Skip to content

Tracking & attribution engineeringClient work

Pixels Firing Before Consent? Consent Mode v2 and US Opt-Out Audit, Then the Fix

A read-only consent audit — Consent Mode v2 defaults, competing CMPs, US opt-out and GPC — followed by the fix, with a verdict in both reject and accept states.

For
EU, UK and US stores
Checked

Sounds familiar?

Tick what applies to you

The situation Tracking & attribution engineering
Are my pixels firing before consent? Consent Mode v2 and US opt-out audit

Tick the lines that describe your case.

Describe my task

How I solve it

What I build

I build a read-only consent audit first, then the fix. The audit captures runtime in both the reject and the accept state, on the public container and the consent tool’s config, and reports what fires, under which default, and whether anything fires before a choice — no logins needed. The fix sets Consent Mode v2 defaults per region, wires US opt-out, removes competing consent tools and hard-coded granted states, and re-verifies in both states. This is technical implementation, not legal advice.

The process

How it works

6 steps. Scope and a fixed price are agreed before the first one.

  1. Capture runtime in both states

    Reject and accept, on the public GTM container and the consent configs, without touching your accounts.

  2. Read every default

    Consent Mode defaults and each consent tool on the page.

  3. Flag the failures

    Pre-ticked consent, granted hard-coded, duplicate defaults, cookies set before consent, and pixels that fire with no choice made.

  4. Write the verdict

    What fires before consent, what it costs you, and what stays unknown and why.

  5. Fix it

    Consent Mode v2 defaults per region, US opt-out with GPC honoured before any tag loads, competing tools removed.

  6. Verify again

    Re-check both states on the live site and hand over a change record.

Handover

What you get

  • A written, read-only verdict: what fires before consent, in plain language.
  • Consent Mode v2 defaults per region, not one hard-coded value for the whole world.
  • US opt-out: Global Privacy Control honoured, a reachable opt-out link, no cookie wall.
  • Competing consent tools and granted-hard-coded states removed where they cause the leak.
  • A change record and a re-verification in both the reject and the accept state.

Built with

  • Consent Mode v2
  • consent tools (Klaro, CookieYes, Borlabs, Usercentrics)
  • GTM
  • GA4
  • Google Ads
  • Meta Pixel
  • server-side GTM
  • Shopify Customer Privacy

Proof

Done before, with dates and numbers

Client work Done for real clients. Client details are anonymised.

Before → after

A consent app switched on an opt-in requirement for about 20 US states, and the requirement survived the app’s uninstall. Proving the cause against a control group: the affected state lost 6 of 11 web orders in the window versus 0 of 25 outside it, and the non-consent states lost 0 of 10 — Fisher p = 0.0002, re-checked on 2026-09-02.

Rated 5 out of 5 on Upwork.

He provided a fantastic audit with real insights and easy to understand terms for those of us who aren't as technical.

Soojee F. Upwork · 2018

What you can look at

A redrawn consent-state matrix (each tag × reject × accept) on synthetic data, plus a redacted pre-consent network capture showing a tag firing before a choice.

Client details anonymised. Figures read from live reads in August–September 2026. This covers technical implementation, not legal advice.

Price and timeline

What it costs and how it runs

The audit is a Tracking Health Check: USD 395, read-only, one site, one agreed problem, up to three agreed systems, with a written verdict two working days after the kickoff and confirmed access. The fix is a separate, bounded Focused Fix from USD 450. If you have a single question, a Working Session is USD 195. This is technical implementation, not legal advice.

QuoteFixed before work starts

Price
Read-only Tracking Health Check USD 395, then the fix as a Focused Fix from USD 450. One pre-chosen question is a Working Session USD 195.
Timeline
Health Check verdict two working days after the kickoff and confirmed read-only access, Europe/Madrid, weekends excluded. The fix is a bounded Focused Fix with a fixed quote before start.
First step
Describe the task. I reply within one working day, free, and tell you which option fits — or that you can fix it yourself.
Describe a task like this

A note from Daniilbefore you decide

When you don’t need this

If your Consent Mode defaults are correct, one consent tool owns the site, and nothing fires before a choice, you don’t need this — I’ll say so. This covers technical implementation, not legal advice; if you are a health provider or another regulated business, have your counsel review what data may be sent before I build anything.

— Daniil

Questions

What people ask about this

Do you need logins to audit consent?

No. The audit reads the public container and the consent configs and captures runtime in both states. Read-only access only becomes useful for the fix.

Is this legal advice?

No. It is technical implementation: what fires, when, and under which default. What you are permitted to collect is your counsel's decision.

What is the difference for EEA/UK/CH versus the US?

Regions get defaults set per area, and the US gets opt-out — GPC and an opt-out link rather than a cookie wall.

What if a consent app is the cause of the drop?

Then we prove it. In the dated case a control-group comparison (p = 0.0002) showed the opt-in change caused it, and that the setting survived the app's removal.

How fast is the verdict?

Two working days after the kickoff and confirmed access for the Health Check; the fix is a separate bounded job.

Daniil Maximkin

Hi, I’m Daniil.

I work with you from defining the problem to implementation and handover. You talk to the person who does the work. I work in English and Russian.

Have a task like this?

Describe your task

The first answer is free, within one working day. Or write directly: next@taskfordaniel.com