Contao Consent Tool: Consent Mode v2, GTM and Google Ads
A Contao consent tool installs in an hour. Whether it feeds your Google Ads account or quietly starves it comes down to what happens after.
4
consent signals to wire
Originally written in German — read it on visnakovs.de.
A Contao consent tool is quick to install: pull the bundle in through the Contao Manager, configure the banner, done. What’s missing from almost every tutorial is the part after that: how consent actually becomes a Consent Mode v2 signal inside Google Tag Manager, and whether your Google Ads conversion really only fires with consent. That’s what this is about, including my clear preference: on Contao I use Usercentrics, even though Klaro and the Contao Marketing Suite sit closer to the CMS itself.
1. What a Contao consent tool has to do for clean tracking
Contao doesn’t ship with a consent tool out of the box. That’s not a gap, it’s architecture: the CMS delivers the page, and the consent tool is an extension or an external script you wire in through the page layout. Before comparing candidates, it’s worth looking at what a tool like this actually does technically.
How a consent tool works
Three jobs, and all three run in the visitor’s browser, not on the server:
- Blocking: scripts and embeds that set cookies or transmit data only load after consent. Technically this happens through script tags marked
type="text/plain"plus a marker the tool reads, or through placeholders for embeds like YouTube and Google Maps. - Storing the decision: the choice lands in a cookie or local storage, with a timestamp and a version number for your settings. If your services change, the visitor gets asked again.
- Passing signals along: the tool tells other systems what the visitor allowed. For Google that means Consent Mode v2 and its four signals:
ad_storage,analytics_storage,ad_user_dataandad_personalization. For everything else, it’s an event in thedataLayerthat Tag Manager reacts to.
That third point decides whether you have a cookie banner or a consent setup. A banner that only blocks but never sends signals lets your Google Ads conversions quietly disappear, with no error message. I’ve written up what Consent Mode v2 actually is, and why remarketing lists run dry without it, in detail here: Consent Mode v2 setup.
Two Contao quirks you need to know
Contao caches pages through its built-in HTTP cache. That means a consent tool must never decide anything server-side per visitor, or the next visitor gets served the cached page with the previous visitor’s consent state. Anything to do with consent belongs in JavaScript. The second quirk: Contao page layouts have their own fields for extra head and script tags. That’s exactly where the CMP loader and the GTM snippet belong, not in some template override that gets lost on the next update.
Klaro, Contao Marketing Suite or Usercentrics: choosing by your setup
The three options realistically on the table for Contao projects differ less in the banner itself than in what happens behind it.
Klaro is an open-source consent manager available as a Contao bundle. You configure services in the back end, and the bundle renders the banner and blocks the marked scripts. Solid if you don’t want licence costs and have someone to maintain the configuration carefully. The catch for advertisers: Klaro itself doesn’t speak Consent Mode v2, that’s on the integration. Either the bundle ships a bridge, or you set the four Google signals yourself through the service configuration’s callbacks and keep them updated with every change. That’s doable, but it’s manual work, and manual work gets forgotten during updates.
Contao Marketing Suite is the option that sits deepest inside the CMS. Cookie categories, blocked content elements and the banner are all part of the Contao back end, which editors like. For a project that’s mainly content-driven with one analytics tool running alongside, that’s convenient. Once serious ad budget is attached, check before buying how the Suite handles Consent Mode v2 and Tag Manager, and whether the result actually arrives as a signal in the browser. More on that test below, it’s the same for every tool.
Usercentrics is my choice, on Contao just like everywhere else. Not because the banner looks nicer, but for the three things that matter for campaigns: Consent Mode v2 is built in and maintained by the vendor, the official GTM template from the template gallery sets default and update cleanly, and geo rules, multiple languages and multiple domains are standard rather than custom-built. That Usercentrics needs no Contao bundle isn’t a downside: the loader is one line in the page layout, which is exactly why it survives every Contao update.
Quick summary:
- No ad budget, in-house developers, don’t want a licence: Klaro, with a hand-built Consent Mode bridge.
- Content-heavy site, light tracking, editors handle everything themselves: Contao Marketing Suite, after the test below.
- Google Ads with budget, conversion tracking, remarketing: Usercentrics.
2. Wiring Consent Mode v2 and GTM together in Contao
The order is always the same, whichever CMP you pick. I describe the steps for Usercentrics; with Klaro or the Marketing Suite they are the same, only the field names differ.
Step 1: the CMP into the page layout
In the Contao back end, open the page layout under Themes and paste the Usercentrics loader into the field for extra head tags. It has to be the first script on the page that has anything to do with tracking. If you use multiple layouts (homepage, subpages, landing pages), the loader belongs in every one of them. A forgotten layout is the classic reason a single landing page later ships without a banner. Afterward, clear the Contao cache through system maintenance, or you’ll be testing against the old page.
Step 2: loading GTM, properly
Google Tag Manager also goes into the page layout, and there are two routes:
- Strict: the GTM snippet itself is a blocked service inside the CMP and only loads after consent. Inside the container, only tags that already had consent ever run. This is my default for clients, because in Germany it’s well defensible that loading
gtm.jsitself already counts as accessing the user’s device under §25 TDDDG, the German law governing consent for information stored on or read from a device. - Advanced Consent Mode: GTM always loads, and Google tags run cookieless when declined, sending anonymous pings from which Google models conversions. More data, more to discuss with your data protection officer.
