Over 253x 5-star
reviews
DATA INTELLIGENCE

/

Consent Mode & Privacy Compliance

Compliant tracking that still reports the truth.

still reports the truth

We implement Google consent mode, your consent management platform and the tag governance around them, so a lawful cookie banner stops costing you measurement. Consent signals are wired correctly in Google Tag Manager, every tag waits for a real consent state, and your analytics, paid search and server-side setups keep working after the banner appears.

Book your free
strategic call

Tell us a little about your brand and we'll be in touch within 24 hours to lock in a time.

Reply in less than 24h
We read every single request
We are specialists, not generalists
1:1 w/ Senior Executive
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
750+ brands
Engineer's hands on a keyboard in a dark room, network cables lit by a single desk lamp

THE FOUR LAYERS

Consent mode is four layers, in order.

four layers

The consent banner and CMP, the default and update consent state in the container, the tags that must respect it, and the reporting that has to survive it. Nearly every broken consent mode setup we audit fails at layer two: the default state fires late, so tags run before the user grants or denies anything.

CMP & consent banner

CMP & consent banner

Google Tag Manager

Google Tag Manager

Tags, storage & governance

Tags, storage & governance

Recovering the measurement

Recovering the measurement

A banner that is lawful and still gets consent.

Regulators are active. The CNIL reports fines totalling EUR 486,839,500 in 2025, with cookies among the main subjects of sanction, and the CMS enforcement tracker puts cumulative GDPR fines at around EUR 5.65 billion. A consent banner that nudges too hard is a liability; one that scares users is a measurement problem. Both are avoidable.

We select or fix your consent management platform, configure the categories honestly, wire the TCF or Google-certified template correctly, and make sure the reject path is as easy as the accept path — because that is what makes consent valid. Then we optimise the banner within the rules: plain language, timing, placement, layout and copy that explains the exchange. Commanders Act's 2025 barometer of more than 1,300 banners found an average consent rate of 78.06%, so a poor rate is usually a design failure rather than an audience one.

Every consent state and category is documented, so a legal review can be answered with evidence instead of screenshots.

  • CMP selected or repaired, categories configured honestly
  • Reject as easy as accept, so consent is genuinely valid
  • Banner copy, timing and layout optimised inside the rules
  • Consent states and cookies documented for legal review

78.06%

average consent rate across 1,300+ banners in 2025

EUR 5.65bn

cumulative GDPR fines tracked to 2025

Default state first, update state second.

This is where implementations break. Google's own documentation is explicit about the mechanics: when ad_storage is denied, no new advertising cookies are set, and existing third-party cookies on google.com and doubleclick.net are not used except for spam and fraud purposes. If the default consent state does not fire before every other tag, cookies are written before the user has chosen and the whole setup is worthless.

So we build it in the right order: a default consent state set on the consent initialization trigger, region-specific defaults where the law differs, a consent update from the CMP when the user grants or denies, and additional consent checks on every tag that touches analytics storage or ad storage. Google tags run in advanced consent mode wherever it is appropriate, so denied users still send cookieless pings; basic mode is used only when a client's legal position requires it, and we say which one you are on.

Then we test properly — grant, deny, partial, returning visitor, reconsent — and record the results, because a consent mode setup that has only been tested on accept is untested.

  • Default consent state on the consent initialization trigger
  • Region-specific defaults where the law differs
  • Consent update wired from the CMP, verified in the data layer
  • Every state tested: grant, deny, partial, return, reconsent

2-5x

how much more likely consented users are to convert

Every tag knows what it is allowed to do.

Consent mode covers Google tags. It does not police the rest of your container, and that is where most real exposure sits: a chat widget, a heatmap tool, a remarketing pixel from a campaign three years ago, all firing regardless of what the user chose. We inventory every tag, cookie and third-party request, assign each to a category, and add explicit consent checks so nothing fires without permission.

Then we make it stay fixed. Naming conventions, a change log, workspace permissions, a documented template for adding new tags, and monitoring that flags an unapproved request appearing on the site. Ads data redaction is switched on where appropriate, and data retention is set deliberately rather than left at a default nobody chose.

The deliverable is a governed container your developers, your marketing team and your legal counsel can all read — and a written record of who added what, and why.

  • Full inventory of tags, cookies and third-party requests
  • Explicit consent checks on non-Google tags too
  • Ads data redaction and retention set deliberately
  • Change log, permissions and monitoring for new requests

1

documented owner and consent category per tag

Keep the numbers usable after the banner.

