Privacy & Compliance

Consent Mode v2 Without Losing Your Attribution

Compliant tracking is an engineering problem, not a banner. We implement consent signalling that satisfies regulation and still feeds your bidding algorithms.

GDPR & Consent Mode v224h Response TimeUK-Registered Agency50+ Projects Delivered
Get My Free Compliance Audit →

Not ready to write it all out? Book a 15-minute discovery call →

The Problem

Two Expensive Failure Modes

Two failure modes, opposite directions, both expensive.

The first is over-collecting. A banner is installed, it looks compliant, and tags fire before consent is granted anyway — because the CMP was never actually wired to the tag manager. This is the configuration that draws regulatory attention, and "we installed a plugin" is not a defence.

The second is over-blocking. Consent is implemented so bluntly that denied users generate no signal at all. Google Ads loses conversion modelling inputs, GA4 loses behavioural modelling, and campaign performance degrades for a compliance gain you did not actually need.

Consent Mode v2 exists precisely to avoid this trade-off. Denied consent sends cookieless pings — no identifiers, no personal data — which preserve modelling while respecting the user's choice. Getting that right requires the CMP, the tag manager, the default consent state, and every individual tag to agree with each other. In practice they rarely do until someone checks.

What We Do

What We Do

Compliance Audit

  • Network-level check of what actually fires before consent
  • CMP configuration review against your declared purposes
  • Default consent state verification
  • Cookie inventory versus your published cookie policy
  • Cross-domain consent persistence

Consent Mode v2 Implementation

  • `ad_storage`, `analytics_storage`, `ad_user_data`, `ad_personalization` correctly mapped
  • Default denied state before CMP load, with correct region targeting
  • Consent update on user interaction, propagated to every tag
  • Server-side consent forwarding for GTM server containers
  • Verified across granted, denied, and partial-consent journeys

CMP Configuration

  • Complianz, Cookiebot, or your existing platform
  • Purpose and vendor mapping
  • Multilingual banners for multi-market stores
  • TCF integration where your ad stack requires it

Documentation

  • Data flow diagrams for your privacy policy and DPA responses
  • Records of what is collected, on what basis, and where it goes
  • Handover notes so new tags do not silently bypass consent
Field Notes

Common Mistakes We Find

Patterns from audits we have run. If you recognise two or more, the gap is probably costing you more than it appears to.

Tags firing before the CMP loads.

No default consent state, so the race between the banner and the tags is decided by network conditions. This is the configuration that draws regulatory attention.

A banner that is not wired to anything.

The CMP is installed and displays correctly. Rejecting has no effect on what fires, because consent was never connected to the tag manager.

Over-blocking on denial.

Denied consent sends nothing at all, so Google receives no cookieless pings and conversion modelling has no inputs. Compliant, and needlessly expensive.

Consent state stopping at the browser.

The client respects the choice, the server container does not. Denied users are still processed identifiably one layer down.

A cookie policy that does not match the cookies.

The published list was written once and never reconciled with what the site actually sets. It is the first thing anyone checks.

How We Work

How We Work

01

Step 01 — Observe

We watch what your site actually does before consent, not what it claims to do.

02

Step 02 — Map

Purposes to storage types to individual tags.

03

Step 03 — Implement

CMP wiring, default states, tag-level consent checks.

04

Step 04 — Test

Every consent path, every market, verified in Tag Assistant and network traces.

05

Step 05 — Document

Evidence you can hand to a regulator or a client's legal team.

No Surprises

What Happens Next

01

Step 01 — You hear back within 24 hours.

A real reply from the person who would do the work, not an autoresponder or a junior scheduling a call about a call.

02

Step 02 — We look before we talk.

Send us access or a URL and we review your actual setup first, so the conversation starts with findings instead of discovery questions.

03

Step 03 — 30 minutes, findings first.

We walk you through what we found and what it is costing. You get that regardless of whether you hire us.

04

Step 04 — A written scope, or an honest no.

If it is a fit, you get scope, timeline, and cost in writing. If it is not, we say so and point you somewhere better.

No retainer required. No minimum term. No obligation at any step.

Stack
Consent Mode v2Google Tag ManagerGTM Server-SideComplianzCookiebotGA4Google AdsMeta CAPIIAB TCF
100%

CAPI Event Coverage

Full Meta Conversions API with server-side deduplication, external_id matching, and Consent Mode — zero data loss post-iOS.

PAJ GPS · Server-Side Tracking
Fit Check

Is This Right For You?

We would rather tell you now than after an invoice. Here is who this work pays off for, and who it does not.

A good fit if:

  • You are doing €25,000+ per month in online revenue, where a few percent of recovered attribution is real money
  • You are running paid media and the reported numbers do not match your bank
  • You sell across more than one market, currency, or storefront
  • You have a developer or agency who can act on what we find
  • You want to own the implementation afterwards, not rent it

Probably not a fit if:

  • You are early stage and validating the product — fix demand first, measure it later
  • You want someone to manage ad spend day to day; we build the measurement layer, we are not a media buying agency
  • You need it live this week; proper implementation has a validation phase and we will not skip it
  • You want the cheapest quote — we are not it, and the cheapest tracking build usually gets rebuilt

Most engagements start from €1,500. We confirm scope and cost in the discovery call, before anything is committed.

Get Your Free Audit

Tell us about your setup. We respond within 24 hours.

Not ready to write it all out? Book a 15-minute discovery call →

FAQ

Common
Questions

Ready to Build Something That Works?

Book a free 30-minute strategy audit. No pitch deck, no pressure — just an honest look at your setup and what to fix first.

Not ready to write it all out? Book a 15-minute discovery call →

Get My Free Audit →