Consent Mode on Arab Websites: What 29 Brand Homepages Actually Run

Arab brand websites load ad tags but rarely tell Google about consent. In our crawl of 29 Arab brand homepages on 2 October 2026, a Google tag ran on 20, yet only 3 of those 20 (15%) declared a Consent Mode default. Sixteen ran in Google’s implicit state, where tags behave as if every visitor said yes.
Key takeaways
- 20 of 29 homepages ran a Google tag within 4.5 seconds. 3 declared a Consent Mode default, and only 1 completed the default-then-update flow.
- 16 of those 20 sites declared nothing, so Google’s tags treated every visitor as consenting.
- Ad pixels were common: Meta on 12 sites, TikTok on 9, Snap on 7, X on 5. Four sites ran all four. A consent platform showed up on 4.
- Google requires consent signals for visitors in the EEA, the UK and Switzerland. Saudi, UAE and Egyptian law require a lawful basis and clear notice, but none names Consent Mode.
- Egypt’s one-year transition under the Executive Regulations of Law No. 151 of 2020 ends on 1 November 2026, according to law firm summaries.
What did we find on 29 Arab brand homepages?
Ad tags were common and consent signals were rare. Across 29 homepages from Saudi Arabia, the UAE, Egypt, Qatar and Kuwait, 20 ran a Google tag within 4.5 seconds and 11 ran a Google Ads tag. Only 3 declared a Consent Mode default, and 2 of the 4 sites with a consent platform sent Google no default at all.
| Signal in the live page (2 Oct 2026) | Sites | Base |
|---|---|---|
| Google tag running within 4.5 seconds | 20 | 29 homepages |
| Google Ads (AW-) tag running | 11 | 29 homepages |
| Consent Mode default declared | 3 (15%) | 20 with a running Google tag |
| Default and update both ran | 1 | 20 with a running Google tag |
| Update ran with no default | 1 | 20 with a running Google tag |
| Implicit state (no default declared) | 16 | 20 with a running Google tag |
| Consent management platform detected (2 OneTrust, 2 IAB TCF API) | 4 | 29 homepages |
| Meta / TikTok / Snap / X pixel in the page | 12 / 9 / 7 / 5 | 29 homepages |
| All four ad pixels together | 4 | 29 homepages |
| GTM container in source, nothing running in 4.5 seconds | 3 | 29 homepages |
| Google tag script served from the brand’s own domain | 2 | 29 homepages |
No market stands out. None of the 6 Saudi homepages with a running Google tag declared a default, though one Saudi retailer sent an update without one.
| Country | Homepages reached | Google tag running | Consent default declared |
|---|---|---|---|
| Saudi Arabia | 9 | 6 | 0 |
| UAE (one regional retailer served its Egypt store to us) | 7 | 3 | 1 |
| Egypt | 9 | 7 | 1 |
| Qatar | 2 | 2 | 1 |
| Kuwait | 2 | 2 | 0 |
| Total | 29 | 20 | 3 |
All 3 defaults sat on Google Ads sites, leaving 8 of 11 Google Ads sites with none. None of the 4 sites running all four social pixels declared one.
What is Consent Mode, and how do basic and advanced differ?
Consent Mode is Google’s API for telling its tags what a visitor agreed to. You set a default state before any tag fires, then send an update when the visitor answers your banner. GA4, Google Ads, Floodlight and the Conversion Linker read that state and change what they store and send.
Version 2 arrived in November 2023 and added two parameters to the original pair. Google’s Consent Mode overview (updated 30 July 2026) describes them as follows.
| Parameter | What it controls | What changes when it is denied |
|---|---|---|
| ad_storage | Advertising cookies and device identifiers | No ad cookies written or read; Ads truncates IP addresses |
| analytics_storage | Analytics cookies, such as visit duration | No GA4 first-party cookies; cookieless pings go to Analytics instead |
| ad_user_data | Sending user data to Google for advertising | user_id and hashed enhanced conversion data are off |
| ad_personalization | Personalised advertising | Remarketing in Google Ads, DV360 and SA360 receives no data |
The two implementations differ in what reaches Google before a choice. Basic blocks Google tags until the visitor interacts with the banner, so a visitor who declines sends nothing, not even the consent state, and Ads falls back to a general model. Advanced loads tags at once with your defaults, sends cookieless pings while consent is denied, and earns an advertiser-specific conversion model.
