

Compliant tracking that still reports the truth.
still reports the truth
We implement Google consent mode, your consent management platform and the tag governance around them, so a lawful cookie banner stops costing you measurement. Consent signals are wired correctly in Google Tag Manager, every tag waits for a real consent state, and your analytics, paid search and server-side setups keep working after the banner appears.
Tell us a little about your brand and we'll be in touch within 24 hours to lock in a time.

THE FOUR LAYERS
Consent mode is four layers, in order.
four layers
The consent banner and CMP, the default and update consent state in the container, the tags that must respect it, and the reporting that has to survive it. Nearly every broken consent mode setup we audit fails at layer two: the default state fires late, so tags run before the user grants or denies anything.
CMP & consent banner
Google Tag Manager
Tags, storage & governance
Recovering the measurement
A banner that is lawful and still gets consent.
Regulators are active. The CNIL reports fines totalling EUR 486,839,500 in 2025, with cookies among the main subjects of sanction, and the CMS enforcement tracker puts cumulative GDPR fines at around EUR 5.65 billion. A consent banner that nudges too hard is a liability; one that scares users is a measurement problem. Both are avoidable.
We select or fix your consent management platform, configure the categories honestly, wire the TCF or Google-certified template correctly, and make sure the reject path is as easy as the accept path — because that is what makes consent valid. Then we optimise the banner within the rules: plain language, timing, placement, layout and copy that explains the exchange. Commanders Act's 2025 barometer of more than 1,300 banners found an average consent rate of 78.06%, so a poor rate is usually a design failure rather than an audience one.
Every consent state and category is documented, so a legal review can be answered with evidence instead of screenshots.
- CMP selected or repaired, categories configured honestly
- Reject as easy as accept, so consent is genuinely valid
- Banner copy, timing and layout optimised inside the rules
- Consent states and cookies documented for legal review
78.06%
average consent rate across 1,300+ banners in 2025
EUR 5.65bn
cumulative GDPR fines tracked to 2025
Default state first, update state second.
This is where implementations break. Google's own documentation is explicit about the mechanics: when ad_storage is denied, no new advertising cookies are set, and existing third-party cookies on google.com and doubleclick.net are not used except for spam and fraud purposes. If the default consent state does not fire before every other tag, cookies are written before the user has chosen and the whole setup is worthless.
So we build it in the right order: a default consent state set on the consent initialization trigger, region-specific defaults where the law differs, a consent update from the CMP when the user grants or denies, and additional consent checks on every tag that touches analytics storage or ad storage. Google tags run in advanced consent mode wherever it is appropriate, so denied users still send cookieless pings; basic mode is used only when a client's legal position requires it, and we say which one you are on.
Then we test properly — grant, deny, partial, returning visitor, reconsent — and record the results, because a consent mode setup that has only been tested on accept is untested.
- Default consent state on the consent initialization trigger
- Region-specific defaults where the law differs
- Consent update wired from the CMP, verified in the data layer
- Every state tested: grant, deny, partial, return, reconsent
2-5x
how much more likely consented users are to convert
Every tag knows what it is allowed to do.
Consent mode covers Google tags. It does not police the rest of your container, and that is where most real exposure sits: a chat widget, a heatmap tool, a remarketing pixel from a campaign three years ago, all firing regardless of what the user chose. We inventory every tag, cookie and third-party request, assign each to a category, and add explicit consent checks so nothing fires without permission.
Then we make it stay fixed. Naming conventions, a change log, workspace permissions, a documented template for adding new tags, and monitoring that flags an unapproved request appearing on the site. Ads data redaction is switched on where appropriate, and data retention is set deliberately rather than left at a default nobody chose.
The deliverable is a governed container your developers, your marketing team and your legal counsel can all read — and a written record of who added what, and why.
- Full inventory of tags, cookies and third-party requests
- Explicit consent checks on non-Google tags too
- Ads data redaction and retention set deliberately
- Change log, permissions and monitoring for new requests
1
documented owner and consent category per tag
Keep the numbers usable after the banner.
A correct consent setup costs you visible data, and there are legitimate ways to get most of the signal back. Google Analytics models the behaviour of users who decline analytics cookies, and Google Ads notes that consented users are typically 2-5x more likely to convert than unconsented users — which is exactly why modelling needs enough consent volume to work at all. Advanced consent mode, sufficient traffic and a healthy consent rate are the prerequisites, not optional extras.
Alongside that we strengthen first-party collection: server-side tagging for the conversions that matter, enhanced conversions with hashed data where consent allows, offline conversion imports from your CRM, and blended reporting so a drop in cookie-visible traffic is not mistaken for a drop in demand. We also rebaseline your reports at the switch-over date, so the step in the chart is explained rather than investigated.
The result is a measurement layer that is lawful, documented, and still good enough to spend money on.
- Advanced consent mode and modelling prerequisites met
- Server-side tagging for the conversions that matter
- Enhanced conversions and CRM imports where consent allows
- Reports rebaselined so the switch-over is explained
Modelled
declined-consent behaviour estimated by Analytics
Grant, deny, partial, return and reconsent all verified
Every cookie and consent state written up for legal review
Container, CMP and accounts stay in your name
Long-term lock-ins
We made the difference for those brands
01 — The challenge
The banner went live and the reporting fell apart.
Legal asked for a compliant cookie banner. It arrived, conversions dropped by a third overnight, and nobody could say how much of that was lost tracking versus lost sales. Meanwhile the tag audit shows pixels firing before anyone clicks accept, so the site is both under-measured and non-compliant.
“We are missing the data and we are still not compliant. Worst of both.”
It is a solvable engineering problem. Google's documentation is unambiguous that denied ad storage means no new advertising cookies are set, so the fix is to set a default consent state before any tag fires, update it from the CMP, and add consent checks to every tag — then recover the signal with modelling, server-side collection and first-party data. Done in that order you get a lawful setup and numbers you can still budget against.
02 — Our approach
Fix the container, then win the consent back.
We audit what actually happens on your site: every tag, cookie and third-party request, before and after consent, across grant, deny and partial states. Then we repair the foundation — a default consent state on the consent initialization trigger, region-specific defaults, a verified consent update from your CMP, and explicit consent checks on every tag including the non-Google ones. Google tags move to advanced consent mode where appropriate so denied users still send cookieless pings. Next we improve the consent rate itself with lawful banner design: plain language, honest categories, reject as easy as accept. Finally we rebuild the measurement around it — server-side tagging for key conversions, enhanced conversions and CRM imports where consent allows, modelling prerequisites met, and reports rebaselined at the switch-over. Everything is documented for legal review, and the container is left governed rather than merely working.
03 — What we did
Audit, repair, govern, recover.
Four phases with a written test log at each state, so compliance and measurement are both evidenced rather than asserted.
Week 1 / Audit
Record what fires before consent
Every tag, cookie and third-party request captured across grant, deny and partial states, with the compliance gaps ranked by exposure.

