Home / Blog / Compliance

GDPR and Consent Mode v2: A Practical Compliance Checklist for Growing Brands

Data privacy compliance is often treated as a box to tick once and forget. In reality, it's an ongoing operational practice - and getting it wrong carries real financial and reputational risk, especially for brands running paid media into the EU/UK or handling EU customer data. This is a practical starting checklist, not legal advice - pair it with a qualified privacy lawyer for your specific situation.

Why this matters more than it used to

Two things have changed the urgency here. First, enforcement has intensified - regulators across the EU are issuing larger fines and targeting more mid-sized companies, not just tech giants. Second, Google now requires Consent Mode v2 for any advertiser serving ads to users in the EEA; without it, you lose access to remarketing audiences and see degraded conversion measurement, which quietly erodes paid media performance even before a regulator gets involved.

The practical checklist

1. Cookie and consent banner

  • Reject is as easy as Accept - no dark patterns, no pre-ticked boxes
  • Categorise cookies clearly (necessary, analytics, marketing, personalisation)
  • No non-essential cookies fire before consent is given
  • Consent choices are logged with a timestamp for audit purposes

2. Consent Mode v2 implementation

  • Both required signals - ad_user_data and ad_personalization - are correctly wired to your consent banner
  • Basic (cookieless pings) or Advanced Consent Mode is implemented depending on your data needs
  • Google Ads and Analytics conversion modelling is verified as working correctly after implementation, not just assumed

3. Data collection and retention

  • You can list, in plain language, exactly what personal data you collect and why
  • Retention periods are defined and enforced (data isn't kept indefinitely by default)
  • Data collected for one purpose isn't silently reused for an unrelated one

4. Third parties and processors

  • Data Processing Agreements (DPAs) are in place with every ad platform, CRM, email tool and analytics vendor that touches personal data
  • You know where each processor stores and processes that data

5. User rights

  • There's a working process for handling access, deletion and correction requests within the required timeframe
  • Your privacy policy is accurate, current, and actually reflects what your systems really do

6. Incident readiness

  • A basic breach-response process exists, including who gets notified and within what timeframe
  • You know your reporting obligations for the jurisdictions your customers are in

Common mistakes we see

  • A polished consent banner sitting in front of tracking tags that were never actually reconfigured to respect the user's choice
  • Consent Mode implemented on the site but never verified end-to-end in Google Tag Manager's preview mode
  • A privacy policy that describes a data setup the company changed a year ago and never updated

Where to start this week

Run a tag audit: open your site in an incognito window, don't click accept, and check your network tab or Tag Assistant for anything firing before consent. That single five-minute check reveals more real compliance gaps than most banner vendors' marketing pages ever will.

Keep Reading

More from the blog.

Ready to put this into practice?

Tell us where you're stuck. We'll show you the fastest way through it.

Talk to Our Team →