Oatmeal raisin or chocolate chip? Cookie consent that isn’t half-baked
Monday, October 5th, 2026
Tuesday, October 20, 2026, 4:00pm – 4:45pm EDT
Slides: TBD
Description
Consent isn’t just important, it is increasingly becoming the law. With regulations like GDPR, CCPA and VCDPA on the rise, your institution may soon need its own cookie consent solution. The problem? Most consent banners feel invasive, clunky and half-baked to users. There has to be a better way. After evaluating vendor options, we chose to leverage Google Tag Manager (GTM) and build our own solution. The result: a consent module that’s free, accessible, customizable — and hopefully, a bit less annoying than the typical vendor popup. In this session, we’ll break down real-world examples (including some truly terrible ones), explore the requirements for compliant consent management and show how GTM can do most of the heavy lifting. We’ll also take time to discuss what you should expect once your new consent banner is in place. You’ll leave with a clear path to building a solution that works for your users and your institution.
Resources
Google provides several good resources and tutorials to helping you build your own consent module:
- Consent mode support in tag manager
- Consent mode tag behaviours and best practices
- Setting up consent mode video
Code walkthrough:
I created a very minimal example page with a consent banner hooked to GTM.
Note that consent_debug is set to true, meaning that banner will reappear on every page load. You can also view the current settings using a browser console.
Start by creating your banner. On this page, it is placed near the end of the body:
<div id="consent">
<p>We will only use essential cookies unless you accept all...
<button id="consent-allow">Allow all</button>
<button id="consent-deny">Use essential only</button>
</div>
Step 1. Set defaults to ‘denied’ before including GTM
The user’s consent options will be stored in the browser local storage. If not found, we should assume they have not yet opted-in and set all the defaults to denied.
gtag('consent', 'default', {'ad_storage':'denied','ad_user_data':'denied', ...
Step 2. Interactions
Here we use JS to show the banner and wait for the user to make a selection. When a button interaction happens, we send the correct values to a function that handles the update.
if(event.target.id === 'button-allow'){
consent_update({ analytics: false, marketing: false });
}
else{
consent_update({ analytics: true, marketing: true });
}
Step 4: Update consent values
Set the values and notify GTM of the changes. Also store the changes to the local storage for the next visit.
const consentMode = {
'functionality_storage': 'granted',
'analytics_storage': consent.analytics ? 'granted' : 'denied',
'ad_storage': consent.marketing ? 'granted' : 'denied'
...
gtag('consent', 'update', consentMode);
localStorage.setItem('consentMode', JSON.stringify(consentMode));
