In short: Google Tag Manager is a single container that loads on your site once, and from which you manage every measurement tag without touching code. In 2026 the interesting question is no longer how to install it. It is three other things: which of Google's seven consent types you transmit, where the tag actually runs (browser, tag gateway, or your own server), and whether the container is still clean. Three numbers decide it: Google states that ad_user_data consent is required for measurement use cases such as enhanced conversions and tag-based conversion tracking; remarketing in Google Ads, Display & Video 360 and Search Ads 360 receives no data unless both ad_user_data and ad_personalization are granted; and Google says a container whose Size indicator passes 70% needs to be optimised.
This guide covers what Tag Manager is and what it is not, the account, container, workspace and version hierarchy, tags, triggers and variables, the consent layer with the full seven-type table, the three deployment layers of 2026, how to verify a setup actually works, four myths against the documentation, and the exact lead-measurement setup we run on this site. Every product and regulatory fact was checked against Google's primary documentation on 03.09.2026.
What Google Tag Manager is, and what it is not
Google Tag Manager (GTM) is a tag management system. Instead of embedding a separate snippet for every platform, you install one container once, and from its interface you add, edit and disable tags without editing the site's code and, in most cases, without a developer.
Here is what it is not, and this is where most businesses go wrong:
- It is not an analytics product. Tag Manager collects nothing and reports nothing. It fires the Google Analytics 4, Google Ads and Meta tags. The reports stay in those platforms.
- It is not a pixel. The Meta pixel is a tag that runs inside the container, not a replacement for it.
- It is not a cookie banner or a compliance product. Tag Manager can read a consent state and behave accordingly, but the consent itself has to be collected by a separate mechanism. See the consent layer.
- It does not guarantee correct measurement. A container set up once and never reviewed is usually a source of double-counted conversions, not of accuracy.
A double install, gtag in the site code plus a tag in Tag Manager, is the most common cause of double-counted page views and purchases. How to spot it, and 24 other measurement faults, is covered in our GA4 audit checklist.
Signing up is free with any Google account at tagmanager.google.com. The standard product costs nothing; Tag Manager 360 is a paid enterprise tier.
Account, container, workspace, version
These four terms are the first source of confusion, and they also determine who can break your measurement. This is the hierarchy as Google defines it, with the practical rule we work by:
| Level | What it is | Practical rule |
|---|---|---|
| Account | The top level. Usually one account per organisation. | The account belongs to the client, never to the agency. Always. |
| Container | The snippet that lives on the site and holds all of its tags. | One container per site. Do not split by department; do split by domain. |
| Workspace | A draft area where changes are made before going live. | A separate workspace per meaningful change, so you never publish someone else's half-finished work. |
| Version | A snapshot of the container created on every publish. | Name and describe every publish. That is what lets you roll back in a minute when something breaks. |
The practical conclusion shows up in almost every audit we run: with no version descriptions there is no way to know which change did what. Publishing without a description is the single most common reason nobody can explain why conversions jumped or vanished in a given month.
How the data actually flows
Once you have an account and a container, you get a snippet to install on the site, with instructions on where to place it. From that point every measurement change happens in the interface rather than in the code.
Between the site and the tags sits a layer called the data layer. It is a JavaScript object that the site pushes events and parameters into, and that Tag Manager reads from. Simple sites can get by without touching it, but on any real ecommerce site the data layer is the difference between tracking that reports "someone reached the thank-you page" and tracking that reports a transaction ID, a value, a currency and the items purchased. If you measure ecommerce without a proper data layer, you are measuring conversions without value, and every ROAS-based optimisation built on top of that will be wrong.
Tags, triggers and variables
Three elements make up everything you will ever build in the tool:
Tags
A tag is the code that fires when a defined condition is met: a GA4 event, a Google Ads conversion, a Meta pixel event. Tag Manager offers a catalogue of built-in tag types so most setups need no custom code at all.
Triggers
A trigger tells a tag which action on the site fires it. The six most commonly used ones:
- Page View: fires when a user views a specific page or any page, depending on your configuration.
- Window Loaded: fires after the browser has finished loading every element of the page, including images and scripts.
- Just Links: fires when a visitor clicks a link you have defined. Useful for tracking clicks on phone and WhatsApp links.
