catches the most common problem on practice sites. Google tags respect Consent Mode, but a pixel added separately by a previous supplier often ignores the banner completely.
Measurement impact
Consent has a cost in data, and it's better to know the size of the gap than to pretend it isn't there.
| What happens | Effect on reporting |
|---|---|
| A visitor declines | Their visit and any conversion are not observed with cookies |
| Google models the gap | Some reports include modelled conversions, estimated rather than counted6 |
| Remarketing lists | Only visitors who granted consent can be added |
| Offline conversion import | Harder to match a later booking to the ad click for visitors who declined |
| Your practice management system (PMS) | Unaffected. Bookings and treatment are still recorded in full |
That last row is why I measure against booked and completed treatment in the practice's own system. The ad platform's view of results is partial by law. The appointment book isn't. The gap between the two is a number worth reporting every month, not hiding.
Consent rules don't stop at the website: the rules on email and SMS marketing cover the messages that follow. For a free first test of your banner and tags, email [email protected].
Sources
-
ICO: Guidance on the use of storage and access technologies, last updated 29 April 2026, accessed 1 October 2026. ↩
-
Data (Use and Access) Act 2025, Schedule 12, in force 5 February 2026 under SI 2026/82, regulation 2, accessed 1 October 2026. ↩
-
ICO: What are the exceptions?, accessed 1 October 2026. ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
ICO: What is special category data?, accessed 1 October 2026. ↩
-
Google: EU user consent policy, accessed 1 October 2026. ↩
-
Google for Developers: Consent mode overview, accessed 1 October 2026. ↩ ↩2 ↩3
-
Google for Developers: Troubleshoot consent mode with Tag Assistant, accessed 1 October 2026. ↩ ↩2
Further sources
- SI 2026/82, regulation 2, accessed 1 October 2026.