Posts

Why Your Cookie Banner Should Speak Your Visitor's Language

Image
  Imagine you open a website and the first box asks you to agree to cookies. But the words are in a language you do not know. What do you do? Most people close the box or leave the site. That one moment can cost a business a customer. This is why the language of your cookie banner matters so much. It is often the first thing a visitor reads. If it feels foreign, it starts the visit on the wrong foot. The law wants clear language GDPR Article 12(1) says privacy information must be in clear, plain words that people can understand. A banner shown only in English to French, German, or Japanese visitors does not meet that test. If people cannot read what they agree to, their consent is weak. This is not just theory. In 2021 the Dutch privacy watchdog fined TikTok because it showed its privacy notice only in English to Dutch users. The message was simple: people must understand what they say yes to. How a multi-language banner works The banner finds the visitor's language in one of...

Why Your Google Ads Conversions Drop After Adding a Cookie Banner

Image
  You added a cookie banner to follow the law. A week later, your Google Ads conversions fell. Many owners hit this and think the setup is broken. It is not. Let us walk through what really happens and how to fix it. First, the cause. A cookie banner lets users say yes or no to cookies. When a user says no, Google tags cannot write cookies for that person. So Google cannot track the sale the normal way. Your reports show fewer conversions, even though your real sales did not change. The drop is a tracking gap, not a sales problem. Now, the fix. Google Consent Mode reads the choice from your banner and passes it to Google. It does not show the banner itself. It tells Google what each visitor allowed. This lets Google act on the choice instead of losing the data. There are two ways to run it. Basic consent mode blocks Google tags until the user clicks the banner. If the user says no, no data is sent. Advanced consent mode loads the tags with consent set to denied by default. While...

Why Your Facebook Ads Lose Data After You Add a Cookie Banner

Image
  Adding a cookie consent banner is the right thing to do. It keeps your website on the correct side of privacy law. But many marketers notice something odd soon after: their Facebook and Instagram ad reports start showing fewer conversions, even though real sales have not dropped. If that sounds familiar, this guide explains what is happening and how to fix it. The hidden problem Your Meta Pixel usually fires the moment a page loads. Once you add a consent banner, every visitor who clicks "Reject" should not be tracked with cookies.  An unmanaged pixel handles this badly. It either keeps tracking people who said no, which breaks the law, or it loses their activity completely. In the EU, UK, and several US states, declined visitors can be a large part of your traffic, so the data gap is real. Why it matters There are two costs here. The first is legal. GDPR and the ePrivacy Directive require consent before non-essential cookies load. Fines reach up to €20 million or 4% o...

EU AI Act Compliance in 2026: Deadlines, Fines and the Four Risk Categories Explained

Image
  Artificial intelligence is now regulated law in Europe, and many businesses are further behind than they realise. The EU AI Act entered into force on 1 August 2024 as the first legal framework built entirely around AI. Its rules arrive in stages, and some of the most important ones already apply. The four risk categories The Act sorts every AI system into one of four tiers, and your obligations depend on where your systems land. Unacceptable risk systems are banned outright. Since 2 February 2025, the EU prohibits AI that manipulates people into harm, exploits vulnerable groups, runs social scoring for public authorities, scrapes facial images from the internet, or reads emotions in workplaces and schools. High-risk systems are allowed, with strict conditions. This tier covers AI used in hiring, credit scoring, education, critical infrastructure, law enforcement and border control. Providers must complete conformity assessments, keep detailed technical documentation, register...

AI Governance Basics: What It Is, Which Rules Apply, and How to Start

Image
  Artificial intelligence now sits inside hiring tools, credit checks, chatbots and marketing platforms. Yet many organisations use these systems without any structure for managing the risks they create. That structure has a name: AI governance. What AI governance means AI governance is the set of internal policies, roles and checks that guide how an organisation builds, buys and monitors AI. It covers the full life of a system, from the data used to train it through to how its outputs are reviewed once it is live. The central idea is accountability. Someone must be able to answer for what each system does. It is worth separating governance from regulation. Regulation is imposed from outside by law. Governance is what an organisation builds internally, and good governance usually goes further than the legal minimum. The rules that now apply The most important law in this area is the EU AI Act. According to the official implementation timeline published at artificialintelligenc...

