Compliant with GDPR, CCPA, COPPA, LGPD, PECR, PDPA, PIPEDA, and more.
This guide is for publishers. It sets up UniConsent with the tags most sites run, so that each tag gets the consent signal it needs in Europe and in the other regions where you have visitors. Not a publisher? For ecommerce, SaaS and marketing websites, see Ecommerce, SaaS and Marketing Websites.
Time needed: about 1 to 2 hours: about 10 minutes for Steps 1 and 2, 5 to 15 minutes for each tag in Step 4, and about 30 minutes to test and check in Steps 6 and 7. Changes you publish in the dashboard can take a few minutes to reach your site.
Who does what: Steps 1, 3, 6 and 7 are done in your UniConsent dashboard and your browser. Steps 2, 4 and 5 change your website's code or your Google Tag Manager, so your web developer may want to help with those.
| Your site | Banner type | Why |
|---|---|---|
| Runs programmatic ads: Google Ad Manager, AdSense, Prebid or Amazon | IAB TCF | Ad tech in Europe reads the IAB TCF string. Google requires a Google-certified CMP that uses IAB TCF for ads served in the EEA, the UK and Switzerland. UniConsent is a Google-certified CMP, Gold tier. |
| Runs analytics and marketing tags only | Consent Categories | A simpler banner with four categories: Strictly Necessary, Performance, Functionality, and Targeting or Advertising. |
Then, in your project settings, turn on the policies for your other regions: CCPA and US State Privacy for the US, and IAB TCF Canada for Canada. Turn on IAB GPP as well, so ad tech outside Europe receives the US and Canada choices.
Add the UniConsent tag at the top of <head>, before every other tag, so it can hold the other tags until the visitor's choice is known. See Install UniConsent Tags for Web.
If you manage your tags in Google Tag Manager, load the UniConsent CMP tag with the Consent Initialization - All Pages trigger instead. See Consent Mode for Google Tag Manager.
| Region | Banner | Signals your tags receive |
|---|---|---|
| Europe | IAB TCF or Consent Categories. Tags wait for the visitor's choice. | The IAB TCF string (IAB TCF banner), Google Consent Mode (denied until the visitor accepts), and IAB GPP when it is on |
| United States | CCPA or US State Privacy. Tags load, and the visitor can opt out. | The US Privacy string, the IAB GPP US sections, and Google Consent Mode. After a "Do Not Sell or Share" opt-out or a Global Privacy Control signal, advertising turns off: ad_user_data and ad_personalization are denied, and analytics keep running. |
| Canada | IAB TCF Canada | The IAB GPP Canada section after the visitor's choice, and Google Consent Mode |
| Brazil, South Africa, China, Vietnam and your other countries rules, when turned on | Consent Categories | Google Consent Mode and the consent categories |
| Everywhere else | No banner | Tags load, and Google Consent Mode is granted |
Europe covers the European Union, Norway, Iceland and Liechtenstein, the United Kingdom, Switzerland, and Albania, Andorra, Belarus, Bosnia and Herzegovina, Kosovo, Moldova, Monaco, Montenegro, North Macedonia, San Marino, Serbia and Ukraine.
In the United Kingdom, the UK GDPR and the ICO's guidance require consent before non-essential cookies are set, so keep the UK in your Europe region: tags are held until the visitor accepts.
If you turn off the policy for a region, visitors from that region are treated as if no CMP were installed: no banner appears, and no tags or cookies are blocked.
| Where | Law | What UniConsent does |
|---|---|---|
| California | CCPA / CPRA | Shows a privacy notice and the Do Not Sell or Share My Personal Information link, records the visitor's opt-out, and treats a Global Privacy Control signal from the browser as an opt-out. Sends the choice as the US Privacy string and in IAB GPP. |
| Virginia, Colorado, Utah, Connecticut, Florida, Montana, Oregon, Texas, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island | The state's consumer privacy law | Shows the US State Privacy notice and the opt-out link. Visitors can opt out of the sale and sharing of their data and of targeted advertising, and a Global Privacy Control signal counts as an opt-out. When you use sensitive data purposes, visitors must opt in to them first. Sends the choice in IAB GPP. |
IAB GPP (Global Privacy Platform) is the standard way to pass a visitor's US privacy choices to advertising partners. Google Ad Manager, Prebid, Amazon and other ad tech read it automatically, so you do not need to set anything up for them. UniConsent sends the US National section, which covers every state, together with the section for the visitor's own state. Under GPP Sections in your project settings you can send only one of the two. See US State Privacy Setup.
