Consent, Privacy & Data Governance
Consent is where compliance and measurement collide, and it is usually resolved badly in one direction or the other. We implement consent properly: a CMP configured against a real cookie audit, Consent Mode v2 wired into tag firing and modelling, governance that documents who can do what with which data, and evidence you can hand to a regulator or a client-side legal team without a two-week fire drill.
Challenges we solve
Either the banner is configured so loosely that tags fire before consent — a genuine legal exposure — or it is configured so tightly that modelling never kicks in, conversions collapse, and the media team quietly stops trusting the platform. Both outcomes come from the same root cause: the CMP was installed by one team, the tags by another, and nobody tested the interaction. The work is unglamorous and entirely doable. Audit what actually sets cookies and storage, categorise honestly, wire consent signals into every tag and into Consent Mode v2, verify with evidence, and document the governance around it so the next person does not undo it.
What we deliver
Cookie and storage audit
A real inventory of what your site sets: first- and third-party cookies, localStorage, sessionStorage, pixels, fingerprinting-adjacent scripts and vendor chains loaded by other vendors. Each item categorised, purposed, duration-checked and mapped to the tag that sets it.
CMP implementation and configuration
Implementation or remediation of OneTrust, Cookiebot, Usercentrics, Tealium or a custom CMP: geo-rules, category mapping, pre-consent blocking, banner and preference-centre behaviour, reconsent cadence, and correct integration with your tag manager rather than a script pasted above it and hoped for.
Google Consent Mode v2
Full Consent Mode v2 implementation across ad_storage, analytics_storage, ad_user_data and ad_personalization, including default and update states, region-specific defaults, url_passthrough, and validation that modelling is actually eligible — which is the step most implementations skip.
Privacy-first and server-side collection
Reducing unnecessary data collection: PII detection and stripping in server-side containers, IP handling, hashed identifiers, data minimisation in event payloads, and retention settings aligned to your actual policy rather than the platform default.
Data governance framework
Data inventory and classification, purpose registers, lawful-basis mapping, retention schedules, access control and role definitions, vendor and sub-processor register, and a change process that keeps the documentation current.
Regional compliance mapping
Practical mapping of requirements across GDPR and ePrivacy, the UK regime, CCPA/CPRA and other US state laws, Brazil’s LGPD, India’s DPDP Act and Google’s own platform policies — translated into concrete tag and CMP configuration rather than a legal summary.
Compliance testing and evidence
Automated and manual verification that nothing non-essential fires pre-consent, across regions, devices and journey types, with screenshots and network logs retained as evidence. Repeatable as a monitored check rather than a one-off test.
DSAR and deletion workflow support
Practical support for subject access, deletion and opt-out requests across analytics and marketing platforms, including GA4 user deletion, warehouse deletion patterns and ad-platform suppression.
Platforms & tooling
- OneTrust
- Cookiebot
- Usercentrics
- Tealium Consent
- Google Consent Mode v2
- Google Tag Manager
- Server-Side GTM
- GA4
- Adobe Web SDK
- BigQuery
Process
Audit
Cookie, storage and vendor inventory across regions and journeys.
Classify
Categorisation, purpose and lawful-basis mapping with your legal team.
Implement
CMP configuration, Consent Mode v2, blocking and firing rules.
Verify
Region and device testing, evidence pack, modelling confirmation.
Monitor
Scheduled re-scans and alerting on new or changed cookies.
FAQs
Usually less than people fear, and often less than the status quo. Correctly implemented, consent mode allows Google to model conversions for non-consenting users, which recovers a meaningful share of what a hard block would lose. Incorrectly implemented, you get the worst of both: no cookies and no modelling. The difference is entirely in the configuration.
Having a CMP and having a working consent implementation are different things. The common failure is that the CMP is installed correctly but tags are not actually gated by it, or the categories in the banner do not match what the tags really do. The audit answers this in days.
Your lawyers. We are engineers and analysts, not a law firm. We produce the inventory, the classification, the configuration and the evidence, and we work to the positions your legal or privacy team takes. We will flag where a technical configuration looks inconsistent with the stated policy.
Yes, and it helps if it is done properly. Server-side collection does not exempt you from consent — the same rules apply — but it does give you a place to enforce minimisation, strip PII, control what leaves your infrastructure and reduce the number of third parties touching user data directly.
That is the normal arrangement. Most of our work is alongside an internal team — we take the implementation and architecture load, and hand over documentation and enablement so the team can run it afterwards.
A region matrix: default consent states, category definitions, banner behaviour and tag firing rules per jurisdiction, implemented in the CMP and the tag manager and then tested from each region rather than assumed.
Quarterly as a minimum, plus after any significant site release or new vendor. New tags arrive constantly, often through other tags. We set up scheduled scans so drift is caught automatically.
Ready To Make Your Data Work Harder?
Let’s build a trusted measurement foundation that drives smarter decisions and measurable growth.