Compliant with GDPR, CCPA, COPPA, LGPD, PECR, PDPA, PIPEDA, and more.
This guide is for ecommerce stores, SaaS products and marketing websites. It sets up UniConsent with the analytics, advertising and marketing tags your website runs, so that each tag gets the consent it needs in Europe and in the other regions where you have visitors.
Time needed: about 1 hour: about 10 minutes for Steps 1 and 2, 5 to 10 minutes for each tag in Step 4, and about 30 minutes to test and check in Steps 6 and 7. Changes you publish in the dashboard can take a few minutes to reach your site.
Who does what: Steps 1, 3, 6 and 7 are done in your UniConsent dashboard and your browser. Steps 2, 4 and 5 change your website's code or your Google Tag Manager, so your web developer may want to help with those.
Choose Consent Categories. Visitors choose between four categories, and Google Consent Mode follows their choice:
| Category | What it covers | Examples |
|---|---|---|
| 1. Strictly Necessary | Cookies your site cannot work without. Always on. | Shopping cart, checkout, payments, login, security |
| 2. Performance / Analytics | Measuring how visitors use your site | Google Analytics 4, Hotjar, Microsoft Clarity |
| 3. Functionality | Features and personalization | Live chat, saved preferences, embedded videos and maps |
| 4. Targeting / Advertising | Advertising, retargeting and conversion tracking | Google Ads, Meta Pixel, TikTok Pixel, LinkedIn, Pinterest, Microsoft Advertising |
If your site also runs programmatic ads, or your advertising partners need IAB TCF or IAB GPP signals, choose IAB TCF Advanced instead.
Add the UniConsent tag at the top of <head>, before every other tag, so it can hold the other tags until the visitor's choice is known. See Install UniConsent Tags for Web. There are also a WordPress plugin and a Shopify app: see the same page and Set Up the CMP for Shopify.
If you manage your tags in Google Tag Manager, load the UniConsent CMP tag with the Consent Initialization - All Pages trigger instead. See Consent Mode for Google Tag Manager.
| Region | What visitors see | What happens to your tags |
|---|---|---|
| Europe | The Consent Categories banner | Tags wait for the visitor's choice. Google Consent Mode is denied until the visitor accepts. |
| United States, with Show Banner in the US on | The Consent Categories banner, in all states or the states you select | Tags load straight away, and visitors can turn categories off. A Global Privacy Control signal from the browser turns Targeting or Advertising off until the visitor saves a choice. |
| Other countries you add to the banner | The Consent Categories banner | Tags load, and visitors can turn categories off. |
| Everywhere else | No banner | Tags load, and Google Consent Mode is granted. |
Europe covers the European Union, Norway, Iceland and Liechtenstein, the United Kingdom, Switzerland, and Albania, Andorra, Belarus, Bosnia and Herzegovina, Kosovo, Moldova, Monaco, Montenegro, North Macedonia, San Marino, Serbia and Ukraine.
In the United Kingdom, the UK GDPR and the ICO's guidance require consent before non-essential cookies are set, so keep the UK in your Europe region: tags are held until the visitor accepts.
If you turn off the banner for a region, visitors from that region are treated as if no CMP were installed: no banner appears, and no tags or cookies are blocked.
Some vendors read the visitor's choice themselves, so you do not need to block them: load them as usual and they adjust to the choice. These are Google tags through Google Consent Mode, Microsoft Clarity and Microsoft Advertising through Microsoft Consent Mode, the Meta Pixel and TikTok Pixel through the UniConsent consent tags, and Shopify through its Customer Privacy API. Blocking them is optional: if you prefer that they do not load at all before consent, use Basic Consent Mode for Google tags, or UnicScript for the others.
