How to configure consent management using GTM and iubenda

Uliana Lesiv

Uliana Lesiv

Author
Updated
Sep 17, 2026

Setting up consent management is more important than ever, taking into account regulations like GDPR and CCPA. In this article, we will guide you through configuring consent management using iubenda and Google Tag Manager (GTM). The setup includes the following steps, which we will describe in detail further in the article:

  1. Activating Privacy Controls and Cookie Solution in iubenda.
  2. Integrating iubenda with GTM and setting up consent via GTM.
  3. Setting up the server GTM container, custom domain, and Custom Loader.
  4. Configuring server-side GA4 and consent settings for GA4.
Consent management with iubenda and GTM

Besides the configuration process, we will also highlight the benefits of server-side consent management, how it works, and implementation options in Google Consent Mode v2. 

Server-side tracking offers numerous benefits that make consent management easier:

  • Improved data privacy compliance. Managing user consent on the server level makes meeting data regulations (such as GDPR, CCPA, and ePrivacy) easier, as you have high control over the data collected. Also, server-side connection minimizes unauthorized third-party access, improving data protection and user trust.
  • High data security. Data is handled securely on servers, and there is a lower risk of tampering or interception than client-side methods.
  • More reliable data collection. The data collected is not affected by browser restrictions and ad blockers. Besides, server-side tracking provides anonymized data handling, which means that in consent-restricted scenarios, the data is collected through anonymized methods, supporting machine learning and decision-making based on aggregated insights.
  • Cross-platform consent management. To maintain consistent data handling, apply the same consent preferences across web and mobile platforms. With server-side consent management, creating centralized consent configurations by synchronizing settings across various tools and systems is easier.

Despite the common misconception, using server-side tracking doesn't mean you shouldn't ask for consent to collect website visitors' data. Just like with client-side tracking, you need to add a cookie banner asking for consent to gather data.

The consent management within the server Google Tag Manager (GTM) works the following way:

  1. The consent banner captures the user's consent choices and relays them to a tag (e.g., Google Tag) that transmits consent status from the web to the server GTM.
  2. Google tag transmits a parameter reflecting the user’s consent status to the server container.
  3. Within the server GTM, tags behave depending on the value of that consent parameter.
How consent management works

Basic Consent Mode

With this implementation option, user consent determines how data is handled. If users accept cookies, tags are triggered, and data is collected completely. If users decline, no data is collected, and cookieless pings are not sent. This approach is simple to implement but significantly restricts data collection when consent is denied.

Advanced Consent Mode

Advanced Consent Mode is a more flexible solution. The site can send anonymous, cookieless pings to Google even if users do not allow cookies. The anonymous pings allow data modeling, so that the website owners have a more complete picture of users' behavior.

Here is a list of our articles about consent. We have covered this topic extensively in other blog posts:

Before starting

To complete the setup below, you need to have configured a web GTM container.

Step 1. Activate compliance policies in iubenda

In this step, you need to activate the compliance policies:

  • Privacy Controls & Cookie Solution – that's a primary and mandatory option to activate. It activates the Consent Management Platform itself, allowing it to display the cookie banner to visitors, block tracking scripts before consent, and log user privacy preferences.
  • Privacy & Cookie Policy – the legal document that includes what personal data and cookies your site collects, why it processes them, which third-party services are used, etc.
  • Terms & Conditions (available on Advanced plan) – a binding legal contract between you and your website visitors that sets site usage rules, protects your intellectual property, outlines payment/refund policies, and limits legal liability.
iubenda compliance policies activation

We will focus on the Privacy Controls & Cookie Solution activation since it's required to display the consent banner on your website.

1.1 Open your project on iubenda and click Activate below the Privacy Controls and Cookie Solution tile. 

Activate now button

1.2 Check where you and your website visitors are based and click Confirm and Proceed.

Click Confirm and Proceed

1.3 Check the Compliance Settings section.

Here, you can specify which data protection laws you need to comply. For example, if you target EU/EEA countries, be sure to enable the toggle next to GDPR. If you target the USA, you need to activate the US State Laws toggle. 

Once done, click Confirm and Proceed.

Compliance Settings section

The next steps are focused on banner customization; iubenda provides a detailed guide on its cookie banner config.

iubenda has an Automatic Blocking feature that can automatically restrict certain services until user consent is obtained. By default, it uses Basic Consent Mode, where Google services are not entirely blocked upfront; their behavior is controlled through Consent Mode signals.

You can enable Advanced Consent Mode by selecting the option Do not block Google's services that adhere to Consent Mode.

Automatic Blocking feature in iubenda

2.1 Go to your web GTM container and add the iubenda Privacy Controls and Cookie Solution tag from the template gallery.

iubenda Privacy Controls and Cookie Solution tag import

2.2 Create a new tag with iubenda Privacy Controls and Cookie Solution as the tag configuration.

iubenda Privacy Controls and Cookie Solution tag type selection

2.3 Configure the tag.

  • Purpose default consents section.

All values are set to Denied by default. Keep these settings unchanged unless you have a specific tracking requirement.

Default consent values
  • Select how to embed CS.

The recommended approach is to use the Unified snippet via GTM template. If you opt for this option, any updates or changes made in Privacy Controls or Cookie Solution will automatically be applied to your website, without requiring you to re-embed the snippet or republish the GTM container.

To use the Unified snippet via GTM template tag configuration method, ensure that in the Privacy Controls and Cookie Solution settings, you have the option Enable remote configuration enabled.

How to switch on the “Enable remote configuration”
  • Add Embedding URL.

To get the value for this field, go to your iubenda account → in the project you configure, scroll to the Unified embedding code section → copy the URL only.

Unified embedding code
  • Check the Enable emitGtmEvents box (optional).