Mobile App Compliance in 2026: GDPR, CCPA and App Store Rules Explained

Image
Mobile app compliance means meeting the legal and technical rules that govern how your app collects, uses, and stores personal data. In 2026 that covers privacy laws such as GDPR, CCPA, and LGPD, and also the frameworks Apple and Google enforce through their app stores. Getting it wrong risks fines, store removal, and advertising data you cannot legally use. Which laws apply to your app The laws that apply depend on where your users are, and this catches many app owners out because a company registered in one country can still owe duties in many others. If you have users in the EU or UK, GDPR requires explicit opt-in consent before non-essential data processing, and consent must be specific to each purpose.  If you have users in California, CCPA gives them the right to opt out of the sale or sharing of their data, and since 2026 businesses must confirm they have processed opt-out requests, including Global Privacy Control signals. Brazilian users fall under LGPD, and several ...

What Is a Mobile Application SDK and What Does It Do With User Data?

Image
If you own or manage a mobile app, third-party SDKs are almost certainly inside it. Understanding what they are and what they collect is now a basic requirement for running an app legally. What an SDK actually is A mobile application SDK is a pre-built software toolkit that developers add to an app to get specific functionality without building it from scratch. Analytics, advertising, crash reporting, and payments are the most common uses.  A typical SDK contains an initialisation module that activates when the app loads, an API layer that connects to the provider's service, a data collection module, and a logging component. People often mix up SDKs and APIs. An API is a set of rules that lets two systems talk to each other. An SDK is a bigger package that usually contains APIs along with libraries, sample code, and documentation.  An SDK saves development time, but it also brings a third-party dependency into your app that needs ongoing management. What SDKs collect Eac...

Google Consent Manager: How It Works With Google Ads and GA4

Image
  If you run Google Ads or track visitors with GA4, a cookie banner alone does not tell Google anything. Google Ads and Analytics need structured consent signals, and a standard banner does not send them. This is what a Google consent manager actually does. It is the layer that sits between your visitor's choice and your Google tags, translating "accept" or "reject" into signals Google can read. The four signals that matter Google's Consent Mode covers four parameters: ad_storage , analytics_storage , ad_user_data , and ad_personalization . The first two have existed since the original Consent Mode launch and control advertising and analytics cookies. The other two were added in November 2023, according to Google's developer documentation, and specifically govern whether Google Ads can personalise ads or match Enhanced Conversions using hashed customer data. Basic versus advanced implementation Google offers two ways to run Consent Mode. Basic mod...

How to Make a Mobile App GDPR Compliant: A Complete Checklist

Image
  If your mobile app collects any personal data from users in Europe, GDPR applies to you, regardless of where your company is based or how large it is. Many app owners assume GDPR is a website issue. It is not. Mobile apps often collect more personal data than websites, through location tracking, device identifiers, contact lists and behavioural logs. Here is what GDPR compliance actually requires in practice. Start with consent. GDPR requires consent to be freely given, specific, informed and unambiguous. That means no pre-ticked boxes, no bundled permissions, and a separate opt-in toggle for each purpose you process data for. Present Accept and Reject with equal visual weight so neither option is designed to be harder to find. Build a proper privacy policy. It should name your data controller, list every type of data you collect, explain your legal basis for processing it, and set out user rights, including access, correction, deletion, restriction, portability and objectio...

GA4 Server-Side Tracking: How to Stop Losing Conversion Data to Ad Blockers

Image
  If your Google Analytics 4 reports show fewer conversions than your CRM, you are not looking at a reporting quirk. You are looking at a data gap — and it is caused by something most marketing teams do not see coming. Ad blockers affect between 25 and 40 percent of web traffic, depending on the industry and device type. Every blocked request is a conversion event your analytics never receives.  Browser privacy tools like Safari's Intelligent Tracking Prevention (ITP) compound the problem further by capping the lifespan of JavaScript-set cookies at just seven days. If a customer converts eight days after their first visit, that attribution gets lost entirely. Why Client-Side Tracking Has a Structural Weakness Client-side tracking works by running JavaScript tags directly in the user's browser. The browser then sends the event data to Google Analytics 4. This approach is simple to set up and has worked for years — but browser privacy controls now sit directly in its path. A...

