Skip to content
Consent Management Services

Consent management
that actually blocks.

A banner that doesn't block anything is worse than no banner, because it documents what you promised the visitor while your tags fire anyway. We audit what genuinely loads before and after a visitor clicks, wire real blocking on WordPress or Shopify, and wire Google Consent Mode v2 so the measurement you're allowed to keep still reaches Google. Our consent management services cover the implementation end to end, from the first cookie scan to the GPC check on the live site. Your counsel decides the policy, and we build what they specify.

  • A scan and inventory of everything actually firing on your site
  • Non-essential tags don't fire before consent, and you see the proof
  • We implement what your counsel specifies. We don't give legal advice

Get Your Free Growth Audit

A free, no-obligation look at exactly why you aren't getting found or converting online, with a clear roadmap for how to fix it.

We reply within one business day. No spam, ever.

What Your Consent Management Setup Is Doing Right Now

A banner went up two years ago. Nobody has opened it since, and nothing on the site tells you whether it works. A visitor clicks Reject, the banner disappears, and your analytics, your ad pixel and three scripts nobody remembers installing load anyway.

That’s worse than having no banner at all. The banner is a written record of what you told that visitor you’d do, so when the tags fire regardless, you’ve documented the promise and missed the behavior. Nothing in the stack reports the gap, so it surfaces only when somebody looks.

The measurement side breaks in the same quiet way. Installing a consent platform doesn’t wire Google’s consent signals, and wiring those signals doesn’t give you a banner. They’re two separate jobs, and skipping the second one is how a GA4 property and a Google Ads account lose the modeled conversions they were supposed to keep.

Our position

Consent Management Is An Implementation Job With A Legal Boundary

A consent management platform is a tool, not an outcome. Google's own GA4 documentation (opens in new tab) says it plainly: "Consent mode does not provide a consent banner or widget." The banner collects the choice. Something else has to make every tag on the page respect it.

So the work is mechanical, and it's checkable. Scan what's actually loading. Categorize every script and cookie in writing. Wire blocking that holds before anyone clicks, then prove it by showing the tag list before consent and after consent on the same page.

We've written more on why cookie consent is a system, not a banner.

We don't write your privacy policy, we don't review one, and we don't give legal advice. We won't tell you which laws apply to your business. What we do is hand your counsel a written record of what's collected on your site, by whom, and under which category, so they're drafting against something real instead of a guess.

That work runs on WordPress and on Shopify, with different mechanics on each. We implement CookieYes on both. For enterprise clients who need consent alongside subject rights workflows, vendor risk and data mapping, we implement Osano.

PlatformsWordPress, Shopify
ToolsCookieYes, Osano
Based inDenver, CO
Out of scopePrivacy policy drafting and legal advice
What we implement

What CMP Implementation Actually Covers

Audit

Audit And Inventory, Before Anything Is Configured

We scan the site and inventory what's actually loading: every cookie, every pixel, every third-party script, including the ones nobody remembers adding. CookieYes says its deep scan checks against "100,000+ categorised cookies and trackers", and Osano advertises automatic site scans with AI-powered cookie classification and curated block lists. Whichever tool you're on, you get the list.

  • Every cookie and script loading on your site, written down
  • CookieYes lists scanning behind logins and static IPs on Ultimate only
  • CookieYes lists scheduled scanning as monthly on Pro and weekly on Ultimate
  • The scripts a scanner misses, found by hand
Categories

Every Script And Cookie Categorized In Writing

Strictly necessary, analytics, or marketing. Every item on the inventory gets one, and you sign off on the mapping before any of it goes live. The categorization is the part that decides what a visitor's click actually does, so a marketing pixel filed as essential will fire for every visitor who declined.

  • A written category for every cookie and script
  • Your sign-off before the mapping goes live
  • Essential means essential, not convenient
  • The same document your counsel needs, handed to them
Blocking

Real Blocking, Then Proof That It Blocks

CookieYes says it can automatically block third-party scripts such as Google Analytics and Facebook Pixel until a visitor consents, and lets you name more scripts by hand. Automatic is a starting point, not a result, so we test it. You get the tag list before consent and the tag list after consent, captured on the same page. A non-essential tag that fires before consent is a defect, and we fix it.

