Privacy and Compliance for Your Analytics and Marketing Tags
The guides below are written for the people responsible for getting this right, marketers, analysts, and privacy and legal teams, not for specialists in privacy law. Each one answers a real question in plain language and points to the next step.
The hub starts with the question most teams bring, whether their tracking is legal, and moves on to verifying your consent setup. After that come the laws themselves, compliance by region, platform-specific questions, and the mechanisms and signals behind consent.

Summary
Every analytics and marketing tag on your site collects data and sends it somewhere. Privacy law governs what those tags may collect, when they may fire, and where the data may go. This hub answers the questions that follow: whether your tracking is legal, which laws apply, whether a platform is compliant, and how to verify your own site.
Start here: is your tracking legal?
If you are not sure where to begin, start with the overview. It frames the whole space and links to everything else.
Verify your consent setup
The practical core of the cluster. Confirming that your tags actually honor the consent your banner records.
Consent verification
How to prove your tags respect consent, and how DataTrue tests it.
How-toDo your tags fire before consent?
The first failure to rule out.
How-toHow to verify your tags respect consent
Confirming each tag follows the exact choice a visitor made.
How-toHow to prove your cookie banner blocks tags
Testing that a banner enforces what it displays.
Understand the laws
Evergreen explainers, written for marketers and privacy leads, one per law.
California Invasion of Privacy Act (CIPA) and website tracking
Law guideVideo Privacy Protection Act (VPPA) and pixels
Law guideCCPA and CPRA for analytics and tags
Law guideGDPR for analytics and marketing tags
Law guideUS state privacy laws for marketers
(Colorado, Virginia, and the growing list)
Law guideFERPA and COPPA for website tracking
(student and children’s data)
Law guideGLBA and financial-site tracking
(banks, lenders, fintechs)
Law guideHIPAA and tracking pixels
(healthcare)
For the EU, UK, Canada, and Australia, see Compliance by region below.
Compliance by region
Which laws apply depends on where your visitors are. Each regional hub covers that market’s rules and links to its enforcement cases.
Is a specific platform compliant?
Direct answers to the pairings we get asked about most.
Mechanisms and consent signals
How specific tracking methods and signals work, and where each creates compliance risk.
Server-side tracking and compliance
What moving tags server-side (Meta CAPI and similar) does, and does not, change for compliance.
ExplainerSession replay and privacy
When session-recording tools cross into wiretap and consent exposure.
ExplainerGlobal Privacy Control (GPC): what it is and how to honor it
ExplainerGoogle Consent Mode v2 explained
ExplainerConsent dark patterns
How a rigged consent choice becomes a compliance problem, and how to test yours.
Cookies and PII
The existing guides, reworked into the cluster.
Looking for a specific enforcement case?
Fines, settlements, and company-specific actions live in our Enforcement Watch tracker. This hub is the prevention side: what the rules require and how to check your own site. Enforcement Watch is the proof of what happens when tracking is not checked.
Questions
What does “compliant tracking” actually mean?
Compliant tracking means your tags collect and share data in line with the law and with the choices your visitors make. In practice that comes down to three things: tags wait for consent, tags stop when a visitor opts out, and tags do not send personal or health data they should not.
Where should I start if I only have time for one thing?
Verify what your tags do in each consent state on your most sensitive pages, such as checkout, registration, or anything involving health. Two common failures are tags firing before consent and tags ignoring an opt-out, and verification catches both.
Do these guides cover EU rules or just US ones?
Both. The US laws (CIPA, VPPA, CCPA/CPRA, HIPAA) and GDPR each have their own explainer, because the GDPR reaches companies outside the EU when they offer goods or services to people in the EU or monitor their behavior there, and tracking people online counts as monitoring.
See what your tags do in every consent state
DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