Mobile App Compliance for iOS and Android: What Every App Owner Needs to Know in 2026

Image
  If you own or manage a mobile app, privacy compliance has changed significantly in the past two years. Regulators are no longer satisfied with a privacy policy page buried in your settings. They want to see how your app actually handles data at the moment of collection, and app stores have added their own requirements on top of that. This post covers what mobile app compliance means in 2026, which regulations apply, what a proper consent flow looks like, and where most apps fall short. Which Regulations Apply to Your App The regulations that apply depend on where your users are located, not where your company is registered. If your app has users in the EU or UK, GDPR applies. This regulation requires explicit opt-in consent before you collect data for non-essential purposes like analytics or advertising. Pre-ticked boxes and bundled consent do not meet the standard. If your app has users in California, CCPA gives those users the right to opt out of the sale or sharing of ...

Why B2B Advertisers Are Losing Microsoft Ads Data (And What Consent Mode Does About It)

Image
  If your Microsoft Ads campaigns target visitors in the EEA, UK, or Switzerland, there is a specific compliance step that has been mandatory since May 5, 2025. Without it, a portion of your conversion data goes unrecorded, your smart bidding operates on incomplete information, and your remarketing lists may include users whose data was collected without valid consent. That step is Microsoft Consent Mode. This article explains what it does, why it matters specifically for B2B advertisers, and how to get it working without a technical team. What Microsoft Consent Mode Does Microsoft Consent Mode connects your UET tag to each visitor's consent decision. The tag reads a signal from your Cookie Consent banner, specifically the ad_storage parameter, and adjusts its behaviour accordingly. When a visitor accepts cookies, UET records the full conversion event as normal. When a visitor declines, UET switches to cookieless mode and sends only anonymised, aggregate signals. No individua...

Why the iOS Tracking Prompt Timing Affects Your Ad Revenue More Than You Think

Image
Apple's App Tracking Transparency framework put a hard gate in front of IDFA access. The user permission prompt is now mandatory for every iOS app before cross-app tracking begins. Most development teams shipped the minimum viable implementation and moved on. The revenue effect of that decision took a few quarters to show up clearly. When users decline, ad platforms switch to modelled attribution. They use statistical inference about cohorts rather than real signal from individual users. Audience targeting becomes less accurate. Budget allocation drifts toward average users rather than high-value ones. ROAS numbers look stable until they don't. What the pre-prompt actually changes Apple's system dialog is fixed. Two options, standard wording, no customisation. What happens before it appears is entirely up to the developer. A pre-prompt screen — shown before the Apple dialog — can explain what tracking enables for that specific user. Not legal language. Not vague assurances....

Why Your Ad Reports Are Missing Real Conversions (And What Server-Side Tagging Does About It)

Image
  If you run paid ads on Google, Meta, or TikTok, there is a good chance your dashboard is undercounting real conversions. Research on client-side tracking loss shows the gap is commonly 20 to 40 percent of actual events. This is not a platform problem. It is a structural one caused by where your tracking runs. Why Browser-Based Tracking Loses Data Traditional ad tracking uses pixels and scripts that fire directly inside the user's browser. Today, ad blockers remove known tracking scripts before they run. Safari's Intelligent Tracking Prevention shortens cookie lifespans to as little as 24 hours. GDPR and CCPA consent banners block entire tracking tools when a user declines. Slow mobile connections cause tags to time out before a page fully loads. Each of these factors removes real conversion events from your reports, quietly and continuously. By the time the data reaches your dashboard, a significant slice of real purchases, sign-ups, and leads is already gone. Your bidding al...

Does Amazon Consent Signal Affect ROAS? What UK and EEA Advertisers Need to Know

Image
  If you run Amazon Ads campaigns targeting users in the UK or European Economic Area, there's a good chance your ROAS reports are not showing your true performance. The cause is the Amazon Consent Signal — a requirement that has been in place since February 2025 and reaches full enforcement on June 30, 2026 . This post explains what the consent signal is, why it matters for ROAS, and what you need to do before the deadline. What Is the Amazon Consent Signal? The Amazon Consent Signal (ACS) is a set of data parameters that tells Amazon's advertising systems whether a specific user has agreed to data processing for advertising purposes. It must be passed alongside any personal data sent to Amazon Ads. The signal includes two parameters: one for consent to store or access information on a user's device, and one for consent to use their personal data for advertising. Both must be present and valid. If either is missing or denied, Amazon treats all data associated with that us...

