Real inventory, prior blocking, a correct banner, Consent Mode v2 and verification
Not because of the wording. Because of what the page loads before the user decides.
Analytics, the Meta pixel, the map, the YouTube video. The banner is there, but it blocks nothing. It is the most common failure and the easiest to prove with browser tools.
Accept on a big button; reject two clicks and a grey panel away. The Spanish DPA's guidance calls this out explicitly, and so do inspectors.
Modules, themes and third-party widgets bring their own scripts without the owner knowing. The cookie policy lists four; the site sets twenty.
Blocking bluntly leaves Analytics and Ads blind. Consent Mode v2 exists to keep modelled measurement while respecting the user's choice, but it has to be configured and the signals verified.
Technical implementation and verification. Legal validation of the texts belongs to your legal adviser.
Crawl of the site to identify every cookie, local storage entry and third-party script that loads, including those brought in by modules, themes or integrations without the owner knowing. We document what each one loads, for what purpose and when.
Configuration so that nothing beyond the strictly necessary runs before consent: measurement tags, advertising pixels, maps, embedded videos, fonts and external resources. It is the point most implementations fail.
Notice with accept and reject equivalent in visibility and number of clicks, granularity by purpose, accessible withdrawal and a record of what was consented.
Configuration of consent signals in Google Tag Manager, Analytics and Ads, verifying that they are transmitted correctly and that measurement behaves as it should in each state.
Cookie policy written from the real inventory, with the table of cookies, purpose and duration. Review of the site's legal texts against the requirements of the Spanish LSSI-CE and LOPDGDD.
Post-implementation check with audit tools and review of network requests before and after consent, with a report of the final state.
Scope: technical implementation and verification service. It does not include legal advice and does not replace validation by a legal professional.
First look at what really loads. Then block, configure and verify.
We go through the site as a new user and record every cookie, storage entry and third-party script, who sets it and when. That inventory is the basis for everything else.
We configure the consent platform (yours or the one we recommend) so nothing non-essential loads before the choice, with equivalent accept and reject and options by purpose.
Consent signals in Google Tag Manager, Analytics and Ads, and a check that each tag behaves according to the chosen state.
Review of network requests before and after consenting, a report of the final state and a cookie policy generated from the real inventory.
Sites and stores that measure, advertise and don't want compliance and measurement to get in each other's way.
Without Consent Mode v2 properly configured, conversions stop being attributed and campaigns optimise blind. Here compliance and performance go together.
PrestaShop, WordPress and WooCommerce accumulate third-party scripts with every module. The real inventory is usually a surprise.
If the DPA or a client has asked, or if you would rather not wait for them to, the verification report documents the state before and after.
Consent is one piece of your site’s measurement and security.
With measurement and consent properly set up, campaigns optimise on real data. We manage Ads with conversion tracking included.
See Google AdsHeaders, session cookies, third-party scripts and site exposure, reviewed from a security standpoint.
See the auditEvery new module can bring a new script. Under maintenance we review the inventory whenever the site changes.
See maintenanceThe URL is enough for the first crawl. We tell you what loads before consent and what it would take to fix it.