Tracking and privacy often feel like opponents: marketing wants to see every conversion, privacy wants as little data as possible. The good news is that you can have both. GDPR-compliant tracking does not mean giving up on measurement. It means asking properly, loading only what you have permission for, and being able to prove it.
This guide covers the legal basics in plain language, the mistakes we see most often, how Google Consent Mode v2 works, and a step-by-step walkthrough for building a clean setup with LeadSignal.
This guide is not legal advice. It summarises the common interpretation of the GDPR and the ePrivacy rules as of October 2026, with a focus on the EU and Germany. Case law and regulator guidance keep evolving, and rules differ between countries. If in doubt, have your setup reviewed by your data protection officer or a specialised lawyer.
The legal basics in plain language
Two sets of rules matter for website tracking in the EU. They work together but cover different things.
GDPR: when can you process personal data?
The General Data Protection Regulation defines when you may process personal data. That includes not only names and email addresses but also IP addresses, cookie IDs and click IDs once they can be linked to a person. For advertising purposes, the legal basis is almost always consent under Art. 6(1)(a) GDPR.
ePrivacy and the TDDDG: when can you access the device?
The ePrivacy Directive covers access to the user's device. Each EU country implements it in national law. In Germany that is § 25 of the TDDDG, which was called the TTDSG until May 2024. The rule: you need consent before storing or reading information on a device, such as cookies, local storage or fingerprinting. The only exception is what is strictly necessary for the service the user asked for, like a shopping cart cookie or storing the consent choice itself.
This applies whether or not the data is personal. Even setting a marketing cookie needs consent, regardless of whether it is a first-party cookie or third-party cookies.
What makes consent valid
Consent only counts if it meets a few conditions:
- Informed: visitors need to understand which tools process which data and for what purpose.
- Freely given and active: no opt-out, no pre-ticked boxes. The CJEU made this clear in its 2019 Planet49 ruling.
- Granular: statistics and marketing should be separate choices, not all or nothing.
- Revocable: withdrawing consent must be as easy as giving it (Art. 7(3) GDPR).
- Documented: you must be able to demonstrate that consent was given (Art. 7(1) GDPR).
The most common tracking mistakes
Most problems are not bad intent. They come from setups that grew over the years. These are the ones we see most.
Pixels firing before consent
The classic: a tracking pixel such as the Meta Pixel or the Google Ads tag is hardcoded into the theme and loads immediately, while the cookie banner is still on screen. At that point the banner is decoration. Test it yourself: open your site in a private window, do not click anything in the banner, and check the network tab in your developer tools for requests to ad platforms.
Dark patterns in the banner
A big, colourful "Accept all" button next to a tiny grey "Settings" link that leads to a second layer: many regulators and courts take a critical view of designs like this. The widespread expectation is that rejecting should be as easy as accepting, on the first layer.
No proof of consent
If a regulator asks, you need to show when and for what consent was given. A banner that only stores the choice in the browser gives you no evidence.
Processing full IP addresses
IP addresses are personal data. Storing them in full when you do not need them goes against the principle of data minimisation. Truncating the IP address is a simple, sensible step.
Using server-side tracking to bypass consent
This misconception is surprisingly common. Server-side tracking via the Conversions API makes your tracking more robust against ad blockers and browser restrictions. It does not change the legal situation. If you send data to Meta, Google, LinkedIn or TikTok for advertising, you need consent, no matter which route the data takes. Our article on why server-side tracking matters covers the technical benefits.
Server-side tracking is a tool for better data quality, not a loophole. Used properly, it sends events only for visitors who consented, and does so more reliably than a browser pixel alone.
Google Consent Mode v2 explained
Google Consent Mode v2 is how your website tells Google tags which permissions a visitor has granted. The tags then adjust their behaviour. Consent Mode is not a cookie banner. It is the interface between your banner and Google's services.
The four consent signals
| Signal | What it controls |
|---|---|
ad_storage | Can data be stored on the device for advertising (e.g. ad cookies)? |
analytics_storage | Can data be stored for analytics (e.g. Google Analytics cookies)? |
ad_user_data | Can user data be sent to Google for advertising? |
ad_personalization | Can the data be used for personalised ads and remarketing? |
ad_user_data and ad_personalization were added in version 2. Since March 2024, Google requires them for users in the European Economic Area. Without them, features like remarketing audiences and parts of conversion measurement in Google Ads are unavailable or limited. That is a Google policy rather than a law, but if you run Google Ads it is effectively just as binding.
Basic vs. advanced mode
- Basic mode: Google tags only load after consent. Without consent, nothing is sent to Google. Google models missing conversions from general data.
- Advanced mode: Google tags load right away but, without consent, only send cookieless pings with no identifiers. Google uses those to build more precise models.
