Install GoTrust with Google Tag Manager
Install and configure the GoTrust consent banner through Google Tag Manager, with Google Consent Mode v2 configured for your site.
What the template does
Every time a page loads, the template:
- Sets the Consent Mode default before any other tag runs. Visitors in the EEA, UK and Switzerland always start with every consent type denied (except
security_storage). Everywhere else starts with the defaults you choose in the tag, which are all granted unless you change them. - Restores a returning visitor's choice straight away, before the banner loads, so tags on the first page view already see it.
- Loads the GoTrust banner. When the visitor accepts, rejects or saves their choices, the template passes the new state to your Google tags with Google's
updateConsentStateAPI.
Appearance, categories, languages and cookie lists are still managed in your GoTrust dashboard, exactly as with the HTML embed. To set up a banner that meets Google's banner requirements, follow these steps.
Use this template or the HTML embed code from your dashboard, not both. Loading GoTrust twice sends consent signals twice.
Before you start
- Edit and publish access to your GTM container.
- From your GoTrust dashboard (Cookie Consent Management → your domain → Consent Code, under “Configuration Details”): your Config ID, Domain and Environment.
Install
- Add the template. In GTM, open Templates → Tag Templates → Search Gallery, search for “GoTrust”, select GoTrust – Consent Mode & CMP Loader and click Add to workspace.
- Create the tag. Go to Tags → New, name it (for example “GoTrust CMP”) and choose the GoTrust template as the tag type.
- Fill in the three required fields from your dashboard: GoTrust Domain ID (Config ID), Registered Site URL (Domain) and GoTrust Platform Base URL (Environment). The other settings work as they are; see Settings if you want to change them.
- Set the trigger to Consent Initialization - All Pages. If your container doesn't have it yet, create it under Triggers → New → Consent Initialization. This is required: on any other trigger the default is set too late, after other tags may already have run.
- Preview and check. Click Preview, open your site and confirm that:
- the GoTrust banner appears;
- in Tag Assistant, the tag fired on Consent Initialization, before any other tag;
- the Consent tab shows the default state, and an update after you make a choice in the banner.
- Publish the container.
Google tags (GA4, Google Ads, Floodlight) read Consent Mode automatically. For other tags, use each tag's Consent Settings → Require additional consent to make it wait for the consent types it needs.
Settings
Required
| Field | What to enter |
|---|---|
| GoTrust Domain ID | The Config ID from your dashboard's Consent Code step. |
| Registered Site URL | The Domain value, for example https://www.example.com. |
| GoTrust Platform Base URL | The Environment value (an https:// URL). |
Consent Mode Type
This sets wait_for_update, which Google describes as controlling how long to wait before data is sent: up to Wait For Update milliseconds (2000 by default) with Advanced, no wait with Basic. Whether a tag is blocked until the user interacts with the banner (Google's Basic consent mode) or loads with the default consent states (Advanced) is set in each tag's own consent settings in GTM.
Consent Mode Defaults
One setting per consent type (ad_storage, analytics_storage, ad_user_data, ad_personalization, functionality_storage, personalization_storage, security_storage). These apply to visitors outside the EEA, UK and Switzerland until they make a choice. All are Granted by default. If you set them to Denied, GoTrust still grants consent for visitors in countries where no banner is configured, so measurement continues there.
The EEA, UK and Switzerland always start denied and can't be changed here.
Regional overrides (optional)
Add a row to give specific regions their own defaults, for example specific US states. Enter comma-separated ISO codes such as US-CA, US-CO, BR and choose Granted or Denied for the types you want to change; types left “Not set” use the global default. Google applies the most specific matching region.
Codes for the EEA, UK and Switzerland (including subdivisions such as ES-CT) are ignored.
Advanced Settings
| Setting | Default | When to change it |
|---|---|---|
| Wait For Update (ms) | 2000 | How long to wait before data is sent (wait_for_update). Only used with Advanced; change it only if GoTrust support advises it. |
| GoTrust CDN Bundle Base URL | https://cdn.gotrust.tech/gotrust-client | Leave as is. The template can only load scripts from GoTrust's CDN; contact support if your deployment serves the script from another domain. |
| Banner Mount Selector | #gotrust-cookie-banner | Only to place the banner inside a specific element. If the element doesn't exist, the banner adds its own container, so no HTML changes are needed. |
Redact ads data (ads_data_redaction) | On | When ad_storage is denied, ad click identifiers sent in network requests by Google Ads and Floodlight tags are redacted. |
Pass ad click information through URLs (url_passthrough) | On | Passes ad click, client ID, and session ID information in URLs. |
Debug Mode
Logs the template's steps to the browser console. Turn it on while testing and off before publishing. Errors are always reported, whether or not it's on (see Troubleshooting).