A correct consent setup costs you visible data, and there are legitimate ways to get most of the signal back. Google Analytics models the behaviour of users who decline analytics cookies, and Google Ads notes that consented users are typically 2-5x more likely to convert than unconsented users — which is exactly why modelling needs enough consent volume to work at all. Advanced consent mode, sufficient traffic and a healthy consent rate are the prerequisites, not optional extras.

Alongside that we strengthen first-party collection: server-side tagging for the conversions that matter, enhanced conversions with hashed data where consent allows, offline conversion imports from your CRM, and blended reporting so a drop in cookie-visible traffic is not mistaken for a drop in demand. We also rebaseline your reports at the switch-over date, so the step in the chart is explained rather than investigated.

The result is a measurement layer that is lawful, documented, and still good enough to spend money on.

  • Advanced consent mode and modelling prerequisites met
  • Server-side tagging for the conversions that matter
  • Enhanced conversions and CRM imports where consent allows
  • Reports rebaselined so the switch-over is explained

Modelled

declined-consent behaviour estimated by Analytics

Tested

Grant, deny, partial, return and reconsent all verified

Documented

Every cookie and consent state written up for legal review

Yours

Container, CMP and accounts stay in your name

0

Long-term lock-ins

We made the difference for those brands

Beauty, personal care & wellness

Consumer tech and platforms

B2B software, fintech, insurance

B2B software, fintech, insurance

B2B software, fintech, insurance

Healthcare & regulated services

Consumer tech and platforms

Healthcare & regulated services

SMB

Healthcare & regulated services

Healthcare & regulated services

Beauty, personal care & wellness

Beauty, personal care & wellness

B2B software, fintech, insurance

Travel & mobility

Consumer tech and platforms

Retail & commerce

Beauty, personal care & wellness

Beauty, personal care & wellness

Creative, content, arts & culture

SMB

Retail & commerce

B2B software, fintech, insurance

Healthcare & regulated services

Creative, content, arts & culture

B2B software, fintech, insurance

Consumer tech and platforms

Beauty, personal care & wellness

Healthcare & regulated services

Creative, content, arts & culture

B2B software, fintech, insurance

B2B software, fintech, insurance

SMB

Consumer tech and platforms

01 — The challenge

The banner went live and the reporting fell apart.

Legal asked for a compliant cookie banner. It arrived, conversions dropped by a third overnight, and nobody could say how much of that was lost tracking versus lost sales. Meanwhile the tag audit shows pixels firing before anyone clicks accept, so the site is both under-measured and non-compliant.

“We are missing the data and we are still not compliant. Worst of both.”

It is a solvable engineering problem. Google's documentation is unambiguous that denied ad storage means no new advertising cookies are set, so the fix is to set a default consent state before any tag fires, update it from the CMP, and add consent checks to every tag — then recover the signal with modelling, server-side collection and first-party data. Done in that order you get a lawful setup and numbers you can still budget against.

02 — Our approach

Fix the container, then win the consent back.

We audit what actually happens on your site: every tag, cookie and third-party request, before and after consent, across grant, deny and partial states. Then we repair the foundation — a default consent state on the consent initialization trigger, region-specific defaults, a verified consent update from your CMP, and explicit consent checks on every tag including the non-Google ones. Google tags move to advanced consent mode where appropriate so denied users still send cookieless pings. Next we improve the consent rate itself with lawful banner design: plain language, honest categories, reject as easy as accept. Finally we rebuild the measurement around it — server-side tagging for key conversions, enhanced conversions and CRM imports where consent allows, modelling prerequisites met, and reports rebaselined at the switch-over. Everything is documented for legal review, and the container is left governed rather than merely working.

03 — What we did

Audit, repair, govern, recover.

Four phases with a written test log at each state, so compliance and measurement are both evidenced rather than asserted.

Week 1 / Audit

Record what fires before consent

Every tag, cookie and third-party request captured across grant, deny and partial states, with the compliance gaps ranked by exposure.

Requests captured before and after consent

Weeks 2-3 / Wire

Default state first, then the update

Default consent set on initialization, region defaults applied, the CMP update verified in the data layer, consent checks added per tag.

Consent states wired in the container

Weeks 3-4 / Banner

Raise the consent rate lawfully

Honest categories, plain language, reject as easy as accept, then timing, placement and copy tested inside the rules.

