Guide · June 17, 2026

Consent Mode v2 for Shopify: How to enable and connect GA4/Ads?

Guide to enable Consent Mode v2 for Shopify via Customer Privacy API, connect consent app to GA4/Ads correctly.

consent.vn Editorial7 min read

Quick answer

If you’re running Shopify in Vietnam, the right approach is to enable the Customer Privacy API/Customer Privacy to manage consent status, then connect your consent app to GA4 and Google Ads via Consent Mode v2. This syncs consent signals, limits measurement before consent, and makes compliance easier to demonstrate.

What is Consent Mode v2 for Shopify and when should you enable it?

Consent Mode v2 for Shopify is how you pass users’ consent status from your banner/consent app into Google’s measurement systems such as GA4 and Google Ads. You should enable it when your website uses cookies/SDKs for analytics, remarketing, or conversion tracking and has users in the EU/EEA, or when you implement under PDPL/Decree 13.

With Shopify, the important point is not just “showing a banner.” You need to ensure consent is actually recorded, evidence is stored, and that status is correctly passed into your measurement systems. Otherwise, you may see missing traffic or wrong attribution, especially for ad conversions.

How do you enable Consent Mode v2 for Shopify using the Customer Privacy API?

A common approach is to use Shopify’s Customer Privacy API/Customer Privacy as the consent recording layer, then have the consent app push status to Google tags. This is a suitable path for SMEs because you don’t need to build a full CMP from scratch.

  1. Audit your current stack:

    Identify whether you’re using a standard Shopify theme, which consent app, whether you already have the Google tag/Google Tag Manager, and how GA4/Google Ads are installed.

  2. Enable Shopify’s Customer Privacy:

    Activate the privacy management mechanism so the site can receive and read consent status by purpose, such as analytics and marketing.

  3. Configure the banner/consent app:

    Choose a consent app that supports Consent Mode v2, and map the right consent groups such as analytics_storage, ad_storage, ad_user_data, ad_personalization.

  4. Connect to GA4 and Google Ads:

    Install the Google tag/gtag or GTM as the app recommends, ensuring consent status is pushed before tags fire.

  5. Verify with preview/debug:

    Test on a clean browser, check whether default/updated consent values change correctly, and confirm that no tags fire before consent.

  6. Store consent evidence:

    Record the timestamp, banner version, notice content, and user choices for future audits/DSAR.

How do you connect a consent app with GA4 and Google Ads on Shopify?

The principle is that the consent app must do three things: present clear choices, store the user’s decision, and update the consent state for Google tags. If the app only displays a banner but doesn’t pass the state, GA4/Ads won’t receive the correct consent signals.

A common real-world configuration is:

  • The banner/CMP appears immediately when the user lands on the site.
  • The user chooses “Accept,” “Reject,” or customizes their choices.
  • The app records the choice and calls the consent update mechanism.
  • GA4 and Google Ads read the new state and only activate to the permitted level.

Example: a cosmetics shop in Ho Chi Minh City uses Shopify + a consent app + GA4. Previously they installed measurement scripts manually, which skewed ad data. After switching to a consent app that supports Consent Mode v2, they separated analytics and marketing, reduced the risk of tags firing before consent, and made reporting reconciliation easier.

Which consent fields should you configure correctly?

At a minimum, map the consent fields that Google uses for Consent Mode v2. For most shops, the focus is analytics and advertising; avoid merging everything into a single button if you have multiple processing purposes.

Consent groupPurposeWhen it’s typically enabled
analytics_storageBehavioral measurement, GA4When the user consents to analytics
ad_storageStore/read advertising dataWhen the user consents to marketing
ad_user_dataSend user data for advertisingWhen you have appropriate consent
ad_personalizationAd personalizationWhen the user allows remarketing

Practical note: if your consent app only has two buttons (“Accept/Reject”) without separating purposes, check whether that default is sufficiently clear under your internal rules and data policy. For strong legal claims, have a lawyer review it.

What should Shopify merchants watch for to avoid “ticking the box” only?

The most common weakness is that a banner exists, but the consent status isn’t consistently propagated to all tags. You need to check the theme, third-party apps, pixels, and any manually injected scripts.

Recommended actions:

  • Check whether Google tags are hardcoded before the banner.
  • Review whether Shopify marketing apps set cookies on their own.
  • Log the banner version and notice content.
  • Have a process to handle data access/deletion requests (DSAR).
  • Prepare a process to notify data breaches within 72 hours of discovery, as required.

Under Vietnamese law, the Personal Data Protection Law is the Personal Data Protection Law (Law 91/2025/QH15), effective 01/01/2026, replacing/upgrading Decree 13/2023/ND-CP. The enforcement authority is the Ministry of Public Security (A05). Specific penalties will be defined by a guiding decree; serious violations may be subject to criminal liability.

What’s a quick configuration template for Shopify?

You can use this internal checklist to speed up implementation:

Item Required status Notes
Consent banner Present Shows before loading non-essential tags
Customer Privacy API Present Stores and reads consent status
GA4 Present Only fires according to appropriate consent
Google Ads Present Separate remarketing/conversion by consent
Consent log Present Store timestamp, version, user choice
DSAR Present Process to handle data requests

Short sample wording for your privacy notice: “We use cookies and similar technologies to operate the website, measure performance, and show relevant ads. You can accept, reject, or change your choices at any time in the privacy settings.”

Is Consent Mode v2 for Shopify hard without a dev?

Not too hard if you use a suitable consent app and only need a standard basic setup. But if you have multiple themes, many marketing apps, or a complex GTM setup, have a dev review it, because issues often come from script load order and consent mapping.

If you use GA4/Google Ads and process personal data/cookies under the regulations, you should enable it to sync consent status and reduce compliance risks.
Not enough if you haven’t connected it to your consent app and Google tags. The API is just the foundation; you still need to configure the end-to-end consent flow.
It can, if the app truly displays the banner, stores evidence of consent, and correctly passes consent to GA4/Ads. You should test thoroughly before going live.
If you only run a basic setup, you can start with a technical checklist. But if you do remarketing, cross-border data transfers, or process sensitive data, have a lawyer review for compliance.

If you need a banner template + consent logging + GA4/Ads mapping for Shopify, consent.vn can help standardize it for easy implementation by your dev and marketing teams.

Source: the Personal Data Protection Law (Law 91/2025/QH15) on thuvienphapluat.vn; Decree 13/2023/ND-CP on thuvienphapluat.vn; Ministry of Public Security (A05) on bocongan.gov.vn.

Get started — set up in 5 minutes.

Need help with PDPL compliance?

Get started