After adding a cookie banner to your site with Google Analytics 4, you notice fewer users in your reports and your ad campaigns show fewer conversions. This is not a bug — it is a natural consequence of asking for consent. In this article, I explain why this happens, how the two versions of Consent Mode differ, and what Polish law says about it. You will also learn how to check which configuration your site uses and what to do to keep your analytics reports readable despite these restrictions.
If you run a business in Poland and want your website to comply with regulations, this text will help you understand what happens with your visitors' data and what options you have.

Why you see less data in GA4 after the cookie banner
When a cookie banner asking for consent appears on your site, the user makes a choice: they agree or they refuse. In either case, the behavior of the analytics system changes compared to when data was collected without asking.
In the basic version, Google tags — including Google Analytics 4 — do not fire at all until consent is given. This means that a user who clicks "Reject" or closes the banner without making a choice will not be counted in the statistics. Even if they later browse the site, add products to the cart and complete a purchase, these actions will not appear in GA4.
In the advanced version, tags load by default but with a limited data set. Only when the user gives consent does the system expand the scope of collected information. The difference is that in the advanced version you have partial data even from users who refused consent — in the basic version this data does not exist at all.
In practice, this means that after implementing a banner that complies with legal requirements, the number of visits in GA4 drops — this is normal, not a failure. You cannot precisely estimate this drop because it depends on your industry, target audience, and the banner design itself.
Article 399 of the Electronic Communications Law — what the law says
The Polish act of July 12, 2024 — Electronic Communications Law (Dz.U. 2024 poz. 1221) — regulates the storage and access to information on users' devices. Article 399 states that storing information or gaining access to information already stored on the user's terminal equipment is allowed under three conditions.
First, the user must be informed in advance in a clear, easy and understandable way about the purpose of storing and accessing this information and about the possibility of defining conditions through software settings or service configuration. Second, the user must give consent after receiving this information. Third, the operation itself must not cause configuration changes on the user's device.
Exceptions apply when storage or access is necessary to carry out electronic communication transmission or to deliver a service requested by the user — in these cases consent is not required. In practice, this means that a cookie banner must clearly inform about the purpose, give the possibility to choose, and not force default consent.
According to Article 399 of the Electronic Communications Law, storing information or accessing information on a user's terminal device is allowed after prior user information and consent. The full text of the act is available in the Journal of Laws.
Whether your specific implementation complies with these requirements — assess a lawyer or DPO (Data Protection Officer). Article 399 provides the framework, but each case may be different.
The four Consent Mode signals — what each means
Google Consent Mode passes four parameters to advertising and analytics systems indicating the user's consent status. Each of them controls a different scope of data. Understanding these parameters is key to managing consents on your site consciously.
How parameters affect ad performance
If you run campaigns in Google Ads, you need to know how each signal affects their performance. When a user refuses ad_storage consent, Google pixels won't track user behavior on other sites — this means remarketing (showing ads to people who visited your site) won't work for those people. At the same time, if a user gives consent only for analytics_storage but refuses ad_user_data, your campaigns will still see traffic but without user-identifying data.
Why measuring e-commerce matters
For online stores, tracking purchase events is crucial. GA4 measures e-commerce with events such as add_to_cart (adding to cart), begin_checkout (starting the checkout process), and purchase (completed order). This data helps understand how many users actually make a purchase and how many abandon their cart. Read more about this in our article on reporting automation.
What official Google sources say
Google's developer documentation explains that Consent Mode allows two approaches: basic (blocks tags until consent is given) and advanced (tags run with default settings and adapt to consent). More details are available in the Google for Developers documentation.
ad_storage — controls whether advertising-related cookies can be stored. When a user refuses consent for marketing, this parameter has the value "denied", which means Google advertising tags will not store advertising identifiers or track user behavior for remarketing purposes.
ad_user_data — determines whether user data can be used for advertising purposes. Even if ad_storage is allowed, ad_user_data may be restricted, which affects the ability to send user data to Google Ads.
ad_personalization — controls personalized ads. When a user does not consent to personalization, the system will not show ads tailored to the user's previous behavior or create advertising profiles.
analytics_storage — controls analytics data collection. In the basic version, analytics tags do not fire until the user gives consent. In the advanced version, data is collected in a limited scope and expanded after consent is given. If you run a store and want to track purchase behaviors, you need this parameter set to "granted" after the user gives consent.