  • Non-essential tags held until the visitor chooses
  • A before-and-after tag list you can see for yourself
  • CookieYes lists Google Tag Manager and Microsoft UET triggers that fire only on consent
  • Scripts the scanner missed, named and blocked by hand
Consent Mode

Consent Mode v2 Wired Signal By Signal

All four signals configured explicitly, including ad_user_data and ad_personalization, rather than left to whatever a default hands you. Per Google's consent mode documentation (opens in new tab), tags you build yourself without built-in consent checks can have them added in Tag Manager, under Advanced > Consent Settings. You also get a written answer on whether you're running basic or advanced consent mode and what each one costs you in modeling.

  • ad_storage, analytics_storage, ad_user_data and ad_personalization, all set on purpose
  • Region-specific defaults where your traffic needs them
  • Consent checks added in Tag Manager for tags you build yourself
  • Basic or advanced, decided in writing, not by accident
Opt-Out Signals

Cookie Consent And Universal Opt-Out Signals, Verified On The Live Site

Global Privacy Control is a browser-level signal, and honoring it isn't the same as flipping a toggle. CookieYes's pricing page (opens in new tab) lists Global Privacy Control as No on Free and Basic and Yes on Pro and Ultimate, so the plan you're paying for decides whether the feature exists at all. On Shopify, per Shopify's Customer Privacy API documentation (opens in new tab), the GPC signal is collected and honored automatically in regions configured for data sale opt-out and can't be adjusted through setTrackingConsent. We verify GPC on your live site instead of trusting the switch.

  • GPC checked on the live site, not assumed from a setting
  • Your CookieYes plan checked against the features you're relying on
  • On Shopify, the data sale opt-out region configuration confirmed
  • Osano advertises GPC handling as a platform capability
Upkeep

Consent Management Upkeep, Because Your Stack Keeps Changing

A new reviews app. A pixel for a channel you tested once. A tag somebody added for a two-week campaign and never removed. We re-scan on a set cadence and review new vendors and pixels before they launch, so the inventory you signed off on still describes the site a year from now.

  • Re-scans on a set cadence
  • New vendors and pixels reviewed before they launch
  • An inventory that still matches the site next year

Find Out What Your Cookie Consent Banner Isn't Blocking

A free Growth Audit looks at what's actually loading on your site, when each thing loads, and which of it fires before a visitor consents. You get the list either way. Not a sales call. Not a quote request.

Platform mechanics

Cookie Consent Management On WordPress And On Shopify

Two banners on a Shopify store isn't a design problem. It's two systems each assuming the other one handled consent.

On WordPress, consent management is a plugin plus a tag-manager configuration. The plugin renders the banner and blocks scripts. The tag configuration decides what your Google tags do with the answer. Both have to agree, and the plugin’s automatic blocking has to be checked against what your theme and your other plugins actually load.

Shopify adds places to get it wrong. Per Shopify’s Customer Privacy API documentation (opens in new tab), the API is a browser-based JavaScript API, and its scope is specific: it’s used “to apply consent decisions to Shopify-managed surfaces, like pixels, audiences, and checkout.” Shopify’s docs describe the native banner governing those Shopify-managed surfaces and don’t describe it blocking scripts you installed yourself. That’s an absence in the documentation rather than Shopify saying it’s impossible, and it’s why a CMP still has a job on a Shopify store.

Then there’s the banner count. CookieYes’s Shopify install guide (opens in new tab) tells you to open Settings, then Customer Privacy, then Cookie banner, confirm the CookieYes app appears in Installed privacy apps, remove Shopify’s own cookie banner, and then set the regions. Shopify’s docs say that when its native banner is enabled it displays in the configured regions and passes consent to the API automatically, and that if an app provides the banner instead you should ask that app’s developer where it renders. Two banners is a real failure mode, and the regions get set in two places.

So the Shopify checklist is short and specific: exactly one banner live, the CMP registered in Shopify’s Installed privacy apps, and the regions in Shopify admin matching the regions in the CMP. We check all three. Shopify’s docs also state that consent should only ever be recorded on a visitor interaction, never set automatically on the visitor’s behalf, which is worth confirming on a store where somebody has customized the theme.

