Privacy & Consent

GDPR-Compliant Tracking: Cookie Banner, Consent Mode v2 and Conversion Tracking Done Right

GDPR-compliant tracking in plain English: what valid consent means, how Consent Mode v2 works and how to set up your cookie banner and conversion tracking.

Updated October 10, 202610 min read

Tracking and privacy often feel like opponents: marketing wants to see every conversion, privacy wants as little data as possible. The good news is that you can have both. GDPR-compliant tracking does not mean giving up on measurement. It means asking properly, loading only what you have permission for, and being able to prove it.

This guide covers the legal basics in plain language, the mistakes we see most often, how Google Consent Mode v2 works, and a step-by-step walkthrough for building a clean setup with LeadSignal.

This guide is not legal advice. It summarises the common interpretation of the GDPR and the ePrivacy rules as of October 2026, with a focus on the EU and Germany. Case law and regulator guidance keep evolving, and rules differ between countries. If in doubt, have your setup reviewed by your data protection officer or a specialised lawyer.

Two sets of rules matter for website tracking in the EU. They work together but cover different things.

GDPR: when can you process personal data?

The General Data Protection Regulation defines when you may process personal data. That includes not only names and email addresses but also IP addresses, cookie IDs and click IDs once they can be linked to a person. For advertising purposes, the legal basis is almost always consent under Art. 6(1)(a) GDPR.

ePrivacy and the TDDDG: when can you access the device?

The ePrivacy Directive covers access to the user's device. Each EU country implements it in national law. In Germany that is § 25 of the TDDDG, which was called the TTDSG until May 2024. The rule: you need consent before storing or reading information on a device, such as cookies, local storage or fingerprinting. The only exception is what is strictly necessary for the service the user asked for, like a shopping cart cookie or storing the consent choice itself.

This applies whether or not the data is personal. Even setting a marketing cookie needs consent, regardless of whether it is a first-party cookie or third-party cookies.

Consent only counts if it meets a few conditions:

  • Informed: visitors need to understand which tools process which data and for what purpose.
  • Freely given and active: no opt-out, no pre-ticked boxes. The CJEU made this clear in its 2019 Planet49 ruling.
  • Granular: statistics and marketing should be separate choices, not all or nothing.
  • Revocable: withdrawing consent must be as easy as giving it (Art. 7(3) GDPR).
  • Documented: you must be able to demonstrate that consent was given (Art. 7(1) GDPR).

The most common tracking mistakes

Most problems are not bad intent. They come from setups that grew over the years. These are the ones we see most.

The classic: a tracking pixel such as the Meta Pixel or the Google Ads tag is hardcoded into the theme and loads immediately, while the cookie banner is still on screen. At that point the banner is decoration. Test it yourself: open your site in a private window, do not click anything in the banner, and check the network tab in your developer tools for requests to ad platforms.

Dark patterns in the banner

A big, colourful "Accept all" button next to a tiny grey "Settings" link that leads to a second layer: many regulators and courts take a critical view of designs like this. The widespread expectation is that rejecting should be as easy as accepting, on the first layer.

If a regulator asks, you need to show when and for what consent was given. A banner that only stores the choice in the browser gives you no evidence.

Processing full IP addresses

IP addresses are personal data. Storing them in full when you do not need them goes against the principle of data minimisation. Truncating the IP address is a simple, sensible step.

This misconception is surprisingly common. Server-side tracking via the Conversions API makes your tracking more robust against ad blockers and browser restrictions. It does not change the legal situation. If you send data to Meta, Google, LinkedIn or TikTok for advertising, you need consent, no matter which route the data takes. Our article on why server-side tracking matters covers the technical benefits.

Server-side tracking is a tool for better data quality, not a loophole. Used properly, it sends events only for visitors who consented, and does so more reliably than a browser pixel alone.

Google Consent Mode v2 is how your website tells Google tags which permissions a visitor has granted. The tags then adjust their behaviour. Consent Mode is not a cookie banner. It is the interface between your banner and Google's services.