How consent reaches Google
| Moment | What happens |
|---|---|
| Consent Initialization | Default set with setDefaultConsentState: your global defaults, denied in the EEA/UK/CH, plus any regional overrides. |
| Returning visitor | Their saved choice is applied with updateConsentState before the banner loads. |
| Visitor makes a choice | The new state is sent with updateConsentState as soon as they click. |
| No banner configured for the visitor's country (outside the EEA, UK and Switzerland) | All consent types are granted with updateConsentState, so measurement continues. |
| After every consent update | GoTrust pushes a gotrust_consent_update event to the dataLayer, with the new consent state in gotrust_consent. |
| Browser sends Global Privacy Control | All non-essential consent types are set to denied and the banner is not shown. |
How GoTrust categories map to Consent Mode:
| GoTrust category | Consent types |
|---|---|
| Marketing / Advertising | ad_storage, ad_user_data, ad_personalization, personalization_storage |
| Analytics | analytics_storage |
| Functional | functionality_storage |
| Necessary | security_storage (always granted) |
Basic and Advanced consent mode
Google describes two setups (see Google's consent mode guide): in Basic consent mode, Google tags are blocked until the user interacts with the consent banner; in Advanced consent mode, Google tags load when a user opens the website, with the default consent states set. With this template you choose per Google tag in your container:
- Basic: on the Google tag, open Advanced Settings → Consent Settings, choose Require additional consent for tag to fire and add the consent types it needs (for example
analytics_storagefor Google Analytics,ad_storageandad_user_datafor Google Ads). Fire the tag on a Custom Event trigger with event namegotrust_consent_updateinstead of a page-view trigger. GoTrust pushes this event after every consent update — when the visitor makes a choice, and on each page for returning visitors — so the tag fires once consent is granted. In the GoTrust tag, set Consent Mode Type to Basic. - Advanced: keep your Google tags on their usual triggers with no additional consent required; they load with the default consent states set. In the GoTrust tag, set Consent Mode Type to Advanced.
Reopening cookie preferences
The banner has its own floating settings button. To open preferences from your own link or button as well, call showGoTrustCookiePreferences:
<button type="button" onclick="window.showGoTrustCookiePreferences && window.showGoTrustCookiePreferences(true)">
Cookie preferences
</button>You can add this to your site's HTML or as a GTM Custom HTML tag.
Troubleshooting
When something fails, the template always pushes a gotrust_template_error event to the dataLayer, with gotrust_error_stage and gotrust_error_message. Look for it in Tag Assistant's Data Layer tab.
| Symptom or error stage | Likely cause | Fix |
|---|---|---|
| Banner never appears | The tag isn't firing, or is on the wrong trigger. | Attach it to Consent Initialization - All Pages and check it fires in Preview. |
| Tags ignore consent choices | Another tag reads consent before this one runs, or non-Google tags have no consent settings. | Keep this tag on Consent Initialization; add Require additional consent to non-Google tags. |
config | A required field is empty or not a valid URL. | Re-copy the three required values from the Consent Code step. |
permission_denied | The template's permissions were changed in your container. | Restore the template's default permissions, or re-add it from the Gallery. |
shim_load_failed / bundle_load_failed | Network or CDN problem, or a changed GoTrust CDN Bundle Base URL. | Reset that setting to the default and try again. |
sdk_api_missing | The GoTrust script loaded but isn't the expected version. | Contact GoTrust support. |
Misconfiguration debug mode
GoTrust can check whether your installation lets a Google tag run before the consent default or the IAB TCF stub is in place. This works for both GTM and HTML embed installs.
Open your site with ?gt-shim-debug=1 added to the URL (for example https://www.example.com/?gt-shim-debug=1) and check the browser console. Nothing is logged for normal visitors.
- Setup correct:
[GoTrust Shim] Debug: OKconfirms the Consent Mode default and TCF stub were set before any Google tag. For GTM template installs, the message says the template sets the default on the Consent Initialization trigger; check in Tag Assistant that it fires before your other tags. - Problem found: a warning starting with
[GoTrust Shim] MISCONFIGURATION DETECTED:names what was found.
The checks look for:
- A Google or ad-tech script placed before the GoTrust script in the page HTML, the most common mistake with HTML embeds.
- A Google tag (gtag.js or Google Tag Manager) that had already run before GoTrust loaded.
- Entries already in
window.dataLayerbefore GoTrust set the default.
For GTM template installs, where GTM always loads first, the last two checks and the check for Google's own tag scripts are skipped.
Check Google Tag Gateway first. A flagged late signal may come from a tag that uses Google Tag Gateway, which serves it from your own domain. Check whether it does, and if so follow GoTrust's Google Tag Gateway guidance: gotrust.tech/docs/cmp#google-tag-gateway. If Tag Gateway isn't involved, move the GoTrust script (or this GTM tag's trigger) earlier so it runs before other tags.
Google documentation
- Set up consent mode — Google's developer guide to consent mode, including Basic and Advanced setups.
- Consent mode in Tag Manager templates — how CMP templates like this one set defaults and updates.
- Troubleshoot consent mode with Tag Assistant — checking the default and update commands on your site.
Support
Email support@gotrust.tech, or open an issue on github.com/gotrust-technologies/gotrust-gtm-community-template.


India
Noida
303, Tower C, ATS Bouquet, Noida Sector 132, U.P.
mumbai
1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059
Bengaluru
Workden Exucutive 2, Address: 372, 100 Feet Road, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008

UAE
DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands
Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands
