Posts

There are three AI Act fine tiers. Most people only know one of them.

Everyone knows the headline number. Almost nobody plans for the other two. That gap tells you exactly how most organisations are preparing, and why so many will still be caught. The three tiers Prohibited practices cost up to 35 million euros or 7% of worldwide annual turnover, whichever is higher. Breaching operator or general-purpose model duties runs to 15 million euros or 3%. Giving an authority incorrect, incomplete or misleading information costs up to 7.5 million euros or 1%. Small and medium companies are capped at the lower of the two figures rather than the higher. Read the third tier twice. It does not punish reckless AI. It punishes an inaccurate answer. You can act in good faith, answer a regulator from a spreadsheet nobody updated, and land inside it. Which is the cheapest tier to avoid, and the only one that is purely an admin problem. Why that tier is a governance failure, not a legal one AI compliance means proving your AI meets rules somebody els...

What Counts as Personal Data Under GDPR, and the Six Things People Get Wrong

Image
  GDPR uses one sentence to define personal data. Article 4(1) calls it "any information relating to an identified or identifiable natural person". Everything else follows from that sentence, so it helps to read it slowly. Two words do the work. Identified means you already know who it is. Identifiable means you could work it out. Things that count The European Commission gives a plain list: a name and surname, a home address, an email address, an IP address, an identification card number, a cookie ID, and the advertising identifier of your phone. Video recording from CCTV is on the list too. Things that do not count A company registration number is not personal data. A generic mailbox such as info@company.com is not personal data. Truly anonymised information is outside GDPR, and only when the anonymisation cannot be reversed. The six mix ups Assuming work emails are exempt. A named address like sarah.jones@company.com identifies a person, so it counts. Treating coded record...

Meta Pixel Not Tracking Purchases? Check These 7 Causes Before You Reinstall It

The short answer If your purchases dropped soon after you added a cookie banner, the banner is almost certainly the cause. The Meta Pixel starts in a paused state and needs a signal to switch on. Many banners send the pause and never send the switch. Reinstalling the pixel will not fix that. Here is the full list, in the order worth checking. 1. Your cookie banner never sends the "on" signal Meta's developer documentation describes pausing pixel fires until consent is granted, then sending them once it is. The two states are revoke (paused) and grant (active). Plenty of banners handle the first half correctly and forget the second. The pixel then waits forever. How to test: open your site in a private window, accept cookies, then open your browser's network tab and look for requests going to facebook.com/tr. If nothing appears after you accept, the "on" signal never arrived. 2. You have two pixels on the page A theme app and a manual install both adding the ...

California AI Transparency Act Summary: Who Must Comply, and by Which Date

Image
  People keep calling this one deadline. It is four groups of companies with three different dates, and mixing them up is why so many plans are wrong. What the law asks for If a machine made it, say so. Big AI companies must put a visible label on the images, video and sound their tools produce. They must hide a tag inside the file so software can read it. And they must give the public a free tool to check any file. The date that changed SB 942 was signed on 19 September 2024. It said the rules start 1 January 2026. AB 853 was signed on 13 October 2025 and pushed the start to 2 August 2026, adding three more types of company. Many pages online still print the old date because nobody went back to fix them. Here are the correct dates for the AI Transparency Act . Group 1: big AI companies, from 2 August 2026 You build the AI tool, it has over a million users a month, and people in California can use it. You owe all three duties. The free checker also has to return the...

Why One Cookie Banner No Longer Works for a Global Website

Does your website show the same cookie banner to every visitor? If it does, you are probably doing two things at once: annoying people in relaxed regions and breaking the rules in strict ones. Geo-targeted cookie banners fix both by matching the notice to where each visitor is. What geo-targeting does When someone lands on your site, the consent system checks their IP and works out their country or region. Then it shows the banner built for that place. A visitor in Germany sees a GDPR opt-in. A visitor in California sees a CCPA opt-out with a Do Not Sell or Share option. A visitor in a light-rules region may see a short notice or none. Why one banner cannot cover everyone The laws do not agree. GDPR needs opt-in before non-essential cookies load. CCPA uses opt-out. Brazil's LGPD asks for consent per purpose. A single banner either over-asks people who do not need a full opt-in or falls short for those who do. The cost of falling short is real, with GDPR fines reaching €20 m...

