Problem/Motivation
The module does not work correctly with Google Tag Manager. Our GTM setup loads only things which we want to use where consent is given. Therefore we block loading of GTM script unless consent is given. If the user clicks consent, GTM does load. On the other hand, if we do not show the banner outside the GDPR area (whether or not using the Varnish or non-Varnish setup), but default to allowing cookies only for non-GDPR users, these non-GDPR users never click 'OK'. Google Tag Manager does not register a page load or any other interaction which it can use as a trigger for its tags. Instead it returns a 404.
The result is that GTM does load for users who see the banner, with opt-in setup, if they click 'OK'. This works as expected. However, if with this setup we do not show the banner for users outside GDPR areas, GTM at least intermittently returns a 404 for those non-GDPR users who are not seeing the banner but defaulting to allow cookies.
Steps to reproduce
Proposed resolution
There is a workaround: check the user's location, and only remove / add back the JS files if the user is GDPR. Otherwise, if the user is not in a GDPR territory, bypass the code which disables and re-enables blocked files.
If there is any chance of getting a patch in for this, I will make one. However, as far as I can see there is no way to make this setup work with Varnish, so perhaps it would not be acceptable.
Remaining tasks
Get indication from maintainers whether the above patch would be an acceptable approach, and if so, make one for both D7 and D9.
User interface changes
Possibly a checkbox which switches off the 'disable JavaScripts' for non-GDPR users. Possible have two disabled JavaScript lists, one of which works for all users, one for GDPR users only.
API changes
Data model changes
| Comment | File | Size | Author |
|---|---|---|---|
| #17 | eu_cookie_compliance-3217266-does-not-work-with-geolocatlion-and-gtm-1.patch | 990 bytes | john_b |
Comments
Comment #2
svenryen commentedThat's an interesting issue. Thanks for bringing this up. From what I understand, you want consent to be given (cookie-agreed=2) for users that are not in the GDPR-area?
Comment #3
john_b commentedYes, we want to ask users in GDPR area to give consent manually, and avoid tracking them and serving Google Tag Manager if they do not give consent. We want users outside the GDPR area to be served cookies and scripts without any user interaction. We are a charity and as such subject to EU Cookie + GDPR rules, but exempted from Californian & smiliar rules in USA.
Comment #4
svenryen commentedSo currently when you use the Javascript based region detector, does it break for visitors that are not in the GDPR governed area, so that cookies are being deleted or not set?
Comment #5
john_b commentedYes, region detect (both JS-based tested with Varnish, and non-JS-based tested without Varnish) break for visitors not in GDPR area. However, the reason cookies are not set is because Google Tag Manager is not loading.
Our GTM uses a page view as a trigger for loading tags. We block loading Google Tag Manager script in EU Cookie Compliance module, pending consent. This works for GDPR users, either because when they click 'Accept' that completes a page load, or at least it provides some kind of interaction GTM can respond to. Where there is no user interaction, GTM is waiting for a trigger and never gets one. After a delay it returns a 404.
The 'official' way of integrating GTM with cookie compliance modules is to use clicking 'Accept' as a trigger in GTM to trigger tags. Though not tested, I doubt this would work for non-GDPR users, because they never interact with the banner. GTM does not appear to provide a trigger which responds to setting a cookie such as the 'Accept cookies' cookie.
Our way of integrating GTM is simpler: load GTM if the user accepts, otherwise not. (To make this work, it is necessary to disable the noscript version of GTM, and to load GTM as a file, not inline). This works well for GDPR users who must click to opt in. It is not working for non-GDPR users who are automatically opted in.
The issue is unaffected by whether we user JS or non-JS geolocation. It just seems to be that users who do not interact do not provide any trigger which GTM can use to trigger tags. My (non-Varnish friendly) solution is to add a condition to prevent the module blocking GTM and other scripts for non-GDPR users, so GTM is already present once the page view completes, with the result that GTM does receive a 'page view' trigger.
Comment #6
svenryen commentedOK, gotcha. We will test and see if this can be improved. It's likely, though, that we won't be able to tackle this one until version 2.0 is released.
Comment #7
john_b commentedI cannot think of a way to combine this with Varnish unles the Varnish geoip module is used, as the code must be un on firrst page load. Pehraps there is way.
Comment #8
svenryen commented@John_B, do you still have this issue?
