Leading Consent Management Platform

Compliant with GDPR, CCPA, COPPA, LGPD, PECR, PDPA, PIPEDA, and more.

Publisher Setup: Common Tags by Region

This guide is for publishers. It sets up UniConsent with the tags most sites run, so that each tag gets the consent signal it needs in Europe and in the other regions where you have visitors. Not a publisher? For ecommerce, SaaS and marketing websites, see Ecommerce, SaaS and Marketing Websites.

Time needed: about 1 to 2 hours: about 10 minutes for Steps 1 and 2, 5 to 15 minutes for each tag in Step 4, and about 30 minutes to test and check in Steps 6 and 7. Changes you publish in the dashboard can take a few minutes to reach your site.

Who does what: Steps 1, 3, 6 and 7 are done in your UniConsent dashboard and your browser. Steps 2, 4 and 5 change your website's code or your Google Tag Manager, so your web developer may want to help with those.

Step 1: Choose Your Banner Type

Your siteBanner typeWhy
Runs programmatic ads: Google Ad Manager, AdSense, Prebid or AmazonIAB TCFAd tech in Europe reads the IAB TCF string. Google requires a Google-certified CMP that uses IAB TCF for ads served in the EEA, the UK and Switzerland. UniConsent is a Google-certified CMP, Gold tier.
Runs analytics and marketing tags onlyConsent CategoriesA simpler banner with four categories: Strictly Necessary, Performance, Functionality, and Targeting or Advertising.

Then, in your project settings, turn on the policies for your other regions: CCPA and US State Privacy for the US, and IAB TCF Canada for Canada. Turn on IAB GPP as well, so ad tech outside Europe receives the US and Canada choices.

Step 2: Install the UniConsent Tag First

Add the UniConsent tag at the top of <head>, before every other tag, so it can hold the other tags until the visitor's choice is known. See Install UniConsent Tags for Web.

If you manage your tags in Google Tag Manager, load the UniConsent CMP tag with the Consent Initialization - All Pages trigger instead. See Consent Mode for Google Tag Manager.

Step 3: What Each Region Gets

RegionBannerSignals your tags receive
EuropeIAB TCF or Consent Categories. Tags wait for the visitor's choice.The IAB TCF string (IAB TCF banner), Google Consent Mode (denied until the visitor accepts), and IAB GPP when it is on
United StatesCCPA or US State Privacy. Tags load, and the visitor can opt out.The US Privacy string, the IAB GPP US sections, and Google Consent Mode. After a "Do Not Sell or Share" opt-out or a Global Privacy Control signal, advertising turns off: ad_user_data and ad_personalization are denied, and analytics keep running.
CanadaIAB TCF CanadaThe IAB GPP Canada section after the visitor's choice, and Google Consent Mode
Brazil, South Africa, China, Vietnam and your other countries rules, when turned onConsent CategoriesGoogle Consent Mode and the consent categories
Everywhere elseNo bannerTags load, and Google Consent Mode is granted

Europe covers the European Union, Norway, Iceland and Liechtenstein, the United Kingdom, Switzerland, and Albania, Andorra, Belarus, Bosnia and Herzegovina, Kosovo, Moldova, Monaco, Montenegro, North Macedonia, San Marino, Serbia and Ukraine.

In the United Kingdom, the UK GDPR and the ICO's guidance require consent before non-essential cookies are set, so keep the UK in your Europe region: tags are held until the visitor accepts.

If you turn off the policy for a region, visitors from that region are treated as if no CMP were installed: no banner appears, and no tags or cookies are blocked.

United States: State Privacy Laws

WhereLawWhat UniConsent does
CaliforniaCCPA / CPRAShows a privacy notice and the Do Not Sell or Share My Personal Information link, records the visitor's opt-out, and treats a Global Privacy Control signal from the browser as an opt-out. Sends the choice as the US Privacy string and in IAB GPP.
Virginia, Colorado, Utah, Connecticut, Florida, Montana, Oregon, Texas, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode IslandThe state's consumer privacy lawShows the US State Privacy notice and the opt-out link. Visitors can opt out of the sale and sharing of their data and of targeted advertising, and a Global Privacy Control signal counts as an opt-out. When you use sensitive data purposes, visitors must opt in to them first. Sends the choice in IAB GPP.

IAB GPP (Global Privacy Platform) is the standard way to pass a visitor's US privacy choices to advertising partners. Google Ad Manager, Prebid, Amazon and other ad tech read it automatically, so you do not need to set anything up for them. UniConsent sends the US National section, which covers every state, together with the section for the visitor's own state. Under GPP Sections in your project settings you can send only one of the two. See US State Privacy Setup.

