Services

Data Privacy Consultant

Expert setup and configuration of Google Consent Mode v2 and consent management platforms within Google Tag Manager for data privacy compliance.

Trusted by

WordPress web application for The Worldbank to assist with bulk PDF creation and distribution during the COVID-19 pandemic
MIT Technology Review's custom headless WordPress stack combines content published in both Drupal and WordPress with a single API and frontend (Next.js/React)
Tufts Medical Center: Custom WordPress CMS development work to build out a custom design with in-house teams.
Puck.news SaaS subscription engineering and content paywall architecture supporting >100k customers.
Cred.ai's WordPress powered custom websites providing headless CMS APIs to Android and iOS apps, and for powering a custom onboarding flow at apply.cred.ai
MIT: custom WordPress plugin, theme and brand implementation work for CSAIL and the Internet Policy Research Initiative, MIT Arts and Sloan Review
Internationalized and localized custom WordPress theme built for TripAdvisor
Certified WordPress VIP approved developer with experience committing and shipping code on the platform
SBLI's custom life insurance WordPress application development using Angular & Typescript
Swagger.io's open-source custom content theme powered by democratized content on GitHub, anyone can create a PR and contribute.
NetBrain enterprise B2B software: a custom WordPress theme with specific security and back-office application requirements
American Student Assistance custom theme support and ongoing maintenance and support for asa.org

Privacy and consent work that holds up. Cookie banners that actually block tags, Consent Mode v2 configured correctly, and the documentation your legal team asked for.

Consent that blocks, not decorates. Most banners on the web are theatre: the banner renders, the visitor clicks reject, and the marketing tags fire anyway. I audit what fires before opt-in, gate it at the tag, and prove it in GTM preview.

Built with your counsel, not around them. I work directly with outside attorneys and in-house legal, implement their guidance in the codebase, and hand back cookie reports and disclosures they can sign off on.

Compliance that keeps marketing working. Consent Mode v2, server-side signals, and modeled conversions keep GA4 and ad platforms fed with the data they are allowed to have, so compliance does not blank out your reporting.

Requests, not just banners. CCPA and CPRA give people the right to see and delete what you hold. I build the intake form, the validation behind it, and the authenticated hand-off to whoever fulfills the request.

Let's Chat

If you're looking for expert consulting from a seasoned specialist schedule a consultation on Google Meet, or contact me by email.

Privacy & Consent Work in Production

Puck News: Cookiebot, Cookie Audit and Consent-Aware Analytics

A sitewide cookie audit categorized into essential, analytics, marketing and preferences, published as a cookie report for legal review, then Cookiebot deployed with every GTM tag rewired to respect the consent state it returns.

Full Case Study

Bastille: Consent Mode v2 With Counsel Sign-Off

A website privacy review run with in-house stakeholders and outside counsel, then implemented: denied-by-default Consent Mode v2, a CookieConsent to gtag bridge, HubSpot moved off its native banner onto the CMP, and a container-wide audit that closed the pre-consent firing gap.

Full Case Study

Cred.ai: Consent Across Web, Server and Mobile SDK

A fintech running paid acquisition across Meta, Google, TikTok and Snapchat. Consent state variables and gating configured in GTM, opt-out handling forwarded through server-side events, Firebase SDK consent brought in line with Consent Mode v2, and an open-source banner deployed across every property.

Full Case Study

Paperless Parts: PII Controls and an ITAR-Grade CSP

A consent management review that documented the gaps and recommended a path with no third-party licensing, a form tracking module rebuilt with PII field exclusions, and a Content Security Policy tightened until it passed their security audit for ITAR compliance.

Full Case Study

Coastal1 Credit Union: Security Headers Under Audit

Rhode Island's largest credit union, audited monthly. Content Security Policy launched in report-only mode and then enforced, referrer-policy and permissions-policy headers added, and every blocked payment frame, e-signature and video embed tracked down and fixed rather than exempted.

Full Case Study

CCPA & CPRA Data Subject Requests

California gives residents the right to ask what you hold and to have it deleted, and your site needs a working intake for that. I build the request flow end to end, from the form to the vendor API to the confirmation the visitor sees.

  • Privacy request forms built to your design

  • Conditional field logic for request types

  • Server-side validation and sanitization

  • OAuth-authenticated delivery to your privacy vendor

  • Request ID shown on confirmation for follow-up

  • API credentials managed in the CMS, never hardcoded

server status

PII, Ad Platforms & Server-Side

Privacy problems are not only cookies. Personal data leaks into tracking through form fields, logs and ad platform audiences, and in regulated verticals that is what gets an ad account suspended rather than fined.

  • PII field exclusions in form tracking modules

  • PII-free logging for form and email delivery

  • Consent signals forwarded to server-side tagging

  • Opt-out handling on server-side conversion events

  • Ad platform policy reviews for finance and health

  • Cookie clearing verified per vendor on reject

What Businesses Worry About
Before Fixing Consent

Privacy work has a reputation for breaking analytics and slowing marketing down. Done properly it does neither, and these are the concerns I hear most often before we start.

Concern Solution

Losing Our Analytics Data

If we block tags until someone consents, do we lose most of our traffic data and conversion tracking?

You lose less than you expect. Consent Mode v2 keeps cookieless pings flowing for users who decline, and Google models the gap. Configured correctly with server-side signals behind it, reporting stays usable and ad platform optimization keeps working.

