Service 03 · Consent and privacy measurement
Turn the client's privacy requirements into a working measurement setup.
I help agencies implement and validate Consent Mode v2, consent management platforms, tag blocking, regional consent behavior, and privacy-related measurement changes. The client or legal team defines the requirements. I translate them into the technical configuration across the website, CMP, Google Tag Manager, analytics, and advertising platforms. Your agency keeps the client relationship. I handle the technical work.
Where consent projects go wrong
The banner is only one part of the implementation.
A consent platform can appear to be working while the tracking underneath it is not. Tags may fire before the visitor makes a choice. Consent signals may never update. Regions may receive the wrong experience. Advertising platforms may receive incomplete or conflicting signals. Or the implementation may block more tracking than the client's approved requirements call for.
The result is usually a mix of privacy risk, reporting gaps, and confusion between the agency, developer, legal team, and media partners.
- 01Marketing and analytics tags are loading before the visitor makes a consent choice.
- 02The banner records a choice, but Consent Mode never updates.
- 03GA4 and Google Ads reporting dropped sharply after the CMP launched.
- 04Different regions are seeing the wrong banner or consent behavior.
- 05The client has more than one CMP, cookie script, or consent implementation active.
- 06Tags are categorized incorrectly or are not responding to consent changes.
- 07Global Privacy Control signals are not being recognized or honored as required.
- 08Forms, personalization tools, chat platforms, or embedded content are being blocked unexpectedly.
- 09The legal team approved one setup, but the website is behaving differently.
Technical implementation
Start with the approved privacy requirements.
I do not determine the client's legal position. The client, privacy team, or legal counsel must define the applicable requirements — regions, consent models, categories, opt-in or opt-out behavior, and Global Privacy Control handling.
Once those decisions are documented, I configure and validate the technical implementation.
- LegalCounsel defines the requirements. Regions, consent model, categories, opt-in or opt-out, GPC handling.
- DocRequirements are documented. A written basis for the configuration and every test that follows.
- BuildI configure the implementation. CMP, Consent Mode, GTM, analytics, and advertising platforms.
- ProofI validate the behavior. Evidence that the site matches the approved requirements.
Scope
What the implementation covers.
Consent Mode v2
Configuration and validation of default and update states for analytics storage, ad storage, ad user data, ad personalization, and other applicable consent types.
Consent management platforms
Implementation, remediation, or validation for OneTrust, Cookiebot, CookieYes, Shopify Customer Privacy, or another agreed CMP.
Regional consent behavior
Configuration and testing of regional, national, state-level, or jurisdiction-specific experiences based on the requirements provided by the client or counsel.
Tag blocking and release
Validation of which tags load before consent, after consent, after rejection, and after a visitor changes their preferences.
Google Tag Manager integration
Consent-aware triggers, consent requirements, CMP events, default states, update events, sequencing, and tag-level validation.
Global Privacy Control
Technical testing and implementation of Global Privacy Control behavior based on the client's documented requirements.
Cookie and technology review
Review of detected cookies, tags, pixels, SDKs, embedded tools, and other website technologies to support categorization. Final legal classification should be confirmed by the client or counsel.
Analytics and advertising validation
Testing of GA4, Google Ads, Meta, LinkedIn, TikTok, and other included platforms before and after consent choices.
Consent across forms and third-party tools
Validation of forms, chat tools, video embeds, booking platforms, ecommerce systems, CRM integrations, and other third-party technologies affected by consent.
Measurement impact
Comparison of relevant analytics and advertising data before and after implementation where baseline data is available. The report distinguishes expected consent-driven changes from technical configuration issues.
Documentation
Unbranded implementation notes, consent behavior matrix, testing evidence, known limitations, and maintenance guidance.
Deliverables
A setup your agency can explain, validate, and hand off.
Working consent implementation
Configured CMP, Consent Mode, GTM behavior, regional rules, and platform integrations included in the agreed scope.
Validation evidence
Testing across consent states, regions, tag behavior, network requests, browser storage, and platform diagnostics.
Consent behavior matrix
A clear record of what should happen before a choice, after acceptance, after rejection, and after a visitor updates their preferences.
