For site owners: how to stop loading trackers before consent
Published September 27, 2026
This describes common technical approaches, not legal advice about your specific site. What counts as compliant depends on facts specific to your business and your regulator, and the rules themselves vary by country and change over time — see what counts as valid cookie consent for the underlying legal picture.
If you've landed on this page from your own site's report, the finding is usually simple to state and less simple to fix: a scan saw an advertising, analytics or social-media company's script run, or its cookie set, on the very first load — before any visitor had a chance to answer a consent banner. Here's what actually closes that gap, in roughly the order it's worth doing it.
Step 1: know what's actually loading
Before changing anything, get a concrete list of what fires before consent and where each thing comes from — a tag manager container, a theme or plugin that quietly bundles its own analytics, a script pasted directly into the page's <head> years ago and forgotten. Checking with browser DevTools yourself, on a fresh private window, is the fastest way to get a real list; your own site's report here is a second, independent data point, scanned monthly from Germany with no clicks. If a report looks stale or you've since made changes, ask for a rescan rather than guessing whether a fix worked.
Step 2: understand why a banner alone doesn't do this
Installing a consent management platform (CMP) gets you a banner, a recorded choice, and — if you've wired it up — a signal other scripts can check. It does not, by itself, stop anything from running. Whether tags actually wait for that signal depends entirely on how each one is loaded. See how consent management platforms actually work for the full picture; the short version is that a CMP reports a choice, and something else has to be built to act on it.
Step 3: gate tags on consent, not just report it
The fix is called tag gating (or "consent-based blocking"): configuring each tag so it genuinely does not fire until the relevant consent category is granted, rather than firing regardless and merely recording that a choice was made.
Concretely, this usually means:
- In a tag manager (Google Tag Manager or similar): most modern tag managers support consent-based triggering natively — a tag can be configured to require, say, "Analytics storage: granted" before it fires at all, rather than firing on page load and hoping a downstream script respects the choice. Set this up per-tag; a tag manager doesn't gate anything automatically just because a CMP is also installed on the same page.
- For hard-coded scripts: any script pasted directly into your template — a chat widget, a legacy analytics snippet, a script tag added by a theme — needs to be loaded conditionally in your own code, only after the CMP reports consent, rather than sitting unconditionally in the page's
<head>or<body>. - For server-rendered or server-side-tagged setups: if data is sent from your own server rather than the visitor's browser (see first-party vs third-party cookies), the gating has to happen on your server too — checking the recorded consent choice before making that outbound call, not just on the client.
The one thing that should almost never be gated behind consent is the CMP's own script and any strictly necessary cookies your site depends on to function — those are the specific case the ePrivacy Directive's exemption is built for, discussed in what counts as valid consent.
Step 4: configure Google Consent Mode, if you use Google's tools
If you use Google Analytics, Google Ads or Google's ad network, Google's own Consent Mode needs its own configuration, separate from your CMP's banner:
- Choose Basic Consent Mode if you want Google's tags to load only after an answer, full stop — the simpler, more conservative option, at the cost of measurement data for anyone who never answers.
- Choose Advanced Consent Mode if you want Google's modeled-conversion features, which send cookieless pings before consent to statistically estimate what direct measurement would have shown. This still sends something before an answer, which is worth knowing before you pick it, given the emphasis EU regulators put on nothing non-essential loading before consent.
Most CMPs built for the EU market have a specific integration for setting Google's gtag('consent', 'update', …) signals automatically when a visitor responds — check your CMP's own documentation for how it wires into Consent Mode specifically, since the two are configured separately even when the same platform handles both.
Step 5: verify it actually worked
Configuration mistakes here are common and easy to miss from the inside, because once you've clicked "accept" once while testing, your own browser stops showing you the "before consent" state at all. Verify properly:
- Test in a fresh private/incognito window every time, the same way described in how to check what a site loads — load the page, and check DevTools' Network and Application tabs before touching the banner.
- Check that the specific tags you gated are genuinely absent from that list, not just reordered to appear after a delay.
- Re-check periodically. Tag managers get new tags added by other people on your team, plugins update and sometimes reintroduce their own bundled analytics, and a setup that was gated correctly at launch can quietly stop being gated after an unrelated change.
- Use an independent, automated check as a second opinion — that's exactly what a monthly scan like this site's is for: it catches drift between "we configured this once" and "this is still true today," without depending on someone remembering to test with the banner unanswered. If your site's report here still shows tracking before consent after you believe you've fixed it, request a rescan once the fix is live.
What this doesn't cover
None of the above is a compliance guarantee, and it's deliberately scoped to the technical piece — actually preventing tags from firing before consent — rather than the parts of consent law that depend on facts a technical fix can't settle: whether your banner's wording and design meet the equal-prominence standard for "reject", whether your privacy notice is accurate and complete, or how a specific regulator in a specific country currently reads the rule for a business like yours. Those are worth checking with someone qualified to advise on your specific situation, separately from getting the tag-loading behavior itself right.