Android App Privacy Policy Requirements: What Every Developer Must Know Before Launching

Image
  Every Android app that collects personal data must have a privacy policy. This applies whether your app handles payments, tracks location, or simply records crash data. Google Play enforces this requirement, and regulators in Europe and the US can impose significant penalties when developers fall short. What Is an Android App Privacy Policy? A privacy policy is a legal document that discloses how your app collects, processes, stores, and shares user data. It must be publicly accessible — it cannot be placed behind a login screen or hidden within your app settings. The policy must be accurate and reflect your actual data practices at all times. If you update your SDKs, analytics tools, or data sharing arrangements, the policy must be updated to match. What Must the Policy Include? The types of personal data your app collects, including both active inputs like registration forms and passive signals like device identifiers and location data. The specific purpose for each category of...

AWS Data Privacy and GDPR Compliance: What Your Consent Setup Actually Controls

Image
  Many businesses assume that hosting on AWS covers their GDPR obligations. In practice, AWS handles the infrastructure layer while consent management sits entirely with you. Understanding this split is important for any company collecting user data on AWS-powered systems. What AWS Handles for You AWS manages physical security in its data centers, encryption at rest and in transit, access control, and compliance certifications including ISO 27017, ISO 27701, and ISO 27018. These protections secure data once it is inside your AWS environment, and they give your business a credible foundation for meeting many regulatory requirements. What AWS does not control is whether users gave proper consent for their data to be collected in the first place. That decision point happens before data enters AWS, and it is your responsibility to capture, record, and act on it correctly. Where the Consent Gap Usually Appears The most common gap shows up in marketing workloads. Businesses running...

Does Meta Consent Mode Actually Improve Facebook Ads Performance?

Image
Facebook advertisers across Europe, the US and other regulated markets are seeing a growing problem. More visitors are declining cookies on websites. Each decline stops the Facebook Pixel from recording that session. Conversion reports show less data than before. Campaign ROAS looks weaker, and the bidding algorithm gets fewer signals to work with. Meta Consent Mode is Meta's answer to this problem. When a user declines cookies, the standard Facebook Pixel fires nothing. Meta Consent Mode changes that behaviour. It tells the Pixel to send a reduced, privacy-safe signal to Meta even after a decline. Meta uses these reduced signals alongside conversion modelling to estimate what happened in those sessions, without identifying any individual user. The result is that your conversion reporting stays accurate even when a significant portion of your site visitors say no to tracking. Your attributed conversions reflect real business outcomes more closely. What this means for ROAS and biddi...

Does Amazon Consent Signal Actually Improve Your Ad Campaign Results?

Image
  If you run Amazon Ads for your ecommerce store, your campaign data already has gaps in it. Every time a shopper clicks "reject all" on your cookie consent banner, Amazon stops receiving tracking data for that session. Amazon Consent Signal (ACS) is the mechanism that tells Amazon what a visitor chose and keeps your ad performance measurable. This is not a minor technical detail. According to the Seers AI ecommerce blog , ecommerce brands lose nearly half their visitor-level data without consent signals in place. For a store spending thousands on Sponsored Products or DSP campaigns, that gap translates directly into wasted budget and inaccurate reporting. What Amazon Consent Signal Actually Does ACS sends three pieces of information to Amazon's advertising systems. The first is whether the shopper approved processing of their personal data. The second is whether they approved ad-related data storage. The third is their country code, which helps Amazon apply the corre...

What Your Mobile App Consent Banner Must Include Under GDPR and CCPA

Image
  If you run a mobile app that collects personal data, a consent banner is not optional. Under GDPR, which applies to any app with users in the EU or UK, consent must be freely given, specific, informed, and unambiguous. Under CCPA, California users have the right to opt out of the sale of personal data. Both laws apply based on where your users are, not where your company is registered. What a compliant banner actually needs Many app teams get the front end right but skip the back end. A compliant consent setup requires both: a clearly designed user-facing banner and a backend system that stores consent records with timestamps and version references. If a regulator or legal team requests an audit trail, that stored record is what they examine. The mobile app consent guide details exactly what those records must contain and how long they should be retained. The visual design is also regulated in practice. Data protection authorities have issued enforcement decisions against ap...