[GDPR & Cookie Tech Compliance]

Compliance is not a hindrance to tracking; it is its condition of existence.

We plan and implement Cookie Compliance solutions and GDPR-compliant tracking to align analytics and marketing setup with European regulations (GDPR, ePrivacy, Italian Privacy Authority) without sacrificing data quality. We work on Consent Management Platform (CMP), Consent Mode v2, compliant Cookie Banners, preemptive tag blocking, and granular purpose management. One goal only: to transform cookie compliance from a sanction risk and tracking block into a structured system that protects the company, respects the user, and maintains the effectiveness of digital marketing activities.

Main Objectives

  1. COOKIE BANNER AND CMP OBJECTIVES

    • Implement Consent Management Platform (CMP) compliant with IAB TCF v2.2 and Italian Privacy Authority guidelines
    • Configure cookie banner with granular choices for purposes (analytics, marketing, profiling) without pre-selected choices
    • Ensure that refusal is accessible with the same effort as acceptance (no dark patterns, no hidden buttons)
    • Customize banner design and copy while maintaining brand consistency without compromising regulatory requirements
  2. PREVENTIVE BLOCKING OBJECTIVES TAG

    • Implement preventive block (prior block) of all tracking tags before the user’s explicit consent
    • Configure GTM and individual tags for firing conditional on actual consent for each specific category
    • Validate preventive block with periodic audits to identify tags firing before valid consent
    • Build fallback for traffic without consent with Consent Mode modeling where possible and applicable
  3. CONSENT MODE V2 OBJECTIVES AND MODELING

    • Implement Google Consent Mode v2 with the four mandatory consent states from 2024 onwards
    • Configure Consent Mode on GA4, Google Ads, and Floodlight for cookieless conversion modeling
    • Synchronize consent signal between CMP and Consent Mode ensuring consistency between declared and implemented
    • Monitor data recovery through Google Consent Mode modeling on users who have denied consent
  4. COOKIE AUDIT AND CLASSIFICATION OBJECTIVES

    • Conduct periodic cookie audits identifying each cookie and active tag on the site with its actual purpose
    • Classify cookies by purpose (technical, analytics, marketing, profiling) according to Privacy Authority definitions
    • Eliminate obsolete cookies, tags no longer used, and purposes no longer justified by actual activities
    • Document an updated cookie policy with a complete list, purpose, duration, and category for each active cookie
  5. Documentation and Accountability Objectives

    • Build updated, accessible, and consistent cookie policy and privacy policy with the actual technical setup
    • Document extended privacy notice with purposes, legal bases, and data subject rights clearly stated
    • Manage DPA (Data Processing Agreement) with marketing and analytics providers processing data on behalf of the client
    • Implement processing records and documentary accountability for inspection audits or requests from supervisory authorities
  6. OBJECTIVES OF MANAGEMENT OF RIGHTS HOLDERS

    • Implement technical procedures for managing Right to Be Forgotten, access, and user data portability
    • Configure User Deletion API on GA4, Google Ads, and other platforms for effective deletion upon request
    • Build user request intake processes with SLA, business owner, and execution tracking of activities
    • Document each request handled with proof of technical execution and response times compliant with GDPR

How do we work?
19ADV’s operational framework
in Performance Marketing

GDPR & Cookie Tech Compliance Campaigns

Methodological approach

  • Initial audit with cookie scanning, active tag mapping, existing CMP validation, and regulatory gap analysis
  • Implementation of CMP compliant with IAB TCF v2.2 with granular configuration for purposes and Garante guidelines
  • GTM configuration with prior block, Consent Mode v2, and firing logic conditioned on actual consent
  • Complete documentation with cookie policy, privacy policy, supplier DPA, and updated processing register

GDPR and Cookie Compliance Services available

  • Complete cookie audit with scanning, classification, and remediation of non-compliant or undocumented tags
  • Implementation of compliant CMPs (Iubenda, OneTrust, Cookiebot, Usercentrics) with full GTM configuration
  • Setup of Google Consent Mode v2 with CMP synchronization, conversion modeling, and technical validation
  • Ongoing compliance consulting with periodic audits, regulatory updates, and support in case of inspections

Integrated technology stack

  • CMP: Iubenda, OneTrust, Cookiebot, Usercentrics, CookieYes with GTM configuration and integrated Consent Mode
  • Google Tag Manager with prior block configuration, Consent Mode v2, and conditional tag firing logic
  • Cookie scanning tools (Cookiebot Scanner, OneTrust Cookie Scanner) for periodic audits and continuous remediation
  • DPA management with dedicated tools or documentary processes for external marketing and analytics vendors

Frequently Asked Questions about GDPR and Cookie Compliance