Posts

How to migrate from client-side to server-side Google Tag Manager

  Migrating from client-side to server-side Google Tag Manager is one of the most common analytics projects on marketing team backlogs right now. Ad blockers, Safari's Intelligent Tracking Prevention and consent regulations keep removing events before they reach GA4 or Google Ads. What server-side GTM actually is Client-side GTM loads a container script in the visitor's browser. That script fires tags. Server-side GTM adds a second container that runs on your own cloud infrastructure and receives events over a subdomain of your website. The browser sends one lean request to your subdomain. The server container reads it, applies any transformation or filtering logic, then forwards clean events to Google Ads, GA4, Meta Conversions API and any other supported endpoint. Why the migration matters Cookies set by your subdomain read as first-party, so Safari keeps them beyond the seven-day limit that hits browser-set cookies. Requests to your own subdomain sit outside typical ad...

What Actually Makes a Mobile App GDPR Compliant? A Real Answer for 2026

Image
  Search for "how to make a mobile app GDPR compliant" and you will find hundreds of guides. Most of them repeat the same surface points and stop there. Apps that actually pass GDPR reviews go a lot deeper, and the depth is not in the privacy policy. This piece walks through the layers that decide compliance in a modern mobile app. Layer 1: The consent banner Shown on first launch. Accept and Reject placed side by side with equal design weight. Toggles cover analytics, advertising, personalisation, and functional purposes. Layer 2: The SDK gate Every analytics, ad, and attribution SDK waits for the consent layer to report back before it starts. This is the layer most apps skip. It is also the layer regulators check first with a network proxy on the first launch. Layer 3: The consent record Every choice is stored as a signed IAB TCF v2.2 string, plus a full audit log with timestamps and versions. Layer 4: The user rights flow Users can view, export, and delete their d...

Mobile App Tracking and Consent: A Guide That Actually Makes Sense

Image
  If you own or run a mobile app, you have probably heard about privacy laws like GDPR and Apple's tracking prompt. And you have probably wondered what your app actually does behind the scenes, and whether any of it might get you in trouble. The short answer is that most apps are already doing something risky, and nobody told the team that built the app. What happens the second your app opens Inside every mobile app there are tiny bits of software called tracking tools. Names you might know include Firebase, Google Analytics, AppsFlyer, and Adjust. Their job is to record what users do inside the app. Installs, taps, screen views, purchases, and the ad that brought the user in. The problem is timing. These tools usually start collecting the moment the app opens. That happens before the user has even seen the consent banner. Under GDPR, that alone is enough for a fine. The full guide on how tracking works inside apps breaks it down clearly. Why this keeps happening Two reasons...

Google Signals and Consent Mode in GA4: The 2026 Update Every Marketer Needs to Read

Image
  Google Analytics 4 quietly split two of its most misunderstood features on 15 June 2026. If you run GA4 and Google Ads together, this update changes how you set up consent and how you read your reports. Google Signals in plain terms Google Signals connects the activity of the same visitor across phones, tablets, and desktops. It only works when that visitor is signed into a Google account with Ads Personalisation switched on. Without Google Signals, one person browsing on two devices shows up as two users. With it, the report reflects one journey. Consent Mode in plain terms Consent Mode is the layer that reads the visitor's cookie choices and passes them to Google's tags. It uses four signals: ad_storage , analytics_storage , ad_user_data , and ad_personalization . A tested Google Consent Mode v2 banner from Seers maps these four in the right order without manual code. What changed on 15 June 2026 Before the change, disabling Google Signals also stopped Google Ads da...

Choosing a Consent Management Platform in 2026: What Growing Sites Should Check First

  Cookie consent tools used to be simple to pick. In 2026, they're not. Prices have moved sharply, feature lists overlap, and the choice you make now affects ad revenue, app releases, and regulator response for years. What a modern CMP actually needs to do At a base level, a consent management platform must block non-essential cookies before consent, log every choice, and pass the right signals to Google Consent Mode v2. That is the floor. Anything less and you risk both regulator fines and broken ad attribution. Above the floor, the real differences appear. Pricing model matters more than price Cookiebot charges per domain and roughly doubled base pricing in August 2025. OneTrust removed self-serve pricing and now starts around $10,000 a year, with 20 to 40 percent renewal increases reported by many customers. Osano and Didomi keep pricing behind sales calls. Visitor-based pricing tracks real business growth instead. Seers AI publishes tiers openly: a free plan for 100 visit...