Weeks 2-3 / Wire
Default state first, then the update
Default consent set on initialization, region defaults applied, the CMP update verified in the data layer, consent checks added per tag.

Weeks 3-4 / Banner
Raise the consent rate lawfully
Honest categories, plain language, reject as easy as accept, then timing, placement and copy tested inside the rules.

Weeks 4-6 / Recover
Rebuild the numbers you can spend against
Server-side conversions, enhanced conversions and CRM imports where consent allows, modelling prerequisites met, reports rebaselined.

WHAT YOU GET
Deliverables your counsel can read.
your counsel can read
Everything below is built in your own container and accounts, documented as we go, and yours to keep.
Consent and tag audit
A recorded inventory of every tag, cookie and third-party request across consent states, with gaps ranked by exposure.
Consent mode implementation
Default and update consent states wired in Google Tag Manager, region defaults applied, advanced mode enabled where appropriate.
CMP setup and banner design
Consent management platform configured with honest categories and a valid reject path, then optimised for consent rate.
Tag governance pack
Naming conventions, permissions, a change log, an approval template for new tags, and monitoring for unapproved requests.
Server-side and first-party collection
Server-side tagging for key conversions, enhanced conversions and CRM imports where consent allows.
Documentation and test log
Written evidence of every consent state tested and every cookie set, ready for a legal or partner review.
HOW WE WORK
Operating standards, not promises.
Operating standards

Built on trust. Proven by results.
We partner with SMBs and Fortune 500 companies to deliver more than reach — we bring clarity, execution, and measurable outcomes. Every successful partnership starts with a strong culture fit and a shared drive to grow.