Step 4: Integrate Your Tags

TagHowGuide
Google Analytics 4, Google Ads, FloodlightGoogle Consent Mode. With Advanced Consent Mode, load the tags on every page: they adjust to the visitor's choice.Google tag, Google Tag Manager, Google Consent Mode
Google Ad Manager, AdSenseStart ad requests once the visitor's choice is known. Google reads the IAB TCF string, IAB GPP and the US Privacy string.Google Ad Manager and AdSense
Prebid.jsInclude the Prebid consent management modules for IAB TCF, IAB GPP and US Privacy.Prebid
Amazon ad tags and pixelsAdd the UniConsent Amazon Consent Signal tag.Amazon Consent Signal
Meta PixelHold the pixel with fbq('consent', 'revoke') and add the UniConsent Meta Pixel consent tag.Meta Pixel
TikTok PixelHold the pixel with ttq.holdConsent() and add the UniConsent TikTok Pixel consent tag.TikTok Pixel
Microsoft Advertising (UET), Microsoft ClarityMicrosoft Consent Mode, which UniConsent updates with the visitor's choice.Microsoft UET, Microsoft Clarity
Other analytics and marketing tagsUnicScript with a consent category (see below).UnicScript
YouTube videos, maps and social embedsUnicScript placeholder blocks, which show a message until the visitor allows the content.UnicScript
Tags you cannot editThe Tags Loader in your dashboard.Tags Loader

For other analytics and marketing tags in your page code, set the tag's type to text/unicscript and add the consent category it needs:

<!-- Performance / Analytics, for example Hotjar -->
<script type="text/unicscript" unic-e-purpose-id="2">
  // your analytics tag code
</script>

<!-- Targeting / Advertising, for example LinkedIn or Pinterest -->
<script type="text/unicscript" unic-e-purpose-id="4">
  // your advertising tag code
</script>

unic-e-purpose-id works with both banner types and in every region. Where IAB TCF applies, the categories follow the visitor's IAB TCF choices, and after a US opt-out the Targeting or Advertising category is off. For tags in Google Tag Manager that do not read Consent Mode, see Third party JavaScript Tags Integration.

Visitors must be able to change their choice at any time. Add a privacy settings link, for example in your footer:

<a href="#" onclick='__unicapi("openunic");return false;'>Privacy Settings</a>

For US visitors, add this element where the Do Not Sell or Share My Personal Information link should appear:

<div id="uniconsent-config"></div>

See Install UniConsent Tags for Web and US State Privacy Setup.

Step 6: Test Each Region

Open your site with a test location, then repeat with US, USCA (California), CA (Canada) and the other regions you use:

?uniconsent_test=1&uniconsent_reset=1&uniconsent_geo=EU

In each region, check that the right banner appears, that tags wait for consent where they should, and that Google tags receive Consent Mode. See UniConsent Testing and Debug Tools and the Consent Mode Checker.

Step 7: Confirm Tags and Cookies Are Controlled

Check that your tags and cookies follow the visitor's choice. Use a private browser window for each check, so that earlier choices and cookies do not carry over.

Enter your website address in the free Consent Mode Checker. It confirms that UniConsent is found on your site and that your Google tags receive the visitor's consent. See How to Use the Consent Mode Checker.

Check in Europe

  1. Open your site with the EU test location, and do not click the banner yet:
https://www.example.com/?uniconsent_test=1&uniconsent_reset=1&uniconsent_geo=EU
  1. Click the icon to the left of the address bar and open the list of cookies for the site. Before a choice, only strictly necessary cookies are there: no cookies from Google Analytics (_ga), Google Ads (_gcl_au), Meta (_fbp) or TikTok (_ttp).
  2. Accept all. The cookies of your analytics and advertising tags now appear in the list.
  3. In a new private window, open the same address and reject all. The analytics and advertising cookies stay absent.
  4. Reload the page. The banner does not appear again, and the cookies still follow the choice you made.
  5. Open your privacy settings link from Step 5, change your choice, and check that the cookies follow the new choice.

Check in the United States

  1. Open your site with the test location USCA (California). Tags load straight away: in the US, visitors opt out instead of opting in.
  2. Click Do Not Sell or Share My Personal Information and opt out. The banner closes and the choice is kept when you reload.
  3. Repeat with another state, for example USTX (Texas).

In your dashboard, open the cookie list of your project. The cookie scanner lists the cookies it finds on your site once a day. Check that each cookie has the right category and that no tracking cookie is listed as Strictly Necessary. See Manage Cookies List.

For your developer

Your developer can confirm the signals in the browser's developer tools:

  • In Network, before a choice in Europe, there are no requests to advertising pixels such as facebook.com/tr or analytics.tiktok.com. With Advanced Consent Mode, Google Analytics requests (/g/collect) carry gcs=G100 (storage denied) until the visitor accepts, then gcs=G111.
  • In the Console, these commands show the stored IAB TCF choice, the US Privacy string (1YYN after a California opt-out) and the IAB GPP string:
__tcfapi('getTCData', 2, console.log)
__uspapi('getUSPData', 1, console.log)
__gpp('ping', console.log)

If a tag still sets cookies or sends requests before consent, it loads outside UniConsent's control. Find it in your page code, Google Tag Manager or a plugin, and integrate it as in Step 4.

Common Mistakes

  • Installing the CMP without integrating your tags. The banner appears, but tags that are not integrated still load and set cookies before consent. Integrate every tag as in Step 4, and confirm it with Step 7.
  • Not checking your vendors' reports after setup. A few days after going live, open the reports of your tags, for example Google Ad Manager or AdSense, your header bidding reports and Google Analytics, and compare them with the days before. A drop in line with the share of visitors who decline is expected. A much larger drop, or data that stops, usually means a tag is blocked completely or does not receive the consent signal. Your project's Insights in the dashboard show how many visitors accept.

Still have questions?

Contact us: support@uniconsent.com