07
Consent Mode & CMP Audits
Consent Mode v2, CMP tag gating, GDPR-aware server-side tracking, conversion modeling, and the QA checks that prove consent rules are actually enforced.
Consent architecture is not finished when the banner renders. The operating question is whether tags, server containers, modeled conversions, regions, and vendor destinations behave differently when consent changes — and whether the team can prove that before relying on the reports.
Related writing
Curated field notes and guides that support this topic hub.

Consent Mode v2 and Server-Side Tracking: How They Work Together
Consent Mode v2 and server-side tracking aren't competing solutions. Here's how they actually connect, and why running server-side GTM doesn't make you exempt from consent gating.

Consent Architecture for Healthcare Websites
A HIPAA consent banner that doesn't gate server-side requests isn't protecting patients. Here's how to architect consent so it actually stops PHI from leaving your stack.

Disney's $2.75M CCPA Settlement Is an Opt-Out Architecture Problem, Not a Banner Problem
California's record $2.75M CCPA settlement with Disney targets inconsistent opt-out signals across streaming surfaces. Here's what that means for consent and server-side tagging stacks.

Server-Side GTM Now Ships Unconsented Floodlight Hits Server-to-Server
Floodlight tags in server-side GTM now transmit unconsented requests server-to-server for modeled conversions. Audit consent gating before your numbers move.