Posts

Why Your Cookie Banner Should Speak Your Visitor's Language

Image
  Imagine you open a website and the first box asks you to agree to cookies. But the words are in a language you do not know. What do you do? Most people close the box or leave the site. That one moment can cost a business a customer. This is why the language of your cookie banner matters so much. It is often the first thing a visitor reads. If it feels foreign, it starts the visit on the wrong foot. The law wants clear language GDPR Article 12(1) says privacy information must be in clear, plain words that people can understand. A banner shown only in English to French, German, or Japanese visitors does not meet that test. If people cannot read what they agree to, their consent is weak. This is not just theory. In 2021 the Dutch privacy watchdog fined TikTok because it showed its privacy notice only in English to Dutch users. The message was simple: people must understand what they say yes to. How a multi-language banner works The banner finds the visitor's language in one of...

Why Your Google Ads Conversions Drop After Adding a Cookie Banner

Image
  You added a cookie banner to follow the law. A week later, your Google Ads conversions fell. Many owners hit this and think the setup is broken. It is not. Let us walk through what really happens and how to fix it. First, the cause. A cookie banner lets users say yes or no to cookies. When a user says no, Google tags cannot write cookies for that person. So Google cannot track the sale the normal way. Your reports show fewer conversions, even though your real sales did not change. The drop is a tracking gap, not a sales problem. Now, the fix. Google Consent Mode reads the choice from your banner and passes it to Google. It does not show the banner itself. It tells Google what each visitor allowed. This lets Google act on the choice instead of losing the data. There are two ways to run it. Basic consent mode blocks Google tags until the user clicks the banner. If the user says no, no data is sent. Advanced consent mode loads the tags with consent set to denied by default. While...

Why Your Facebook Ads Lose Data After You Add a Cookie Banner

Image
  Adding a cookie consent banner is the right thing to do. It keeps your website on the correct side of privacy law. But many marketers notice something odd soon after: their Facebook and Instagram ad reports start showing fewer conversions, even though real sales have not dropped. If that sounds familiar, this guide explains what is happening and how to fix it. The hidden problem Your Meta Pixel usually fires the moment a page loads. Once you add a consent banner, every visitor who clicks "Reject" should not be tracked with cookies.  An unmanaged pixel handles this badly. It either keeps tracking people who said no, which breaks the law, or it loses their activity completely. In the EU, UK, and several US states, declined visitors can be a large part of your traffic, so the data gap is real. Why it matters There are two costs here. The first is legal. GDPR and the ePrivacy Directive require consent before non-essential cookies load. Fines reach up to €20 million or 4% o...

EU AI Act Compliance in 2026: Deadlines, Fines and the Four Risk Categories Explained

Image
  Artificial intelligence is now regulated law in Europe, and many businesses are further behind than they realise. The EU AI Act entered into force on 1 August 2024 as the first legal framework built entirely around AI. Its rules arrive in stages, and some of the most important ones already apply. The four risk categories The Act sorts every AI system into one of four tiers, and your obligations depend on where your systems land. Unacceptable risk systems are banned outright. Since 2 February 2025, the EU prohibits AI that manipulates people into harm, exploits vulnerable groups, runs social scoring for public authorities, scrapes facial images from the internet, or reads emotions in workplaces and schools. High-risk systems are allowed, with strict conditions. This tier covers AI used in hiring, credit scoring, education, critical infrastructure, law enforcement and border control. Providers must complete conformity assessments, keep detailed technical documentation, register...

AI Governance Basics: What It Is, Which Rules Apply, and How to Start

Image
  Artificial intelligence now sits inside hiring tools, credit checks, chatbots and marketing platforms. Yet many organisations use these systems without any structure for managing the risks they create. That structure has a name: AI governance. What AI governance means AI governance is the set of internal policies, roles and checks that guide how an organisation builds, buys and monitors AI. It covers the full life of a system, from the data used to train it through to how its outputs are reviewed once it is live. The central idea is accountability. Someone must be able to answer for what each system does. It is worth separating governance from regulation. Regulation is imposed from outside by law. Governance is what an organisation builds internally, and good governance usually goes further than the legal minimum. The rules that now apply The most important law in this area is the EU AI Act. According to the official implementation timeline published at artificialintelligenc...

