Cookie banners and GA4: how big is your data gap really?

Your GA4 numbers are not wrong, they are incomplete, and always in the same direction. How to estimate your consent rate against Search Console, and how to work with the gap anyway.

12 minute readUpdated August 29, 2026Read in German

An accountant in Portland opens her GA4 report: 1,180 users last month. Then Search Console, same date range, 2,900 clicks from Google search. Same site, same thirty days, one tool showing double the other. First thought: one is broken.

Neither is. The difference lives in the grey box every visitor dismisses before they see your page. This piece explains why the gap exists, how to estimate its size in ten minutes, and which four wrong conclusions people draw from it. Fair warning: a measurement guide, not legal advice.

Why GA4 systematically undercounts

Google Analytics recognises a visitor by a cookie in the browser. No cookie, no identifier; no identifier, no session; no session, no row in the report. And the cookie may only be set once someone has agreed in the banner.

Legally that sits on two layers in Europe: the ePrivacy rules require consent before storing or reading information on a device, and the GDPR governs what happens to the data afterwards. In practice: no click on "Accept", no measurement. How you build your banner and which exemptions apply are questions for a lawyer, not an SEO article.

The upshot: your GA4 numbers are not wrong, they are incomplete, and in a known direction. Always too low, never too high. Not knowing your consent rate means not knowing whether you are looking at a third of reality or four fifths. Both feel the same in the report.

Consent Mode is Google's plumbing for passing consent to the Google tags: your banner sets signals, the tags read them. For Analytics only analytics_storage matters; advertising adds ad_storage, ad_user_data and ad_personalization. The last two were the new part of Consent Mode v2, mandatory for EEA advertisers since March 2024.

Two implementations exist, and they differ more than the names suggest.

BasicAdvanced
Before the choicetag does not loadtag loads, throttled
On rejectionnothing leavescookieless ping, no identifier
Modelling possiblenoabove enough volume

With basic, the Google tag only loads once someone has agreed. If the visitor rejects, or clicks nothing, exactly nothing happens: your gap is a real gap.

With advanced, the tag loads immediately but throttled. On rejection it sends a cookieless ping: a sign of life without an identifier, telling Google "there was a pageview here, I am not allowed to say whose". From those Google can estimate how many users and events sat behind the rejections. The price: rejecting still creates a connection to Google. Whether that is acceptable is not a blog post's call, including this one's.

Modelled conversions only appear above a certain volume

This is where most guides get it wrong: modelling is not a switch you flip, it is a state your property falls into or not.

Google names two thresholds for behavioural modelling in GA4: at least 1,000 events per day with analytics_storage denied for at least seven days, and at least 1,000 daily users sending events with consent granted on seven of the previous 28 days. The documentation itself adds that hitting those numbers guarantees nothing, because the model weighs further criteria such as the ratio of new to returning users. The thresholds are only loosely documented.

For small sites the consequence is uncomfortable: you will never reach them. A thousand denied events a day means a few hundred rejections daily. A trade business with 3,000 visitors a month sits an order of magnitude below. At that size, setting up advanced mode and waiting for modelled numbers is a disappointment you can see coming.

And even if you clear the bar, modelled data only appears when Admin → Data display → Reporting identity is set to Blended. Leave it on "Observed" and Google models in the background, showing you none of it.

The trick: Search Console data knows nothing about cookie banners. It is generated on Google's side, the moment someone clicks in the results list. Whether your banner is then ignored, rejected or accepted is irrelevant to that number, which makes it your honest baseline. No extra tool required, just two reports you already have:

  1. Search Console, Performance report, one full month. Note the clicks.
  2. GA4, Reports → Acquisition → Traffic acquisition, same range, channel "Organic Search". Note the sessions.
  3. Divide sessions by clicks.

Example from a plumbing firm in Manchester: 4,200 clicks in Search Console, 2,500 organic sessions in GA4. Ratio 0.60. Roughly 60 percent of Google's recorded clicks reaches your reports.

That 60 percent is not your consent rate, though. Equating them makes the banner look worse than it is: three other causes hide in the same difference.

  • A click is not a session. Someone arriving twice in a day from search produces two clicks but, depending on timing, one session.
  • Bounces before the tag fires. Anyone hitting back before the tag loads appears in Search Console and never in GA4. On slow pages and on phones this is a noticeable share. To see both numbers side by side, connect GA4 and Search Console.
  • Device switching. Click on the phone, visit later on the laptop: that second visit may no longer count as organic in GA4 but as direct traffic.

As a rough working figure: five to fifteen percentage points of that difference come from those three causes, the rest from the banner. At 0.60 your consent rate is around 65 to 75 percent. An estimate, not a measurement, and write it down that way.

The second baseline costs one login: the traffic figures in your hosting panel or server log. Every request is in there, whatever happened in the banner. Bots inflate it, but for a sanity check that is plenty.

Four wrong conclusions the data gap produces

Most Consent Mode guides stop at the setup. But the gap is not the problem, what you build on it is.

The traffic drop that is actually a consent drop. An online shop swaps its consent tool on 3 March. From 4 March GA4 shows a third fewer sessions. A week of panic follows. What happened: the new banner made "Accept all" small and grey, and the rate fell from 72 to 48 percent. If Search Console clicks stay flat over the same period, it is not a traffic problem. Only when both curves fall have you lost visibility, and then lost rankings is next.

Period comparisons across a banner change. "Last 30 days versus previous period" is worthless if the banner was swapped, the button order changed or the consent tool updated in between. You are comparing two instruments. Write those changes down, dated.

