This guide uses Boxzilla, a free pop-up plugin and header and footer scripts, an easy way to add scripts to your theme, to serve a cookie consent experience that prevents any configured tags in Google Tag Manager from firing, if desired. It is also agnostic to the method that you serve your tags. It’s cool with Site Kit, or simply using the traditional <head> and <body> embed codes.
Step One: Configure Boxzilla
Install/activate Boxzilla, then create or edit a box called Tracking Consent. Paste the following HTML into the box’s HTML/Text editor. Just change “-consent-accent:#2563eb;” to match the client’s accent color.
Step Two: Configure Header and Footer Scripts
Install/activate header and footer scripts, then navigate to Settings > Header and Footer Scripts. Paste the below code into the <head>, changing only these two values:
var BOX_ID = 123var GA_IDS = ['G-XXXXXXXXXX'];
The first value is the post id of the box you’ve just created. The second is the GA4 analytics measurement id.
Configure cookie settings footer button
Add the following button in a Custom HTML block in the sitewide footer. It reopens the popup so a visitor can change their choice. An existing footer control with the same data-site-consent="open" attribute can remain.
Step Three: Configure the GTM Template
In GTM, open Templates → Tag Templates → New. Name the template Tracking Consent. Leave the Fields tab empty. Replace the boilerplate in the Code tab with the following code. This is GTM sandboxed template code, not a Custom HTML tag and not WordPress JavaScript.
In the Permissions tab, configure the following. Type site_services as a custom consent type if it is not listed. Save the template after adding the permissions.
| Permission | Scope |
|---|---|
| Accesses consent state | Write: site_services, analytics_storage, ad_storage, ad_user_data, ad_personalization |
| Accesses global variables | Execute: SiteServicesConsent.subscribe |
| Accesses global variables | Read and write: siteServicesConsentUpdate |
| Accesses global variables | Read and write: dataLayer |
Step Four: Configure the GTM Consent Tag
Next go to Tags → New, select the template you just saved, and create Tracking Consent:
- Type: the new template.
- Trigger: Consent Initialization – All Pages.
- Tag firing options: Once per page.
- Additional consent checks: No additional consent required.
Step Five: Configure the GTM Trigger
Create Tracking Consent (I just use this label for everything because it’s obvious in GTM what is a template vs a tag vs a trigger):
- Type: Custom Event.
- Event name:
site_services_ready. - Regex: off.
- Fires on: All Custom Events.
The template emits this once per page, after applying granted consent. It works for first-page acceptance and saved acceptance on later pages.
For a vendor that intentionally loads only on certain pages, create a version of this trigger with its existing URL conditions. Do not broaden that vendor’s page scope accidentally.
Apply these settings to the service tags
Here is a list of common tracking tags that might need to be gated by consent. Open each tag → Advanced Settings → Consent Settings → Require additional consent for tag to fire. Add the following types; all listed types must be granted:
| Tag | Additional consent required | Trigger | Firing option |
|---|---|---|---|
| GA4 base Google tag | site_services, analytics_storage | Tracking Consent | Once per page |
| Shared GA4 + Ads Google tag | site_services, analytics_storage, ad_storage, ad_user_data, ad_personalization | Tracking Consent | Once per page |
| Google Ads base Google tag, if separate | site_services, ad_storage, ad_user_data, ad_personalization | Tracking Consent | Once per page |
| Google Ads Conversion Linker | site_services, ad_storage | Tracking Consent | Once per page |
| CTM tracking-code loader | site_services | Tracking Consent | Once per page |
| Google Ads remarketing tag normally loaded per page | site_services, ad_storage, ad_user_data, ad_personalization | Tracking Consent | Once per page |
| GA4 event tags | site_services, analytics_storage | Existing real event trigger | Once per event |
| Google Ads conversion tags | site_services, 0ad_storage, ad_user_data | Existing real conversion trigger | Once per event |
| Other optional tags / CTM custom event tags | site_services, plus any vendor-specific requirements | Existing real event trigger, or consent-ready for a loader | Appropriate to that tag |
Google Ads conversion gating here is a conservative Basic-mode implementation choice, not a claim that every Ads tag universally requires exactly these states. Preserve relevant built-in checks. Add ad_personalization to any additional tag that actually performs remarketing/personalization.
Step Six: Verify in GTM Preview
- Tracking tags should not load before consent is accepted
- Tracking tags should load immediately after consent is accepted
- Tracking tags should load on page refresh after consent is accepted
- Page should auto refresh when tracking consent revoked.

Leave a Reply
You must be logged in to post a comment.