Consent Mode v2 Without Losing Your Attribution
Compliant tracking is an engineering problem, not a banner. We implement consent signalling that satisfies regulation and still feeds your bidding algorithms.
Get My Free Compliance Audit →Not ready to write it all out? Book a 15-minute discovery call →
Two Expensive Failure Modes
Two failure modes, opposite directions, both expensive.
The first is over-collecting. A banner is installed, it looks compliant, and tags fire before consent is granted anyway — because the CMP was never actually wired to the tag manager. This is the configuration that draws regulatory attention, and "we installed a plugin" is not a defence.
The second is over-blocking. Consent is implemented so bluntly that denied users generate no signal at all. Google Ads loses conversion modelling inputs, GA4 loses behavioural modelling, and campaign performance degrades for a compliance gain you did not actually need.
Consent Mode v2 exists precisely to avoid this trade-off. Denied consent sends cookieless pings — no identifiers, no personal data — which preserve modelling while respecting the user's choice. Getting that right requires the CMP, the tag manager, the default consent state, and every individual tag to agree with each other. In practice they rarely do until someone checks.
What We Do
Compliance Audit
- Network-level check of what actually fires before consent
- CMP configuration review against your declared purposes
- Default consent state verification
- Cookie inventory versus your published cookie policy
- Cross-domain consent persistence
Consent Mode v2 Implementation
- `ad_storage`, `analytics_storage`, `ad_user_data`, `ad_personalization` correctly mapped
- Default denied state before CMP load, with correct region targeting
- Consent update on user interaction, propagated to every tag
- Server-side consent forwarding for GTM server containers
- Verified across granted, denied, and partial-consent journeys
CMP Configuration
- Complianz, Cookiebot, or your existing platform
- Purpose and vendor mapping
- Multilingual banners for multi-market stores
- TCF integration where your ad stack requires it
Documentation
- Data flow diagrams for your privacy policy and DPA responses
- Records of what is collected, on what basis, and where it goes
- Handover notes so new tags do not silently bypass consent
How We Work
Step 01 — Observe
We watch what your site actually does before consent, not what it claims to do.
Step 02 — Map
Purposes to storage types to individual tags.
Step 03 — Implement
CMP wiring, default states, tag-level consent checks.
Step 04 — Test
Every consent path, every market, verified in Tag Assistant and network traces.
Step 05 — Document
Evidence you can hand to a regulator or a client's legal team.
What Happens Next
Step 01 — You hear back within 24 hours.
A real reply from the person who would do the work, not an autoresponder or a junior scheduling a call about a call.
Step 02 — We look before we talk.
Send us access or a URL and we review your actual setup first, so the conversation starts with findings instead of discovery questions.
Step 03 — 30 minutes, findings first.
We walk you through what we found and what it is costing. You get that regardless of whether you hire us.
Step 04 — A written scope, or an honest no.
If it is a fit, you get scope, timeline, and cost in writing. If it is not, we say so and point you somewhere better.
No retainer required. No minimum term. No obligation at any step.
CAPI Event Coverage
Full Meta Conversions API with server-side deduplication, external_id matching, and Consent Mode — zero data loss post-iOS.
Is This Right For You?
We would rather tell you now than after an invoice. Here is who this work pays off for, and who it does not.
A good fit if:
- You are doing €25,000+ per month in online revenue, where a few percent of recovered attribution is real money
- You are running paid media and the reported numbers do not match your bank
- You sell across more than one market, currency, or storefront
- You have a developer or agency who can act on what we find
- You want to own the implementation afterwards, not rent it
Probably not a fit if:
- You are early stage and validating the product — fix demand first, measure it later
- You want someone to manage ad spend day to day; we build the measurement layer, we are not a media buying agency
- You need it live this week; proper implementation has a validation phase and we will not skip it
- You want the cheapest quote — we are not it, and the cheapest tracking build usually gets rebuilt
Most engagements start from €1,500. We confirm scope and cost in the discovery call, before anything is committed.
Tell us about your setup. We respond within 24 hours.
Not ready to write it all out? Book a 15-minute discovery call →
Common
Questions
Google requires Consent Mode v2 signals for advertisers serving users in the EEA and UK in order to keep using measurement and personalisation features. Separately, GDPR and ePrivacy require a lawful basis for storing or accessing information on a device. The two are related but not the same obligation.
Some measured performance drop is normal, because you stop counting conversions you were never entitled to attribute. Consent Mode v2 offsets much of this through modelling — but modelling only works if denied-consent pings are actually being sent, which is exactly the part most setups get wrong.
Yes. Where the processing happens does not change whether you need permission to store or access information on the user's device, or to process their personal data. Server-side tagging is an architecture choice, not a compliance exemption.
Yes. We configure whichever platform you already run rather than pushing a replacement, unless yours genuinely cannot support the purposes you need.
No — we are engineers, not lawyers. We implement what your legal counsel specifies and document exactly what the system does so they can assess it.
A compliance audit plus implementation typically starts around €1,500 for a single-market site. Multi-market stores scale with the number of jurisdictions and languages. If you already have a CMP and only need it wired correctly to your tags, the work is usually smaller — the audit tells us which situation you are in.
Google requires Consent Mode v2 signals for advertisers serving EEA and UK users in order to keep using measurement and personalisation features — without them, remarketing audiences and conversion modelling degrade. Separately and independently, GDPR and ePrivacy still require a lawful basis for storing or accessing information on a device. The commercial consequence arrives faster than the regulatory one, but both are real.
Complianz and Cookiebot both work well and we implement either. The platform matters far less than the wiring — most non-compliant sites we audit have a perfectly good CMP that was never connected to the tag manager. If you already have one, we would rather configure it correctly than sell you a replacement.
Usually one to two weeks for a single market. Most of that is testing rather than building: every consent path — granted, denied, and partial — has to be verified against every tag, and multi-market sites multiply that matrix by the number of jurisdictions.
Google's requirement targets advertisers serving EEA and UK users, so it applies based on your audience rather than your location. Beyond that, comparable consent obligations exist in other jurisdictions with different rules — and if you sell into Europe from anywhere, you are in scope. We implement to whatever your legal counsel specifies rather than guessing at your obligations.
Ready to Build Something That Works?
Book a free 30-minute strategy audit. No pitch deck, no pressure — just an honest look at your setup and what to fix first.
Not ready to write it all out? Book a 15-minute discovery call →