  • +Exactly one banner live, and the CMP in Installed privacy apps
  • +Regions set in Shopify admin and in the CMP, and matching
  • +GPC honored automatically in data sale opt-out regions, per Shopify's docs
  • +Consent recorded on a visitor action, never on page load
Google Consent Mode v2

Google Consent Mode v2, Signal By Signal

ad_storage

ad_storage Governs Advertising Cookies

Google's consent mode overview (opens in new tab) describes ad_storage as enabling storage, such as cookies on web or device identifiers in apps, related to advertising. Deny it and Google's tag behavior table says "No new cookies or device identifiers pertaining to advertising may be written." Existing advertising cookies aren't read either, requests route through a different domain to avoid previously set third-party cookies, and Google Analytics stops reading or writing Google Ads cookies for that traffic. Full page URLs including GCLID and DCLID are still collected.

  • No new advertising cookies or device identifiers written
  • Existing advertising cookies not read
  • Google signals features stop accumulating data for that traffic
  • Ads products truncate IP addresses at collection
analytics_storage

analytics_storage Governs Your GA4 Cookies

Google describes analytics_storage as enabling storage, such as cookies on web or device identifiers in apps, related to analytics, giving visit duration as the example. When it's denied, Google's table says tags "Won't read or write first-party analytics cookies or app identifiers." Measurements without third-party cookies are still sent to Google Analytics for basic measurement and modeling. That's the difference between losing the visit and losing the cookie, and it's worth knowing which one you're accepting.

  • First-party analytics cookies neither read nor written
  • Cookieless measurements still sent for basic measurement and modeling
  • Your GA4 reporting changes shape, and you should know how before it does
ad_user_data

ad_user_data Governs Enhanced Conversions

Google's consent mode overview describes ad_user_data as setting consent for sending user data to Google for online advertising purposes. Deny it and Google's table says "Personal data collection for online advertising is disabled," naming user_id and enhanced conversions using hashed first-party data. If your Google Ads account leans on enhanced conversions, this is the signal that governs them. It isn't ad_storage, and that mix-up is common enough to be worth spelling out.

  • Enhanced conversions hang off this signal, not ad_storage
  • user_id collection for advertising stops
  • Set explicitly rather than inherited from a default
ad_personalization

ad_personalization Governs Remarketing Audiences

Google describes ad_personalization as setting consent for personalized advertising. When it's denied, Google's table says personalized advertising is disabled and names what stops receiving data: remarketing in Google Ads, Display & Video 360, and Search Ads 360. Remarketing hangs off ad_personalization. That one fact is why an audience list can shrink while nothing in the Ads interface looks broken.

  • Remarketing in Google Ads, Display and Video 360, and Search Ads 360
  • Personalized advertising with Google's advertising products
  • The signal most often left at a default, and the one retargeting needs
Basic or advanced

Basic Or Advanced Consent Mode, Chosen On Purpose

Google's documentation describes the basic version as preventing Google tags from loading until a user interacts with a consent banner, with no data transferred to Google at all when the user doesn't consent, not even the consent status. In the advanced version, Google tags load when the page opens, send measurements without cookies while consent is denied, and send full data once it's granted. Google's own comparison table gives basic a general model for conversion and key event modeling, and advanced an advertiser-specific model. Which one you run is a business decision your counsel constrains, so we put the tradeoff in writing rather than picking it quietly.

  • Basic: tags don't load until the visitor interacts with the banner
  • Advanced: tags load and send cookieless measurements while consent is denied
  • Basic buys a general model, advanced buys an advertiser-specific model
  • The choice documented, with what each costs you in modeling
Measurement

What Consent Mode Protects, And What It Doesn't

Consent mode isn’t a banner, and a banner isn’t consent mode. Google’s GA4 documentation (opens in new tab) states that “Consent mode does not provide a consent banner or widget.” It interacts with the CMP you install. Two jobs, two implementations, and skipping either one leaves the other doing nothing useful.

What consent mode buys you is modeling. The same Google article says that when visitors deny consent, tags send pings to Google instead of storing cookies, and that Google fills the data collection gaps with conversion modeling and behavioral modeling. Skip the wiring and there’s no ping, no model, and no record that anything went missing.

There’s a contractual layer underneath the technical one. Google’s EU user consent policy (opens in new tab) requires, where your agreement incorporates it, that you obtain legally valid consent from end users in the European Economic Area, the UK and Switzerland for the use of cookies or other local storage where legally required, and for the collection, sharing and use of personal data to personalize ads. It also requires you to keep records of consent and give users clear instructions for revoking it. Google states it may limit or suspend your use of the Google product in question, or terminate the agreement, for failure to comply.