Is Consent Mode required for sites in Saudi Arabia, the UAE and Egypt?
Google requires consent signals only for visitors in the European Economic Area, the UK and Switzerland. No Saudi, UAE or Egyptian law names Consent Mode or mandates a cookie banner. Those laws do require a lawful basis for processing personal data and clear notice to the person, and ad pixels process personal data.
This is our reading of official texts, not legal advice. Confirm your setup with counsel.
- Google’s EU user consent policy requires consent from end users in the EEA, the UK and Switzerland on any site under your control. Google Analytics help says that, without those signals, linked ad audiences have excluded EEA users since early March 2024.
- In Saudi Arabia, the PDPL and its Implementing Regulation contain no cookie article. SDAIA’s Privacy Policy Guideline (August 2024) asks policies to name cookie data and cookie-based collection, with a purpose and legal basis. Our Saudi PDPL guide for marketers covers the detail.
- In the UAE, Federal Decree-Law No. 45 of 2021 has applied since 2 January 2022. The government’s u.ae summary says it prohibits processing personal data without the owner’s consent, apart from listed exceptions.
- In Egypt, the Executive Regulations for Law No. 151 of 2020 were issued in late 2025, according to a law firm briefing that puts the compliance deadline at 1 November 2026. Check the current status with your counsel.
EU visitors count too. A Dubai developer selling to London buyers, or a Saudi retailer with expats browsing from Germany, falls under Google’s policy for those sessions.
How do you check any site’s consent state in two minutes?
Open the page in Chrome, wait five seconds, and read Google’s consent object from the DevTools Console. Then confirm in Tag Assistant, which lists an On-page Default and an On-page Update column for each consent type. Together they show whether a default exists, whether the banner updates it, and which pixels load before anyone clicks.
- Open the homepage in a clean Chrome profile and leave the banner untouched.
- Paste the snippet below into the Console.
google_tag_data.icsis an undocumented internal object, so treat it as a quick read, not proof. - Run Tag Assistant on the same URL, select the earliest Consent event, and check that all four parameters were set. Then accept the banner and check the latest Consent event.
- In the Network tab, filter for
collectand look for thegcsandgcdparameters, which carry the consent state.
// Paste into the DevTools Console after the page settles
const ics = window.google_tag_data && window.google_tag_data.ics;
console.log('default ran:', ics && ics.usedDefault, '| update ran:', ics && ics.usedUpdate);
console.log((window.dataLayer || []).filter(e => e && e[0] === 'consent'));
console.log({ meta: typeof fbq, tiktok: typeof ttq, snap: typeof snaptr, x: typeof twq });
A result of usedDefault: false with tags running is the implicit state we saw on 16 sites.
What is the correct order for the consent default and update?
The default command must run before the Google tag loads and before any config or event command. Your banner then calls update the moment the visitor chooses, and again on every later page from the stored choice. Google’s own guide is blunt about order: “If your consent code is called out of order, consent defaults won’t work.”
The snippet below denies everything by default for the EEA, the UK and Switzerland, then applies a second default to every other region, including Saudi Arabia, the UAE and Egypt. The second block is an example policy, not a recommendation for your business. Choose it with counsel.
