Scanning

Prior blocking: recording a choice versus gating the tags

A banner that records a choice and a banner that gates your tags are different builds; here is what the second one actually requires.

Scanning 6 min read The UserGuard team

Key takeaways
  • A banner that records a choice and Google Consent Mode v2 both report state; prior blocking instead sits upstream of every non-essential script and decides whether it loads.
  • Tags can be gated in three layers — inert in-page script tags, tag-manager consent settings, or a server that never prints the embed — and most sites need more than one.
  • In a clean browser profile with devtools recording, anything that fires before you touch the banner is not gated, whatever the dashboard says.

A banner that records is not one that blocks

Most cookie banners do one thing competently. They render a box, capture a click, and write a value somewhere — a cookie, localStorage, a dataLayer key. That is record-keeping. Prior blocking is a different job: the stored choice has to sit upstream of every non-essential script, deciding whether it loads at all. A banner can do the first perfectly and the second not at all.

The gap matters because GDPR read alongside the ePrivacy Directive is a prior opt-in regime. Non-essential storage and access wait for the visitor. Reject must be as easy as accept. That equal-prominence expectation comes from regulator guidance and EDPB opinion rather than the GDPR text itself — withdrawal must be as easy as giving, and Article 7(1) requires you to be able to demonstrate the consent you claim. That is a description of the rules, not legal advice about your site.

The UK runs a parallel track: UK GDPR plus PECR, enforced by the ICO, diverging through the Data (Use and Access) Act 2025, which raises PECR fines to UK GDPR levels. The practical consequence is identical on both sides of the Channel. If the tags fired before the click, the banner recorded a decision the page had already made on the visitor's behalf.

Three places a tag can be gated

Gating happens in one of three layers, and most sites need more than one. The first is the page itself. A script tag is rendered inert — the type attribute set to something the browser will not execute, the real source parked in a data attribute, and rewritten into a live script only when the matching consent category turns true. Nothing downloads, nothing executes, no request leaves the browser.

The second is the tag manager. Container-level consent settings hold tags until the required consent types are present, or a custom event published after the choice becomes the trigger for everything non-essential. This is tidy and maintainable. It also only governs tags inside the container, and anything a developer or an agency wired straight into the theme sits outside its jurisdiction.

The third is the server. If the template never prints the embed for a visitor in a region that requires prior consent, there is nothing to block on the client. It is the most reliable layer and the least flexible, and it requires the region decision to be made before the HTML is sent.

  • In-page: inert script tags, rewritten only after the category turns true
  • Tag manager: container consent settings, or a custom event fired post-choice
  • Server: the embed is never printed for a visitor who has not consented

Google Consent Mode v2 has been required since March 2024 for Google advertising and measurement features covering EEA and UK users. It carries four signals: ad_storage, analytics_storage, ad_user_data and ad_personalization. You set them to denied by default, update them when the visitor chooses, and Google's tags adjust what they store and what they send.

Signaling is not blocking. In advanced consent mode — the common default — the Google tag still loads and can send cookieless pings before any choice is made. Basic mode holds the tag until consent arrives, which is closer to a gate, but that is a decision in your own tagging setup rather than something the four signals do on their own. Whether either shape satisfies a given regulator is an argument for your counsel, not a vendor's blog.

Consent Mode belongs in the stack. It does not replace the gate. UserGuard is built to emit all four signals with denied defaults and to update them as soon as a choice is recorded. It is not a Google-certified CMP, and it is not IAB TCF validated — TCF support is on the roadmap, not in the product. If certification matters to your ad stack, confirm it for any tool you evaluate rather than assuming it.

Here is the failure mode that survives most banner rollouts. Somebody pasted a conversion pixel into the header template three years ago. It is not in the tag manager. It does not call your consent API. It is a hard-coded script tag in the theme, and it fires on line one of the page, before the banner has finished measuring the viewport.

No consent tool blocks what it never intercepts, and no banner wraps arbitrary markup that a theme prints ahead of it. The same goes for embedded video players, chat widgets, map embeds, hosted fonts, social iframes and a good share of the plugins on any mature CMS. Each sets storage on its own schedule. The banner is downstream of all of it.

It is also why an over-generous scan is worse than no scan: real findings drown in the noise. UserGuard's evidence gate is built for that problem — a record becomes a cookie only when there is a Set-Cookie header, an HTTP-only record, or a document.cookie value. Everything else is kept and labeled as context, which is what makes a hard-coded pixel easy to spot.

Verify with the network tab, not the dashboard

Open a clean browser profile. Load the site with devtools recording and do not touch the banner. Then read what happened: calls to analytics and ad domains in the network panel, entries under Cookies and Local Storage in the application panel. Anything present before you clicked is not gated, whatever the dashboard says. Repeat the run after accept, after reject, and after withdrawal — those three paths break independently.

Then check the edges. Send Global Privacy Control and confirm it is honored without a click: twelve of the nineteen or more comprehensive US state laws in force as of 2026 require honoring universal opt-out signals, and ignoring GPC cost Sephora $1.2 million in 2022. Test from an EEA address and a US one; correct behavior differs. Those US regimes are opt-out — notice at collection, plus a Do Not Sell or Share My Personal Information mechanism. That describes the laws, not your obligations under them.

Then keep the receipts. UserGuard is designed to tie each consent event to the site, banner version, region and timestamp, and to export the set as CSV — the kind of record you want on hand when someone asks you to demonstrate a consent. GPC handling and geo-targeting are included on every plan, at $10 per site per month with automatic volume discounts, because gating that depends on your billing tier is not gating.

Go deeper: how the evidence gate works

Start today

Evidence from day one. Refundable for thirty.

Create an account, drop one script on a site, and the first scan verifies your cookies in minutes. Honest consent UX, consent analytics and accessibility controls, from $10 a site. Thirty days to get your money back if it is not right.

Get started → 30-day money-back guarantee · cancel anytime