I start a consent audit with the visitor’s choice and the requests the site sends. An admin toggle alone cannot show that they match.
Google’s Help page dates the Signals change to 15 June 2026. For linked Analytics and Ads properties, Consent Mode Ads settings replace Signals as the control over collecting Ads cookies and IDs. Signals keeps its role in associating Analytics data with signed-in information for behavioural reporting.
The page also describes future personalization and encrypted-IP changes. As read on 7 October, it still gives no exact rollout dates for those. I keep announced changes separate from observed behaviour.
Five checks in twenty minutes
This is an initial technical check, not a complete consent audit. Complex checkout or multi-domain flows take longer. I use a browser, Tag Assistant and read access to the linked accounts.
1. Defaults and chosen mode — four minutes
Start a fresh session. Check the defaults for ad_storage, analytics_storage, ad_user_data and ad_personalization.
In basic mode, Google tags remain blocked until consent. In advanced mode, defaults must be applied before measurement runs; denied consent can still produce cookieless pings. I check the payload and cookie behaviour, not just whether a request exists.
The Shopify context is in basic versus advanced Consent Mode.
2. Accept, reject and withdrawal — four minutes
Use separate fresh sessions for accept and reject. Then test withdrawing consent after acceptance.
In Tag Assistant, compare the consent states with the choice and inspect the tags that ran. Check all four types. I do not use gcs alone as a pass condition or infer a missing update from one unchanged parameter.
3. Redaction — three minutes
If the notice promises removal of ad click identifiers when advertising storage is denied, check ads_data_redaction as well.
Google documents additional redaction when it is true and ad_storage is denied. Denying storage alone can still leave full page URLs, including click parameters, in requests. I compare the actual fields with the promise.
4. Linked-property controls — five minutes
Confirm which Ads account receives the property’s data and review the consent configuration with its owner. Google documents consent details under Analytics Admin → Consent settings.
I record the current setup and the announced changes separately. The June change did not move every Analytics privacy control into a new Ads screen.
5. Existing notifications — four minutes
Read the stream’s consent notifications and any Tag Diagnostics findings. Compare them with the browser checks.
Google says consent notifications may take 48–72 hours to update after a change. I use the browser to validate a fix now and return to notifications later. A quiet dashboard is not immediate proof that the fix worked.
What the result means
Comparison table — scroll horizontally to see all columns
| Finding | Next action |
|---|---|
| Advanced-mode tag runs before defaults | Apply defaults before measurement |
| Basic-mode tag sends before consent | Fix the blocking rule |
| Banner choice and consent state differ | Fix the update wiring |
| Payload exceeds the redaction promise | Correct the implementation or review the notice |
| Linked account or notifications are unreviewed | Assign an owner and document the check |
I also test backend event senders separately if the store has them. A correct browser tag does not prove server-side consent handling.
I can turn the findings into a fix
My Consent Mode service covers the defaults, banner updates, server-side consent handling and measurement checks. If the cause is clear, I can quote a bounded fix. If we need to establish what the store sends first, I agree a separate diagnostic engagement.