Conversion rates that look too good. The subtlest error and the most expensive. When Google models your conversions but the sessions in the denominator are measured, an extrapolated number sits on a non-extrapolated one. The rate comes out too high, and anyone allocating ad budget on it overrates their best campaign. If the conversion never reaches GA4 at all, consent is usually not the cause, the setup is: see GA4 conversion not showing.

Channel comparisons with different consent rates. Visitors from a newsletter know you and dismiss the banner on autopilot, often by accepting. From a cold Google search they are warier, and on a phone the banner covers more screen. So "email converts far better than organic search" may be an insight about your channels or about your banner rate per channel.

Wording first. A banner that says in one sentence what is measured and why gets more agreement than a wall of legalese. "We look anonymously at which pages get read, so we improve the right ones" is understandable; four paragraphs on data processing agreements are not.

Equal weight for the buttons is where this gets legally serious. A big coloured accept button next to a grey text link saying "Reject" is a dark pattern, it draws complaints, and regulators do not treat it as valid consent. The rate you win that way can cost you the dataset entirely. Same size, same prominence, equally easy to reach.

Timing matters more than people expect. A banner landing 300 milliseconds into an empty page gets dismissed reflexively; one appearing after the visitor sees they landed in the right place gets a real decision. Same for order: one sentence of benefit before the list of categories. The honest route to a better rate is a banner that explains briefly rather than nags.

Working with the gap instead of against it

Work with relative movement rather than absolute numbers. "The landing page has 18 percent more sessions than last month" holds up, as long as nothing changed in the banner. "We had 2,500 visitors" does not, because that figure is too small by construction.

Determine a conversion factor once and write it down. At a click-to-session ratio of 0.60, 2,500 organic sessions is roughly 4,000 real visits for the board slide. The factor belongs in a dated note, rechecked twice a year.

Split the jobs: Search Console is the source of truth for reach, meaning clicks, impressions, positions. Analytics is the source of truth for behaviour, meaning click paths, engagement time, conversions. The sample behind those patterns is incomplete, but not skewed. How to read it is covered in reading GA4 reports.

Shrinking the gap technically takes one of two roads, both costly. Server-side tagging moves processing into your own container, usually in Google Cloud: it routes around ad blockers and browser restrictions, but not the consent requirement, and it carries ongoing maintenance. Log analysis is the only complete method: every request, but no interaction inside a page, and you filter bots yourself. For small companies the sober answer is usually neither: know your factor and account for it.

Where to start

  1. Note Search Console clicks and organic GA4 sessions for the same completed month; form the ratio.
  2. Check whether your consent tool reports accept and reject counts. Many do, and then you have the rate directly.
  3. Check whether Consent Mode is active and in which variant. If your banner just blocks the Google tags without setting signals, you are running basic.
  4. Start a text file listing the date of every banner change, one line each.
  5. Put your conversion factor wherever you report numbers, so nobody mistakes the GA4 figure for reality.

Point four pays off later. Traffalyzer logs drops in Search Console data with dates, keeping that cross-check ready; by hand, a text file does the same job as long as somebody keeps it up.

Frequently asked questions

Why does GA4 show fewer users than Search Console?

Because Search Console clicks are recorded on Google's side and know nothing about cookie banners, while GA4 only counts once a visitor has consented to analytics storage. Three smaller causes add to it: repeat clicks from one person can be a single session, visitors leave before the tag fires, and device switches move the second visit into another channel. A ratio below 1.0 is normal, not a fault. What should worry you is it changing suddenly.

What is a normal consent rate?

There is no benchmark anyone can quote in good conscience, because the rate depends heavily on country, banner design, industry and device. A single percentage sold as an industry average came from a source that does not match your site. Only your own number is useful: get it from the Search Console comparison or your consent tool's statistics, then track it against its own history.

What are modelled conversions?

When a visitor rejects consent, Google cannot measure their conversion. Instead it estimates, from the cookieless pings and the behaviour of comparable users who did consent, how many conversions sit inside the rejected group. That estimate appears in the report looking measured. It is an extrapolation, and dividing it by measured sessions skews the rate upward.

Do I need Consent Mode v2?

If you run Google Ads in the EEA or use Google advertising data, you have no way around it; that has been the condition for Google accepting the data since March 2024. Running GA4 alone with no ads connection, it is not compulsory, but without it you have no chance of modelled data. And for whether your setup is legally clean, Consent Mode replaces no document: it transmits signals, it does not obtain consent.

Is Google Analytics allowed without a cookie banner?

Under the ePrivacy rules, consent is required before information is stored on or read from a device, and analytics cookies are not generally treated as strictly necessary. In practice: no consent, no analytics cookie. That is orientation, not legal advice. For a binding assessment, ask a qualified lawyer in your jurisdiction.

Why did my numbers drop after the new cookie banner?

Because a new banner changes the consent rate, and with it the size of the slice GA4 can see. Typical triggers: a different default selection of categories, a less prominent accept button, a changed button order, or a banner that fires earlier than before.

The test takes two minutes: compare Search Console clicks over the same period. Flat there and falling in GA4 means the consent rate, not your rankings.

Can I get data for visitors who rejected, after the fact?

No. For a visitor who rejected, no raw data exists to collect later. All Google offers is modelling, starting from the point your property qualifies, and it does not apply retroactively. To prove reach for a past period, use Search Console or your server log: both saw the visits, banner or no banner.

What is the difference between basic and advanced Consent Mode?

With basic, the Google tag only loads after consent. Anyone who rejects leaves no trace, so there is nothing to model. With advanced, the tag loads immediately and sends a cookieless ping without an identifier on rejection, which Google uses to estimate what sat in the gap. The catch: that estimate only starts above roughly 1,000 denied events per day for a week or more. Small sites set up advanced mode and still never see a modelled number.

Keep reading