This is the seam between consent and measurement, and it’s why the two pieces of work belong on the same desk. Our GA4 setup and reporting work builds the event architecture, the conversion definitions and the dashboards. Consent mode decides how much of that Google is allowed to collect and how much it has to model. Get one right and the other wrong, and your reporting is confidently incomplete.

How it works

How A Consent Management Engagement Runs

Cookie Scan And Inventory

It starts with a free Growth Audit. We scan the site and inventory every cookie, pixel and third-party script that's actually loading, including the ones nobody remembers adding. You get the list. No assumptions, and no selling you work you don't need.

Category Mapping

Every cookie and script is mapped to a category in writing: strictly necessary, analytics, or marketing. You review and sign off on that mapping before anything goes live, because the categories decide what a visitor's click actually does. That same document goes to your counsel, which is the point of writing it down.

Banner And Preference Center Design

The banner and the preference center get built to look like your brand rather than a default template. The preference center is where a visitor changes their mind later, so it has to be findable and it has to work. Per Shopify's developer docs, consent should only ever be recorded on a visitor interaction and never set automatically on the visitor's behalf, which is a rule worth honoring on every platform.

Script Blocking And Tag Rules

We wire the blocking, then we test it. CookieYes says it can block third-party scripts automatically until a visitor consents and lets you name additional scripts by hand, and whichever tool you're on, automatic is a starting point rather than a result. You get the tag list before consent and the tag list after consent, on the same page. A non-essential tag that fires before consent is a defect, and we fix it.

Consent Mode v2 Setup

All four signals configured explicitly, with region-specific defaults where your traffic needs them, and consent checks added in Tag Manager for tags you build yourself. You get a written answer on whether you're running basic or advanced consent mode and what each one costs you in modeling. See what that protects in our GA4 setup and reporting work.

Quality Assurance

We validate the behavior on the live site rather than trusting the toggles. That includes GPC handling, which on CookieYes depends on the plan you're paying for, and on Shopify includes confirming the data sale opt-out region configuration. Exactly one banner live, the CMP registered in Shopify's Installed privacy apps, and the regions matching in both places.

Maintenance Plan

Your stack changes, so the inventory has to keep up with it. We re-scan on a set cadence and review new vendors and pixels before they launch. A consent setup that was accurate at launch and never touched again is exactly the thing we get hired to replace.

Bring Us The Cookie Consent Banner Nobody Has Touched Since Install

If a banner went up years ago and nobody has checked it since, bring it to a free Growth Audit. We'll tell you what's firing before consent, whether your Consent Mode signals are configured or defaulted, and whether the plan you're paying for includes the features you think it does. No obligation.

The shift

What Changes When Consent Management Is Implemented, Not Installed

A banner nobody has audited since install
A categorized inventory of every cookie and script, reviewed and signed off
Tags firing before the visitor chooses
A before-and-after tag list you can see for yourself
Consent Mode left at whatever the default was
Four signals configured explicitly, basic or advanced on purpose
GPC toggled on and trusted
GPC verified on the live site, against the plan you're actually on
Two banners fighting each other on a Shopify store
One banner, registered in Shopify's Installed privacy apps
Regions set in one place and forgotten in the other
Shopify admin and the CMP set to the same regions
Your lawyer guessing at what the site collects
Your counsel drafting against a written record of what's collected
State law

Universal Opt-Out Signals And US State Law

BLKDG is in Denver, so Colorado is where this starts. The Colorado Attorney General’s office (opens in new tab) states that beginning July 1, 2024, businesses falling within the Colorado Privacy Act’s application thresholds must allow consumers to opt out of the sale of their personal data, or its use for targeted advertising, using Global Privacy Control. The same office states that GPC was the first universal opt-out mechanism recognized to meet the CPA’s standards, and that GPC is currently the only universal opt-out mechanism the Department considers valid. Its published list of recognized mechanisms has exactly one row on it.

California words it differently, and the difference is worth keeping. The California Attorney General’s CCPA page (opens in new tab) says that under law GPC must be honored by covered businesses as a valid consumer request to stop the sale or sharing of personal information, and that for businesses collecting personal information online, a user-enabled global privacy control is one acceptable opt-out method.