SignalWhat it controls
ad_storageCan data be stored on the device for advertising (e.g. ad cookies)?
analytics_storageCan data be stored for analytics (e.g. Google Analytics cookies)?
ad_user_dataCan user data be sent to Google for advertising?
ad_personalizationCan the data be used for personalised ads and remarketing?

ad_user_data and ad_personalization were added in version 2. Since March 2024, Google requires them for users in the European Economic Area. Without them, features like remarketing audiences and parts of conversion measurement in Google Ads are unavailable or limited. That is a Google policy rather than a law, but if you run Google Ads it is effectively just as binding.

Basic vs. advanced mode

  • Basic mode: Google tags only load after consent. Without consent, nothing is sent to Google. Google models missing conversions from general data.
  • Advanced mode: Google tags load right away but, without consent, only send cookieless pings with no identifiers. Google uses those to build more precise models.

Advanced mode tends to give better modelling but is more contested from a privacy point of view, since requests reach Google before consent. Many German data protection officers therefore recommend basic mode. Discuss the choice with yours.

A realistic picture helps set expectations.

Without consent, you can typically use:

  • Aggregated, anonymous visit counts via cookieless tracking, as long as nothing is stored on or read from the device and individuals cannot be identified
  • Modelled conversions through Google Consent Mode, extrapolated by Google
  • Metrics such as page views, top pages and referrers in anonymised form

Only with consent should you:

  • Load ad pixels such as the Meta Pixel, the Google Ads tag or the TikTok Pixel
  • Send first-party data such as hashed email addresses to ad platforms for matching
  • Send person-level server events through the Conversions API
  • Recognise visitors across sessions

The share of visitors who decline varies a lot by industry, audience and banner design. Many advertisers report rejection rates somewhere between 20 and 50 percent. That makes it all the more important to make full use of the consent you do get.

How to set up GDPR conversion tracking with LeadSignal

LeadSignal is built so that consent and tracking come from one place. You do not need a separate consent tool or Google Tag Manager. For a general introduction to the setup, see our guide to simple conversion tracking.

Step 1: Add the snippet

Paste the LeadSignal snippet into the head of your site. During onboarding, LeadSignal checks the installation live. Then remove any old pixels hardcoded in your theme or plugins, so nothing loads around the consent check.

The built-in cookie banner comes as a bar, box or floating layout, in light, dark or system theme, with your accent colour. It is available in German, English, French and Spanish. Visitors choose separately between the categories Necessary, Preferences, Statistics, Marketing and Unclassified.

Visitors see an overview of the cookies in use. Review the list so it matches the tools you actually run and your privacy policy.

Step 4: Connect your ad platforms

Connect Meta, Google Ads, LinkedIn and TikTok. Their pixels and tags only load once the visitor has consented to the Marketing category. For Meta, LinkedIn and TikTok you can also enable server-side delivery, deduplicated via an event ID. For Google Ads, LeadSignal loads the Google tag and passes the Consent Mode v2 signals ad_storage, ad_user_data and ad_personalization automatically. See the Google Ads integration for details.

Step 5: Minimise data

LeadSignal anonymises IP addresses (last octet for IPv4, last 80 bits for IPv6). Email, phone number and name are only passed to platforms after consent, using hashing with SHA-256, for example for Advanced Matching on Meta or Enhanced Conversions on Google.

Before a visitor consents, LeadSignal counts visits with a daily-rotating salted hash. Nothing is stored on the device and no persistent identity is created. Your dashboard still shows how much traffic you get. If the visitor consents later, their earlier anonymous visits are linked to their identity. Have your data protection officer assess this logic too, and describe it in your privacy policy.

LeadSignal stores every consent decision with a timestamp and consent ID, which serves as your proof for audits. Also sign the data processing agreement, available at /en/avv. The dashboard shows your consent rate, so you can see the effect of banner changes directly.