Banner design tested within the rules

Weeks 4-6 / Recover

Rebuild the numbers you can spend against

Server-side conversions, enhanced conversions and CRM imports where consent allows, modelling prerequisites met, reports rebaselined.

Measurement rebuilt after the switch-over

WHAT YOU GET

Deliverables your counsel can read.

your counsel can read

Everything below is built in your own container and accounts, documented as we go, and yours to keep.

Consent and tag audit icon

Consent and tag audit

A recorded inventory of every tag, cookie and third-party request across consent states, with gaps ranked by exposure.

Consent mode implementation icon

Consent mode implementation

Default and update consent states wired in Google Tag Manager, region defaults applied, advanced mode enabled where appropriate.

CMP setup and banner design icon

CMP setup and banner design

Consent management platform configured with honest categories and a valid reject path, then optimised for consent rate.

Tag governance pack icon

Tag governance pack

Naming conventions, permissions, a change log, an approval template for new tags, and monitoring for unapproved requests.

Server-side and first-party collection icon

Server-side and first-party collection

Server-side tagging for key conversions, enhanced conversions and CRM imports where consent allows.

Documentation and test log icon

Documentation and test log

Written evidence of every consent state tested and every cookie set, ready for a legal or partner review.

HOW WE WORK

Operating standards, not promises.

Operating standards

Developer holding a phone showing a consent prompt against a rain-streaked window
Initialization
Default consent set before any other tag can fire
Per tag
Consent checks applied to non-Google tags as well
Rebaselined
Reports annotated at switch-over so the step is explained
Named
The same engineer on your container throughout
Shape

B2B

Lawful lead tracking with CRM stages fed back where consent allows.

Explore

Local

Call, form and booking tracking that survives a compliant banner.

Explore

eCommerce

Purchase and revenue events collected server-side, consent respected per region.

Explore

Built on trust. Proven by results.

We partner with SMBs and Fortune 500 companies to deliver more than reach — we bring clarity, execution, and measurable outcomes. Every successful partnership starts with a strong culture fit and a shared drive to grow.

Over 253x 5-star
reviews
TikTokGoogle AdsShopifyWebflowSEMrushMeta

CASE STUDIES

Industry leaders we measure today

we measure today

Discover our work
Discover our work

Case studies

Video Ads

Static Ads

Santoy Calgary Painters — SEO and local search case study background image

Calgary, Alberta, Canada

Home services & trades

Santoy Calgary Painters

Across twelve matched months, a Calgary painting contractor grew all-channel sessions from 841 to 1,229 and profile direction requests from 473 to 571.

Peintres Montréal — SEO and audience growth case study background image

Montreal and Laval, Quebec, Canada

Home services & trades

Peintres Montréal

Across twelve matched months, a Montreal and Laval painting contractor grew all-channel sessions from 529 to 2,862 and new users from 472 to 1,823, with a two-month spike accounting for part of the gain.

Peinture Marcil — SEO and local search case study background image

Rive-Nord, Montreal, Quebec, Canada

Home services & trades

Peinture Marcil

A Rive-Nord commercial and industrial painting contractor went from no measurable search presence to 2,176 all-channel sessions and 55 organic clicks in its first eight months, with profile website clicks up 72%.

https://s3.amazonaws.com/webflow-prod-assets/69dce281d3b49704d8c8cdd0/6a78b886157ed9bc2f507c28_out2.mp4

Wearables - Health Tech

InBeat OURA SOW001 D2 UGC Matthew 9x16 — video ad creative

https://s3.amazonaws.com/webflow-prod-assets/69dce281d3b49704d8c8cdd0/6a7889cfe1dedd519c829fc4_out.mp4

Wearables - Health Tech

Track your health more accurately with a sleek smart ring

https://s3.amazonaws.com/webflow-prod-assets/69dce281d3b49704d8c8cdd0/6a78b86e14801b4217b47458_out2.mp4

Wearables - Health Tech

Monitor your health effortlessly without changing your lifestyle

Unclassified

Access expert allergy treatment from anywhere in the country

Unclassified

Overcome food allergies with a proven tolerance program

Unclassified

Help your child build lasting tolerance to food allergies

FAQ

What teams ask us first.

What is consent mode, in plain terms?