These four parameters work independently. For example, you can allow analytics (analytics_storage = granted) but refuse ad personalization (ad_personalization = denied). In practice, this means you can measure traffic and user behaviors but won't show them personalized ads in Google. The configuration depends on your business needs and legal requirements.

Basic or advanced — comparison table
The choice between basic and advanced versions affects how much data reaches your reports and how the system behaves toward users who refuse consent. The following table shows the key differences.
| Feature | Basic version | Advanced version |
|---|---|---|
| Tags before consent is given | Completely blocked | Loaded with default settings |
| Data from users who refused | No data | Partial data (without advertising identifiers) |
| Data from users who gave consent | Full data | Full data |
| Impact on GA4 reports | Visible drop after banner implementation | Smaller impact, but data may be incomplete |
In the basic version, you are certain that data is collected only from users who gave consent. This is the safer approach from a legal perspective, but it means that some traffic — those who refused or did not choose any option — will not be visible in analytics. If you run an online store, you might not see users who actually made a purchase but did not consent to tracking.
In the advanced version, you gain partial data even from users without consent, which allows for better understanding of behavior on the site. You can, for example, see that a user visited a product page, added it to the cart, but did not complete the purchase — and this even if they refused consent for marketing. However, the configuration is more complex and requires careful verification that it meets the requirements of Article 399. Incorrect configuration can lead to non-compliance or incorrect data in reports.
The choice depends on your priorities. If you value legal certainty and simplicity — choose the basic version. If you need more data for user behavior analysis and have resources for correct configuration — consider the advanced version.
How to check which version you have on your site
You do not need to know code to find out which Consent Mode version is implemented on your site. Here are four simple methods.
Test one: banner before any interaction. Open the site in incognito (private) mode. If the cookie banner appears automatically and Google tags (e.g., GA4, Google Ads) do not load until you make a choice — you have the basic version. If tags load immediately but with limited data scope — this is the advanced version.
Test two: check via Tag Assistant. Open your site in a browser and add the Tag Assistant extension for Chrome. After launching, go to your site and open Tag Assistant — on the Consent tab you will see the current consent status for each parameter. More details in the Google documentation.
Test three: ask your contractor. Ask the person or company that set up your analytics: "Are we using Consent Mode? Is it basic or advanced? What are the default values for ad_storage and analytics_storage?" A professional contractor should know the answer.
Test four: the Network tab in developer tools. Open the site in incognito mode, press F12 and switch to the Network tab before clicking anything in the banner. If at that moment you see no requests to Google servers at all (for example to google-analytics.com or googletagmanager.com) — you have the basic version: tags wait for your decision. If requests to Google appear immediately, before you choose anything in the banner — you have the advanced version: tags load with restricted default settings and send so-called cookieless pings, which register only the fact of a visit without user identifiers. In both versions the default consent value in the code is denied — the difference is not in that value, but in whether requests to Google go out at all before your choice.
Additionally, record the banner implementation date in your analytics journal or spreadsheet — you will need it for comparing periods later. Also note what the average daily number of users was in the month before implementation — this will serve as your reference point.
What the data in reports means after banner implementation
Once you know which version you have, you need to be able to read reports in the context of the changes made. Comparing the period before the banner with the period after it without considering this fact leads to wrong conclusions. You might, for example, incorrectly evaluate the effectiveness of an advertising campaign if you don't account for the drop resulting from the banner implementation.
In GA4, select the period before implementation and note the number of users, sessions and conversions. Then select the period after implementation and compare the same metrics. The drop is natural — it results from the fact that some users did not give consent for tracking. Note the exact implementation date and compare data in full weeks or months so the results are comparable.