Comment #9
john_b commentedYes, this is still an issue. And my fix is currently working. (We have removed Varnish, and use the JS version of EU Cookie Compliance geolocation).
My fix at eu_cookie_compliance.module l.439 is as follows:
Not the cleanest way to do it, but
eu_cookie_compliance_is_gdpr()refers toComment #10
john_b commentedThe same issue appears on Drupal 9.
In other words, our staging and live D7 sites are working normally because of the fix in the above post. Our staging D9 site has the issue.
Steps to reproduce:
1. Set up a Google Tag Manager container where an identifiable tag (in our case Google Analytics) fires, provided the page hostname matches a regex such as .*example\.com
3. Set up a site which is loading the GTM container set up in 1., with EU Cookie Compliance set to show banner only in GDPR countries.
[ Alternatively to steps 1 & 2 above, visit an existing site set up this way, such as our D9 staging site which I mentioned privately.]
3. Have a way to identify whether the tag in question is firing. E.g. Google Tag Assistant (Legacy) Chrome extension.
4. If in a GDPR country, use VPN to connect via non-GDPR address.
5. Clear cookies in browser.
6. Visit the site.
7. Notice that the GTM tag set up to fire on page load (in our case, GA) is not loading.
8. On second page load, once the EU Cookie Compliance cookies have been set, GTM works normally and the tags fire.
Comment #11
svenryen commentedHi again!
Can you provide some screenshots with highlights of the GTM tags being (and not being) loaded so that I know what to look for?
Comment #12
john_b commentedI have dropped images in Slack chat showing use of Google Tag Assistant. Also have removed my hack from the D7 copy of the module on our staging site and dropped the URL in the Slack chat.
I was seeing the problem yesterday on both D7 and D9 staging sites, and cannot reproduce it today. But the problem always was intermittent. On the basis that the problem appears to be related to order of execution of async scripts, it may be worth clearing browser cache as well as cookies for testing.
It was definitely a real problem on D7 a year ago, and was messing up our GA analytics data.
I would not want you to spend time on an intermittent problem which you may not be able to reproduce. However, given the history we have with this issue, I probably will look into porting my hack in #9 to the D8/9 version of the module as a patch, unless you are able to reproduce and fix the issue.
Comment #13
svenryen commentedI have tried to reproduce. From what I understand, this is related to having a file for the google_tag module saved to the file system and adding that file to "Disable JavaScripts" in the EUCC settings.
I've tried to replicate the settings and set up both GTM and GA, with GA being added through GTM for all pages, but I'm unable to find a situation where the visits are not being tracked by GA.
I'm thus a bit reluctant to add the patch when I can't verify that the issue exists in all configurations.
I was also given a preview test address for the web site in question, but was unable to reproduce the issue also on that site.
Please update this issue and set the status back to Active should you have more details.
Comment #14
john_b commentedThere is a real issue here, which appears again since we launched a D9 version of the site on 13 June 2022. The site is using JS-based geolocation, with smart_ip module. The D7 site had the hack described above in #9, but the new site (a D9 clone of the D7 site) does not have that hack.
Steps to reproduce:
1.Have some method to see whether Google tag manager is loading (Could be Tag Assistant Legacy extension for Chrome, and/or Google Analytics Debugger extension for Chrome: if GTM is loading, so will GA).
2. Visit our site from Europe.
3. Clear all cookies.
4. Reload.
5. Now your Chrome extension will show Google Tags are not loading. This is correct.
6. Click "Accept" on the EU Cookie Compliance banner. Now Google Tags start loading.
7. Visit our site a second time from USA.
8. Clear all cookies.
9. Reload.
10. On first load, the EU Cookie Compliance cookies get set. However, GTM does not load. It should load.
11. Reload again. Now, with EU Cookie Compliance cookies in place, GTM and Google Analytics start working.
Comment #15
john_b commentedComment #16
john_b commentedI can fix this by running
euCookieComplianceLoadScripts();for non-GDPR visitors. In eu_cookie_compliance.js I doThis has had minimal testing, but so far it is working on a test site, & not throwing a JS error.
Comment #17
john_b commentedPatch implementing above fix. We will test it in production.
Comment #18
svenryen commentedComment #19
svenryen commentedComment #20
john_b commentedthanks!