<script>
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
// 1. EEA + UK + Switzerland: deny until the visitor chooses
gtag('consent', 'default', {
'ad_storage': 'denied',
'ad_user_data': 'denied',
'ad_personalization': 'denied',
'analytics_storage': 'denied',
'region': ['AT','BE','BG','HR','CY','CZ','DK','EE','FI','FR','DE','GR','HU','IE',
'IT','LV','LT','LU','MT','NL','PL','PT','RO','SK','SI','ES','SE',
'IS','LI','NO','GB','CH'],
'wait_for_update': 500
});
// 2. Every other region (SA, AE, EG and the rest): your documented policy
gtag('consent', 'default', {
'ad_storage': 'denied',
'ad_user_data': 'denied',
'ad_personalization': 'denied',
'analytics_storage': 'granted',
'wait_for_update': 500
});
gtag('set', 'ads_data_redaction', true);
gtag('set', 'url_passthrough', true);
</script>
<script async src="https://www.googletagmanager.com/gtag/js?id=G-XXXXXXX"></script>
<script>
gtag('js', new Date());
gtag('config', 'G-XXXXXXX');
// 3. Call from the banner's Save handler, and on each page load from the stored choice
function applyConsent(choice) {
gtag('consent', 'update', {
'ad_storage': choice.ads ? 'granted' : 'denied',
'ad_user_data': choice.ads ? 'granted' : 'denied',
'ad_personalization': choice.ads ? 'granted' : 'denied',
'analytics_storage': choice.analytics ? 'granted' : 'denied'
});
}
</script>
Region codes follow ISO 3166-2, and the most specific region wins. A default without a region covers everyone else; with no default at all, Google treats the state as granted. wait_for_update gives an async banner 500 milliseconds to answer. Consent Mode does not store choices, so persist them in a first-party cookie and replay the update on each page, per Google’s website setup guide.
In Google Tag Manager, load the banner on the Consent Initialization trigger, ideally through a Community Template Gallery CMP template, and use updateConsentState rather than gtag('consent','update'), which Google says can be queued too late.
Not sure your own container fires in this order? Check my tag order and consent setup.
How do you gate Meta, TikTok, Snap and X pixels on consent?
Google’s consent state does not reach other vendors’ pixels. Meta and TikTok each ship their own consent calls, so wire them to the same banner handler as the Google update. For Snap and X we found no equivalent public command, so the reliable gate is not loading their scripts until the visitor grants advertising consent.
| Pixel | Sites in our crawl | Consent control | Gate it this way |
|---|---|---|---|
| Meta | 12 of 29 | fbq('consent','revoke') before init, fbq('consent','grant') on accept |
Call revoke on every page, as Meta’s developer docs require |
| TikTok | 9 of 29 | ttq.holdConsent(), ttq.grantConsent(), ttq.revokeConsent() |
Hold before the first page event, grant or revoke from the banner |
| Snap | 7 of 29 | None found in the public script | Load snaptr only after ad consent |
| X | 5 of 29 | None found in the public script | Load twq only after ad consent |
We confirmed the three TikTok methods exist in TikTok’s live pixel library on 2 October 2026. In GTM, set each non-Google tag’s Additional Consent Checks to “Require additional consent for tag to fire” with ad_storage, and the tag stays silent until the update arrives. The OpenAI Pixel needs the same treatment, as our ChatGPT Ads conversion tracking guide explains.
What happens to GA4 numbers when you switch consent on?
Reported users and conversions drop for every visitor who declines, unless GA4 can model them. Behavioral modeling needs advanced mode on every page, at least 1,000 events a day with analytics_storage denied for 7 days, and at least 1,000 daily consenting users on 7 of the previous 28 days.
Those thresholds come from Google’s behavioral modeling article, which adds that meeting them does not guarantee eligibility. A mid-size Arab brand site with a few hundred daily users never reaches the bar, so its GA4 totals simply fall after launch. Basic mode gets no GA4 modeling at all, because declining visitors send nothing.
Three habits keep the numbers readable:
- Annotate the launch date in GA4 and Google Ads, so nobody reads the drop as an SEO or campaign failure.
- Scope the strict default to the regions that need it, so measurement elsewhere follows your chosen policy instead of collapsing everywhere.
- Remember the other blind spots. Our study of how GA4 classifies AI traffic for Arab sites shows a second undercount.
A consent banner without modeling is a measurement change, and it needs a dated note in every report.
Where does server-side tagging fit?
Server-side tagging changes where tags run, not whether a visitor consented. The browser still reads the banner, and the Google tag passes the consent parameters to your server container with each request. The server container then fires vendor tags according to those signals. Two sites in our crawl served the Google tag script from their own domain.
