Skip to content

Data tracking · Privacy compliance

Compliant in every market you sell to.

UK GDPR says ask first. California says let people opt out. Quebec wants both, in French. We implement all of it on the site itself: honest consent, a cookie inventory that matches reality, a privacy policy someone can actually read, and the records to prove it.

3 regions UK & EU, US states, Canada, one setup
Opt in / opt out The right model shown to the right visitor
Inventory Every cookie and script, catalogued from the live site
Evidence Consent logs and a DSAR procedure you can hand over
What each region requires

Three rulebooks. One site that satisfies all of them.

UK & EU Ask before you set anything. UK GDPR · PECR · EU GDPR · ePrivacy
  • Opt-in consent before any non-essential cookie
  • Reject as easy as accept, no pre-ticked boxes
  • Lawful basis recorded for every processing purpose
  • Privacy notice in plain English, updated with the site
  • Subject access requests answered within one month
California & US states Let people say no, and honour it. CCPA / CPRA · Colorado · Virginia · Connecticut · Texas
  • Do Not Sell or Share link in the footer
  • Global Privacy Control signal detected and obeyed
  • Opt-out applied to ad pixels and data sharing
  • Notice at collection on forms and checkout
  • Threshold check: do these laws apply to you at all
Canada Consent that is meaningful, in both languages where it must be. PIPEDA · Quebec Law 25 · CASL
  • Express consent for sensitive data and tracking
  • French-language notice and banner for Quebec visitors
  • Privacy policy naming a responsible person
  • Breach record kept and reportable
  • CASL-compliant email consent on every form
What we do

Four things, in this order.

01 Find out what the site actually does. A scan of every cookie, script and third party the live site sets, on every template, in both consent states. The inventory is built from reality, not from a plugin’s template list.
02 Decide which rules apply. Where your visitors are, what you sell, how much data you hold. Most small businesses are under the California thresholds and over the UK ones. We write down which laws bind you and why.
03 Build the consent layer to match. Opt-in for UK and EU visitors, opt-out with Global Privacy Control for US states, French for Quebec, all from one banner that shows the right thing to the right person. Wired to Consent Mode v2 so the tags obey.
04 Write it down and keep it true. Privacy policy and cookie notice rewritten from the inventory, consent logs retained, a one-page procedure for access and deletion requests. Then checked every month, because sites change.

The audit

What we usually find in the first hour.

Almost every site has a banner. Almost none of them would survive a complaint. These are the usual gaps.

The policy is fiction

  • Lists cookies the site stopped using in 2022
  • Copied from another business, names included
  • No mention of GA4, Meta or the CRM

The banner is theatre

  • Cookies set before anyone clicks
  • Reject buried two clicks deep
  • Same banner for a visitor in Leeds and one in Los Angeles

Nothing to show

  • No consent log at all
  • No Do Not Sell link, no GPC handling
  • Nobody knows what to do with a data request
How it works

Three weeks, then a routine.

Week one Full scan of the live site, inventory of every cookie and third party, and a written view of which laws apply to you and why.
Week two Banner configured by region, tags mapped to consent categories, Do Not Sell and GPC handling built, all on staging.
Week three Policy and notices rewritten from the inventory, consent logging confirmed, DSAR procedure handed over, live.
Every month New scripts checked against the inventory, policy kept current, logs retained. Regulations move; the site moves with them.

Part of data tracking, which is inside every maintenance retainer. As standalone work it is quoted after the audit. This is implementation, not legal advice; where you have counsel, we build to their position.

Keep reading

Let’s look at your site together.

Thirty minutes with Ali. He will ask about the business first, then go through the site with you on the call.

Book a call with Ali
Ali Demirci
Ali Demirci
Founder
What we would fix first
The handful of things actually holding it back.
What we would leave alone
Usually more than you expect.
Whether we are a fit
And we will tell you if we are not.

Common questions

Is this legal advice?+

No. It is implementation to the published guidance of the ICO, the California Privacy Protection Agency and the Canadian OPC. If you have counsel, we build to their position and give them a document to review.

We are a UK business. Does California apply to us?+

Only if you meet the CCPA thresholds, which most small businesses do not. We check the thresholds with you and, where you are under them, still honour Global Privacy Control because it costs nothing and builds trust.

What happens when someone asks for their data?+

You get a written procedure and a shared inbox template. The site tells us what data lives where, so a subject access request is a checklist, not a scramble.

Do we need a Data Protection Officer?+

Usually not at your size. Where UK GDPR requires one we say so plainly and can point you to people who do that work.

How is this different from the Consent Mode page?+

Consent Mode v2 is the technical side: how tags behave when someone says no. This page is the legal frame around it: what you must ask, what you must publish, and what you must be able to prove.