Write down the banner implementation date next to your GA4 chart or in a separate spreadsheet — without that date, comparing periods before and after does not make sense. It also helps to keep a note there of which Consent Mode version was set at the time, so you are not guessing months later.
Remember that GA4 measures e-commerce with events such as add_to_cart, begin_checkout, and purchase. The number of these events can also drop if users who refused consent are no longer tracked — the same mechanism applies to them as to any other GA4 event. If you notice a drop in conversions, first check how many users gave consent before concluding that the problem lies in the site or offer itself.
What to avoid when implementing a banner
Not every solution meets legal requirements and not every one provides useful data. Here are the most common mistakes to avoid.
Banner that does not block anything. If the banner is displayed only as information and does not affect tag behavior, it does not meet the requirements of Article 399. The user must have a real possibility to refuse consent, and the system must respect that refusal.
"Accept" button without "Reject" option. The law requires that the user can choose — agree or refuse. Hiding the refusal option or making it difficult to find violates the principle of clarity and voluntariness of consent.
Default consent without explicit user action. You cannot assume that the user gives consent by simply browsing the site. There must be an active choice.
Whether a specific case is legally compliant — assess a lawyer or DPO. The above guidelines are general, not legal advice.
Check yourself — what you have on your site
Before contacting a specialist, you can do a basic audit yourself. It will take a few minutes.
First, make a list of all tags on your site related to Google: GA4, Google Ads, Floodlight, Tag Manager. Check which of them are for advertising (ad_storage, ad_user_data, ad_personalization) and which for analytics (analytics_storage).
Second, establish the cookie banner implementation date. Write it down — you will need it when comparing periods in reports.
Third, check the Consent Mode version using one of the methods described above. Write down what the default consent parameter values are for new users.
Fourth, compare reports before and after implementation. Note how much the number of users and conversions dropped — this is your baseline for further analysis.
How it looks when a system handles analytics
When a system takes over consent management, the process looks like this:
- 01Consent in the banner
- →02signals in Google tags
- →03reports with period marking
- →04verification in CRM
The visitor sees the banner and chooses consent or refusal, the system passes the matching signal to Google tags (ad_storage, ad_user_data, ad_personalization, analytics_storage), the tags behave accordingly, and the data lands in GA4 reports marked with the implementation period. It is worth comparing the results with actual CRM records to check how many of those users actually placed an order or asked for a service.
This solution does not guarantee that you will "recover" the "lost" data — it simply cannot be collected without consent. However, the system gives you tools for conscious management of this process and for transparent reporting.
Check how Analytics and BI works — you start with a free preliminary audit, then get ongoing measurement of inquiries, calls and bookings. If you need help with Websites and stores, Google Ads campaigns, Meta Ads campaigns, or UX and conversion that work according to requirements, contact a specialist. Learn more about automation and GDPR, reporting automation and why customers don't leave inquiries.
Frequently asked questions
Is a cookie banner mandatory in Poland?
Yes, if you use cookies or other tracking technologies on your site. Article 399 of the Electronic Communications Law requires that the user be informed about the purpose and possibility of managing consents before data is stored on their device. Exceptions apply only to necessary technical files.
Can I use GA4 without user consent?
Not fully. After the user gives consent, GA4 collects full data. If the user refuses, in the basic version data will not be collected at all, and in the advanced version — only in limited scope.
Is the advanced version better than the basic?
It depends on the goal. The basic version is legally safer and simpler to configure. The advanced version gives more analytics data but requires more careful configuration and verification that it meets legal requirements. The choice depends on your priorities: legal certainty or more data.
What to do if conversions in ads dropped after the banner?
The conversion drop after banner implementation may result from users who were previously tracked by ad pixels now not being tracked. Check if Consent Mode is enabled in Google Ads — without this, remarketing does not work. Also consider comparing periods with the banner implementation date taken into account.
Do I need a developer to implement Consent Mode?
Collaboration with a specialist who correctly configures Consent Mode — e.g. in Google Tag Manager or in a consent management platform — is recommended. Incorrect configuration can lead to non-compliance or incorrect data in reports. However, you can check which version you have yourself using the methods described.