Setting up consent management is more important than ever, taking into account regulations like GDPR and CCPA. In this article, we will guide you through configuring consent management using iubenda and Google Tag Manager (GTM). The setup includes the following steps, which we will describe in detail further in the article:

Besides the configuration process, we will also highlight the benefits of server-side consent management, how it works, and implementation options in Google Consent Mode v2.
Server-side tracking offers numerous benefits that make consent management easier:
Despite the common misconception, using server-side tracking doesn't mean you shouldn't ask for consent to collect website visitors' data. Just like with client-side tracking, you need to add a cookie banner asking for consent to gather data.
The consent management within the server Google Tag Manager (GTM) works the following way:

Basic Consent Mode
With this implementation option, user consent determines how data is handled. If users accept cookies, tags are triggered, and data is collected completely. If users decline, no data is collected, and cookieless pings are not sent. This approach is simple to implement but significantly restricts data collection when consent is denied.
Advanced Consent Mode
Advanced Consent Mode is a more flexible solution. The site can send anonymous, cookieless pings to Google even if users do not allow cookies. The anonymous pings allow data modeling, so that the website owners have a more complete picture of users' behavior.
Here is a list of our articles about consent. We have covered this topic extensively in other blog posts:
To complete the setup below, you need to have configured a web GTM container.
In this step, you need to activate the compliance policies:

We will focus on the Privacy Controls & Cookie Solution activation since it's required to display the consent banner on your website.
1.1 Open your project on iubenda and click Activate below the Privacy Controls and Cookie Solution tile.

1.2 Check where you and your website visitors are based and click Confirm and Proceed.

1.3 Check the Compliance Settings section.
Here, you can specify which data protection laws you need to comply. For example, if you target EU/EEA countries, be sure to enable the toggle next to GDPR. If you target the USA, you need to activate the US State Laws toggle.
Once done, click Confirm and Proceed.

The next steps are focused on banner customization; iubenda provides a detailed guide on its cookie banner config.
iubenda has an Automatic Blocking feature that can automatically restrict certain services until user consent is obtained. By default, it uses Basic Consent Mode, where Google services are not entirely blocked upfront; their behavior is controlled through Consent Mode signals.
You can enable Advanced Consent Mode by selecting the option Do not block Google's services that adhere to Consent Mode.

2.1 Go to your web GTM container and add the iubenda Privacy Controls and Cookie Solution tag from the template gallery.

2.2 Create a new tag with iubenda Privacy Controls and Cookie Solution as the tag configuration.

2.3 Configure the tag.
All values are set to Denied by default. Keep these settings unchanged unless you have a specific tracking requirement.

The recommended approach is to use the Unified snippet via GTM template. If you opt for this option, any updates or changes made in Privacy Controls or Cookie Solution will automatically be applied to your website, without requiring you to re-embed the snippet or republish the GTM container.
To use the Unified snippet via GTM template tag configuration method, ensure that in the Privacy Controls and Cookie Solution settings, you have the option Enable remote configuration enabled.

To get the value for this field, go to your iubenda account → in the project you configure, scroll to the Unified embedding code section → copy the URL only.

If enabled, iubenda automatically sends the iubenda_gtm_consent_event event to GTM whenever a user updates their consent preferences.
This option is useful if you have Custom HTML tags or tags that don’t have built-in Consent Mode support.
The native Google tags in GTM already support Consent Mode. These Google tags include the following: Google Ads, Google Analytics/GA4, Floodlight, Conversion Linker.
Some custom tags may have a built-in option; you can check it in the Consent Settings section. If there's no such option, you need to check the Enable emitGtmEvents box.

Here's an example of a tag configuration:

2.4 Add a trigger for the iubenda tag.
Select Consent Initialization – All Pages as a trigger.

2.5 Check the tags you have in the web GTM container and update triggers for them if needed.
You need to set up consent for tags without built-in consent checks.
In the tag, under the Consent Settings section, select Require additional consent for tag to fire and choose a purpose; in our case, it is analytics_storage. Check the complete list of consent types in Google’s documentation.

2.6 Add a trigger group for such tags.
First, configure a trigger that checks whether the required consent has been granted based on the consent statuses. It should have the following properties:
iubenda_gtm_consent_event (that's an event that iubenda pushes to dataLayer; it contains the consent statuses)
Then you can create trigger groups, so to have a few triggers for the tag – one for a consent status check and another for firing the tag after the event happens.

The configuration of server-side tracking is recommended as it provides greater control over how consented data is processed and shared.
😎If you are already on the server-side, please skip this step.
To manage consent on the server side, you need to complete a few basic configurations:
➡️ Note
Before setting up your server-side Google Tag Manager container, it’s important to have web GTM container configured, because:
Please follow the official Google documentation.
1. Select your GTM account → Click Admin → Click + next to the Container name.