Measurement impact summary
An explanation of what changed in the data, which changes are expected, and which issues point to a technical problem.
Unbranded documentation
Reports and technical notes can be delivered without Atem Analytics branding so your agency can use them with the client.
Agency and client walkthrough
I can brief your internal team, join the client meeting as part of your agency, or provide notes for your team to present directly.
Common use cases
Bring me in when privacy requirements reach the implementation layer.
New CMP implementations
The client or legal team has selected a CMP and needs the website, GTM, analytics, and advertising configuration completed properly.
Existing consent problems
The banner is live, but tags, signals, regions, categories, or preferences are not behaving as intended.
Consent Mode remediation
Consent Mode v2 is missing, partially implemented, or sending incorrect default and update states.
Multi-region websites
The client needs different consent behavior by country, region, or state and the current configuration cannot support it reliably.
Measurement decline after launch
GA4, Google Ads, or paid media reporting changed after a consent implementation and the agency needs to understand why.
Privacy complaints or legal review
The client's counsel or privacy team identified a concern and needs technical changes made across the website and tracking stack.
Website redesigns and migrations
Consent, tag blocking, and measurement requirements need to be included in the new website before launch.
Platform and vendor coordination
Several agencies, developers, CMP vendors, legal stakeholders, and internal teams are involved and need one technical owner for the implementation.
Scope and pricing
Defined around the client's requirements and environment.
- Price
- Projects start at $2,900 for a single website and one consent management platform. Final pricing depends on the number of websites, brands, regions, consent models, platforms, tags, and third-party technologies included in the scope.
- Turnaround
- Most implementations take two to three weeks after the approved requirements, access, and technical dependencies have been provided. Additional measurement monitoring may follow the launch where before-and-after comparison is included.
- Access required
- Access may be needed to the CMP, website platform, Google Tag Manager, GA4, advertising platforms, ecommerce system, and other tools included in the scope.
- Deliverables
- Configured implementation, validation evidence, consent behavior matrix, technical documentation, and measurement impact summary where applicable.
- Legal boundary
- Atem Analytics provides technical implementation and measurement consulting, not legal advice. The client or its legal counsel is responsible for defining the applicable privacy requirements and approving the final consent model.
Frequently asked questions
What agencies ask about consent work.
Do you determine which consent model the client should use?
No. The client or its legal counsel must determine the applicable legal requirements and approved consent model. I configure and validate the technical implementation based on those instructions.
Can you guarantee the setup is legally compliant?
No technical consultant should make that guarantee. I can validate whether the website and tracking systems behave according to the documented requirements provided by the client or counsel. Final legal approval remains with the client's legal team.
Will Consent Mode recover all lost data?
No. Consent Mode can support modeled reporting and improve how consent signals are communicated to Google platforms. It does not replace unconsented data or guarantee a specific level of reporting recovery.
Does rejecting consent mean all tracking must stop?
That depends on the client's approved requirements, applicable jurisdictions, the technology involved, and the type of data being collected. I implement the behavior defined by the client or counsel.
Can you work with our client's legal team?
Yes. I can translate their requirements into technical rules, explain current website behavior, and provide validation evidence after implementation.
Can you repair an existing OneTrust or Cookiebot setup?
Yes. I can review and remediate existing CMP configurations, GTM integrations, regional rules, consent signals, tag blocking, categorization, and preference center behavior.
Do you write the privacy policy or legal language?
No. The client's legal team should provide or approve privacy notices, banner language, category descriptions, and legal disclosures. I can help identify where that approved language must appear within the technical implementation.
Can you measure the effect on reporting?
Yes, when reliable baseline and post-launch data are available. The analysis will separate expected consent-related changes from technical issues, but it will not promise a specific recovery percentage.
Start with the current behavior
Not sure whether the consent setup is working as intended?
Send me the client website and tell me what changed or what your team is concerned about. I'll review the publicly visible consent behavior, Consent Mode signals, and tag activity, then explain whether the issue appears to require configuration changes, account access, legal clarification, or a deeper technical audit.