CMP build that starts with prior blocking: TCF v2.2, GPP and Consent Mode v2 wired, then signed off against a geo and consent-state QA grid.
About this service
Prior blocking is the whole job. A banner that renders correctly over a page which has already written _ga, _fbp and four vendor cookies before the dialog painted has failed, and that is the state I find on most sites that already own a consent platform. Usually the cause is a tag manager loading beside the consent layer rather than under it, or a vendor script writing storage from inside an iframe the blocking layer never inspects. Week one of every build goes to making the page silent before a choice exists. Nothing else ships until it is.
The build, in order:
Silence first. The tag manager comes under the consent layer, not next to it. Every tag gates on a consent trigger rather than a page-view trigger, iframes and pixels sit behind placeholders, and the site is retested from a cold profile until the pre-consent request list contains nothing but your own origin and the platform itself.
Signal layer second. Consent Mode v2 in advanced mode where the modelling earns its cost and basic mode where it does not, which is a decision with a measurement consequence and gets my recommendation with the reasoning, not a default. TCF v2.2 where you sell inventory or run programmatic: legitimate interest is gone for Purposes 3 through 6, vendor disclosures have to be readable by a person, and a vendor list carried over from v2.0 will not validate. GPP for the US, with the national string and section IDs mapped to the states you actually sell in rather than all of them.
Geo routing third. I do not recommend one global opt-in wall. It costs measurable analytics coverage in markets that never required it, and the case that it is simpler is a case about your build cost, not your risk. Routing goes by served jurisdiction with a documented rule for each, and Quebec gets its own rule rather than inheriting Canada's.
Records last. Consent proof storage that can answer, per user, what was shown, what was chosen and when, because that is the artefact a regulator asks for and a platform with proof retention switched off cannot produce it.
The QA grid:
Every build signs off against a grid: each governing geography, times four consent states including a returning visitor who changed their mind, across Safari with ITP, Chrome, and an in-app webview, plus a Global Privacy Control session. I run it, and you receive the grid with request evidence in each cell so your team can rerun it after any release.
Platforms I work in:
Didomi, Sourcepoint, OneTrust, Usercentrics, Cookiebot and Axeptio. I hold no reseller agreement with any of them and take no referral fee. If the platform you already pay for can do the job, I configure it rather than sell you a migration; where it genuinely cannot, I show you the specific capability it lacks before you buy anything.
What I will not ship:
Pre-ticked purposes. A reject path with more clicks than accept. A cookie wall in a market whose supervisory authority has already ruled against them. A legitimate interest tab over advertising personalisation. Consent lifetimes stretched past thirteen months with re-prompting pushed beyond six. Where any of that is in the brief because a growth target depends on the consent rate, I am the wrong person and the conversation is short.
Not included:
Analytics rebuilds, server-side container architecture, and the media-side consequences of a lower consent rate. I forecast the coverage loss before you commit, in your own numbers.
Scope
- Target market
- Worldwide, Canada, Germany, France
- Working language
- English, French
- Industry
- Ecommerce and DTC, Marketplaces, Travel and hospitality, Media and publishing
- Engagement model
- One-off project
- Turnaround
- 1 month or more
- Seller type
- In-house-grade specialist