A higher consent rate means more data, but only if it is earned honestly. These levers are fair and they work:

  • Plain language: explain in one sentence what you use the data for, such as "so we can see which ads actually help". Walls of legal text put people off.
  • The right layout: a subtle, readable banner that does not cover the whole page feels more trustworthy. Test the bar, box and floating variants.
  • On-brand design: a banner in your colours feels like part of your site, not a foreign object.
  • The visitor's language: a banner in someone's own language is more likely to be read and understood.
  • Fewer tools: every extra tool in the banner adds scepticism. Remove tags nobody uses anymore.
  • Measure and compare: watch your consent rate after each change instead of going by gut feeling.

Stay away from hidden reject buttons, misleading colours or pre-selected categories. They may win a few percent in the short term, but they can lead to complaints, fines and lost trust.

GDPR tracking checklist

  • Ad pixels and tags only load after marketing consent
  • Rejecting is as easy as accepting on the first banner layer
  • Categories can be chosen separately, nothing is pre-selected
  • Consent can be withdrawn easily at any time, for example via a footer link
  • Consent decisions are stored with a timestamp as proof
  • Google Consent Mode v2 signals are passed correctly
  • Server events are only sent for visitors who consented
  • IP addresses are truncated
  • Cookie inventory and privacy policy are up to date and consistent
  • Data processing agreements are in place with all providers
  • The setup has been tested in a private browser window

If you can tick off most of these, you are in good shape. If not, take a look at LeadSignal's pricing and plans: the free plan is enough to try the banner and tracking on one project.

Frequently asked questions

Do I need consent for conversion tracking?+

In most cases, yes. Ad pixels such as the Meta Pixel or the Google Ads tag store or read information on the device and serve marketing purposes. Under the GDPR and the ePrivacy rules (in Germany the TDDDG), that generally requires prior, freely given consent. Check your specific setup with your data protection officer or a lawyer.

Does server-side tracking replace consent?+

No. Server-side tracking only changes how the data travels, not the legal basis. If you send personal data to Meta, Google or other ad platforms for advertising purposes, you still need consent, whether the data comes from the browser or from a server.

Is Google Consent Mode v2 mandatory?+

Since March 2024, Google requires Consent Mode v2 signals for users in the European Economic Area if you want to use features such as remarketing, personalised ads and full conversion measurement in Google Ads. It is a Google requirement, not a legal one.

What can I measure without consent?+

Without consent you are mostly limited to aggregated, anonymous counts, for example cookieless visit counting with nothing stored on the device. Google can also model missing conversions through Consent Mode. Sending personal advertising data to ad platforms without consent is generally not permitted.

Is LeadSignal GDPR compliant?+

LeadSignal provides the building blocks for GDPR-compliant tracking: a cookie banner with categories, consent records, Consent Mode v2 signals, pixels that only load after marketing consent, IP anonymisation and a data processing agreement. Whether your overall setup is compliant also depends on your website, your privacy policy and the other tools you use.

Terms in this guide

Privacy & ConsentGDPRGeneral Data Protection RegulationThe GDPR is the EU regulation protecting personal data. It defines when websites may process data such as IP addresses, cookie IDs or click IDs.Privacy & ConsentCookie BannerConsent banner and consent management platformA cookie banner asks visitors which cookies and tracking purposes they accept, then controls which scripts are allowed to load on the website.Privacy & ConsentGoogle Consent Mode v2Google Consent Mode v2 passes your visitors' consent choices to Google tags, so Google Ads and GA4 only use data to the extent visitors allowed.Privacy & ConsentCookieless TrackingCookieless tracking measures visits and conversions without storing cookies or other identifiers on the device, for example through anonymous hashes.TrackingTracking PixelA tracking pixel is a piece of code from an ad platform that records page views and conversions in the browser and reports them back to the platform.Ad PlatformsMeta PixelFormerly the Facebook PixelThe Meta Pixel is a JavaScript snippet from Meta that records actions on your website and sends them to Meta so Facebook and Instagram ads can measure and optimize.TrackingServer-Side TrackingServer-side tracking sends conversion events from a server straight to ad platforms instead of the browser, so ad blockers and cookie limits matter less.Ad PlatformsConversions APIMeta Conversions API (CAPI)The Conversions API (CAPI) is Meta's interface for sending conversion events straight from a server to Meta, independent of the browser, the pixel and ad blockers.

Related articles

More guides