| Tag | How | Guide |
|---|---|---|
| Google Analytics 4, Google Ads, Floodlight | Google Consent Mode. With Advanced Consent Mode, load the tags on every page: they adjust to the visitor's choice. | Google tag, Google Tag Manager, Google Consent Mode |
| Google Ad Manager, AdSense | Start ad requests once the visitor's choice is known. Google reads the IAB TCF string, IAB GPP and the US Privacy string. | Google Ad Manager and AdSense |
| Prebid.js | Include the Prebid consent management modules for IAB TCF, IAB GPP and US Privacy. | Prebid |
| Amazon ad tags and pixels | Add the UniConsent Amazon Consent Signal tag. | Amazon Consent Signal |
| Meta Pixel | Hold the pixel with fbq('consent', 'revoke') and add the UniConsent Meta Pixel consent tag. | Meta Pixel |
| TikTok Pixel | Hold the pixel with ttq.holdConsent() and add the UniConsent TikTok Pixel consent tag. | TikTok Pixel |
| Microsoft Advertising (UET), Microsoft Clarity | Microsoft Consent Mode, which UniConsent updates with the visitor's choice. | Microsoft UET, Microsoft Clarity |
| Other analytics and marketing tags | UnicScript with a consent category (see below). | UnicScript |
| YouTube videos, maps and social embeds | UnicScript placeholder blocks, which show a message until the visitor allows the content. | UnicScript |
| Tags you cannot edit | The Tags Loader in your dashboard. | Tags Loader |
For other analytics and marketing tags in your page code, set the tag's type to text/unicscript and add the consent category it needs:
<!-- Performance / Analytics, for example Hotjar -->
<script type="text/unicscript" unic-e-purpose-id="2">
// your analytics tag code
</script>
<!-- Targeting / Advertising, for example LinkedIn or Pinterest -->
<script type="text/unicscript" unic-e-purpose-id="4">
// your advertising tag code
</script>
unic-e-purpose-id works with both banner types and in every region. Where IAB TCF applies, the categories follow the visitor's IAB TCF choices, and after a US opt-out the Targeting or Advertising category is off. For tags in Google Tag Manager that do not read Consent Mode, see Third party JavaScript Tags Integration.
Visitors must be able to change their choice at any time. Add a privacy settings link, for example in your footer:
<a href="#" onclick='__unicapi("openunic");return false;'>Privacy Settings</a>
For US visitors, add this element where the Do Not Sell or Share My Personal Information link should appear:
<div id="uniconsent-config"></div>
See Install UniConsent Tags for Web and US State Privacy Setup.
Open your site with a test location, then repeat with US, USCA (California), CA (Canada) and the other regions you use:
?uniconsent_test=1&uniconsent_reset=1&uniconsent_geo=EU
In each region, check that the right banner appears, that tags wait for consent where they should, and that Google tags receive Consent Mode. See UniConsent Testing and Debug Tools and the Consent Mode Checker.
Check that your tags and cookies follow the visitor's choice. Use a private browser window for each check, so that earlier choices and cookies do not carry over.
Enter your website address in the free Consent Mode Checker. It confirms that UniConsent is found on your site and that your Google tags receive the visitor's consent. See How to Use the Consent Mode Checker.
https://www.example.com/?uniconsent_test=1&uniconsent_reset=1&uniconsent_geo=EU
_ga), Google Ads (_gcl_au), Meta (_fbp) or TikTok (_ttp).USCA (California). Tags load straight away: in the US, visitors opt out instead of opting in.USTX (Texas).In your dashboard, open the cookie list of your project. The cookie scanner lists the cookies it finds on your site once a day. Check that each cookie has the right category and that no tracking cookie is listed as Strictly Necessary. See Manage Cookies List.
Your developer can confirm the signals in the browser's developer tools:
facebook.com/tr or analytics.tiktok.com. With Advanced Consent Mode, Google Analytics requests (/g/collect) carry gcs=G100 (storage denied) until the visitor accepts, then gcs=G111.1YYN after a California opt-out) and the IAB GPP string:__tcfapi('getTCData', 2, console.log)
__uspapi('getUSPData', 1, console.log)
__gpp('ping', console.log)
If a tag still sets cookies or sends requests before consent, it loads outside UniConsent's control. Find it in your page code, Google Tag Manager or a plugin, and integrate it as in Step 4.
Contact us: support@uniconsent.com