[GDPR & Cookie Tech Compliance]
Compliance is not a hindrance to tracking; it is its condition of existence.
We plan and implement Cookie Compliance solutions and GDPR-compliant tracking to align analytics and marketing setup with European regulations (GDPR, ePrivacy, Italian Privacy Authority) without sacrificing data quality. We work on Consent Management Platform (CMP), Consent Mode v2, compliant Cookie Banners, preemptive tag blocking, and granular purpose management. One goal only: to transform cookie compliance from a sanction risk and tracking block into a structured system that protects the company, respects the user, and maintains the effectiveness of digital marketing activities.
Main Objectives
- 01
COOKIE BANNER AND CMP OBJECTIVES
- Implement Consent Management Platform (CMP) compliant with IAB TCF v2.2 and Italian Privacy Authority guidelines
- Configure cookie banner with granular choices for purposes (analytics, marketing, profiling) without pre-selected choices
- Ensure that refusal is accessible with the same effort as acceptance (no dark patterns, no hidden buttons)
- Customize banner design and copy while maintaining brand consistency without compromising regulatory requirements
- 02
PREVENTIVE BLOCKING OBJECTIVES TAG
- Implement preventive block (prior block) of all tracking tags before the user’s explicit consent
- Configure GTM and individual tags for firing conditional on actual consent for each specific category
- Validate preventive block with periodic audits to identify tags firing before valid consent
- Build fallback for traffic without consent with Consent Mode modeling where possible and applicable
- 03
CONSENT MODE V2 OBJECTIVES AND MODELING
- Implement Google Consent Mode v2 with the four mandatory consent states from 2024 onwards
- Configure Consent Mode on GA4, Google Ads, and Floodlight for cookieless conversion modeling
- Synchronize consent signal between CMP and Consent Mode ensuring consistency between declared and implemented
- Monitor data recovery through Google Consent Mode modeling on users who have denied consent
- 04
COOKIE AUDIT AND CLASSIFICATION OBJECTIVES
- Conduct periodic cookie audits identifying each cookie and active tag on the site with its actual purpose
- Classify cookies by purpose (technical, analytics, marketing, profiling) according to Privacy Authority definitions
- Eliminate obsolete cookies, tags no longer used, and purposes no longer justified by actual activities
- Document an updated cookie policy with a complete list, purpose, duration, and category for each active cookie
- 05
Documentation and Accountability Objectives
- Build updated, accessible, and consistent cookie policy and privacy policy with the actual technical setup
- Document extended privacy notice with purposes, legal bases, and data subject rights clearly stated
- Manage DPA (Data Processing Agreement) with marketing and analytics providers processing data on behalf of the client
- Implement processing records and documentary accountability for inspection audits or requests from supervisory authorities
- 06
OBJECTIVES OF MANAGEMENT OF RIGHTS HOLDERS
- Implement technical procedures for managing Right to Be Forgotten, access, and user data portability
- Configure User Deletion API on GA4, Google Ads, and other platforms for effective deletion upon request
- Build user request intake processes with SLA, business owner, and execution tracking of activities
- Document each request handled with proof of technical execution and response times compliant with GDPR
How do we work?
19ADV’s operational framework
in Performance Marketing
01
Briefing and definition of requirements
We analyze the business model, target audience, and reference markets — B2C, B2B, and D2C — and define concrete objectives and measurable KPIs: listens, visits, leads, awareness, and cost per acquisition.
02
Free diagnostic audit
If you are already investing in Spotify Ads, we analyze your account to identify issues and opportunities in campaign structure, segmentation, audiences, and audio and video creatives.
03
Strategy definition
We build the campaign strategy starting from the objectives not from the available formats and we define the targeting budget, mix of formats and integration with the other active channels
04
Production and setup
Gestiamo o coordiniamo la produzione degli asset creativi script audio voiceover e video e configuriamo le campagne su Spotify Ad Studio con tracciamento preciso degli obiettivi
05
Ottimizzazione continua
We monitor performance and constantly optimize exposure frequency, targeting and creativity. No campaign is left running unsupervised.