Mobile App Compliance in 2026: GDPR, CCPA and App Store Rules Explained

Image
Mobile app compliance means meeting the legal and technical rules that govern how your app collects, uses, and stores personal data. In 2026 that covers privacy laws such as GDPR, CCPA, and LGPD, and also the frameworks Apple and Google enforce through their app stores. Getting it wrong risks fines, store removal, and advertising data you cannot legally use. Which laws apply to your app The laws that apply depend on where your users are, and this catches many app owners out because a company registered in one country can still owe duties in many others. If you have users in the EU or UK, GDPR requires explicit opt-in consent before non-essential data processing, and consent must be specific to each purpose.  If you have users in California, CCPA gives them the right to opt out of the sale or sharing of their data, and since 2026 businesses must confirm they have processed opt-out requests, including Global Privacy Control signals. Brazilian users fall under LGPD, and several ...

What Is a Mobile Application SDK and What Does It Do With User Data?

Image
If you own or manage a mobile app, third-party SDKs are almost certainly inside it. Understanding what they are and what they collect is now a basic requirement for running an app legally. What an SDK actually is A mobile application SDK is a pre-built software toolkit that developers add to an app to get specific functionality without building it from scratch. Analytics, advertising, crash reporting, and payments are the most common uses.  A typical SDK contains an initialisation module that activates when the app loads, an API layer that connects to the provider's service, a data collection module, and a logging component. People often mix up SDKs and APIs. An API is a set of rules that lets two systems talk to each other. An SDK is a bigger package that usually contains APIs along with libraries, sample code, and documentation.  An SDK saves development time, but it also brings a third-party dependency into your app that needs ongoing management. What SDKs collect Eac...

Google Consent Manager: How It Works With Google Ads and GA4

Image
  If you run Google Ads or track visitors with GA4, a cookie banner alone does not tell Google anything. Google Ads and Analytics need structured consent signals, and a standard banner does not send them. This is what a Google consent manager actually does. It is the layer that sits between your visitor's choice and your Google tags, translating "accept" or "reject" into signals Google can read. The four signals that matter Google's Consent Mode covers four parameters: ad_storage , analytics_storage , ad_user_data , and ad_personalization . The first two have existed since the original Consent Mode launch and control advertising and analytics cookies. The other two were added in November 2023, according to Google's developer documentation, and specifically govern whether Google Ads can personalise ads or match Enhanced Conversions using hashed customer data. Basic versus advanced implementation Google offers two ways to run Consent Mode. Basic mod...

How to Make a Mobile App GDPR Compliant: A Complete Checklist

Image
  If your mobile app collects any personal data from users in Europe, GDPR applies to you, regardless of where your company is based or how large it is. Many app owners assume GDPR is a website issue. It is not. Mobile apps often collect more personal data than websites, through location tracking, device identifiers, contact lists and behavioural logs. Here is what GDPR compliance actually requires in practice. Start with consent. GDPR requires consent to be freely given, specific, informed and unambiguous. That means no pre-ticked boxes, no bundled permissions, and a separate opt-in toggle for each purpose you process data for. Present Accept and Reject with equal visual weight so neither option is designed to be harder to find. Build a proper privacy policy. It should name your data controller, list every type of data you collect, explain your legal basis for processing it, and set out user rights, including access, correction, deletion, restriction, portability and objectio...

GA4 Server-Side Tracking: How to Stop Losing Conversion Data to Ad Blockers

Image
  If your Google Analytics 4 reports show fewer conversions than your CRM, you are not looking at a reporting quirk. You are looking at a data gap — and it is caused by something most marketing teams do not see coming. Ad blockers affect between 25 and 40 percent of web traffic, depending on the industry and device type. Every blocked request is a conversion event your analytics never receives.  Browser privacy tools like Safari's Intelligent Tracking Prevention (ITP) compound the problem further by capping the lifespan of JavaScript-set cookies at just seven days. If a customer converts eight days after their first visit, that attribution gets lost entirely. Why Client-Side Tracking Has a Structural Weakness Client-side tracking works by running JavaScript tags directly in the user's browser. The browser then sends the event data to Google Analytics 4. This approach is simple to set up and has worked for years — but browser privacy controls now sit directly in its path. A...