Consent managementthat actually blocks.
A banner that doesn't block anything is worse than no banner, because it documents what you promised the visitor while your tags fire anyway. We audit what genuinely loads before and after a visitor clicks, wire real blocking on WordPress or Shopify, and wire Google Consent Mode v2 so the measurement you're allowed to keep still reaches Google. Our consent management services cover the implementation end to end, from the first cookie scan to the GPC check on the live site. Your counsel decides the policy, and we build what they specify.
- A scan and inventory of everything actually firing on your site
- Non-essential tags don't fire before consent, and you see the proof
- We implement what your counsel specifies. We don't give legal advice
Get Your Free Growth Audit
A free, no-obligation look at exactly why you aren't getting found or converting online, with a clear roadmap for how to fix it.
What Your Consent Management Setup Is Doing Right Now
A banner went up two years ago. Nobody has opened it since, and nothing on the site tells you whether it works. A visitor clicks Reject, the banner disappears, and your analytics, your ad pixel and three scripts nobody remembers installing load anyway.
That’s worse than having no banner at all. The banner is a written record of what you told that visitor you’d do, so when the tags fire regardless, you’ve documented the promise and missed the behavior. Nothing in the stack reports the gap, so it surfaces only when somebody looks.
The measurement side breaks in the same quiet way. Installing a consent platform doesn’t wire Google’s consent signals, and wiring those signals doesn’t give you a banner. They’re two separate jobs, and skipping the second one is how a GA4 property and a Google Ads account lose the modeled conversions they were supposed to keep.
Consent Management Is An Implementation Job With A Legal Boundary
A consent management platform is a tool, not an outcome. Google's own GA4 documentation (opens in new tab) says it plainly: "Consent mode does not provide a consent banner or widget." The banner collects the choice. Something else has to make every tag on the page respect it.
So the work is mechanical, and it's checkable. Scan what's actually loading. Categorize every script and cookie in writing. Wire blocking that holds before anyone clicks, then prove it by showing the tag list before consent and after consent on the same page.
We've written more on why cookie consent is a system, not a banner.
We don't write your privacy policy, we don't review one, and we don't give legal advice. We won't tell you which laws apply to your business. What we do is hand your counsel a written record of what's collected on your site, by whom, and under which category, so they're drafting against something real instead of a guess.
That work runs on WordPress and on Shopify, with different mechanics on each. We implement CookieYes on both. For enterprise clients who need consent alongside subject rights workflows, vendor risk and data mapping, we implement Osano.
What CMP Implementation Actually Covers
Audit And Inventory, Before Anything Is Configured
We scan the site and inventory what's actually loading: every cookie, every pixel, every third-party script, including the ones nobody remembers adding. CookieYes says its deep scan checks against "100,000+ categorised cookies and trackers", and Osano advertises automatic site scans with AI-powered cookie classification and curated block lists. Whichever tool you're on, you get the list.
- Every cookie and script loading on your site, written down
- CookieYes lists scanning behind logins and static IPs on Ultimate only
- CookieYes lists scheduled scanning as monthly on Pro and weekly on Ultimate
- The scripts a scanner misses, found by hand
Every Script And Cookie Categorized In Writing
Strictly necessary, analytics, or marketing. Every item on the inventory gets one, and you sign off on the mapping before any of it goes live. The categorization is the part that decides what a visitor's click actually does, so a marketing pixel filed as essential will fire for every visitor who declined.
- A written category for every cookie and script
- Your sign-off before the mapping goes live
- Essential means essential, not convenient
- The same document your counsel needs, handed to them
Real Blocking, Then Proof That It Blocks
CookieYes says it can automatically block third-party scripts such as Google Analytics and Facebook Pixel until a visitor consents, and lets you name more scripts by hand. Automatic is a starting point, not a result, so we test it. You get the tag list before consent and the tag list after consent, captured on the same page. A non-essential tag that fires before consent is a defect, and we fix it.
- Non-essential tags held until the visitor chooses
- A before-and-after tag list you can see for yourself
- CookieYes lists Google Tag Manager and Microsoft UET triggers that fire only on consent
- Scripts the scanner missed, named and blocked by hand
Consent Mode v2 Wired Signal By Signal
All four signals configured explicitly, including ad_user_data and ad_personalization, rather than left to whatever a default hands you. Per Google's consent mode documentation (opens in new tab), tags you build yourself without built-in consent checks can have them added in Tag Manager, under Advanced > Consent Settings. You also get a written answer on whether you're running basic or advanced consent mode and what each one costs you in modeling.
