How to Honor Global Privacy Control in Google Tag Manager

Most marketing tags on a typical site are not hardcoded. They live in a Google Tag Manager container, which means that whether your site honors a visitor's Global Privacy Control signal is mostly a question about one container, and nothing in Tag Manager reads that signal for you.

What GPC means for a container

GPC reaches a page as a Sec-GPC: 1 request header and as navigator.globalPrivacyControl in the browser. Under the CCPA regulations, a business that sells or shares personal information has to treat that signal as a valid opt-out request for the browser that sent it. Tag Manager has no built-in GPC variable, so the container fires every tag its triggers allow until you teach it otherwise.

What website owners must do

Tag Manager does ship the right machinery: consent settings, plus a trigger type that runs before everything else. Wiring GPC into it takes three steps.

  1. Set a consent default in the Consent Initialization trigger. Google documents Consent Initialization - All Pages (the gtm.init_consent event) as firing before any other trigger in the container, including Initialization. Put one Custom HTML tag there, and nothing downstream can beat it.
  2. Deny advertising storage when the signal is on. The tag below does it.
  3. Require consent on every tag that sells or shares. Under each tag's Advanced Settings, Consent Settings, choose "Require additional consent for tag to fire" and add ad_storage. Google's own tags read consent state on their own; a Meta pixel or any other third-party template only respects it if you set this.
Custom HTML tag, trigger: Consent Initialization - All Pages·html
<script>
  window.dataLayer = window.dataLayer || [];
  function gtag() { dataLayer.push(arguments); }
  if (navigator.globalPrivacyControl === true) {
    gtag('consent', 'default', {
      ad_storage: 'denied',
      ad_user_data: 'denied',
      ad_personalization: 'denied'
    });
  }
</script>

Order matters with a consent platform. If your CMP later pushes a consent update that grants advertising storage, it can undo the default. The regulation settles who wins: a fresh opt-out signal overrides a stored business-specific setting (§ 7025(c)(3)). Make your CMP rules say the same, then check that they do.

Two things sit outside the container, and neither is fixed by any trigger. Pixels pasted straight into a theme never pass through Tag Manager. And the page has to tell the visitor the signal was processed, as § 7025(c)(6) requires.

Where Privisy fits

A configuration that looks right in the Tag Manager preview can still leak on a live page, because preview mode isn't a real visitor with a real signal. The free GPC checker loads your URL with GPC switched on and reports which third-party requests still go out. If it flags one, our guide to why GPC isn't working on a site covers the usual causes, and the full implementation guide covers the edge and CMP layers.

Test your container with the signal on

The free GPC check loads one URL with Global Privacy Control set and lists the third-party requests that still fire.

Run a free GPC check