Agency specialized inCookies and Trackingwith compliant consent and measurement ready for the post-cookie scenario.
We integrate CMP (OneTrust, Cookiebot, Didomi or yours), Consent Mode v2, first-party data and server-side measurement. Real GDPR compliance — not a banner that says "accept all" and moves on. And with better measurement than before, not worse.
GDPR and ePrivacy are not enemies of measurement — they’re enemies of lazy measurement. Consent that’s well requested, with a clear value proposition and respected across the site, improves measurement: users who accept do so with real intent, and those who reject can be modeled. The opposite — tricky banners, tracking without consent — is a legal liability and a source of dirty data.
Components of a correct implementation
Everything that sits between the visitor and your data.
Integrated CMP
OneTrust, Cookiebot, Didomi, Iubenda or a custom CMP. With a banner compliant with EDPB guidelines, not an "Accept all" button next to an X.
Consent Mode v2
Correct integration with Google (ads_data_redaction, url_passthrough, ad_user_data, ad_personalization). Modeling enabled — you don’t lose everything from those who reject.
GTM with consent triggers
Every tag fires only with the appropriate consent categories. Never "everything with Marketing" — every tag reviewed.
First-party data pipeline
First-party data collection (CRM, login, forms) with explicit and separate consent. Sustainable base when third-party cookies really die.
Server-side where useful
Server-side GTM for critical conversions and for fine control over data leaving the site. With Consent Mode integrated — not a consent bypass.
Consent record
Auditable log of which consent each user gave, when, how. Necessary to respond to AEPD / CNIL / ICO in case of complaint.
How to build a respectful tracking stack
With GDPR as a design constraint, not a last-minute patch.
- L01
CMP
The CMP is the first piece that loads. Before analytics, before pixels. Its decision governs everything else. We choose by ecosystem, budget and country of operation.
- L02
Categories
Clear definition of cookie categories (necessary, functional, analytics, marketing). Every tag and every script is assigned to a category — no ambiguity.
- L03
Tag manager
GTM receives the consent signal and only fires what’s allowed. Triggers configured by category. Consent Mode v2 active by default to avoid losing signal.
- L04
Server-side
When present, the server container still respects consent. It’s a router — not a bypass. It adds value (speed, adblockers, first-party) without dodging the law.
- L05
Record
Every consent decision is logged with timestamp, categories accepted / rejected and version of the banner shown. Base for audit.
Tangible deliverables
Concrete pieces — not a PDF of "best practices".
Current tracking audit
Inventory of what fires today, with what consent, toward where. With findings prioritized by legal risk and by measurement impact.
Configured, personalized CMP
Compliant banner, well-defined categories, clear texts. No dark patterns — which are also increasingly fineable.
GTM with Consent Mode v2
Container with consent triggers applied to every relevant tag. Consent Mode v2 configured and verified.
Cookie policy drafted
Cookie policy page updated, synced with what the CMP actually offers. No mismatch between "what legal says" and "what the site does".
Operational documentation
How to add new tags respecting consent, how to change categories, what to review when the law changes. Living manual — not a dead PDF.
Audit record
Logging system that lets you answer an AEPD / CNIL / ICO request about a specific user’s consent in under 24 hours.
Consent & tracking governance principles
GDPR is not a project — it’s a permanent state.
- 01
Review before every campaign
Before launching new tracking (new platform pixel, partner tag) we verify: which category, which legal basis, which consent. No exceptions.
- 02
Legal ↔ technical sync
The legal team / DPO and the technical team talk every quarter. What the cookie policy says matches what the CMP does. No surprises.
- 03
Regulatory watch
Follow-up of AEPD, CNIL, ICO fines — because they set the real interpretation of the rule. We adjust practice when relevant decisions appear.
- 04
Internal audits
Every 6 months, a full review: banner, CMP, tags, cookie policy, records. With minutes signed by DPO or data controller.
- 05
Team training
Marketing and product understand what’s allowed and what isn’t. No "let’s add this new platform pixel" the day before a campaign.
Honest questions before hiring
Will we lose a lot of measurement by doing things right?
Done well, no. Consent Mode v2 allows modeling users who reject and recovering much of the aggregated signal. Also, the data quality from those who accept improves — because they accept with real intent, not tricked. Losing dirty measurement and gaining clean measurement is usually a good trade.
Is the CMP we already have fine, or do we need to switch?
It depends. If your CMP supports Consent Mode v2, has configurable categories and allows reasonable personalization, no need to switch — just integrate it well. If it’s an outdated CMP or fails to meet guidelines, yes. We audit and tell you honestly.
What about third-party cookies and their disappearance?
Google has walked it back several times, but the trend (reinforced privacy, ITP in Safari, ETP in Firefox, adblockers) is firm. The right response is the same: clean first-party data, server-side where useful and real consent. Whoever does that is prepared — whatever happens with Chrome.
How do you handle B2B clients with limited personal data?
GDPR applies equally — the rights subject is the person, not the consumer. The difference is that in B2B legitimate interest carries more weight as a legal basis (professional marketing, justified prospecting). We document and defend the legal basis choice case by case.
Do you work with internal / external DPO / lawyer?
Yes, we coordinate with your DPO and your legal advisors when they exist. We don’t practice law — we do the technical and organizational part. But we translate between both worlds, which is usually where projects get lost.
Would your cookie banner hold up in an AEPD / ICO inspection today?
Give us access to the site and we’ll return an honest audit: what’s fine, what’s low risk, what’s high risk and what we’d do first.
Let’s talk?Consent and tracking audit under NDA. No proposals before understanding the context.