Privacy & Compliance

Privacy & Compliance / Start here

Privacy and Compliance for Your Analytics and Marketing Tags

The guides below are written for the people responsible for getting this right, marketers, analysts, and privacy and legal teams, not for specialists in privacy law. Each one answers a real question in plain language and points to the next step.

The hub starts with the question most teams bring, whether their tracking is legal, and moves on to verifying your consent setup. After that come the laws themselves, compliance by region, platform-specific questions, and the mechanisms and signals behind consent.

Summary

Every analytics and marketing tag on your site collects data and sends it somewhere. Privacy law governs what those tags may collect, when they may fire, and where the data may go. This hub answers the questions that follow: whether your tracking is legal, which laws apply, whether a platform is compliant, and how to verify your own site.

Section 04

Compliance by region

Which laws apply depends on where your visitors are. Each regional hub covers that market’s rules and links to its enforcement cases.

Looking for a specific enforcement case?

Fines, settlements, and company-specific actions live in our Enforcement Watch tracker. This hub is the prevention side: what the rules require and how to check your own site. Enforcement Watch is the proof of what happens when tracking is not checked.

Questions

What does “compliant tracking” actually mean?

Compliant tracking means your tags collect and share data in line with the law and with the choices your visitors make. In practice that comes down to three things: tags wait for consent, tags stop when a visitor opts out, and tags do not send personal or health data they should not.

Where should I start if I only have time for one thing?

Verify what your tags do in each consent state on your most sensitive pages, such as checkout, registration, or anything involving health. Two common failures are tags firing before consent and tags ignoring an opt-out, and verification catches both.

Do these guides cover EU rules or just US ones?

Both. The US laws (CIPA, VPPA, CCPA/CPRA, HIPAA) and GDPR each have their own explainer, because the GDPR reaches companies outside the EU when they offer goods or services to people in the EU or monitor their behavior there, and tracking people online counts as monitoring.

30-day free trial

See what your tags do in every consent state

DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

A DataTrue opt-out consent test listing the tags that should be blocked, with pass or fail for each
A consent-state test in DataTrue