Data tracking · Privacy compliance
Compliant in every market you sell to.
UK GDPR says ask first. California says let people opt out. Quebec wants both, in French. We implement all of it on the site itself: honest consent, a cookie inventory that matches reality, a privacy policy someone can actually read, and the records to prove it.
Three rulebooks. One site that satisfies all of them.
- —Opt-in consent before any non-essential cookie
- —Reject as easy as accept, no pre-ticked boxes
- —Lawful basis recorded for every processing purpose
- —Privacy notice in plain English, updated with the site
- —Subject access requests answered within one month
- —Do Not Sell or Share link in the footer
- —Global Privacy Control signal detected and obeyed
- —Opt-out applied to ad pixels and data sharing
- —Notice at collection on forms and checkout
- —Threshold check: do these laws apply to you at all
- —Express consent for sensitive data and tracking
- —French-language notice and banner for Quebec visitors
- —Privacy policy naming a responsible person
- —Breach record kept and reportable
- —CASL-compliant email consent on every form
Four things, in this order.
The audit
What we usually find in the first hour.
Almost every site has a banner. Almost none of them would survive a complaint. These are the usual gaps.
The policy is fiction
- —Lists cookies the site stopped using in 2022
- —Copied from another business, names included
- —No mention of GA4, Meta or the CRM
The banner is theatre
- —Cookies set before anyone clicks
- —Reject buried two clicks deep
- —Same banner for a visitor in Leeds and one in Los Angeles
Nothing to show
- —No consent log at all
- —No Do Not Sell link, no GPC handling
- —Nobody knows what to do with a data request
Three weeks, then a routine.
Part of data tracking, which is inside every maintenance retainer. As standalone work it is quoted after the audit. This is implementation, not legal advice; where you have counsel, we build to their position.
Keep reading
Common questions
Is this legal advice?+
No. It is implementation to the published guidance of the ICO, the California Privacy Protection Agency and the Canadian OPC. If you have counsel, we build to their position and give them a document to review.
We are a UK business. Does California apply to us?+
Only if you meet the CCPA thresholds, which most small businesses do not. We check the thresholds with you and, where you are under them, still honour Global Privacy Control because it costs nothing and builds trust.
What happens when someone asks for their data?+
You get a written procedure and a shared inbox template. The site tells us what data lives where, so a subject access request is a checklist, not a scramble.
Do we need a Data Protection Officer?+
Usually not at your size. Where UK GDPR requires one we say so plainly and can point you to people who do that work.
How is this different from the Consent Mode page?+
Consent Mode v2 is the technical side: how tags behave when someone says no. This page is the legal frame around it: what you must ask, what you must publish, and what you must be able to prove.