Do Tags Fire Before Consent?

Privacy & Compliance / How-to

Do Your Tags Fire Before Consent?

Summary

A tag fires before consent when a tracking script loads and sends data on page open, before the visitor has answered the consent banner. In the EU and UK, that is collection without a lawful basis. A pixel talking to Meta or Google while the banner is still on screen means the banner has not done its job.

The problem is usually invisible from the front end. The banner appears, the visitor has not touched it, and underneath the page a marketing pixel or an analytics tag has already fired. You cannot see it by looking at the page. You have to look at what the page sent.

The sections below explain why firing before consent matters, then how to check whether your own tags do it. The last section covers how to catch the problem before a release puts it on your live site.

In the EU, consent is a precondition for those tags to fire lawfully. GDPR requires a lawful basis before a tag processes personal data, and for analytics and advertising that basis is consent given first. In California and most US states with privacy laws, advertising use of personal data is opt-out: people have the right to stop it, and a GPC signal counts as that request in the states that require it. A tag that ignores an opt-out or a GPC signal takes that choice away.

Timeline: analytics and marketing tags send data after the page opens, before the visitor accepts or rejects the banner.

The exposure is concrete. Class actions under laws like CIPA and VPPA are built on trackers that collected or transmitted data before anyone agreed. Regulators have acted against businesses whose banners were present and whose tags fired anyway. Enforcement Watch: pre-consent tracking cases.

You can do a first-pass check by hand, and you can verify it properly across your site with automated testing.

A DataTrue opt-out consent test: Facebook Pageview was blocked as expected, while two DoubleClick tags and Snapchat failed their block checks.

The manual check, one page at a time:

  1. Open the page in a fresh browser session with no stored consent, using your browser’s developer tools.
  2. Open the Network tab and filter for the requests your tags make, such as calls to Meta, Google Analytics, or Google Ads.
  3. Load the page and do not touch the consent banner.
  4. Watch what appears. Any analytics or advertising request that fires before you interact with the banner is a tag firing before consent.

This tells you about one page, in one browser, at one moment. It does not scale to a whole site, it misses tags that only fire on specific pages or journeys, and it depends on someone remembering to look.

How DataTrue verifies it across the site:

DataTrue loads your site the way a visitor would, in a real browser, without granting consent, and records every tag that fires and what it sent. A Coverage test crawls the whole site and reports every tag it finds, including tags added outside your tag manager that a consent banner never controls. A Simulation test walks a specific journey, such as a checkout or a registration, and checks what fired at each step before consent. The Tag Policy and Cookie Policy rules define which tags are allowed before consent, so a tag that should not fire is flagged as a failure rather than left for someone to notice. There’s nothing of ours to install on your pages.

The result is a timestamped record of exactly which tags fired before consent, on which pages, and what data they carried. That is the evidence a privacy team needs and the earliest warning a marketing team gets.

Catch it before it ships

Most pre-consent failures are introduced by a change, such as a new campaign pixel or a tag manager edit. DataTrue can run this same check against a draft GTM Preview or Adobe Tags container before it goes live, and automatically on each release through its CI API, so a tag that would fire before consent is caught in staging rather than in production.

See how consent verification works

Questions

What does “firing before consent” mean?

It means a tracking tag loads and sends data as soon as the page opens, before the visitor has accepted or declined on the consent banner. Because the data is collected before any agreement, EU and UK cookie rules treat it as collection without a lawful basis.

Is it illegal for a tag to fire before consent?

Under EU and UK rules, collecting personal data through a non-essential tag before consent is a violation. US state privacy laws work on an opt-out model, so there the violation is a tag that keeps sharing data after the visitor opts out. The tag itself is not illegal. When and how it fires is where the exposure comes from.

Can I check this myself?

Yes, for one page at a time. Open your browser’s developer tools, watch the Network tab, load the page without touching the consent banner, and look for analytics or advertising requests. Checking a whole site, and every journey, reliably is what automated testing is for.

Does a consent banner stop tags from firing before consent?

Not on its own. A banner records choices but does not physically block a tag. Tags hardcoded onto a page, added outside your tag manager, or loaded by another script can fire on page load regardless of the banner. That is why firing before consent has to be tested, not assumed.

30-day free trial

See what your tags do in every consent state

DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

A DataTrue opt-out consent test listing the tags that should be blocked, with pass or fail for each
A consent-state test in DataTrue