Originally published March 2024. Fully revised July 2026.
This post was written before Google’s March 2024 consent deadline, when the question was whether businesses would be ready in time. Two years on, the deadline is long gone, the rules have hardened, and the UK has rewritten its own cookie law in a way that changes the sums considerably. Here is where things actually stand.
The short version: Google’s consent requirements are still in force and still bite. Third-party cookies did not disappear after all. And since 5 February 2026, getting UK consent wrong can cost you up to £17.5 million rather than £500,000.
Did Google’s March 2024 consent deadline actually happen?
Yes, and it stuck. Advertisers running Google’s advertising products in the EEA and the UK were required to implement Consent Mode v2 from March 2024. Publishers using AdSense, Ad Manager or AdMob faced a separate and earlier requirement, in force from 16 January 2024, to use a Google-certified consent management platform integrated with the IAB’s Transparency and Consent Framework.
Neither was a one-off exercise. Both requirements are permanent conditions of using the platforms. Google’s position on publisher traffic is unambiguous: traffic that does not come through a certified CMP is eligible only for non-personalised or limited ads. Switzerland was added to the same regime from 31 July 2024.
Worth knowing, since it is widely misunderstood: Google’s certification checks a CMP’s TCF integration, not whether it makes you compliant with the law. Google says so explicitly. A certified CMP satisfies Google. It does not satisfy the ICO.
What is Consent Mode v2, in practice?
Consent Mode v2 added two signals to the existing pair. ad_user_data tells Google whether the user consented to their personal data being used for advertising. ad_personalization covers consent for remarketing. Both sit alongside the original analytics and advertising storage parameters.
The distinction that matters commercially is between basic and advanced implementations. In basic mode, Google’s tags do not fire at all until the user consents, so a refusal means no data. In advanced mode the tags load, and where consent is refused they send cookieless pings that Google uses to model conversions.
Advanced mode recovers a meaningful share of the conversions you would otherwise lose, which is why most advertisers with real budget at stake use it. It also collects something from users who declined, which is precisely why some legal teams refuse to sign it off. That is a decision for your DPO rather than your media buyer, and it is worth having the conversation before your agency picks one for you.
Weren’t third-party cookies supposed to be gone by now?
They were, and they are not. This is the single biggest thing to have changed since the original post.
Google spent years signalling that Chrome would phase out third-party cookies. In summer 2024 it retreated to a plan involving a user choice prompt instead. Then on 29 April 2025, Anthony Chavez, VP of Privacy Sandbox, confirmed Google would not roll out that prompt either. Third-party cookies stay in Chrome, managed through the browser’s existing privacy settings. Google cited divergent views from publishers, regulators and the advertising industry.
A number of businesses read the original deprecation plan as a reason to defer their consent work, on the logic that the tracking was going away regardless. That turned out to be exactly wrong. The cookies remain, the consent obligations remain, and the enforcement risk has grown.
What changed in UK law in 2026?
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and its key provisions came into force on 5 February 2026. Two changes matter here.
First, the penalties. Fines under the Privacy and Electronic Communications Regulations have risen from a £500,000 ceiling to £17.5 million or 4% of global annual turnover, whichever is higher, bringing cookie and direct marketing breaches into line with UK GDPR. Cookie compliance stopped being a rounding error on the balance sheet.
Second, a narrow relaxation. Consent is no longer required for three categories: cookies that solely collect statistical information to improve a service, cookies that adapt the appearance of a site, and cookies used to establish geolocation for emergency assistance. Security and fraud prevention cookies are treated as strictly necessary. For the statistical and appearance categories you must still give users a clear and simple way to opt out.
Read that list carefully, because of what is missing from it. Nothing in the relaxation touches advertising, remarketing or personalisation. Every cookie you actually care about for Google Ads still requires consent, freely given and specific. If anything, the change makes the boundary sharper: a smaller set of things you may do quietly, and a much larger fine if you cross the line.
There is also a divergence problem. The EU has not relaxed its rules. Any business serving both markets now has two regimes to satisfy, and the safe approach is to build to the stricter one.
Do I still need a consent management platform?
For publishers on Google’s ad products in the EEA, UK or Switzerland, yes, and it has to be one from Google’s certified list with TCF integration. For advertisers the requirement is less prescriptive, but implementing Consent Mode v2 properly across a real website without a CMP is more trouble than it is worth.
Cookiebot, Usercentrics and OneTrust remain among the established options, and there are plenty of others. The things to compare are whether the platform is on Google’s certified list if you need that, how cleanly it integrates with Google Tag Manager, whether it supports both basic and advanced consent mode, and how it handles the new UK exemptions, since a tool built purely to EU rules will ask for consent you no longer need.
What should you do now?
If you implemented all this in early 2024 and have not looked at it since, that is the common position and it needs auditing rather than rebuilding.
- Check that consent signals are genuinely reaching Google, using the Tag Assistant consent view rather than assuming the banner works
- Confirm which consent mode you are running and whether that was a deliberate choice
- Review your Google Ads and Analytics accounts for consent-related warnings, which is where problems usually surface first
- Re-examine your cookie categories against the February 2026 exemptions, and stop asking for consent you no longer need
- Check your banner still offers a reject option as prominently as accept, which the ICO has been consistent about
- If you are a publisher, verify your CMP is still on Google’s certified list
The point of getting this right is not only avoiding a fine. Advertisers with clean consent signals and advanced mode running get better conversion modelling, which means better bidding, which means lower acquisition costs. The businesses treating consent as a compliance chore are handing a measurable advantage to the ones treating it as data infrastructure.
Where to check for changes
Privacy rules move, as this post rather demonstrates. Google’s own documentation for Consent Mode and its EU user consent policy are the primary sources for the platform requirements, and the ICO’s guidance on storage and access technologies is the one that matters for UK law. Both are worth a scheduled review rather than an annual panic.
If you would rather someone else kept an eye on it, get in touch and we will audit your current setup and tell you plainly what needs fixing.
I stumbled upon your article while researching, and I must say, it’s concise and to the point.
Really helps to cut through the noise
Valuable take