If enabled, iubenda automatically sends the iubenda_gtm_consent_event event to GTM whenever a user updates their consent preferences.

This option is useful if you have Custom HTML tags or tags that don’t have built-in Consent Mode support.

The native Google tags in GTM already support Consent Mode. These Google tags include the following: Google Ads, Google Analytics/GA4, Floodlight, Conversion Linker. 

Some custom tags may have a built-in option; you can check it in the Consent Settings section. If there's no such option, you need to check the Enable emitGtmEvents box.

Consent Settings section

Here's an example of a tag configuration:

Tag configuration example

2.4 Add a trigger for the iubenda tag.

Select Consent Initialization – All Pages as a trigger.

"Consent Initialization – All Pages" as a trigger

2.5 Check the tags you have in the web GTM container and update triggers for them if needed.

You need to set up consent for tags without built-in consent checks.

In the tag, under the Consent Settings section, select Require additional consent for tag to fire and choose a purpose; in our case, it is analytics_storage. Check the complete list of consent types in Google’s documentation.

"Require additional consent for tag to fire" selected

2.6 Add a trigger group for such tags.

First, configure a trigger that checks whether the required consent has been granted based on the consent statuses. It should have the following properties:

  • Trigger type – Custom Event
  • Event name – iubenda_gtm_consent_event (that's an event that iubenda pushes to dataLayer; it contains the consent statuses)
  • Trigger fires on all custom events
Trigger configuration

Then you can create trigger groups, so to have a few triggers for the tag – one for a consent status check and another for firing the tag after the event happens.

!

Note: the second triggered event in the trigger group will vary in your case. We demonstrate All pages view as an example, but you would need to select product_view, add_to_cart, purchase, or any other event that corresponds to your tracking setup.

iubenda trigger configuration in GTM

Step 3. Set up the server GTM container and Custom Loader

The configuration of server-side tracking is recommended as it provides greater control over how consented data is processed and shared. 

😎If you are already on the server-side, please skip this step.

To manage consent on the server side, you need to complete a few basic configurations:

  • Set up your server GTM container and host it on Stape.
  • Enable the Custom Loader to make data collection less susceptible to ad blockers.
  • Configure your web container to send data to the server GTM container.

Note:

This step assumes that you already have GA4 configured in your web GTM container. If not, refer to our guide on GA4 web and server-side configuration.

To ensure that the server GTM container receives the correct consent status, you only need to update the Google tag in your web GTM container. When configuring it, choose either Advanced or Basic consent mode.

Advanced Mode configuration

With Advanced Consent Mode enabled, Google tags can continue sending cookieless, consent-aware signals even when users decline analytics cookies. To enable this behavior, you only need to configure the consent settings for the Google tag in your web GTM container. No additional consent configuration or setup is required in the server-side GTM container.

Advanced Mode configuration - no additional consent

Basic Mode configuration

To prevent Google Analytics from collecting data before the user explicitly grants consent, configure the Google tag in your web GTM container to require the appropriate consent. The server-side GA4 setup will then respect the consent signals passed from the web GTM container, so no additional consent configuration is required in the server container.

Basic Mode configuration - with additional consent

Debugging the iubenda banner configuration

For a convenient debugging process, we will use the Stape GTM Helper Chrome extension. In the context of consent debugging, it will allow you to see the consent statuses in the server GTM container preview (by default, the option isn't available in GTM).

The Stape Chrome extension also offers several features that make debugging more convenient, including an entity filter, request URL formatter, website tracking scanner and evaluator, and others. For a complete overview of the Stape Chrome extension's features, refer to our guide.

To debug iubenda banner setup, follow the steps below:

1. Run Preview mode in both web and server GTM containers.

Preview button

2. Interact with your cookie banner. For example, accept all the cookies or reject some of the cookies.

3. Return to the Preview window in your web GTM container.

You should see the Consent Update event fire before any other events configured in the container, such as page views or clicks. This indicates that the consent state was initialized before any tracking tags were triggered, ensuring that analytics and marketing tools respect the visitor’s consent preferences from the beginning of the session.

Consent Update event

4. If you enabled the emitGtmEvents option within tag configuration, you should see the iubenda_gtm_consent_event being pushed after the Consent Update event. 

Open the iubenda_gtm_consent_event and navigate to the Consent tab. Here, you should see that:

  • Default statuses (the first column) are set to Denied (as you specified in the iubenda tag configuration). 
  • On-page Update and Current State (the second and third columns) correspond to the status you've specified on the page via the consent banner. 
iubenda_gtm_consent_event Consent tab

If you change your consent settings on the banner (decline some cookies), the Consent Update will launch again, and the corresponding columns in the Consent tab of the event will display Denied.

Updated consent settings. -declined cookies

5. Verify that the consent status is correctly transferred to the server GTM container.

To check it, be sure to turn on the toggle Consent mode server side in the Stape GTM Helper.

Consent mode server side toggle

Then, navigate to the server GTM preview window, open the latest event triggered → check whether the consent status for ad_storage and analytics_storage are the same as in your web GTM preview.

consent status for ad_storage and analytics_storage in sGTM

Conclusion

Server-side consent management platforms (such as iubenda) offer a privacy-conscious approach to collecting and processing user data. Businesses can achieve higher data privacy and security by shifting consent logic to the server.

Whether implementing Basic or Advanced Consent Mode, integrating tools like Google Tag Manager and iubenda provides a flexible solution that adapts to users’ consent preferences and allows staying compliant.

Want to start using server-side tags?sign up now!

Uliana Lesiv

Uliana Lesiv

Author

Uliana is a Content Manager at Stape, specializing in analytics and integration setups. She breaks down complex tracking concepts into clear insights, helping businesses optimize data collection.

Comments

Try Stape for all things server-side