A working OneTrust banner does not prove that the intended Google Tag Manager container receives its events. On a WordPress site with a custom data-layer name, the consent integration and GTM can write to different objects. Trace that wiring before changing trigger conditions or forcing tags to fire.
Separate three names
The data-layer object name, the event name and a data-layer variable key are different settings. For example, dataLayer is an object, a consent-update event describes a transition, and OnetrustActiveGroups is a variable used by the OneTrust integration. Renaming one does not automatically rename the others.
Google's data-layer guide documents custom object names, case sensitivity and the risk of overwriting an existing layer. OneTrust's GTM integration guidance describes its category variable. Compare your published integration with the vendor configuration rather than guessing category IDs.
Inventory the actual page installation
Open a clean test session on the affected landing page. Record the GTM container IDs visible in Network and the installation owners: theme snippet, tracking plugin, CMP template or custom code. Two containers may be intentional, but an old installation can make a test appear successful in the wrong workspace.
Inspect the live GTM loader and its configured data-layer name. Then inspect the CMP installation configuration and the object receiving the consent transition. In Tag Assistant, follow the event sequence for the intended container, including the consent state before and after the visitor's choice.
Use this evidence sheet with synthetic sessions:
| Observation |
Record |
| Container |
Published ID and installation owner |
| Event destination |
Exact object name and casing |
| Trigger input |
Event name and category variable |
| Consent state |
Default and update for each required type |
Fresh visit: Default state precedes tags. Reject: Approved denied behavior. Grant: Intended category only. Withdraw: Updated state after navigation. Explanatory checklist, not a customer test result.
Repair the wiring without inventing consent
Have the integration owner align the intended event destination with the container configuration. Make the smallest change on staging and publish the matching CMP and GTM versions together. A category ID copied from another account may represent a different purpose, so use this site's published category mapping.
Do not solve a mismatch by copying every message between two arrays. That can duplicate purchase events, expose fields to another container or apply transitions twice. Do not replace window.dataLayer with a fresh array after GTM has initialized.
Google recommends its consent APIs for default and update processing. Prefer the supported CMP template and documented mapping over hand-written Custom HTML that grants consent. The repair must preserve the approved behavior for denied and unknown states, including any distinctions between basic and advanced consent mode.
Run the four-state check
Test a fresh visitor, reject, grant only an intended category, and withdraw that choice through the preference center. For each, record the container's state and the resulting requests. A firing indicator alone does not prove that a request reached its destination or that it was permitted.
Repeat after navigation and on the actual form page. Use the broader banner and form-tracking checklist if the problem is not a name mismatch. The CookiePro profile provides product context. HandL WP can review the integration without weakening visitor controls.
References reviewed October 10, 2026. Examples are explanatory, not customer test results.