2. Add Container Name → Under Target platform, choose Server. Click Create.

3. Choose Manually provision tagging server. Copy your container config. We will need it in the following steps.

1. Go to stape.io and create an account or log in.

2. Click Create sGTM container on the main page.

3. Enter your container details.
Then click Create Container.

4. Choose a plan for your container. You can start with a Free plan. Click Continue with a Free plan.

5. You will see the status of your container, container config, and plan name. It takes around 5 minutes to deploy a server container.
Please reload the page to update the status. If the Google Tag Manager server-side setup was done correctly, you should see the status Running.

1. Log in to your Stape account and select your sGTM container from the dashboard.

2. Go to Power-ups and click Use next to the Custom Loader panel.

3. Toggle the Custom Loader switch to enable it.

4. If you want to encode tracking requests sent from the browser to your sGTM container, toggle the Enhanced ad blocker protection. By masking recognizable URL patterns and tracking signatures, it prevents ad blockers from identifying and intercepting those requests.
5. Click Save changes.

6. In the Code & Setup information section, choose the Platform - here you can either:
1. Configure the following settings:
gtag.js load through it.2. Click Generate. You’ll get configuration and app installation instructions on the right panel for your selected platform. Follow the app installation guide.

1. Configure the following settings:
gtag.js load through it.2. You can also configure Advanced settings:
3. Click Generate and add the provided code to your website.
Warning:

To verify the setup is working:
200 OK status code.
Note:
Setup Wizard is a free solution developed by Stape. It's available to all users who have an account on Stape. It will help you:
✅Automatically generate and add all the required entities for web and server GTM containers, so you can start tracking data right away;
✅Configure data sending from the web to the server container;
✅Guide you through the process of CMS app configuration (if that's required for your tracking needs).
To start using the Setup Wizard, go to your Stape account → within the sGTM section, click on the required container → locate the Setup Wizard icon next to Container settings.
Warning:
Make sure that within the Setup Wizard interface, you select that you don't use a cookie banner. If you have already configured the iubenda tag and added trigger groups to existing tags, specifying "Yes" in the question about the cookie banner will duplicate the logic.

Note:
This step assumes that you already have GA4 configured in your web GTM container. If not, refer to our guide on GA4 web and server-side configuration.
To ensure that the server GTM container receives the correct consent status, you only need to update the Google tag in your web GTM container. When configuring it, choose either Advanced or Basic consent mode.
Advanced Mode configuration
With Advanced Consent Mode enabled, Google tags can continue sending cookieless, consent-aware signals even when users decline analytics cookies. To enable this behavior, you only need to configure the consent settings for the Google tag in your web GTM container. No additional consent configuration or setup is required in the server-side GTM container.

Basic Mode configuration
To prevent Google Analytics from collecting data before the user explicitly grants consent, configure the Google tag in your web GTM container to require the appropriate consent. The server-side GA4 setup will then respect the consent signals passed from the web GTM container, so no additional consent configuration is required in the server container.

For a convenient debugging process, we will use the Stape GTM Helper Chrome extension. In the context of consent debugging, it will allow you to see the consent statuses in the server GTM container preview (by default, the option isn't available in GTM).
The Stape Chrome extension also offers several features that make debugging more convenient, including an entity filter, request URL formatter, website tracking scanner and evaluator, and others. For a complete overview of the Stape Chrome extension's features, refer to our guide.
To debug iubenda banner setup, follow the steps below:
1. Run Preview mode in both web and server GTM containers.

2. Interact with your cookie banner. For example, accept all the cookies or reject some of the cookies.
3. Return to the Preview window in your web GTM container.
You should see the Consent Update event fire before any other events configured in the container, such as page views or clicks. This indicates that the consent state was initialized before any tracking tags were triggered, ensuring that analytics and marketing tools respect the visitor’s consent preferences from the beginning of the session.

4. If you enabled the emitGtmEvents option within tag configuration, you should see the iubenda_gtm_consent_event being pushed after the Consent Update event.
Open the iubenda_gtm_consent_event and navigate to the Consent tab. Here, you should see that:

If you change your consent settings on the banner (decline some cookies), the Consent Update will launch again, and the corresponding columns in the Consent tab of the event will display Denied.

5. Verify that the consent status is correctly transferred to the server GTM container.
To check it, be sure to turn on the toggle Consent mode server side in the Stape GTM Helper.

Then, navigate to the server GTM preview window, open the latest event triggered → check whether the consent status for ad_storage and analytics_storage are the same as in your web GTM preview.

Server-side consent management platforms (such as iubenda) offer a privacy-conscious approach to collecting and processing user data. Businesses can achieve higher data privacy and security by shifting consent logic to the server.
Whether implementing Basic or Advanced Consent Mode, integrating tools like Google Tag Manager and iubenda provides a flexible solution that adapts to users’ consent preferences and allows staying compliant.
Comments