- ad_storage, analytics_storage, ad_user_data and ad_personalization, all set on purpose
- Region-specific defaults where your traffic needs them
- Consent checks added in Tag Manager for tags you build yourself
- Basic or advanced, decided in writing, not by accident
Cookie Consent And Universal Opt-Out Signals, Verified On The Live Site
Global Privacy Control is a browser-level signal, and honoring it isn't the same as flipping a toggle. CookieYes's pricing page (opens in new tab) lists Global Privacy Control as No on Free and Basic and Yes on Pro and Ultimate, so the plan you're paying for decides whether the feature exists at all. On Shopify, per Shopify's Customer Privacy API documentation (opens in new tab), the GPC signal is collected and honored automatically in regions configured for data sale opt-out and can't be adjusted through setTrackingConsent. We verify GPC on your live site instead of trusting the switch.
- GPC checked on the live site, not assumed from a setting
- Your CookieYes plan checked against the features you're relying on
- On Shopify, the data sale opt-out region configuration confirmed
- Osano advertises GPC handling as a platform capability
Consent Management Upkeep, Because Your Stack Keeps Changing
A new reviews app. A pixel for a channel you tested once. A tag somebody added for a two-week campaign and never removed. We re-scan on a set cadence and review new vendors and pixels before they launch, so the inventory you signed off on still describes the site a year from now.
- Re-scans on a set cadence
- New vendors and pixels reviewed before they launch
- An inventory that still matches the site next year
Find Out What Your Cookie Consent Banner Isn't Blocking
A free Growth Audit looks at what's actually loading on your site, when each thing loads, and which of it fires before a visitor consents. You get the list either way. Not a sales call. Not a quote request.
Cookie Consent Management On WordPress And On Shopify
Two banners on a Shopify store isn't a design problem. It's two systems each assuming the other one handled consent.
On WordPress, consent management is a plugin plus a tag-manager configuration. The plugin renders the banner and blocks scripts. The tag configuration decides what your Google tags do with the answer. Both have to agree, and the plugin’s automatic blocking has to be checked against what your theme and your other plugins actually load.
Shopify adds places to get it wrong. Per Shopify’s Customer Privacy API documentation (opens in new tab), the API is a browser-based JavaScript API, and its scope is specific: it’s used “to apply consent decisions to Shopify-managed surfaces, like pixels, audiences, and checkout.” Shopify’s docs describe the native banner governing those Shopify-managed surfaces and don’t describe it blocking scripts you installed yourself. That’s an absence in the documentation rather than Shopify saying it’s impossible, and it’s why a CMP still has a job on a Shopify store.
Then there’s the banner count. CookieYes’s Shopify install guide (opens in new tab) tells you to open Settings, then Customer Privacy, then Cookie banner, confirm the CookieYes app appears in Installed privacy apps, remove Shopify’s own cookie banner, and then set the regions. Shopify’s docs say that when its native banner is enabled it displays in the configured regions and passes consent to the API automatically, and that if an app provides the banner instead you should ask that app’s developer where it renders. Two banners is a real failure mode, and the regions get set in two places.
So the Shopify checklist is short and specific: exactly one banner live, the CMP registered in Shopify’s Installed privacy apps, and the regions in Shopify admin matching the regions in the CMP. We check all three. Shopify’s docs also state that consent should only ever be recorded on a visitor interaction, never set automatically on the visitor’s behalf, which is worth confirming on a store where somebody has customized the theme.
- +Exactly one banner live, and the CMP in Installed privacy apps
- +Regions set in Shopify admin and in the CMP, and matching
- +GPC honored automatically in data sale opt-out regions, per Shopify's docs
- +Consent recorded on a visitor action, never on page load
Google Consent Mode v2, Signal By Signal
ad_storage Governs Advertising Cookies
Google's consent mode overview (opens in new tab) describes ad_storage as enabling storage, such as cookies on web or device identifiers in apps, related to advertising. Deny it and Google's tag behavior table says "No new cookies or device identifiers pertaining to advertising may be written." Existing advertising cookies aren't read either, requests route through a different domain to avoid previously set third-party cookies, and Google Analytics stops reading or writing Google Ads cookies for that traffic. Full page URLs including GCLID and DCLID are still collected.
