Let’s talk?
05.6/MEASUREMENT · COOKIES & TRACKING

Agency specialized inCookies and Trackingwith compliant consent and measurement ready for the post-cookie scenario.

We integrate CMP (OneTrust, Cookiebot, Didomi or yours), Consent Mode v2, first-party data and server-side measurement. Real GDPR compliance — not a banner that says "accept all" and moves on. And with better measurement than before, not worse.

STANCE

GDPR and ePrivacy are not enemies of measurement — they’re enemies of lazy measurement. Consent that’s well requested, with a clear value proposition and respected across the site, improves measurement: users who accept do so with real intent, and those who reject can be modeled. The opposite — tricky banners, tracking without consent — is a legal liability and a source of dirty data.

— eXprimeNet
WHAT WE CONFIGURE

Components of a correct implementation

Everything that sits between the visitor and your data.

01

Integrated CMP

OneTrust, Cookiebot, Didomi, Iubenda or a custom CMP. With a banner compliant with EDPB guidelines, not an "Accept all" button next to an X.

02

Consent Mode v2

Correct integration with Google (ads_data_redaction, url_passthrough, ad_user_data, ad_personalization). Modeling enabled — you don’t lose everything from those who reject.

03

GTM with consent triggers

Every tag fires only with the appropriate consent categories. Never "everything with Marketing" — every tag reviewed.

04

First-party data pipeline

First-party data collection (CRM, login, forms) with explicit and separate consent. Sustainable base when third-party cookies really die.

05

Server-side where useful

Server-side GTM for critical conversions and for fine control over data leaving the site. With Consent Mode integrated — not a consent bypass.

06

Consent record

Auditable log of which consent each user gave, when, how. Necessary to respond to AEPD / CNIL / ICO in case of complaint.

ARCHITECTURE

How to build a respectful tracking stack

With GDPR as a design constraint, not a last-minute patch.

  1. L01

    CMP

    The CMP is the first piece that loads. Before analytics, before pixels. Its decision governs everything else. We choose by ecosystem, budget and country of operation.

  2. L02

    Categories

    Clear definition of cookie categories (necessary, functional, analytics, marketing). Every tag and every script is assigned to a category — no ambiguity.

  3. L03

    Tag manager

    GTM receives the consent signal and only fires what’s allowed. Triggers configured by category. Consent Mode v2 active by default to avoid losing signal.

  4. L04

    Server-side

    When present, the server container still respects consent. It’s a router — not a bypass. It adds value (speed, adblockers, first-party) without dodging the law.

  5. L05

    Record

    Every consent decision is logged with timestamp, categories accepted / rejected and version of the banner shown. Base for audit.

WHAT YOU GET

Tangible deliverables

Concrete pieces — not a PDF of "best practices".

Current tracking audit

Inventory of what fires today, with what consent, toward where. With findings prioritized by legal risk and by measurement impact.

Configured, personalized CMP

Compliant banner, well-defined categories, clear texts. No dark patterns — which are also increasingly fineable.

GTM with Consent Mode v2

Container with consent triggers applied to every relevant tag. Consent Mode v2 configured and verified.

Cookie policy drafted

Cookie policy page updated, synced with what the CMP actually offers. No mismatch between "what legal says" and "what the site does".

Operational documentation

How to add new tags respecting consent, how to change categories, what to review when the law changes. Living manual — not a dead PDF.

Audit record

Logging system that lets you answer an AEPD / CNIL / ICO request about a specific user’s consent in under 24 hours.

HOW IT’S MAINTAINED

Consent & tracking governance principles

GDPR is not a project — it’s a permanent state.

  • 01

    Review before every campaign

    Before launching new tracking (new platform pixel, partner tag) we verify: which category, which legal basis, which consent. No exceptions.

  • 02

    Legal ↔ technical sync

    The legal team / DPO and the technical team talk every quarter. What the cookie policy says matches what the CMP does. No surprises.

  • 03

    Regulatory watch

    Follow-up of AEPD, CNIL, ICO fines — because they set the real interpretation of the rule. We adjust practice when relevant decisions appear.

  • 04

    Internal audits

    Every 6 months, a full review: banner, CMP, tags, cookie policy, records. With minutes signed by DPO or data controller.

  • 05

    Team training

    Marketing and product understand what’s allowed and what isn’t. No "let’s add this new platform pixel" the day before a campaign.

FREQUENTLY ASKED

Honest questions before hiring

Will we lose a lot of measurement by doing things right?

Done well, no. Consent Mode v2 allows modeling users who reject and recovering much of the aggregated signal. Also, the data quality from those who accept improves — because they accept with real intent, not tricked. Losing dirty measurement and gaining clean measurement is usually a good trade.

Is the CMP we already have fine, or do we need to switch?

It depends. If your CMP supports Consent Mode v2, has configurable categories and allows reasonable personalization, no need to switch — just integrate it well. If it’s an outdated CMP or fails to meet guidelines, yes. We audit and tell you honestly.

What about third-party cookies and their disappearance?

Google has walked it back several times, but the trend (reinforced privacy, ITP in Safari, ETP in Firefox, adblockers) is firm. The right response is the same: clean first-party data, server-side where useful and real consent. Whoever does that is prepared — whatever happens with Chrome.

How do you handle B2B clients with limited personal data?

GDPR applies equally — the rights subject is the person, not the consumer. The difference is that in B2B legitimate interest carries more weight as a legal basis (professional marketing, justified prospecting). We document and defend the legal basis choice case by case.

Do you work with internal / external DPO / lawyer?

Yes, we coordinate with your DPO and your legal advisors when they exist. We don’t practice law — we do the technical and organizational part. But we translate between both worlds, which is usually where projects get lost.

NEXT STEP

Would your cookie banner hold up in an AEPD / ICO inspection today?

Give us access to the site and we’ll return an honest audit: what’s fine, what’s low risk, what’s high risk and what we’d do first.

Let’s talk?

Consent and tracking audit under NDA. No proposals before understanding the context.