- Form Submission: fires when a visitor submits a form. This is the one that gives you an accurate lead conversion.
- Scroll Depth: fires at a defined scroll percentage, which tells you where readers abandon a page.
- Timer: fires after a defined interval, useful for showing content or firing events only after real engagement.
Variables
Variables supply the additional information a tag or trigger needs, such as the clicked URL, the form ID or a value from the data layer. Tag Manager ships with a list of built-in variables, and for most standard setups you will not need to create new ones.
Installing the three tags that matter
For the overwhelming majority of businesses, three tags cover everything:
- Google Analytics 4. Install the Google tag with your measurement ID, then add GA4 event tags for the actions that matter. Mark only the genuinely meaningful ones as key events.
- Google Ads conversion tracking, with enhanced conversions. Add the conversion tag plus the conversion linker, and feed enhanced conversions with hashed first-party data from your form. Note that Google lists
ad_user_dataconsent as required for exactly this use case. - The Meta pixel. Deploy the base pixel on all pages and a Lead or Purchase event on the same trigger used for the Google Ads conversion, so both platforms count the same action.
The rule that saves the most cleanup work later: one business action, one trigger, three tags. When each platform gets its own bespoke trigger, the platforms stop agreeing with each other, and no report can be trusted.
The consent layer
Consent mode is the mechanism by which your site tells Google what the user agreed to, and tags change their behaviour accordingly. Tag Manager has a dedicated place for it: Google tags ship with built-in consent checks, and tags without one can have a check added manually under Advanced > Consent Settings.
The seven consent types, and what breaks in each
| Consent type | What it controls | What breaks when denied |
|---|---|---|
ad_storage | Storage such as cookies or device identifiers, related to advertising | No advertising cookies are written. Ad-click identifiers such as GCLID are redacted. |
ad_user_data | Sending user data to Google for advertising purposes | Use of personal data for online advertising is disabled, including enhanced conversions and user-provided data. Google states this type is required for measurement use cases such as enhanced conversions and tag-based conversion tracking. |
ad_personalization | Personalised advertising | Remarketing in Google Ads, Display & Video 360 and Search Ads 360 receives no data. |
analytics_storage | Storage related to analytics, for example visit duration | No analytics cookie. Measurements are sent without cookies and used for modelling. |
functionality_storage | Storage supporting site functionality, for example language settings | Basic user preferences are not retained. |
personalization_storage | Storage related to personalisation, for example video recommendations | No personalised recommendations. |
security_storage | Storage related to security, authentication and fraud prevention | Authentication and user-protection features are impaired. |
The practical point: Google states explicitly that both ad_user_data and ad_personalization need to be granted to enable personalised advertising in its platforms. One of the two is not enough.
Basic versus advanced consent mode
| Feature | Basic consent mode | Advanced consent mode |
|---|---|---|
| Tag loading | Blocked until the user interacts with the consent banner | Loads immediately with defaults set to denied, unless configured otherwise |
| Data transmission | Nothing is sent before consent, not even the consent status itself | When consent is denied, the consent state and cookieless measurements are still sent |
| Conversion modelling | General model, less detailed | Advertiser-specific model, more detailed |
| When to choose it | When your legal position is that nothing may be transmitted before consent | When you want to preserve as much measurement as the consent state allows |
This single choice explains why businesses of identical size report very different conversion volumes. Under basic consent mode, a user who ignores the banner simply does not exist in the data. Under advanced consent mode, that user is counted as a cookieless signal, and Google uses that signal to model the missing conversion.
Who this applies to
Google's consent mode requirement is addressed to those who receive end-user data from users in the European Economic Area. A site whose entire audience is outside the EEA is not covered by that particular Google requirement. Two things still make it relevant to most businesses we work with.
First, local privacy law. In Israel, Amendment 13 to the Privacy Protection Law came into force on 14 August 2025 and removed the ability to rely on implied consent, requiring active and explicit consent instead. So an Israeli site needs a real consent mechanism regardless of what Google requires. Second, any business advertising or selling into Europe falls inside Google's definition anyway. An Israeli ecommerce store shipping to the EU is squarely in scope.
