BigQuery · Status at source date: Newsletter archive
Simo Ahava raises concerns over GTM >g_health=1 health-check requests
Simo Ahava has documented unusual behaviour around >g_health=1 requests appearing alongside Google Tag Manager loads. The request loads a small library snippet from Google's CDN to log the status of a Google Tag load, but it appears only when GA or Ads tags are present in the container.

What changed
Two technical concerns sit underneath the implementation. First, the request ignores server-side tagging endpoints: even if the Google Tag and GTM container are loaded from a first-party server-side endpoint, the health check still goes to www.googletagmanager.com. Second, the throttle mechanism (limiting the request to once per 24 hours) is stored in browser localStorage under the _gcl_ls key, which lacks a native expiration mechanism. Throttle storage only occurs if both ad_storage and ad_user_data consent signals are GRANTED; if either is denied, the health check fires on every page load.
Ahava raises the possibility that Google may be using these signals to gather data about ad consent states ahead of the announced June 15 GA/Ads consent consolidation. He notes that using localStorage for throttling: rather than browser cache instructions: is a questionable design choice.
Why it matters for advertisers
For you, this means that measurement and privacy teams running fully first-party server-side setups should be aware that the health-check request is bypassing the first-party endpoint. Worth flagging to Google during any ongoing technical discussions, and documenting the localStorage write in privacy disclosure reviews.
Perspective from the original PMC newsletter.Sources & contributor credit
- Newsletter coverage · Paid Media Collective newsletter
Original newsletter text, contributor labels and media for this update.
- Source referenced in newsletterwww.googletagmanager.com
Linked from the original newsletter. The source publication date has not been independently confirmed.
- Source referenced in newsletterLinkedIn
Linked from the original newsletter. The source publication date has not been independently confirmed.
Original creator unverified
The names below are source credits. The original creator and first-reporting priority have not yet been independently verified.
Attribution evidence and limitations
Full attribution review pending.
A source link alone does not establish original authorship.
Original image and video creators have not yet been verified.
- Published on this site
This update reflects the dated source reporting. Availability may have changed. Further coverage of this same development will be added to this page.
Original newsletter text and archive evidence
Simo Ahava raises concerns over GTM >g_health=1 health-check requests
Simo Ahava has documented unusual behaviour around >g_health=1 requests appearing alongside Google Tag Manager loads. The request loads a small library snippet from Google's CDN to log the status of a Google Tag load, but it appears only when GA or Ads tags are present in the container. Two technical concerns sit underneath the implementation. First, the request ignores server-side tagging endpoints: even if the Google Tag and GTM container are loaded from a first-party server-side endpoint, the health check still goes to www.googletagmanager.com. Second, the throttle mechanism (limiting the request to once per 24 hours) is stored in browser localStorage under the _gcl_ls key, which lacks a native expiration mechanism. Throttle storage only occurs if both ad_storage and ad_user_data consent signals are GRANTED; if either is denied, the health check fires on every page load.
Ahava raises the possibility that Google may be using these signals to gather data about ad consent states ahead of the announced June 15 GA/Ads consent consolidation. He notes that using localStorage for throttling: rather than browser cache instructions: is a questionable design choice.
For you, this means that measurement and privacy teams running fully first-party server-side setups should be aware that the health-check request is bypassing the first-party endpoint. Worth flagging to Google during any ongoing technical discussions, and documenting the localStorage write in privacy disclosure reviews.
Source captured . No explicit first-contributor label was provided for this update.