CASE STUDIES
Case studies
Video Ads
Static Ads






FAQ
What teams ask us first.
What is consent mode, in plain terms?
It is a way for your site to tell Google tags what the user agreed to, before and after they choose. You set a default consent state when the page loads, then send an update once the banner is answered, and each tag behaves accordingly. As Google's documentation puts it, when ad_storage is denied no new advertising cookies are set, and third-party cookies on google.com and doubleclick.net are not used except for spam and fraud purposes. In advanced mode the tags still send cookieless pings, which is what allows modelling later; in basic mode they do not fire at all until consent is granted.
Why did our conversions drop when the banner went live?
Usually because you stopped seeing some conversions rather than stopping them from happening — and because declined users genuinely convert less. Google Ads notes that consented users are typically 2-5x more likely to convert than unconsented users, so the visible drop overstates the commercial one but is not purely a reporting artefact. The way out is to establish how much is measurement loss (by comparing against your own sales records), recover signal through advanced mode, modelling and server-side collection, and rebaseline the reports at the switch-over date so the step is labelled instead of debated.
Basic or advanced consent mode — which should we use?
Advanced, unless your legal position rules it out. In advanced mode tags load and send cookieless pings when consent is denied, which preserves aggregate signal and makes modelling possible; Analytics can then model the behaviour of users who decline analytics cookies. In basic mode nothing fires until consent is granted, so you get a cleaner story for a cautious counsel and a larger blind spot in your data. Some organisations must choose basic, and that is a legitimate call — what matters is that the choice is deliberate, documented, and that everyone knows which numbers it affects.
Can we improve our consent rate without breaking the rules?
Yes, and there is real headroom. Commanders Act's 2025 barometer of more than 1,300 banners found an average consent rate of 78.06%, so a rate far below that usually points at design rather than audience. The levers that are both effective and lawful are plain language instead of legal boilerplate, honest category names, a visible and genuinely equal reject option, sensible timing and placement, and a short explanation of the exchange. What we will not do is bury the reject path or pre-tick categories: invalid consent is worse than low consent.
Does consent mode cover our non-Google tags?
No, and this is the gap that creates most exposure. Consent mode governs Google tags; a chat widget, heatmap tool, affiliate script or an old remarketing pixel will keep firing unless someone stops it. We inventory every tag, cookie and third-party request on the site, assign each a category, and add explicit consent checks in Google Tag Manager so nothing runs without permission. Then monitoring flags anything new that appears, because the most common cause of a compliant site becoming non-compliant is a well-meaning marketer adding one script.
How do we keep useful data when people decline?
Four things, in order of value. Advanced consent mode so denied traffic still contributes cookieless signal and modelling can run. Server-side tagging for the conversions that matter, so the events that fund your budget do not depend on a browser. Enhanced conversions and CRM or offline imports where consent allows, so the ad platforms optimise toward real revenue. And blended reporting against your own sales data, so a fall in cookie-visible traffic is never mistaken for a fall in demand. Not one part of that requires collecting anything the user refused.
Who is responsible if we get this wrong?
The site owner, which is why we build to evidence. Enforcement is real: the CNIL reported EUR 486,839,500 in fines during 2025 with cookies among the main subjects, and the CMS tracker puts cumulative GDPR fines at around EUR 5.65 billion. Our part is the implementation and the proof of it — a documented cookie inventory, a test log across every consent state, and a change log for the container. Your counsel sets the legal position; we make the site match it and give them the evidence pack they will ask for.
We operate in several regions with different rules. Can that work in one container?
Yes, and it is the normal case. Consent defaults are set per region, so a visitor from the EEA or the UK gets a denied default and a banner, while regions with different requirements get the appropriate state — all from the same container, with the logic documented rather than hidden in a custom script. US state privacy laws, opt-out signals and sector rules are handled the same way. The important discipline is testing each region's path explicitly, because a region-specific default that was never verified is the most common silent failure we find.
How long does an implementation take, and what does it cost?
For most sites the audit takes a few days, the wiring and testing two to three weeks, and server-side work follows as a second phase. We price it as a fixed-scope project — audit, implementation, banner work, documentation and test log — so you approve a number rather than an open-ended engagement, with optional ongoing governance if you want the container monitored. Complex cases are honest about themselves: many regions, several domains, a custom CMP or a heavily customised container all add days, and we will say so before quoting.
Can you work with our developers and our legal team?
That is the arrangement we prefer. Your counsel decides the legal position, your developers own the site, and we own the measurement layer between them: the container, the consent wiring, the server-side endpoints and the documentation that lets both sides check our work. Everything is version-controlled and written in language a non-specialist can follow. Where you also want the reporting rebuilt afterwards, our analytics and server-side teams pick it up directly.









































.webp)
.webp)