- No new advertising cookies or device identifiers written
- Existing advertising cookies not read
- Google signals features stop accumulating data for that traffic
- Ads products truncate IP addresses at collection
analytics_storage Governs Your GA4 Cookies
Google describes analytics_storage as enabling storage, such as cookies on web or device identifiers in apps, related to analytics, giving visit duration as the example. When it's denied, Google's table says tags "Won't read or write first-party analytics cookies or app identifiers." Measurements without third-party cookies are still sent to Google Analytics for basic measurement and modeling. That's the difference between losing the visit and losing the cookie, and it's worth knowing which one you're accepting.
- First-party analytics cookies neither read nor written
- Cookieless measurements still sent for basic measurement and modeling
- Your GA4 reporting changes shape, and you should know how before it does
ad_user_data Governs Enhanced Conversions
Google's consent mode overview describes ad_user_data as setting consent for sending user data to Google for online advertising purposes. Deny it and Google's table says "Personal data collection for online advertising is disabled," naming user_id and enhanced conversions using hashed first-party data. If your Google Ads account leans on enhanced conversions, this is the signal that governs them. It isn't ad_storage, and that mix-up is common enough to be worth spelling out.
- Enhanced conversions hang off this signal, not ad_storage
- user_id collection for advertising stops
- Set explicitly rather than inherited from a default
ad_personalization Governs Remarketing Audiences
Google describes ad_personalization as setting consent for personalized advertising. When it's denied, Google's table says personalized advertising is disabled and names what stops receiving data: remarketing in Google Ads, Display & Video 360, and Search Ads 360. Remarketing hangs off ad_personalization. That one fact is why an audience list can shrink while nothing in the Ads interface looks broken.
- Remarketing in Google Ads, Display and Video 360, and Search Ads 360
- Personalized advertising with Google's advertising products
- The signal most often left at a default, and the one retargeting needs
Basic Or Advanced Consent Mode, Chosen On Purpose
Google's documentation describes the basic version as preventing Google tags from loading until a user interacts with a consent banner, with no data transferred to Google at all when the user doesn't consent, not even the consent status. In the advanced version, Google tags load when the page opens, send measurements without cookies while consent is denied, and send full data once it's granted. Google's own comparison table gives basic a general model for conversion and key event modeling, and advanced an advertiser-specific model. Which one you run is a business decision your counsel constrains, so we put the tradeoff in writing rather than picking it quietly.
- Basic: tags don't load until the visitor interacts with the banner
- Advanced: tags load and send cookieless measurements while consent is denied
- Basic buys a general model, advanced buys an advertiser-specific model
- The choice documented, with what each costs you in modeling
How A Consent Management Engagement Runs
It starts with a free Growth Audit. We scan the site and inventory every cookie, pixel and third-party script that's actually loading, including the ones nobody remembers adding. You get the list. No assumptions, and no selling you work you don't need.
Every cookie and script is mapped to a category in writing: strictly necessary, analytics, or marketing. You review and sign off on that mapping before anything goes live, because the categories decide what a visitor's click actually does. That same document goes to your counsel, which is the point of writing it down.
The banner and the preference center get built to look like your brand rather than a default template. The preference center is where a visitor changes their mind later, so it has to be findable and it has to work. Per Shopify's developer docs, consent should only ever be recorded on a visitor interaction and never set automatically on the visitor's behalf, which is a rule worth honoring on every platform.
We wire the blocking, then we test it. CookieYes says it can block third-party scripts automatically until a visitor consents and lets you name additional scripts by hand, and whichever tool you're on, automatic is a starting point rather than a result. You get the tag list before consent and the tag list after consent, on the same page. A non-essential tag that fires before consent is a defect, and we fix it.
All four signals configured explicitly, with region-specific defaults where your traffic needs them, and consent checks added in Tag Manager for tags you build yourself. You get a written answer on whether you're running basic or advanced consent mode and what each one costs you in modeling. See what that protects in our GA4 setup and reporting work.