| Tag | How | Guide |
|---|---|---|
| Google Analytics 4, Google Ads conversions and remarketing | Google Consent Mode. Google needs Consent Mode V2 signals for visitors in Europe to keep conversion measurement and remarketing working. With Advanced Consent Mode, load the tags on every page: they adjust to the visitor's choice. | Google tag, Google Tag Manager, Google Consent Mode |
| Meta Pixel | Hold the pixel with fbq('consent', 'revoke') and add the UniConsent Meta Pixel consent tag. | Meta Pixel |
| TikTok Pixel | Hold the pixel with ttq.holdConsent() and add the UniConsent TikTok Pixel consent tag. | TikTok Pixel |
| Microsoft Advertising (UET), Microsoft Clarity | Microsoft Consent Mode, which UniConsent updates with the visitor's choice. | Microsoft UET, Microsoft Clarity |
| Shopify store tags | The UniConsent Shopify app passes the visitor's choice to Shopify. | Shopify |
| Other analytics, chat and marketing tags | UnicScript with the matching category (see below). | UnicScript |
| YouTube videos, maps and social embeds | UnicScript placeholder blocks, which show a message until the visitor allows the content. | UnicScript |
| Tags you cannot edit | The Tags Loader in your dashboard. | Tags Loader |
For other tags in your page code, set the tag's type to text/unicscript and add the category from Step 1:
<!-- Performance / Analytics, for example Hotjar -->
<script type="text/unicscript" unic-e-purpose-id="2">
// your analytics tag code
</script>
<!-- Functionality, for example a live chat widget -->
<script type="text/unicscript" unic-e-purpose-id="3">
// your chat widget code
</script>
<!-- Targeting / Advertising, for example LinkedIn or Pinterest -->
<script type="text/unicscript" unic-e-purpose-id="4">
// your advertising tag code
</script>
Do not hold the scripts your checkout, payments, login or shopping cart need: they are Strictly Necessary and must always load. For tags in Google Tag Manager that do not read Consent Mode, see Third party JavaScript Tags Integration.
If your tags are in Google Tag Manager, set them up with the consent signals that UniConsent sends:
Consent Initialization - All Pages trigger. In the tag's Consent Mode Default Consent Settings, set every consent type to denied for Europe, or for all regions. See Consent Mode for Google Tag Manager.All Pages.unic_data, which UniConsent sends with the visitor's choice. In the tag's Advanced Settings > Consent Settings, choose Require additional consent for tag to fire and add the consent type of its category from the table below. Under Tag firing options, choose Once per page.| Category | Consent type to require |
|---|---|
| 2. Performance / Analytics | analytics_storage |
| 3. Functionality | functionality_storage |
| 4. Targeting / Advertising | ad_storage |
unic_data is sent at page load and again after each choice, with the Consent Mode update before it. A tag set up this way fires at the first moment its consent is granted, and only once per page. For conditions on the categories instead, see Third party JavaScript Tags Integration.
Visitors must be able to change their choice at any time. Add a privacy settings link, for example in your footer:
<a href="#" onclick='__unicapi("openunic");return false;'>Privacy Settings</a>
See Install UniConsent Tags for Web.
To keep a record of each visitor's choice, for example to answer a data protection request, turn on Consent Logging.
Open your site with a test location, then repeat with US, USCA (California) and the other regions you use:
https://www.example.com/?uniconsent_test=1&uniconsent_reset=1&uniconsent_geo=EU
See UniConsent Testing and Debug Tools.
Check that your tags and cookies follow the visitor's choice. Use a private browser window for each check, so that earlier choices and cookies do not carry over.
Enter your website address in the free Consent Mode Checker. It confirms that UniConsent is found on your site and that your Google tags receive the visitor's consent. See How to Use the Consent Mode Checker.
_ga), Google Ads (_gcl_au), Meta (_fbp), TikTok (_ttp) or Hotjar (_hjSessionUser).USCA (California). Tags load straight away.In your dashboard, open the cookie list of your project. The cookie scanner lists the cookies it finds on your site once a day. Check that each cookie has the right category and that no tracking cookie is listed as Strictly Necessary. See Manage Cookies List.
Your developer can confirm the signals in the browser's developer tools:
facebook.com/tr or analytics.tiktok.com. With Advanced Consent Mode, Google Analytics requests (/g/collect) carry gcs=G100 (storage denied) until the visitor accepts, then gcs=G111.UNIC_EP_1 to UNIC_EP_4 are the four categories.unicUpdate(console.log)
If a tag still sets cookies or sends requests before consent, it loads outside UniConsent's control. Find it in your page code, Google Tag Manager or a plugin, and integrate it as in Step 4.
Contact us: support@uniconsent.com