Advanced mode tends to give better modelling but is more contested from a privacy point of view, since requests reach Google before consent. Many German data protection officers therefore recommend basic mode. Discuss the choice with yours.
What you can measure with and without consent
A realistic picture helps set expectations.
Without consent, you can typically use:
- Aggregated, anonymous visit counts via cookieless tracking, as long as nothing is stored on or read from the device and individuals cannot be identified
- Modelled conversions through Google Consent Mode, extrapolated by Google
- Metrics such as page views, top pages and referrers in anonymised form
Only with consent should you:
- Load ad pixels such as the Meta Pixel, the Google Ads tag or the TikTok Pixel
- Send first-party data such as hashed email addresses to ad platforms for matching
- Send person-level server events through the Conversions API
- Recognise visitors across sessions
The share of visitors who decline varies a lot by industry, audience and banner design. Many advertisers report rejection rates somewhere between 20 and 50 percent. That makes it all the more important to make full use of the consent you do get.
How to set up GDPR conversion tracking with LeadSignal
LeadSignal is built so that consent and tracking come from one place. You do not need a separate consent tool or Google Tag Manager. For a general introduction to the setup, see our guide to simple conversion tracking.
Step 1: Add the snippet
Paste the LeadSignal snippet into the head of your site. During onboarding, LeadSignal checks the installation live. Then remove any old pixels hardcoded in your theme or plugins, so nothing loads around the consent check.
Step 2: Configure the cookie banner
The built-in cookie banner comes as a bar, box or floating layout, in light, dark or system theme, with your accent colour. It is available in German, English, French and Spanish. Visitors choose separately between the categories Necessary, Preferences, Statistics, Marketing and Unclassified.
Step 3: Review the cookie inventory
Visitors see an overview of the cookies in use. Review the list so it matches the tools you actually run and your privacy policy.
Step 4: Connect your ad platforms
Connect Meta, Google Ads, LinkedIn and TikTok. Their pixels and tags only load once the visitor has consented to the Marketing category. For Meta, LinkedIn and TikTok you can also enable server-side delivery, deduplicated via an event ID. For Google Ads, LeadSignal loads the Google tag and passes the Consent Mode v2 signals ad_storage, ad_user_data and ad_personalization automatically. See the Google Ads integration for details.
Step 5: Minimise data
LeadSignal anonymises IP addresses (last octet for IPv4, last 80 bits for IPv6). Email, phone number and name are only passed to platforms after consent, using hashing with SHA-256, for example for Advanced Matching on Meta or Enhanced Conversions on Google.
Step 6: Understand pre-consent counting
Before a visitor consents, LeadSignal counts visits with a daily-rotating salted hash. Nothing is stored on the device and no persistent identity is created. Your dashboard still shows how much traffic you get. If the visitor consents later, their earlier anonymous visits are linked to their identity. Have your data protection officer assess this logic too, and describe it in your privacy policy.
Step 7: Consent records and DPA
LeadSignal stores every consent decision with a timestamp and consent ID, which serves as your proof for audits. Also sign the data processing agreement, available at /en/avv. The dashboard shows your consent rate, so you can see the effect of banner changes directly.
Improving your consent rate without tricks
A higher consent rate means more data, but only if it is earned honestly. These levers are fair and they work:
- Plain language: explain in one sentence what you use the data for, such as "so we can see which ads actually help". Walls of legal text put people off.
- The right layout: a subtle, readable banner that does not cover the whole page feels more trustworthy. Test the bar, box and floating variants.
- On-brand design: a banner in your colours feels like part of your site, not a foreign object.
- The visitor's language: a banner in someone's own language is more likely to be read and understood.
- Fewer tools: every extra tool in the banner adds scepticism. Remove tags nobody uses anymore.
- Measure and compare: watch your consent rate after each change instead of going by gut feeling.
Stay away from hidden reject buttons, misleading colours or pre-selected categories. They may win a few percent in the short term, but they can lead to complaints, fines and lost trust.
GDPR tracking checklist
- Ad pixels and tags only load after marketing consent
- Rejecting is as easy as accepting on the first banner layer
- Categories can be chosen separately, nothing is pre-selected
- Consent can be withdrawn easily at any time, for example via a footer link
- Consent decisions are stored with a timestamp as proof
- Google Consent Mode v2 signals are passed correctly
- Server events are only sent for visitors who consented
- IP addresses are truncated
- Cookie inventory and privacy policy are up to date and consistent
- Data processing agreements are in place with all providers
- The setup has been tested in a private browser window
If you can tick off most of these, you are in good shape. If not, take a look at LeadSignal's pricing and plans: the free plan is enough to try the banner and tracking on one project.
