INDEPENDENT MINDS. SHARED AMBITION.
Back to the newsfeed
Strategy2 min read

BigQuery · Status at source date: Newsletter archive

Simo Ahava raises concerns over GTM &gtg_health=1 health-check requests

Written by Paid Media Collective
IN BRIEF

Simo Ahava has documented unusual behaviour around &gtg_health=1 requests appearing alongside Google Tag Manager loads. The request loads a small library snippet from Google's CDN to log the status of a Google Tag load, but it appears only when GA or Ads tags are present in the container.

Original newsletter image: Simo Ahava raises concerns over GTM &gtg_health=1 health-check requests
Via the Paid Media Collective newsletter. Original visual creator unverified.View full-size image

What changed

Two technical concerns sit underneath the implementation. First, the request ignores server-side tagging endpoints: even if the Google Tag and GTM container are loaded from a first-party server-side endpoint, the health check still goes to www.googletagmanager.com. Second, the throttle mechanism (limiting the request to once per 24 hours) is stored in browser localStorage under the _gcl_ls key, which lacks a native expiration mechanism. Throttle storage only occurs if both ad_storage and ad_user_data consent signals are GRANTED; if either is denied, the health check fires on every page load.

Ahava raises the possibility that Google may be using these signals to gather data about ad consent states ahead of the announced June 15 GA/Ads consent consolidation. He notes that using localStorage for throttling: rather than browser cache instructions: is a questionable design choice.

THE COLLECTIVE PERSPECTIVE

Why it matters for advertisers

For you, this means that measurement and privacy teams running fully first-party server-side setups should be aware that the health-check request is bypassing the first-party endpoint. Worth flagging to Google during any ongoing technical discussions, and documenting the localStorage write in privacy disclosure reviews.

Perspective from the original PMC newsletter.

Sources & contributor credit

  1. Newsletter coverage · Paid Media Collective newsletter

    Original newsletter text, contributor labels and media for this update.

  2. Source referenced in newsletterwww.googletagmanager.com

    Linked from the original newsletter. The source publication date has not been independently confirmed.

  3. Source referenced in newsletterLinkedIn

    Linked from the original newsletter. The source publication date has not been independently confirmed.

Original creator unverified

The names below are source credits. The original creator and first-reporting priority have not yet been independently verified.

Attribution evidence and limitations

Full attribution review pending.

A source link alone does not establish original authorship.

Original image and video creators have not yet been verified.

FOLLOW THE PEOPLE BEHIND THIS UPDATE
Published on this site

This update reflects the dated source reporting. Availability may have changed. Further coverage of this same development will be added to this page.

Explore the source reporting
Original newsletter text and archive evidence

Simo Ahava raises concerns over GTM &gtg_health=1 health-check requests

Simo Ahava has documented unusual behaviour around &gtg_health=1 requests appearing alongside Google Tag Manager loads. The request loads a small library snippet from Google's CDN to log the status of a Google Tag load, but it appears only when GA or Ads tags are present in the container. Two technical concerns sit underneath the implementation. First, the request ignores server-side tagging endpoints: even if the Google Tag and GTM container are loaded from a first-party server-side endpoint, the health check still goes to www.googletagmanager.com. Second, the throttle mechanism (limiting the request to once per 24 hours) is stored in browser localStorage under the _gcl_ls key, which lacks a native expiration mechanism. Throttle storage only occurs if both ad_storage and ad_user_data consent signals are GRANTED; if either is denied, the health check fires on every page load.

Ahava raises the possibility that Google may be using these signals to gather data about ad consent states ahead of the announced June 15 GA/Ads consent consolidation. He notes that using localStorage for throttling: rather than browser cache instructions: is a questionable design choice.

For you, this means that measurement and privacy teams running fully first-party server-side setups should be aware that the health-check request is bypassing the first-party endpoint. Worth flagging to Google during any ongoing technical discussions, and documenting the localStorage write in privacy disclosure reviews.

Source captured . No explicit first-contributor label was provided for this update.

Newsletter coverage (1)📰 🦸‍♂️ Paid Media News (Week 17) 🦸♀️ · 27 Apr 2026