A trace of every identifier leaving your measurement stack, the basis it runs on, the basis it needs, and the fix, verified in the request payload.
About this service
The banner is rarely the problem. In the measurement stacks I take apart, the failure that matters sits after the click: a hashed email leaving the server-side container for Meta's Conversions API on a consent state the browser never collected, or an offline conversion upload carrying CRM records for people who opted out eleven months ago. A CMP that renders correctly and a stack that behaves correctly are two different audits. This is the second one.
The three failures I find:
First, the consent signal stops at the browser. Consent Mode v2 is wired, ad_user_data and ad_personalization move correctly through gtag, and then the server-side container fires Conversions API, the TikTok Events API and Enhanced Conversions on its own schedule with no consent parameter in the payload at all. The tag is off in the browser and on in the container.
Second, the identifier outruns the purpose. Hashed email gets treated as anonymous because it is hashed. It is not. It is a pseudonymous identifier under GDPR Article 4(5), personal information under Law 25 and under the CPRA, and pushing it into UID2, RampID or a platform's customer match is a processing operation needing its own basis and its own disclosure, not a row in a cookie table.
Third, the opt-out arrives and is discarded. Global Privacy Control is enforceable in California, Colorado and Connecticut, and your CMP probably reads it. Whether that read reaches the audience already synced to your DSP, the suppression list at the ESP, and the clean room match is a separate question, and in most stacks the answer is no.
What the work produces:
A trace of every outbound flow carrying an identifier, from tag to endpoint to what the endpoint does on receipt, collected from the network layer and the server container logs rather than from vendor documentation. Against each flow: the basis it is running on, the basis it needs, and the specific change. Then the changes themselves, made alongside your team in the tag manager and the container, or specified tightly enough that your engineers make them inside one sprint.
Verification is the deliverable:
Every fix comes back with evidence that it holds. Request payloads before and after. A consent state matrix covering rejected, partial and accepted sessions, a GPC session, and one session from each governing jurisdiction. If I cannot show you the payload, the work is not finished.
Where this differs from the usual version:
I do not accept a vendor's compliance page as evidence of anything. I do not write the words legitimate interest over advertising personalisation, because both the EDPB and the Irish supervisory authority have closed that door and repeating it in your records creates a written trace of a decision you cannot defend. And where the honest answer is that an approach cannot be made lawful in a market, I recommend turning the market off rather than engineering something that lasts until the first complaint.
Not included:
Media buying, attribution modelling, marketing mix work, or rebuilding the measurement you lose. I will size what you lose before you approve anything and I will not pretend it is nothing. No legal opinions, no privilege; your counsel signs.
Not for you if:
What you want is a defensible-looking paper trail around tracking you intend to keep either way. That engagement ends at the first finding, and I have ended one there before.
Scope
- Target market
- Worldwide, United States, Canada
- Working language
- English, French
- Industry
- B2B SaaS, Ecommerce and DTC, Fintech, HR and recruiting
- Engagement model
- Monthly retainer
- Turnaround
- 1 month or more
- Seller type
- In-house-grade specialist