Google’s server-side consent guide requires a web container that collects consent, a server container, and a GA4 client in the server container to receive the consent data. The gain is control, with one first-party endpoint and one place to block a vendor. The risk is a server container that forwards events to Meta or TikTok without checking the consent parameters, which bypasses the banner entirely.
How we checked
We loaded each brand’s Arabic homepage in desktop Chrome on 2 October 2026, waited up to 4.5 seconds, then read the live page with JavaScript. We recorded Google tag IDs, Google’s consent object, consent platform globals and the Meta, TikTok, Snap and X pixel functions. The result is a snapshot of 29 sites, not a census.
- One page per site, one visit. Tags that load on scroll, click or after consent are not counted. The 3 sites with a GTM container in the source and nothing running most likely defer loading.
- The 4.5-second window cuts off deferred loading by design.
- Our connection was in Cairo, and at least one regional retailer redirected us to its Egypt store.
- No Core Web Vitals field data was collected.
- 8 of 37 sites (22%) returned a bot challenge or a blank page and are excluded. We did not try to bypass any challenge.
Our read
Declare a consent default on every Arab site that runs a Google tag, even where no local law names Consent Mode. The implicit state leaves you unable to show what your tags did for a given visitor, and EU visitors already trigger Google’s policy. The fix is a few lines of code placed in the right order.
The weak point in our data sits between the banner and the tags. Two of the four sites with a consent platform still sent Google no default, which means a CMP was bought and never wired to the tags it exists to control. Wiring it, plus the Meta and TikTok consent calls, is a small developer task next to the cost of the platform.
A more useful test than any regulator’s question is this: can you say, for any visitor, which tags fired and on what basis? If you can, add region-scoped defaults for EEA, UK and Swiss traffic. If you cannot, run the two-minute check on your homepage and fix the order before touching the banner design.
Want a developer to do that audit for you? Audit my tags, pixels and consent order. If those GA4 numbers also drive your search reporting, help me read my SEO data after the consent change.
FAQ
Is a cookie banner legally required in Saudi Arabia?
Neither the Saudi PDPL nor its Implementing Regulation contains a cookie article or mandates a banner. SDAIA’s Privacy Policy Guideline does require privacy policies to name cookie data and to list cookies and website analytics as collection methods with a purpose and legal basis. This is our reading of the texts, not legal advice.
Our site only targets the Gulf. Do we still need Consent Mode?
Google’s EU user consent policy applies to visitors in the EEA, the UK and Switzerland on any site you control, wherever your company is based. Gulf sites receive expat and travel traffic from Europe. A region-scoped default denies consent for those visitors only and leaves your chosen policy in place for Saudi, UAE and Egyptian visitors.
Will Consent Mode lower our GA4 and Google Ads numbers?
Yes, for every visitor who declines. GA4 models the gap only in advanced mode, and only once a property logs at least 1,000 denied events a day for 7 days plus 1,000 daily consenting users. Smaller sites miss that bar, so annotate the launch date and compare trends rather than raw totals.
We use GTM. Where do the consent settings go?
Load your consent banner on the Consent Initialization trigger, ideally through a CMP template from the Community Template Gallery. Set non-Google tags to require additional consent, such as ad_storage, under Advanced Settings. Inside GTM templates, use updateConsentState instead of a gtag update call, which Google warns can be processed too late for the next event.
What does an implicit consent state mean in our tag setup?
It means no Consent Mode default was declared before your Google tags ran. Google’s documentation treats an unspecified state as granted, so tags write cookies and send full data for every visitor. In our October 2026 crawl, 16 of the 20 Arab homepages with a running Google tag were in this state.
Everything else we have run on Analytics & Measurement
Written by whoever ran the work, not a content team
6 articlesRead also
All Analytics & Measurement
Tracking WhatsApp, Call and Map Clicks in GA4: GTM Recipes for Arab Websites

Server-Side Tagging for Arab Websites: Hosting Regions, First-Party Domains and Data Laws

Tracking ChatGPT Ads Conversions in the Gulf: What OpenAI Measures, What GA4 Sees, and How to Set It Up (2026)

How GA4 Classifies AI Traffic for Arab Websites: What Saudi, UAE and Egyptian Sites Lose (2026 Study)
