Install GoTrust with Google Tag Manager

Sep 30, 2026Article by GoTrust

Install and configure the GoTrust consent banner through Google Tag Manager, with Google Consent Mode v2 configured for your site.

What the template does

Every time a page loads, the template:

  1. Sets the Consent Mode default before any other tag runs. Visitors in the EEA, UK and Switzerland always start with every consent type denied (except security_storage). Everywhere else starts with the defaults you choose in the tag, which are all granted unless you change them.
  2. Restores a returning visitor's choice straight away, before the banner loads, so tags on the first page view already see it.
  3. Loads the GoTrust banner. When the visitor accepts, rejects or saves their choices, the template passes the new state to your Google tags with Google's updateConsentState API.

Appearance, categories, languages and cookie lists are still managed in your GoTrust dashboard, exactly as with the HTML embed. To set up a banner that meets Google's banner requirements, follow these steps.

Use this template or the HTML embed code from your dashboard, not both. Loading GoTrust twice sends consent signals twice.

Before you start

  • Edit and publish access to your GTM container.
  • From your GoTrust dashboard (Cookie Consent Management → your domain → Consent Code, under “Configuration Details”): your Config ID, Domain and Environment.

Install

  1. Add the template. In GTM, open Templates → Tag Templates → Search Gallery, search for “GoTrust”, select GoTrust – Consent Mode & CMP Loader and click Add to workspace.
  2. Create the tag. Go to Tags → New, name it (for example “GoTrust CMP”) and choose the GoTrust template as the tag type.
  3. Fill in the three required fields from your dashboard: GoTrust Domain ID (Config ID), Registered Site URL (Domain) and GoTrust Platform Base URL (Environment). The other settings work as they are; see Settings if you want to change them.
  4. Set the trigger to Consent Initialization - All Pages. If your container doesn't have it yet, create it under Triggers → New → Consent Initialization. This is required: on any other trigger the default is set too late, after other tags may already have run.
  5. Preview and check. Click Preview, open your site and confirm that:
    • the GoTrust banner appears;
    • in Tag Assistant, the tag fired on Consent Initialization, before any other tag;
    • the Consent tab shows the default state, and an update after you make a choice in the banner.
  6. Publish the container.

Google tags (GA4, Google Ads, Floodlight) read Consent Mode automatically. For other tags, use each tag's Consent Settings → Require additional consent to make it wait for the consent types it needs.

Settings

Required

FieldWhat to enter
GoTrust Domain IDThe Config ID from your dashboard's Consent Code step.
Registered Site URLThe Domain value, for example https://www.example.com.
GoTrust Platform Base URLThe Environment value (an https:// URL).

Consent Mode Type

This sets wait_for_update, which Google describes as controlling how long to wait before data is sent: up to Wait For Update milliseconds (2000 by default) with Advanced, no wait with Basic. Whether a tag is blocked until the user interacts with the banner (Google's Basic consent mode) or loads with the default consent states (Advanced) is set in each tag's own consent settings in GTM.

Consent Mode Defaults

One setting per consent type (ad_storage, analytics_storage, ad_user_data, ad_personalization, functionality_storage, personalization_storage, security_storage). These apply to visitors outside the EEA, UK and Switzerland until they make a choice. All are Granted by default. If you set them to Denied, GoTrust still grants consent for visitors in countries where no banner is configured, so measurement continues there.

The EEA, UK and Switzerland always start denied and can't be changed here.

Regional overrides (optional)

Add a row to give specific regions their own defaults, for example specific US states. Enter comma-separated ISO codes such as US-CA, US-CO, BR and choose Granted or Denied for the types you want to change; types left “Not set” use the global default. Google applies the most specific matching region.

Codes for the EEA, UK and Switzerland (including subdivisions such as ES-CT) are ignored.

Advanced Settings

SettingDefaultWhen to change it
Wait For Update (ms)2000How long to wait before data is sent (wait_for_update). Only used with Advanced; change it only if GoTrust support advises it.
GoTrust CDN Bundle Base URLhttps://cdn.gotrust.tech/gotrust-clientLeave as is. The template can only load scripts from GoTrust's CDN; contact support if your deployment serves the script from another domain.
Banner Mount Selector#gotrust-cookie-bannerOnly to place the banner inside a specific element. If the element doesn't exist, the banner adds its own container, so no HTML changes are needed.
Redact ads data (ads_data_redaction)OnWhen ad_storage is denied, ad click identifiers sent in network requests by Google Ads and Floodlight tags are redacted.
Pass ad click information through URLs (url_passthrough)OnPasses ad click, client ID, and session ID information in URLs.

Debug Mode

Logs the template's steps to the browser console. Turn it on while testing and off before publishing. Errors are always reported, whether or not it's on (see Troubleshooting).

MomentWhat happens
Consent InitializationDefault set with setDefaultConsentState: your global defaults, denied in the EEA/UK/CH, plus any regional overrides.
Returning visitorTheir saved choice is applied with updateConsentState before the banner loads.
Visitor makes a choiceThe new state is sent with updateConsentState as soon as they click.
No banner configured for the visitor's country (outside the EEA, UK and Switzerland)All consent types are granted with updateConsentState, so measurement continues.
After every consent updateGoTrust pushes a gotrust_consent_update event to the dataLayer, with the new consent state in gotrust_consent.
Browser sends Global Privacy ControlAll non-essential consent types are set to denied and the banner is not shown.