Breaking the Marketing Stack

Our HubSpot, ad pixels and attribution all depend on cookies. Will consent gating break the whole funnel?

No, but it does need to be rewired rather than switched off. I map each platform to a consent category, bridge the CMP to the platform's own consent API where one exists, and confirm attribution cookies still load for users who accept.

Which Laws Apply To Us

We are a US company with some European traffic. Do we need GDPR, CCPA, both, or something else entirely?

That is a question for your attorney, and I will implement whatever they decide. What I can do is show you exactly what your site collects today, what fires before consent, and what each option would cost to build so counsel is deciding with real information.

A Plugin Already Handles It

We installed a consent plugin. Is that not enough?

Usually not. Most installs render a banner while the tags keep firing underneath it, because nothing connected the banner to the tag manager. That gap is the first thing I audit, and it is the one that creates actual exposure.

Cost of Enterprise CMP Licensing

The enterprise consent platforms quote us serious money. Is that the only route?

Not always. I have implemented both licensed platforms like Cookiebot and CookieYes and open-source alternatives with no per-domain fee. The right answer depends on your scale, your legal requirements and how many domains you run, and I will lay out the tradeoffs before you commit.

Keeping It Compliant Over Time

We fix it once, then marketing adds three new tools next quarter. How does it stay compliant?

That is why most of my privacy work sits inside an ongoing retainer. New vendors get reviewed and categorized before they ship, the cookie report gets updated, and the container gets re-audited after redesigns rather than once at launch.

Common Tasks & Requests

A sample of the privacy and consent requests I handle for clients every month:

  • Auditing which tags fire before consent is given
  • Implementing a cookie banner and branding it to the site
  • Configuring Google Consent Mode v2 in GTM
  • Running a sitewide cookie scan and writing the report
  • Building a CCPA data subject request form
  • Adding Global Privacy Control detection
  • Moving HubSpot and ad pixels behind consent
  • Fixing cookies that survive a reject click
  • Setting region-aware consent defaults with GeoIP
  • Rolling out a Content Security Policy without breaking pages
  • Excluding PII from form tracking and logs
  • Updating disclosures to match counsel's wording

Common Questions About Privacy & Consent

The questions marketing leads, legal teams and founders ask most often when they start looking at consent seriously.

Do we actually need a cookie banner?
What is Google Consent Mode v2 and do we have to use it?
Will consent gating hurt our conversion tracking?
Which consent management platform should we use?
How do we handle CCPA and CPRA data requests?

You need a way for California residents to submit access and deletion requests, and a process behind it that actually answers them. On the website side I build the intake: a request form matching your design, conditional logic for request types, server-side validation, and authenticated delivery into whatever privacy platform or internal queue handles fulfillment.\n\nI also surface the request ID back to the visitor on submission, so both sides have a reference when the response comes due.

What is Global Privacy Control and do we have to honor it?

Global Privacy Control is a browser-level signal that tells a site the visitor opts out of sale and sharing of their personal information. Under CPRA, covered businesses must honor it, and honoring it means detecting the header or JavaScript property and applying the opt-out automatically, without waiting for a banner interaction.\n\nIt is a small piece of code and a frequently missed one, which is exactly why compliance scanners flag it.

Our banner is live but tags still fire before consent. Why?

Because the banner and the tag manager were never connected. The banner renders and stores a choice, but nothing translates that choice into consent state that GTM checks before firing, so the tags carry on as normal.\n\nThe fix is a bridge from the CMP into Consent Mode, denied-by-default state applied before GTM loads, and per-tag consent checks. Then a full container audit for the tags that bypass all of it: hardcoded scripts in the theme, obfuscated Custom HTML tags, and vendor loaders that inject their own pixels.

If someone rejects cookies, are the existing ones removed?

Only if you configured it. Most banners stop future scripts from loading but leave cookies already set by earlier visits sitting in the browser, which is exactly what a compliance scanner screenshots.\n\nI configure automatic clearing per category, then verify vendor by vendor that the cookies really disappear on reject, rather than trusting the library defaults.

How does consent work with HubSpot, Marketo and ad pixels?
Is a Content Security Policy part of privacy compliance?

It is adjacent, and it comes up in the same audits. A CSP controls which scripts are allowed to run at all, which is how you stop an injected third-party script from exfiltrating form data, and security questionnaires and audits routinely require one.\n\nI roll it out in report-only mode first, whitelist asset by asset from real traffic, then enforce, testing page by page. Payment frames, e-signature flows and video embeds are the usual casualties, and they get fixed rather than exempted.

Are you giving us legal advice?

Benefits of working together

Proven Under Real Audits

This work has been reviewed by outside counsel, security auditors and compliance scanning tools for clients in banking, fintech, defense manufacturing and digital media, and it held up.

data trends

Compliance That Keeps Marketing Alive

I come at consent from the analytics side, not the legal side. That means Consent Mode, modeled conversions and server-side signals are configured to preserve as much measurement as the rules allow.

Maintained, Not Just Launched

New vendors, redesigns and new state laws all break a static implementation. Most of my privacy work runs inside an ongoing retainer, so the cookie report and the container stay current.

Let's Chat

If you're looking for expert consulting from a seasoned specialist schedule a consultation on Google Meet, or contact me by email.