We validate the behavior on the live site rather than trusting the toggles. That includes GPC handling, which on CookieYes depends on the plan you're paying for, and on Shopify includes confirming the data sale opt-out region configuration. Exactly one banner live, the CMP registered in Shopify's Installed privacy apps, and the regions matching in both places.
Your stack changes, so the inventory has to keep up with it. We re-scan on a set cadence and review new vendors and pixels before they launch. A consent setup that was accurate at launch and never touched again is exactly the thing we get hired to replace.
Bring Us The Cookie Consent Banner Nobody Has Touched Since Install
If a banner went up years ago and nobody has checked it since, bring it to a free Growth Audit. We'll tell you what's firing before consent, whether your Consent Mode signals are configured or defaulted, and whether the plan you're paying for includes the features you think it does. No obligation.
What Changes When Consent Management Is Implemented, Not Installed
Consent Management Services, Before You Ask
No, and be careful with anyone who says yes. Compliance is a legal determination about your specific business, made by people qualified to make it. What we deliver is implementation: the scan, the written categorization, real script blocking, Consent Mode v2 wiring, and universal opt-out signal handling. Then we hand your counsel a record of what's collected on your site, by whom, and under which category, so they can draft against something real.
Google's documentation describes the basic version as preventing Google tags from loading until a user interacts with the consent banner, with no data transferred to Google at all when the user doesn't consent, not even the consent status. In the advanced version, Google tags load when the page opens, send measurements without cookies while consent is denied, and send full data once it's granted. Google's own comparison table gives basic a general model for conversion and key event modeling, and advanced an advertiser-specific model. That's a business decision rather than a technical default, so we put the tradeoff in writing and you make the call with your counsel.
It covers a specific slice: Shopify's developer documentation describes the Customer Privacy API as applying consent decisions to Shopify-managed surfaces, and it names pixels, audiences and checkout. Shopify's docs don't describe the native banner blocking scripts you installed yourself, and we won't put words in Shopify's mouth about what it can't do. What we will say is that the analytics, ads, reviews, chat and heatmap tags most stores add aren't Shopify-managed surfaces, which is why a CMP still has a job on a Shopify store. If you run one, exactly one banner should be live: CookieYes's own install guide tells you to confirm the app appears in Shopify's Installed privacy apps and then remove Shopify's banner.
CookieYes for most WordPress and Shopify stores. Osano when the requirement is bigger than cookies. Osano sells cookie consent alongside subject rights and DSAR workflows, vendor risk, data mapping and assessments as one platform, and it advertises mobile SDKs, APIs and GRC tool integrations, where CookieYes sells cookie consent and policy generators. One thing to check on CookieYes before you commit: its pricing page lists Global Privacy Control as available on Pro and Ultimate and not on Free or Basic, while Google Consent Mode v2 is listed as available on all four plans.
In Colorado, the Attorney General's office states that beginning July 1, 2024, businesses within the Colorado Privacy Act's application thresholds must allow consumers to opt out of the sale of personal data, or its use for targeted advertising, using GPC, and that GPC is currently the only universal opt-out mechanism the Department considers valid. In California, the Attorney General's office states that under law GPC must be honored by covered businesses as a valid request to stop the sale or sharing of personal information. Whether your business falls inside either set of thresholds is a question for your lawyer. What we can tell you is whether your site is actually honoring the signal, which is a different question and frequently a different answer.
They depend on ad_personalization, one of the four Consent Mode v2 signals. Google's tag behavior table says that when ad_personalization is denied, personalized advertising is disabled and remarketing in Google Ads, Display and Video 360, and Search Ads 360 stops receiving data. Enhanced conversions are governed by a different signal, ad_user_data, and the two get confused constantly. Leaving either at a default is how an audience list shrinks while nothing in the Ads interface looks broken, so we configure all four explicitly.
A decision, not a document. Tell us what your counsel says the site has to do: which regions get a banner, whether consent is opt-in or opt-out in each, whether you're running basic or advanced consent mode, and how universal opt-out requests should be handled. We build exactly that. In return they get a written record of every cookie and script on the site, who it belongs to and which category it's in, which is what Colorado's rules expect them to be able to describe in the privacy policy.
Nothing, and there's no obligation attached. It's a clear look at what's loading on your site, when each thing loads, which of it fires before a visitor consents, and whether your Consent Mode signals are configured or defaulted. Not a sales call. Not a quote request.