It is a way for your site to tell Google tags what the user agreed to, before and after they choose. You set a default consent state when the page loads, then send an update once the banner is answered, and each tag behaves accordingly. As Google's documentation puts it, when ad_storage is denied no new advertising cookies are set, and third-party cookies on google.com and doubleclick.net are not used except for spam and fraud purposes. In advanced mode the tags still send cookieless pings, which is what allows modelling later; in basic mode they do not fire at all until consent is granted.

Why did our conversions drop when the banner went live?

Usually because you stopped seeing some conversions rather than stopping them from happening — and because declined users genuinely convert less. Google Ads notes that consented users are typically 2-5x more likely to convert than unconsented users, so the visible drop overstates the commercial one but is not purely a reporting artefact. The way out is to establish how much is measurement loss (by comparing against your own sales records), recover signal through advanced mode, modelling and server-side collection, and rebaseline the reports at the switch-over date so the step is labelled instead of debated.

Basic or advanced consent mode — which should we use?

Advanced, unless your legal position rules it out. In advanced mode tags load and send cookieless pings when consent is denied, which preserves aggregate signal and makes modelling possible; Analytics can then model the behaviour of users who decline analytics cookies. In basic mode nothing fires until consent is granted, so you get a cleaner story for a cautious counsel and a larger blind spot in your data. Some organisations must choose basic, and that is a legitimate call — what matters is that the choice is deliberate, documented, and that everyone knows which numbers it affects.

Can we improve our consent rate without breaking the rules?

Yes, and there is real headroom. Commanders Act's 2025 barometer of more than 1,300 banners found an average consent rate of 78.06%, so a rate far below that usually points at design rather than audience. The levers that are both effective and lawful are plain language instead of legal boilerplate, honest category names, a visible and genuinely equal reject option, sensible timing and placement, and a short explanation of the exchange. What we will not do is bury the reject path or pre-tick categories: invalid consent is worse than low consent.

Does consent mode cover our non-Google tags?

No, and this is the gap that creates most exposure. Consent mode governs Google tags; a chat widget, heatmap tool, affiliate script or an old remarketing pixel will keep firing unless someone stops it. We inventory every tag, cookie and third-party request on the site, assign each a category, and add explicit consent checks in Google Tag Manager so nothing runs without permission. Then monitoring flags anything new that appears, because the most common cause of a compliant site becoming non-compliant is a well-meaning marketer adding one script.

How do we keep useful data when people decline?

Four things, in order of value. Advanced consent mode so denied traffic still contributes cookieless signal and modelling can run. Server-side tagging for the conversions that matter, so the events that fund your budget do not depend on a browser. Enhanced conversions and CRM or offline imports where consent allows, so the ad platforms optimise toward real revenue. And blended reporting against your own sales data, so a fall in cookie-visible traffic is never mistaken for a fall in demand. Not one part of that requires collecting anything the user refused.

Who is responsible if we get this wrong?

The site owner, which is why we build to evidence. Enforcement is real: the CNIL reported EUR 486,839,500 in fines during 2025 with cookies among the main subjects, and the CMS tracker puts cumulative GDPR fines at around EUR 5.65 billion. Our part is the implementation and the proof of it — a documented cookie inventory, a test log across every consent state, and a change log for the container. Your counsel sets the legal position; we make the site match it and give them the evidence pack they will ask for.

We operate in several regions with different rules. Can that work in one container?

Yes, and it is the normal case. Consent defaults are set per region, so a visitor from the EEA or the UK gets a denied default and a banner, while regions with different requirements get the appropriate state — all from the same container, with the logic documented rather than hidden in a custom script. US state privacy laws, opt-out signals and sector rules are handled the same way. The important discipline is testing each region's path explicitly, because a region-specific default that was never verified is the most common silent failure we find.

How long does an implementation take, and what does it cost?

For most sites the audit takes a few days, the wiring and testing two to three weeks, and server-side work follows as a second phase. We price it as a fixed-scope project — audit, implementation, banner work, documentation and test log — so you approve a number rather than an open-ended engagement, with optional ongoing governance if you want the container monitored. Complex cases are honest about themselves: many regions, several domains, a custom CMP or a heavily customised container all add days, and we will say so before quoting.

Can you work with our developers and our legal team?

That is the arrangement we prefer. Your counsel decides the legal position, your developers own the site, and we own the measurement layer between them: the container, the consent wiring, the server-side endpoints and the documentation that lets both sides check our work. Everything is version-controlled and written in language a non-specialist can follow. Where you also want the reporting rebuilt afterwards, our analytics and server-side teams pick it up directly.

Want a compliant setup that still reports properly?