Services

Consent implementation, end to end.

Six services that cover everything between the regulation and your tag manager. Four of them are engagements we run often enough to have their own page; all six are delivered by the same named team, on the same cycle.

Service
01

Cookie consent implementation

The banner, the preference centre and the tag blocking behind them, configured on your CMP and verified in the browser.

Read about this service →
01.1
Cookie and tracker scanning with manual verification
01.2
Category mapping across cookies, storage, pixels and SDKs
01.3
Banner and preference centre built to your design system
01.4
Tag blocking verified before and after consent, per region
02

Consent & preference management

OneTrust and Universal Consent & Preference Management: configuration, geolocation rules, migrations and remediation of existing setups.

Read about this service →
02.1
Template and geolocation rule configuration
02.2
Purpose and preference taxonomy for UCPM
02.3
Migration from another CMP with consent continuity
02.4
Remediation of implementations that drifted
03

Consent Mode v2 & Google Tag Manager

Consent state wired through Tag Manager so measurement keeps working after consent is enforced.

Read about this service →
03.1
All Consent Mode v2 signals through GTM, basic or advanced
03.2
Consent-gated triggers and data layer implementation
03.3
Server-side container handling where it exists
03.4
Debugging and validation with documented results
04

CCPA, GPC & US state banners

Opt-out mechanics, Global Privacy Control handling and one baseline across the US state laws that apply to you.

Read about this service →
04.1
Do Not Sell or Share links and opt-out flows
04.2
Global Privacy Control recognised automatically
04.3
Sensitive data limits and regional variants
04.4
US Privacy string and GPP configuration
05

Privacy notice management

Clear, compliant privacy policies and layered notices, kept current as your processing activities and the regulations change.

Discuss this service →
05.1
Privacy policy drafting against your actual processing
05.2
Layered notices at the point of collection
05.3
Scheduled reviews when regulations or vendors change
05.4
Presentation that a reader can actually follow
06

Audits, training & documentation

Gap analysis of what fires before consent, verification of existing implementations, and training so your team can run the setup.

Discuss this service →
06.1
Compliance gap analysis across regions and devices
06.2
Cookie and tracking technology audits
06.3
Consent implementation verification with test results
06.4
Training sessions and documentation for internal teams
Platforms we configure
Supporting existing clients

After go-live, the same team stays on.

A consent setup does not stay compliant on its own. Marketing adds a tag, a vendor changes an endpoint, a regulator issues new guidance. Under a support agreement the team that built the implementation keeps it held, with defined response times and a written record of every change.

The agreement at a glance
Coverage
The sites, regions and platforms in scope, listed in the agreement and reviewed when your estate changes.
Support desk
A named channel and named people for questions, change requests and incidents.
Response times
Defined per request type in the agreement: incident, change request, question.
Scheduled scans
Every site and region on a set cadence, each run compared with the last, with alerts on new scripts, cookies or vendors.
Regulatory monitoring
Tracked changes to the regulations and platform requirements that apply to you, each with an impact note and, where needed, an applied update.
Change requests
New vendors, copy, regions, designs or categories, configured on staging and released after verification.
Reviews and reporting
Periodic review of the whole implementation with a written report, findings and actions, and consent metrics by region where the CMP provides them.
Change log
Every change recorded with the reasoning, so the setup can be audited and handed over at any time.
Who does what
Your team
  • Tell us when a tag, vendor, region or design is changing
  • Approve changes before they leave staging
  • Receive reports and the change log
consenteo
  • Monitor: scans, regulations, platform requirements
  • Assess the impact of each finding and decide the fix
  • Configure and verify, staging first
  • Document every change with the reasoning
How a change is handled
  1. 01DetectA scan, an alert or a request from your team.
  2. 02AssessImpact on compliance and measurement, decided by the architect.
  3. 03FixConfiguration or copy change, staged first.
  4. 04VerifyChecked in the browser, before and after consent.
  5. 05ReportLogged, with the reasoning, in your change log.
Support agreements are scoped to your estate.Number of sites, regions, platforms and the review cadence set the agreement. Response times are defined in it, not implied.
Discuss a support agreement
Integrations & automation

Privacy operations that run without anyone remembering to run them.