Colorado names a mechanism and a date. California names an obligation to honor a signal once it arrives. If you want the background on the California side, we’ve written on what CCPA covers.

Whether either applies to your business is a question for your lawyer, and we won’t answer it. What we will do is make the site behave the way your counsel says it should, and hand them a written record of what’s collected on it, by whom, and under which category. Colorado’s rules also require covered businesses to explain in their privacy policy how universal opt-out requests get processed, and that’s policy drafting, which is theirs.

That boundary is deliberate, and it’s the same one our ADA and accessibility work runs on. We build to the standard. The people qualified to interpret the law decide what the standard is. You built something worth finding, and we make sure the way it gets found holds up when someone looks closely.

This page is for informational purposes only and does not constitute legal advice.

Questions

Consent Management Services, Before You Ask

No, and be careful with anyone who says yes. Compliance is a legal determination about your specific business, made by people qualified to make it. What we deliver is implementation: the scan, the written categorization, real script blocking, Consent Mode v2 wiring, and universal opt-out signal handling. Then we hand your counsel a record of what's collected on your site, by whom, and under which category, so they can draft against something real.

Google's documentation describes the basic version as preventing Google tags from loading until a user interacts with the consent banner, with no data transferred to Google at all when the user doesn't consent, not even the consent status. In the advanced version, Google tags load when the page opens, send measurements without cookies while consent is denied, and send full data once it's granted. Google's own comparison table gives basic a general model for conversion and key event modeling, and advanced an advertiser-specific model. That's a business decision rather than a technical default, so we put the tradeoff in writing and you make the call with your counsel.

It covers a specific slice: Shopify's developer documentation describes the Customer Privacy API as applying consent decisions to Shopify-managed surfaces, and it names pixels, audiences and checkout. Shopify's docs don't describe the native banner blocking scripts you installed yourself, and we won't put words in Shopify's mouth about what it can't do. What we will say is that the analytics, ads, reviews, chat and heatmap tags most stores add aren't Shopify-managed surfaces, which is why a CMP still has a job on a Shopify store. If you run one, exactly one banner should be live: CookieYes's own install guide tells you to confirm the app appears in Shopify's Installed privacy apps and then remove Shopify's banner.

CookieYes for most WordPress and Shopify stores. Osano when the requirement is bigger than cookies. Osano sells cookie consent alongside subject rights and DSAR workflows, vendor risk, data mapping and assessments as one platform, and it advertises mobile SDKs, APIs and GRC tool integrations, where CookieYes sells cookie consent and policy generators. One thing to check on CookieYes before you commit: its pricing page lists Global Privacy Control as available on Pro and Ultimate and not on Free or Basic, while Google Consent Mode v2 is listed as available on all four plans.

In Colorado, the Attorney General's office states that beginning July 1, 2024, businesses within the Colorado Privacy Act's application thresholds must allow consumers to opt out of the sale of personal data, or its use for targeted advertising, using GPC, and that GPC is currently the only universal opt-out mechanism the Department considers valid. In California, the Attorney General's office states that under law GPC must be honored by covered businesses as a valid request to stop the sale or sharing of personal information. Whether your business falls inside either set of thresholds is a question for your lawyer. What we can tell you is whether your site is actually honoring the signal, which is a different question and frequently a different answer.

They depend on ad_personalization, one of the four Consent Mode v2 signals. Google's tag behavior table says that when ad_personalization is denied, personalized advertising is disabled and remarketing in Google Ads, Display and Video 360, and Search Ads 360 stops receiving data. Enhanced conversions are governed by a different signal, ad_user_data, and the two get confused constantly. Leaving either at a default is how an audience list shrinks while nothing in the Ads interface looks broken, so we configure all four explicitly.

A decision, not a document. Tell us what your counsel says the site has to do: which regions get a banner, whether consent is opt-in or opt-out in each, whether you're running basic or advanced consent mode, and how universal opt-out requests should be handled. We build exactly that. In return they get a written record of every cookie and script on the site, who it belongs to and which category it's in, which is what Colorado's rules expect them to be able to describe in the privacy policy.

Nothing, and there's no obligation attached. It's a clear look at what's loading on your site, when each thing loads, which of it fires before a visitor consents, and whether your Consent Mode signals are configured or defaulted. Not a sales call. Not a quote request.