Geo-Targeted Cookie Banners: Why One Notice No Longer Fits Every Visitor

Does your website show the same cookie banner to every visitor? If it does, you are likely doing two things at once: over-asking people in relaxed regions and falling short in strict ones. Geo-targeted cookie banners fix that by matching the notice to the visitor's location. What geo-targeting actually does When someone lands on your site, the consent system checks their IP against a geolocation database and works out their country or region. It then shows the banner built for that jurisdiction. A visitor in Germany sees a GDPR opt-in. A visitor in California sees a CCPA opt-out with a Do Not Sell or Share option. A visitor in a region with light rules may see a short notice or none at all. Why one banner cannot cover everyone The laws simply do not agree. GDPR requires opt-in before non-essential cookies load. CCPA follows an opt-out model. Brazil's LGPD asks for consent per purpose. A single banner either restricts users who do not need a full opt-in or under-complies fo...

Server-Side Tagging Explained: What It Is and Why Marketers Are Switching

Image
  Marketing teams rely on data to decide where budget goes. The problem is that a lot of that data no longer arrives. Understanding server-side tagging helps explain why, and what to do about it. The problem with browser tracking Most tracking still runs in the visitor's browser. The browser loads scripts from analytics and ad platforms, then those scripts send data back. Modern browsers now limit this. Apple's Intelligent Tracking Prevention and Chrome's privacy changes restrict third-party tracking, and ad blockers stop many scripts before they run. Some UK analytics studies report client-side data loss above 30%. When events go missing, reports look complete but tell only part of the story. Attribution shifts, campaigns look weaker or stronger than they are, and budget follows the wrong signals. What server-side tagging actually is Server-side tagging moves the work from the browser to a server you control. Your website sends events to that server first, usually a G...

Why Your Cookie Banner Should Speak Your Visitor's Language

Image
  Imagine you open a website and the first box asks you to agree to cookies. But the words are in a language you do not know. What do you do? Most people close the box or leave the site. That one moment can cost a business a customer. This is why the language of your cookie banner matters so much. It is often the first thing a visitor reads. If it feels foreign, it starts the visit on the wrong foot. The law wants clear language GDPR Article 12(1) says privacy information must be in clear, plain words that people can understand. A banner shown only in English to French, German, or Japanese visitors does not meet that test. If people cannot read what they agree to, their consent is weak. This is not just theory. In 2021 the Dutch privacy watchdog fined TikTok because it showed its privacy notice only in English to Dutch users. The message was simple: people must understand what they say yes to. How a multi-language banner works The banner finds the visitor's language in one of...

Why Your Google Ads Conversions Drop After Adding a Cookie Banner

Image
  You added a cookie banner to follow the law. A week later, your Google Ads conversions fell. Many owners hit this and think the setup is broken. It is not. Let us walk through what really happens and how to fix it. First, the cause. A cookie banner lets users say yes or no to cookies. When a user says no, Google tags cannot write cookies for that person. So Google cannot track the sale the normal way. Your reports show fewer conversions, even though your real sales did not change. The drop is a tracking gap, not a sales problem. Now, the fix. Google Consent Mode reads the choice from your banner and passes it to Google. It does not show the banner itself. It tells Google what each visitor allowed. This lets Google act on the choice instead of losing the data. There are two ways to run it. Basic consent mode blocks Google tags until the user clicks the banner. If the user says no, no data is sent. Advanced consent mode loads the tags with consent set to denied by default. While...

Why Your Facebook Ads Lose Data After You Add a Cookie Banner

Image
  Adding a cookie consent banner is the right thing to do. It keeps your website on the correct side of privacy law. But many marketers notice something odd soon after: their Facebook and Instagram ad reports start showing fewer conversions, even though real sales have not dropped. If that sounds familiar, this guide explains what is happening and how to fix it. The hidden problem Your Meta Pixel usually fires the moment a page loads. Once you add a consent banner, every visitor who clicks "Reject" should not be tracked with cookies.  An unmanaged pixel handles this badly. It either keeps tracking people who said no, which breaks the law, or it loses their activity completely. In the EU, UK, and several US states, declined visitors can be a large part of your traffic, so the data gap is real. Why it matters There are two costs here. The first is legal. GDPR and the ePrivacy Directive require consent before non-essential cookies load. Fines reach up to €20 million or 4% o...