How GoTrust categories map to Consent Mode:

GoTrust categoryConsent types
Marketing / Advertisingad_storage, ad_user_data, ad_personalization, personalization_storage
Analyticsanalytics_storage
Functionalfunctionality_storage
Necessarysecurity_storage (always granted)

Basic and Advanced consent mode

Google describes two setups (see Google's consent mode guide): in Basic consent mode, Google tags are blocked until the user interacts with the consent banner; in Advanced consent mode, Google tags load when a user opens the website, with the default consent states set. With this template you choose per Google tag in your container:

  • Basic: on the Google tag, open Advanced Settings → Consent Settings, choose Require additional consent for tag to fire and add the consent types it needs (for example analytics_storage for Google Analytics, ad_storage and ad_user_data for Google Ads). Fire the tag on a Custom Event trigger with event name gotrust_consent_update instead of a page-view trigger. GoTrust pushes this event after every consent update — when the visitor makes a choice, and on each page for returning visitors — so the tag fires once consent is granted. In the GoTrust tag, set Consent Mode Type to Basic.
  • Advanced: keep your Google tags on their usual triggers with no additional consent required; they load with the default consent states set. In the GoTrust tag, set Consent Mode Type to Advanced.

Reopening cookie preferences

The banner has its own floating settings button. To open preferences from your own link or button as well, call showGoTrustCookiePreferences:

<button type="button" onclick="window.showGoTrustCookiePreferences && window.showGoTrustCookiePreferences(true)">
  Cookie preferences
</button>

You can add this to your site's HTML or as a GTM Custom HTML tag.

Troubleshooting

When something fails, the template always pushes a gotrust_template_error event to the dataLayer, with gotrust_error_stage and gotrust_error_message. Look for it in Tag Assistant's Data Layer tab.

Symptom or error stageLikely causeFix
Banner never appearsThe tag isn't firing, or is on the wrong trigger.Attach it to Consent Initialization - All Pages and check it fires in Preview.
Tags ignore consent choicesAnother tag reads consent before this one runs, or non-Google tags have no consent settings.Keep this tag on Consent Initialization; add Require additional consent to non-Google tags.
configA required field is empty or not a valid URL.Re-copy the three required values from the Consent Code step.
permission_deniedThe template's permissions were changed in your container.Restore the template's default permissions, or re-add it from the Gallery.
shim_load_failed / bundle_load_failedNetwork or CDN problem, or a changed GoTrust CDN Bundle Base URL.Reset that setting to the default and try again.
sdk_api_missingThe GoTrust script loaded but isn't the expected version.Contact GoTrust support.

Misconfiguration debug mode

GoTrust can check whether your installation lets a Google tag run before the consent default or the IAB TCF stub is in place. This works for both GTM and HTML embed installs.

Open your site with ?gt-shim-debug=1 added to the URL (for example https://www.example.com/?gt-shim-debug=1) and check the browser console. Nothing is logged for normal visitors.

  • Setup correct: [GoTrust Shim] Debug: OK confirms the Consent Mode default and TCF stub were set before any Google tag. For GTM template installs, the message says the template sets the default on the Consent Initialization trigger; check in Tag Assistant that it fires before your other tags.
  • Problem found: a warning starting with [GoTrust Shim] MISCONFIGURATION DETECTED: names what was found.

The checks look for:

  • A Google or ad-tech script placed before the GoTrust script in the page HTML, the most common mistake with HTML embeds.
  • A Google tag (gtag.js or Google Tag Manager) that had already run before GoTrust loaded.
  • Entries already in window.dataLayer before GoTrust set the default.

For GTM template installs, where GTM always loads first, the last two checks and the check for Google's own tag scripts are skipped.

Check Google Tag Gateway first. A flagged late signal may come from a tag that uses Google Tag Gateway, which serves it from your own domain. Check whether it does, and if so follow GoTrust's Google Tag Gateway guidance: gotrust.tech/docs/cmp#google-tag-gateway. If Tag Gateway isn't involved, move the GoTrust script (or this GTM tag's trigger) earlier so it runs before other tags.

Google documentation

Support

Email support@gotrust.tech, or open an issue on github.com/gotrust-technologies/gotrust-gtm-community-template.

© 2024-26 GoTrust

India

Noida

303, Tower C, ATS Bouquet, Noida Sector 132, U.P.

mumbai

1st Floor, Raheja Platinum, WeWork, K, Marol, Andheri East, Mumbai, Maharashtra 400059

Bengaluru

Workden Exucutive 2, Address: 372, 100 Feet Road, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008

UAE

DIFC Innovation Hub, Gate Avenue, Zone D, Co-working Space Level 1 Al Mustaqbal St, Dubai

Netherlands

Cuserpark Amsterdam, De Cuserstraat 91, 1081CN, Amsterdam, Netherlands