06
Reporting and analysis
Periodic reports with the metrics that really matter: real coverage, ad completion frequency, traffic generated and cost per result, no vanity metrics, just useful data
GDPR & Cookie Tech Compliance Campaigns
Methodological approach
- Initial audit with cookie scanning, active tag mapping, existing CMP validation, and regulatory gap analysis
- Implementation of CMP compliant with IAB TCF v2.2 with granular configuration for purposes and Garante guidelines
- GTM configuration with prior block, Consent Mode v2, and firing logic conditioned on actual consent
- Complete documentation with cookie policy, privacy policy, supplier DPA, and updated processing register
GDPR and Cookie Compliance Services available
- Complete cookie audit with scanning, classification, and remediation of non-compliant or undocumented tags
- Implementation of compliant CMPs (Iubenda, OneTrust, Cookiebot, Usercentrics) with full GTM configuration
- Setup of Google Consent Mode v2 with CMP synchronization, conversion modeling, and technical validation
- Ongoing compliance consulting with periodic audits, regulatory updates, and support in case of inspections
Integrated technology stack
- CMP: Iubenda, OneTrust, Cookiebot, Usercentrics, CookieYes with GTM configuration and integrated Consent Mode
- Google Tag Manager with prior block configuration, Consent Mode v2, and conditional tag firing logic
- Cookie scanning tools (Cookiebot Scanner, OneTrust Cookie Scanner) for periodic audits and continuous remediation
- DPA management with dedicated tools or documentary processes for external marketing and analytics vendors
Frequently Asked Questions about GDPR and Cookie Compliance
Administrative sanctions GDPR up to 4% of annual turnover or 20 million euros, inspections by the Italian Privacy Authority, user class actions, and reputational loss. The Italian Authority in 2024-2025 has intensified controls with sanctions on companies of various sizes — not just enterprises. The main risks are not only economic: you compromise the legal basis of tracking, lose attribution on Google Ads and Meta, and Consent Mode v2 is disabled. Compliance is not an obstacle, it is a technical prerequisite.
It depends on the complexity of the site and the traffic volumes. Free or low-cost CMPs (Cookiebot Free, Iubenda Free, WordPress plugins) cover corporate sites, blogs, and small e-commerce with acceptable basic compliance. For e-commerce with high volumes, multi-market, or B2B with advanced customization needs, enterprise CMPs (OneTrust, Usercentrics) with granular configurations, native multi-language, and SLA support are needed. Often the problem is not the tool, but the poor configuration.
Consent Mode v2 is the evolution of Google’s Consent Mode which, from March 2024, is mandatory to use remarketing and conversion optimization features of Google Ads in the European Economic Area. It adds two new mandatory parameters (ad_user_data, ad_personalization) to the previous two (analytics_storage, ad_storage). Without correct implementation, Google Ads campaigns in the EU lose remarketing capabilities, audience sharing, and AI optimization on cookieless traffic.
Le linee guida del Garante 2021 (e successive) sono chiare: scroll, continuazione di navigazione e chiusura del banner senza scelta non costituiscono consenso valido. Servono azioni esplicite e univoche dell’utente. Il banner deve avere pulsanti chiari di “accetta” e “rifiuta” con stesso effort visivo (dark pattern come “accetta” colorato e “rifiuta” nascosto in link grigio sono sanzionabili). Linee guida specifiche italiane sono più stringenti delle linee guida EDPB europee in alcuni aspetti.
With pure client-side tracking, you typically lose 30-60% of data on users who refuse. With Consent Mode v2 active, Google reconstructs part of the lost data through modeling on consenting users, recovering 60-80% of lost conversions. Combined with GTM Server Side and Conversions API, the recovery goes further. Proper compliance does not result in significant data loss; poor or absent compliance causes data loss due to sanctions or disabling of Google features.
Ogni volta che cambia qualcosa nel setup tecnico (nuovo tag, nuovo strumento, nuovo fornitore) e almeno con audit periodico annuale. Cookie e finalità di trattamento cambiano frequentemente — nuovi pixel marketing, integrazioni CRM, strumenti di analytics — e la policy deve riflettere lo stato reale. Una cookie policy non aggiornata è uno dei primi elementi che il Garante contesta in caso di ispezione. È documentazione viva, non documento da stilare una volta e dimenticare.