Article · June 17, 2026
Consent Mode v2 and Google Ads remarketing: how to stay compliant?
How Consent Mode v2 impacts Google Ads remarketing without consent, proper setup, and storing evidence under Vietnam’s PDPL.
Quick answer
What is Consent Mode v2 Google Ads remarketing?
Consent Mode v2 is a mechanism that lets your website/app adjust how Google measures and personalizes ads based on the user’s consent status. For Google Ads remarketing, the key point is: without appropriate consent, signals to add users to remarketing lists will be reduced or not processed the same way as when consent is given.
For Vietnamese businesses, this isn’t just a question of “whether tracking runs or not,” but a PDPL compliance issue: you must define purposes, provide clear notice, and process data only on a valid legal basis. If you use cookies, pixels, or advertising IDs for remarketing, you need a mechanism to request and record consent in accordance with the rules.
How are remarketing lists affected when consent is missing?
When consent is missing, common impacts include smaller remarketing lists, slower updates, or not meeting thresholds to activate certain user lists. Put simply: users may still access the website, but their data should not be fed into the remarketing pipeline as usual if appropriate consent isn’t present.
Practical impacts include:
- Lower match rates: fewer people are added to your remarketing lists.
- Colder lists: new visitors who don’t consent won’t be fully captured for remarketing.
- Less accurate measurement: conversion data and audiences may lack some signals.
- Slower campaign optimization: algorithms have less data to learn from.
Example: a Vietnamese e-commerce marketplace sets up Google Ads remarketing for users who viewed a product but didn’t buy. If the cookie banner, by default, fires all tags before the user consents, the business faces compliance risks. If Consent Mode v2 is implemented correctly, the non-consenting group may be subject only to restricted mode, while the consenting group is fully processed for remarketing.
How to keep remarketing compliant with the rules?
The safe approach is to build remarketing on a “consent first, trigger later” principle for non-essential tags, while recording consent status so you can demonstrate it when needed. This reduces legal risk while keeping campaigns operable.
Classify processing purposes:
clearly separate necessary cookies, measurement, and advertising/remarketing. Don’t lump them into a vague “Accept all” button.
Show a clear banner/consent notice:
state plainly what you use cookies/pixels for, who receives the data, and where users can refuse.
Set a safe default state:
remarketing tags shouldn’t run fully before appropriate consent is obtained.
Fire signals only with a legal basis:
after the user consents, activate Google Ads tags, audience sync, or related remarketing events.
Store consent evidence:
record the timestamp, banner version, the user’s choices, and the source of the consent so you can reconcile it.
Recheck per market:
if you have users in the EU or other countries, consent policies and mechanisms may need to be stricter. In Vietnam, apply the PDPL and related guidance.
What should SMEs check in Google Tag Manager?
If you use GTM, check whether your Google Ads remarketing tags depend on consent status. Many real-world errors come from firing tags too early or missing a control layer before pushing data to Google.
Minimum checklist:
- Does the cookie banner actually block tags before the user chooses “No”?
- Is consent status passed consistently from the banner to GTM?
- Is consent separated for analytics and advertising?
- Do you have a logging mechanism to prove who consented, when, and to which version?
- If the user declines, do remarketing tags stop entirely or still run in the background?
From a PDPL compliance perspective, businesses should treat this as a data governance system rather than “just a piece of code.” When you need certainty about configuration, consult a lawyer or a privacy specialist for review.
If there’s no consent, should you keep remarketing lists?
Possibly, but only within the limits permitted by law and with the right technical design. If a list was created from data without a valid legal basis, reassess the use, storage, and sharing of that data with the advertising platform.
Safe practices include:
- Don’t default to treating every visitor as a remarketing audience.
- Don’t use advertising data without appropriate notice and consent.
- Don’t share identifiable information beyond what’s necessary.
- Have policies to delete/hide data when a user withdraws consent or requests handling under the rules.
If a leak or misconfiguration causes advertising data to be processed beyond the permitted scope, assess the incident and provide a data breach notice within 72 hours of detection, as required.
How to stay compliant without “killing” performance?
The goal isn’t to turn off all tracking, but to design tracking with discipline. For remarketing, businesses usually can still perform well by doing three things: create clear consent layers, only fire tags when consent is present, and keep complete logs for accountability.
A practical model for SMEs:
- The cookie banner asks only for non-essential purposes.
- Consent Mode v2 passes consent status before Google Ads tags run.
- Audiences are created only from users who consented to advertising.
- A separate dashboard tracks consent rates, not just CTR/CPA.
If you’re implementing a cookie banner, consent evidence storage, or a DSAR process for a website that uses remarketing, consent.vn can help you standardize this for easier operations.
- Not necessarily. It typically reduces or limits data from users who haven’t consented, while the consenting group can be processed according to your configuration.
- Under the rules, you shouldn’t default to adding them to remarketing lists without a valid legal basis and clear notice.
- Store the consent timestamp, consent type, banner/policy version, the user’s selection, and the consent source to reconcile if needed.
- Yes. If you collect or process personal data for advertising/remarketing, you must comply with Vietnam’s PDPL and related regulations.
Source: the Personal Data Protection Law (Law 91/2025/QH15): https://thuvienphapluat.vn; Decree 13/2023/ND-CP: https://thuvienphapluat.vn; Ministry of Public Security (A05): https://bocongan.gov.vn
Get started — no account needed.
Ready to comply with PDPL?