Which variant is defensible for you is something to settle with your lawyer or data protection officer, not a blog article. The technical chain behind it is the same either way. If your Google Ads tracking doesn’t run through GTM yet, start here: set up Google Ads through Google Tag Manager.
Step 3: the consent template inside the container
Inside the GTM container, add the official Usercentrics template from the template gallery, enter your settings ID, and fire it on the Consent Initialization trigger. This trigger runs before every other tag, that’s its entire purpose. The template sets all four signals to denied before the visitor decides, then sends the update to granted or denied after the click. Afterward, turn on the consent overview in the container settings and go through every tag: Google tags check the signals themselves, third-party tags need the right category assigned under “additional consent”.
For tags that don’t understand consent signals, use the event the CMP writes to the dataLayer after every decision (with Usercentrics, that’s consent_status). A trigger on that event plus a condition for the relevant service, and the tag only fires once that service is allowed.
Step 4: wiring up the Google Ads conversion
The Google Ads conversion tag gets no special treatment. It hangs off the Google tag that already knows the consent status, and fires on your conversion event, typically a successful Contao form submission. In Contao, you either redirect to a thank-you page after submission or push an event to the dataLayer. The thank-you page is the more robust option, because it works regardless of how the form module happens to be embedded right now. For importing lead quality back into the account later, it’s worth a look at offline conversion import for lead gen.
If you’d rather not click a container together by hand, my GTM configurator (in German) lets you assemble the consent template, the Google tag and the conversion tag as a ready-made container and import it directly: GTM configurator (in German).
3. Testing, revocation, accessibility: the checklist
The banner is in, the container is published. Now comes the part most guides wave off with “test your settings”. I do it differently, because a consent setup without a test is just a guess.
The test flow for Contao
Always test as a normal visitor in an incognito window, never in the back-end preview mode, and never while logged in. Contao serves the page differently to logged-in back-end users, and caching behaves differently too.
- Page load without clicking: in Tag Assistant’s consent tab, all four signals should read
denied. In network requests, the strict setup should show zero Google requests. In the advanced setup, every Google request should carry agcsparameter with a value that means decline. - Decline everything: no marketing cookie in the browser, no conversion request when submitting the form. If a conversion fires anyway, your blocking is broken, regardless of what the banner displays.
- Accept everything: the signals flip to
granted, the conversion tag fires on the thank-you page, and the request to Google carries the consent status. That’s the truth, not what the banner claims. - Check the aftermath: after two days, check in Google Ads whether the conversion action is receiving data and whether remarketing lists are growing again. A tag test that’s green while the account stays empty is a common pattern.
- Repeat after every Contao update: layouts, templates and bundles change, and the chain breaks silently.
If you want a quick read on whether the basics are in place, there’s my free Tracking Check (in German). What a recurring check across all your conversion actions looks like is covered in the conversion tracking health check.
Revocation: the case nobody tests
A visitor who withdraws consent is, for your tracking, a second visitor who declined. Your setup has to reflect that, measurably:
- There’s a link to reopen the settings, on Contao best placed in the footer module or the privacy policy, so it’s reachable from every page.
- After revocation, the CMP sends an update with
denied. In Tag Assistant you see the switch immediately, without reloading. - From that moment, no Google Ads conversion tag may fire again. Test it: revoke, submit the form, check the network tab.
- Cookies already set get removed by the tool or expire. Which cookies the CMP actually deletes and which it doesn’t is documented by the vendor, check it once.
Why this matters for advertisers: a revocation that doesn’t technically register is consent you no longer have, with data you’re still collecting anyway. I’ve written up how that’s classified legally here: GDPR and conversion tracking.
Accessibility belongs on the same checklist
The Contao community argues over the label on the little icon used to reopen cookie settings later. That’s just the tip of it. Since June 2025, Germany’s Barrierefreiheitsstärkungsgesetz (accessibility law) applies to many consumer-facing websites, and the consent banner is the first element every visitor has to operate. In practice that means:
- The banner is reachable by keyboard, focus lands inside it on open and stays there until a decision is made.
- Every button has visible text, not just an icon. The icon to reopen settings gets an
aria-labeldescribing what it does. - Contrast holds up even on the decline button, which tends to get styled more subtly.
- A screen reader reads the banner in the page’s language, so the language attribute needs to be correct.
Usercentrics and Klaro provide a usable foundation here, but you still have to maintain the wording yourself, in every language your Contao site serves. And an accessible banner is also a better banner: a visitor who can find the decline button is measured more honestly than one who just leaves the page, annoyed.
The bottom line
A Contao consent tool installs in an hour. Whether it feeds your Google Ads account with data or quietly starves it is decided afterward:
- The tool has to speak Consent Mode v2, not just block. With Klaro you build the bridge yourself, with the Marketing Suite you verify it, with Usercentrics it’s already there. That’s why I default to Usercentrics whenever ad budget is involved.
- The CMP loader and GTM belong in the Contao page layout, in every layout, and you clear the cache after every change.
- Consent Initialization sets default and update, third-party tags hang off the CMP’s consent event, and the conversion fires on the thank-you page.
- Testing happens in an incognito window, in both directions, after revocation, and after every update. The network tab is the truth, not the banner.
- Accessibility is part of the same checklist, not a topic for later.
Running Contao with Google Ads live, and not sure your conversions are really only measured with consent? I’ll go through the chain from banner to account with you and tell you honestly what’s missing. Book a free intro call (in German).