How Consent Decides Your Targeted Ad Performance

  If your ad campaigns feel weaker than they used to, the reason is often not your creative or your budget. It is what happens on your site before the ad platforms even see the user. Google, Meta and Amazon now need clear consent signals from every visitor. Without them, your pixels get blocked, your audiences shrink and your conversions look smaller than they really are. This one layer decides how much data your ad stack gets to work with. Fix it well and everything above it works better. What consent actually does for your ads Consent is the user saying yes to tracking. That yes turns on your pixels, feeds your audiences and lets platforms count conversions properly. When consent is missing or messy, ad platforms fill the gap with modelled data. That is a guess, not a reality. Your ROAS drops because you are optimising on softer signals. A clean consent flow flips this. Your data gets richer, your audiences get sharper and your reports start telling the truth again. Why 2...

How to Set Up Google Consent Mode v2 With GA4 in 2026 (No Code, GDPR-Safe)

  Every marketing team wants clean GA4 numbers and a compliant cookie setup. The trouble is, most teams still run a configuration that ignores a big update from 15 June 2026. Since that date, Google Signals no longer controls your Google Ads data inside GA4. Consent Mode does. Old configurations quietly lose users, shrink audiences and drop conversions. What Google Signals is Google Signals connects sessions from the same person across their phone, laptop and tablet. It only turns on when the visitor is signed in and has Ads Personalisation on in their Google account. It does not manage cookies. It only enriches data already collected with consent. What Consent Mode v2 is Consent Mode v2 is the switchboard. It reads a visitor's cookie choice before any Google tag fires. Four flags are involved: ad_storage, analytics_storage, ad_user_data and ad_personalisation. Basic mode blocks tags until consent is given. Advanced mode fires cookie-less pings that GA4 can later model into...

How universal consent works, start to finish.

Image
Universal consent means one central record of every yes and no a person gives you, read by every system you run and updated the moment it changes. Your banner only sees one of those channels. Most companies collect consent well and carry it badly. Here's a plain walk through what happens when it works, plus the one arrival almost nobody has planned for. Step 1: Someone answers They land on your site. Or open your app. Or tick a box on a paper form at your counter. Or reply STOP to a text. All four are consent events. All four count in law, and only the first one usually gets built properly. Step 2: The answer goes to one place Rather than saving into whichever tool caught it, the answer gets written to a single central record. Stored alongside it: who they are, what they agreed to, when, which channel, and which law applied to them at that moment. That last field does a lot of quiet work. It's how you answer "was this lawful?" two years later. Step 3: Everything else ...

There are three AI Act fine tiers. Most people only know one of them.

Everyone knows the headline number. Almost nobody plans for the other two. That gap tells you exactly how most organisations are preparing, and why so many will still be caught. The three tiers Prohibited practices cost up to 35 million euros or 7% of worldwide annual turnover, whichever is higher. Breaching operator or general-purpose model duties runs to 15 million euros or 3%. Giving an authority incorrect, incomplete or misleading information costs up to 7.5 million euros or 1%. Small and medium companies are capped at the lower of the two figures rather than the higher. Read the third tier twice. It does not punish reckless AI. It punishes an inaccurate answer. You can act in good faith, answer a regulator from a spreadsheet nobody updated, and land inside it. Which is the cheapest tier to avoid, and the only one that is purely an admin problem. Why that tier is a governance failure, not a legal one AI compliance means proving your AI meets rules somebody els...

What Counts as Personal Data Under GDPR, and the Six Things People Get Wrong

Image
  GDPR uses one sentence to define personal data. Article 4(1) calls it "any information relating to an identified or identifiable natural person". Everything else follows from that sentence, so it helps to read it slowly. Two words do the work. Identified means you already know who it is. Identifiable means you could work it out. Things that count The European Commission gives a plain list: a name and surname, a home address, an email address, an IP address, an identification card number, a cookie ID, and the advertising identifier of your phone. Video recording from CCTV is on the list too. Things that do not count A company registration number is not personal data. A generic mailbox such as info@company.com is not personal data. Truly anonymised information is outside GDPR, and only when the anonymisation cannot be reversed. The six mix ups Assuming work emails are exempt. A named address like sarah.jones@company.com identifies a person, so it counts. Treating coded record...