Our standing recommendation: if you have any European traffic, implement advanced consent mode. If you are domestic only, you still need a consent mechanism, but you are not obliged to block tags before the banner is answered. This is a legal decision that belongs with a lawyer, not with a guide, ours included.
The three deployment layers of 2026
Deploying Tag Manager stopped being a binary "installed or not" question. There are three layers now, and they are cumulative rather than alternative:
| Layer | What it does | What it solves | What it does not solve |
|---|---|---|---|
| Client-side web container | Tags run in the visitor's browser | Managing measurement without a developer; changes in minutes | Ad blockers, browser cookie restrictions, script weight in the browser |
| Google tag gateway for advertisers | Google's script is served from your own domain via your existing CDN, load balancer or web server | First-party loading and measurement, fewer third-party interactions | It does not move data processing to your server, and it does not remove the need for consent |
| Server-side tagging | An additional container running on your infrastructure, for example Cloud Run or App Engine, that receives data before it is forwarded | Full control over what is sent to each platform, data cleansing and enrichment, less third-party JavaScript in the browser | It does not remove the consent layer, and it does not compensate for a broken data layer |
Server containers use the same tag, trigger and variable model as the web container, so the conceptual jump is smaller than it sounds. What does change is maintenance: a server container is running infrastructure with a running cost and a monitoring requirement, not a one-off configuration.
The order we recommend, and Google recommends completing the last two together: first a correct web container with a data layer and consent mode, then a mapped custom domain and the tag gateway, and only then a server container. Starting with server-side tagging on top of broken measurement buys you the same wrong numbers at a higher price.
Verifying it actually works
- Preview mode in Tag Manager. It opens your site in debug mode and shows, per event, which tags fired, which did not, and why. The right question is not "did the tag fire" but "did it fire once". A tag firing twice on a thank-you page is the most common cause of inflated conversion counts.
- Tag Assistant. Google explicitly names it as the tool that helps you understand the consent fields and how your Google tag is behaving, so you can debug the setup.
- The request parameters themselves. When consent mode is implemented, it is translated into HTTP parameters such as
dma,gcdandgcs, with consent to Google services encoded indma_cps. Thegcsparameter transmits thead_storageandanalytics_storagestates. Worth knowing: thegcdparameter is always sent to Google, whether or not consent mode is active.
The final check is a reconciliation: conversions in Google Ads for the month against leads in the CRM. If the gap exceeds ten percent, you have a measurement problem, not a campaign problem.
Container hygiene: the number Google publishes and nobody measures
Containers accumulate. Every finished campaign, every replaced chat widget and every completed A/B test leaves a tag behind. Google publishes a measurable guideline on this that almost no guide quotes:
For containers with large numbers of tags, triggers or variables, or with large custom HTML tags, a Size indicator appears on the Versions pages. If the Size indicator value is above 70%, Google says you should take steps to optimise your container configuration. The official cleanup guidance: remove tags and variables that are no longer used, and split large containers that span multiple sites, or sections of very large sites, into smaller containers. Tag Manager 360 customers can use zones to load multiple containers conditionally.
Three checks we run on any container we inherit: how many tags fire on a single page view, how many of them belong to tools the business no longer uses, and how many custom HTML tags exist. A custom HTML tag is where a former vendor's code hides, which makes it a security exposure and not merely dead weight.
Four myths against the documentation
| What is commonly said | What the documentation says |
|---|---|
| "Moving to server-side tagging removes the need for consent mode" | No. Server-side tagging changes where tags execute, not whether consent applies. Google publishes a dedicated document on implementing consent mode with server-side Tag Manager, which says the opposite. The web container still collects consent; the server container fires tags according to the signals it receives. |
| "First-party mode is the feature to look for" | That name is retired. The product is now called Google tag gateway for advertisers. The old first-party mode documentation URL returns a 404, checked 03.09.2026. |
| "Tag Manager replaces Google Analytics" | No. Tag Manager is a delivery mechanism. It fires the Analytics 4 tag; the data and the reports live in Analytics. A container with no Analytics tag measures nothing. |
| "If the visitor did not consent, there is no data at all" | It depends on the implementation. Under basic consent mode nothing is sent. Under advanced consent mode the consent state and cookieless measurements are sent, and Google uses them to model the missing conversions and key events. |
The setup we run on this site
Rather than describe a theoretical build, here is the one running on this site, as an example of a minimal setup that works for a lead-generation business rather than an online store:
- One container across the whole site, including the English version.
