Skip to content
Selected work

Two hospitality and consumer web platforms · Hospitality

Consent audits built to survive scrutiny, not just look compliant

  • Comply
case
context

The situation

Two separate clients had installed GDPR consent tooling, but neither had verified it actually behaved correctly at the moment a visitor made a choice. Both assumed they were compliant.

finding

What we found

Applying the test protocol surfaced the gap between "installed" and "working". In one case, tracking requests were firing before consent was captured at all, so the banner was cosmetic.

work

What we did

Applied a systematic testing protocol: fresh sessions for each scenario, before and after snapshots of consent state, and a full audit trail of what fired before and after consent was given or declined.

result

Result

Documentation solid enough to hand to legal counsel, with evidence at each stage, rather than a checkbox that a consent banner was switched on.

stack

Stack

Google Tag ManagerConsent Mode v2CMP verification

contact

Have something like this?

A description of the problem is more useful than a list of requirements.