Most privacy work is repetitive and detectable: a request arrives in an inbox, a tag appears on a page, a release goes out untested. We build the pipelines that handle each of these, deploy them into your own infrastructure so you own them, and operate them under the support agreement.

Intake & case management

A dedicated privacy inbox on your domain, and an intake that turns every message into a tracked case with a deadline.

  1. 01Privacy inboxprivacy@ and, where needed, dsar@ on your mail domain, published in your notices.
  2. 02IntakeMessages and web-form submissions parsed on arrival; attachments and identity evidence captured.
  3. 03ClassificationAccess, deletion, correction, opt-out, complaint, vendor enquiry or general question.
  4. 04Case creationA case opened in your ticketing and mirrored in ours, with the statutory deadline for the applicable regulation.
  5. 05Routing and acknowledgementAssigned to the right owner; the requester receives an acknowledgement in the required language.
  6. 06Fulfilment and recordResponses, evidence and timestamps stored against the case for audit.
Deployed into: your mail domain, your ticketing, your consent records
p.1 · intake & case managementrunning
Built in your infrastructure

You own the pipelines. We operate them.

Every automation is deployed into accounts and systems you control: your mail domain, your ticketing, your CI, your tag manager. Nothing depends on a Consenteo login to keep running. Under the support agreement we monitor, tune and extend them; at handover you receive the runbooks to run them yourself.

  • Inboxes on your mail domain, not ours
  • Cases in your ticketing, mirrored to ours only while we operate them
  • CI checks committed to your repository
  • Credentials and API keys held in your secrets store
  • Runbooks and configuration handed over at the end
  • Everything keeps running if the agreement ends
What we automate
A.1
Privacy inbox and intakeDedicated addresses on your domain; every message parsed, classified and turned into a case with the applicable deadline.
Where it connects
C.1
MailGoogle Workspace and Microsoft 365 mailboxes on your domain for privacy@ and dsar@.
A.2
Case creation in both systemsA case in your ticketing and a mirror in our own, so nothing depends on someone forwarding an email.
C.2
Ticketing and service desksJira, Linear, ServiceNow, Zendesk, HubSpot Service or your own, with a case per request or finding.
A.3
Acknowledgements and deadline trackingRequesters acknowledged automatically; statutory deadlines tracked per regulation with escalation before they lapse.
C.3
MessagingSlack and Microsoft Teams channels for alerts, acknowledgements and reports.
A.4
Scheduled consent scansEvery site and region on a cadence, results diffed against the last run so only real changes surface.
C.4
DeliveryGitHub Actions, GitLab CI or your existing pipeline for release checks.
A.5
Pre-release consent checksA check in your CI pipeline that fails the release if a non-essential tag fires before consent on staging.
C.5
Tag managementGoogle Tag Manager, including server-side containers, and Tealium.
A.6
Configuration change trackingGoogle Tag Manager and CMP configurations versioned, with a notification when something changes outside a planned release.
C.6
CMP APIsOneTrust, Cookiebot, Didomi, CookieYes, TrustArc and others for configuration, consent records and DSAR modules.
A.7
Consent signal monitoringConsent Mode, TCF and US Privacy signals sampled by region, so a broken update call is caught early.
C.7
Data and CRMHubSpot, Salesforce, Marketo and similar for preference synchronisation and request fulfilment.
A.8
Preference synchronisationConsent and preference state passed between the CMP and your CRM or marketing automation platform through their APIs.
C.8
Automation platformsn8n, Make or Zapier where a client already runs them; otherwise small services in your cloud account.
A.9
Vendor and cookie inventoryA maintained inventory of vendors, cookies and categories, updated from scan results and used in your notices.
A.10
ReportingRecurring reports for the DPO and marketing: requests handled, what fired, what was held, what changed, by region.
Discuss privacy operations automation →

Not sure which service you need? Start with what fires before consent.

A free review of your site across regions, with the findings in writing, tells us both where to begin.