- A single conversion event: submission of the contact form or the packages form. Not a page view, not a scroll, not time on site. One event that represents a real lead.
- Three tags on that one event: a GA4 key event, a Google Ads conversion, and a Meta pixel lead event.
- A monthly reconciliation: Google Ads conversions against leads recorded in the lead management system. We treat a gap of up to ten percent as normal, because some leads arrive by phone and WhatsApp and never pass through a form.
- Lead source in the notification email, so the origin of a lead is visible without opening a report.
This looks too simple, and that is the point. Most client accounts we inherit have the opposite problem: eleven configured conversions, seven of which are page views or button clicks, all marked as primary. Google's bidding algorithm then receives a noisy signal and optimises toward the cheapest action rather than toward a lead. A good container is a lean container.
Sources
Every product and regulatory fact on this page was checked against primary sources on 03.09.2026: the Google Tag Manager Help Center on managing accounts, containers and container size; Google Tag Platform documentation on consent mode and consent types; Google's consent mode requirement document for those receiving EEA user data; and the Server-side Tagging and Google tag gateway for advertisers documentation. The commencement date of Amendment 13 to Israel's Privacy Protection Law, 14 August 2025, was verified against Israeli publications. This page is written and maintained by the SFB Digital Marketing team from ongoing work on client measurement accounts.
Frequently asked questions about Google Tag Manager
Is Google Tag Manager free?
The standard version is completely free and you sign up with an ordinary Google account. There is a paid enterprise tier, Tag Manager 360, which adds support and capabilities such as zones for conditionally loading multiple containers. For the vast majority of businesses the free version is enough with no compromise.
What is the difference between Google Tag Manager and Google Analytics?
Tag Manager is a mechanism that fires tags. Analytics is a platform that collects data and produces reports. Tag Manager collects nothing itself; it fires the Analytics 4 tag and every other tag. You can install Analytics without Tag Manager, but then every measurement change requires touching the site's code.
Do I need consent mode?
Google's consent mode requirement is written for those receiving user data from end users in the European Economic Area. A site whose audience is entirely outside the EEA is not covered by that requirement, but local law may still require a consent mechanism. In Israel, Amendment 13 to the Privacy Protection Law took effect on 14 August 2025 and requires active, explicit consent rather than implied consent. Any business advertising or selling into Europe is inside Google's requirement regardless. Treat this as a legal decision.
What is the difference between basic and advanced consent mode?
Under basic consent mode tags are entirely blocked until the user interacts with the banner, and nothing at all is sent to Google beforehand, not even the consent status. Under advanced consent mode tags load immediately with defaults set to denied, and when consent is denied cookieless measurements are still sent. The consequence is that basic mode receives a general conversion model while advanced mode receives a more accurate advertiser-specific model.
Does server-side tagging remove the need for consent?
No. Server-side tagging changes where tags execute, not whether consent applies. The web container still collects consent, and the server container fires tags according to the signals it receives. Google publishes a dedicated document on implementing consent mode with server-side Tag Manager.
What is Google tag gateway for advertisers?
It is the capability that lets you serve Google's script from your own domain using your existing CDN, load balancer or web server, so that some measurement requests are also sent in a first-party context. The earlier name for this idea was first-party mode, and that documentation URL now returns a 404. Google recommends combining it with server-side tagging and a mapped custom domain.
How many tags are too many in one container?
Google does not publish a maximum tag count. It publishes a Size indicator that appears on the Versions pages of large containers. The official rule is that above 70% you should optimise: remove unused tags and variables, and split a container spanning multiple sites into separate containers.
Why do my Google Ads conversions not match my lead count?
Three common causes, in the order worth checking them: a tag firing more than once on the same thank-you page, which inflates the count; conversions defined on a page view or a click rather than on an actual form submission; and leads arriving by phone or WhatsApp that never pass through a form at all, which deflates it. A gap of up to ten percent against the CRM is reasonable; more than that is a measurement problem.




