Google Analytics 4 (direct)
- Purpose
- Site measurement
- Consent category
- Analytics
- Installation and configuration
- Add a GA4 Measurement ID in Managed technologies. Remove direct, theme, plugin and GTM duplicates.
- Before consent / initial rejection
- Basic mode: the managed gtag script is not loaded before Analytics consent or after initial rejection.
- After approval
- Loads gtag after Analytics approval; sends updated Google consent when choices change.
- Later withdrawal and limits
- Updates Google consent and removes the managed loader. Already executed SDK behavior and cookieless signals must be verified with your tag configuration.
- How to verify
- Check the gtag loader, analytics requests, Google DebugView and duplicate events in each choice state.
Meta Pixel
- Purpose
- Advertising and attribution
- Consent category
- Marketing
- Installation and configuration
- Enter the Pixel ID. Remove existing hardcoded pixels; pixels inside GTM or apps require separate review.
- Before consent / initial rejection
- The managed pixel is withheld.
- After approval
- Loads the pixel and supplies vendor consent.
- Later withdrawal and limits
- Sends the vendor revoke signal. A second pixel installation or server-side Conversion API is not controlled by this loader.
- How to verify
- Check fbevents.js, pixel requests and Meta test events before/reject/allow/withdraw, including a late-loading script.
TikTok Pixel
- Purpose
- Advertising and attribution
- Consent category
- Marketing
- Installation and configuration
- Enter the Pixel ID; remove copies installed in theme code, plugins, apps or GTM.
- Before consent / initial rejection
- The managed pixel is withheld.
- After approval
- Loads the pixel and grants consent.
- Later withdrawal and limits
- Sends the vendor revoke signal, including when a script finishes loading after withdrawal. Server-side events are separate.
- How to verify
- Check TikTok script requests and test events in every state; confirm a single installation.
Klaviyo
- Purpose
- Signup forms and behavioral marketing
- Consent category
- Marketing tracking; forms remain available
- Installation and configuration
- Use the public site ID, never a private API key. Remove independently installed Klaviyo scripts and review first-party identification features.
- Before consent / initial rejection
- Loads Klaviyo onsite forms with the documented __kla_off tracking opt-out set synchronously before the loader.
- After approval
- Removes the adapter-owned opt-out cookie when Marketing is allowed.
- Later withdrawal and limits
- Restores tracking opt-out while preserving forms. Other-domain cookies, identity workers and app-side tracking require account-specific validation.
- How to verify
- Prove forms still open and submit with Marketing off, while behavioral tracking does not fire. Repeat allow/revoke/reload on your actual account.
Google Tag Manager
- Purpose
- Container for independently controlled tags
- Consent category
- Per-tag consent, not one blanket tracking category
- Installation and configuration
- Enter a container ID. Set consent requirements on GA4, Meta, TikTok and every other tag inside the container.
- Before consent / initial rejection
- Loads the container with denied Google Consent Mode defaults established before tags run.
- After approval
- Sends consent updates from the selected categories.
- Later withdrawal and limits
- Sends updated denied states. Tags that ignore consent or advanced-mode cookieless behavior require manual review.
- How to verify
- Use GTM Preview plus the browser Network panel. Verify every individual tag, duplicates and non-Google consent checks.
Custom scripts and purposes
- Purpose
- Site-specific optional functionality
- Consent category
- Any enabled optional category
- Installation and configuration
- Add a named HTTPS script and purpose in the editor, or use an inert script declaration. Custom categories use stable custom_ keys and independent stored decisions.
- Before consent / initial rejection
- No loader is created before its own purpose is granted.
- After approval
- The configured script is created only after evidence is acknowledged.
- Later withdrawal and limits
- The element is removed and the page reloads for already-running generic code. The adapter cannot erase third-party cookies or stop server-side processes.
- How to verify
- Prove a custom purpose does not grant Functional, Analytics, Marketing or Media; test blocked grants, withdrawal, reload and expired policy state.
Media, social widgets and tracking pixels
YouTube, Vimeo, Spotify, SoundCloud, Maps and vendor-provided social iframe URLs use the same inert-frame declaration. The runtime shows a placeholder, grants only the relevant category and restores the source after a later regrant. Images/pixels can use the same data attributes; remove src and srcset from their original HTML.
Inert frame
<iframe title="Product video"
data-strongprivacy-category="media"
data-strongprivacy-src="https://www.youtube-nocookie.com/embed/VIDEO_ID"
></iframe>For Instagram, Facebook, TikTok or X widgets that require both markup and a vendor script, wrap the complete trusted vendor snippet in a template. Nothing in the template is loaded until the category is allowed. Script-based widgets reload the page on withdrawal; test the exact vendor embed format on your site.
Script-based widget
<template title="Social post" data-strongprivacy-category="media">
<!-- Insert your vendor’s complete reviewed embed markup and script here. -->
</template>Only use reviewed vendor embed URLs and markup
Provider references
These are integration capabilities, not a legal determination or vendor certification. Keep a site-specific acceptance record and review provider changes.