Glossary

Tag manager

A container loaded once that can inject any number of other tags at runtime, which makes it a single point of control and a single point of failure for consent.

Examples
Google Tag Manager, Tealium, Ensighten
Scanner category
tag_manager
Risk
Tags that ignore consent

What it is, and why it is a special case

A tag manager is a container: one script that fetches a configuration and creates other tags according to rules that marketing can change without a deploy. That is its value and its hazard. What loads through it is not visible in your codebase and can change after you last verified the site.

Do not treat the container as one consent decision

Blocking a container entirely often breaks non-tracking tags that belong in necessary or functional; allowing it wholesale grants everything inside it. The workable answer is per-tag consent settings inside the container, with denied defaults established before it loads.

How StrongPrivacy handles a container

  • The container is loaded with denied Google Consent Mode defaults established before any tag runs
  • Consent updates are sent as the visitor’s selected categories change
  • Withdrawal sends updated denied states
  • Tags that ignore consent, and non-Google vendors inside the container, still need manual review

Verification means GTM Preview alongside the browser network panel, checking every individual tag in each consent state, not just confirming that the container itself waited.

Common questions

Should the tag manager be blocked until consent?

Usually not wholesale. Load it with denied defaults and gate the tags inside it. Blocking the container is a blunt instrument that tends to break functional tags and hide what is actually happening.

Why does the scanner have its own tag_manager category?

Because a container is not a purpose. Calling it analytics or advertising would misstate what it is: a delivery mechanism whose consent implications depend entirely on its contents.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.