A reference for each technology.

Use a vendor's consent signal where available and block its loader where required. Document and verify the actual installation path.

Google Analytics 4 (direct)

Purpose
Site measurement
Consent category
Analytics
Installation and configuration
Add a GA4 Measurement ID in Managed technologies. Remove direct, theme, plugin and GTM duplicates.
Before consent / initial rejection
Basic mode: the managed gtag script is not loaded before Analytics consent or after initial rejection.
After approval
Loads gtag after Analytics approval; sends updated Google consent when choices change.
Later withdrawal and limits
Updates Google consent and removes the managed loader. Already executed SDK behavior and cookieless signals must be verified with your tag configuration.
How to verify
Check the gtag loader, analytics requests, Google DebugView and duplicate events in each choice state.

Meta Pixel

Purpose
Advertising and attribution
Consent category
Marketing
Installation and configuration
Enter the Pixel ID. Remove existing hardcoded pixels; pixels inside GTM or apps require separate review.
Before consent / initial rejection
The managed pixel is withheld.
After approval
Loads the pixel and supplies vendor consent.
Later withdrawal and limits
Sends the vendor revoke signal. A second pixel installation or server-side Conversion API is not controlled by this loader.
How to verify
Check fbevents.js, pixel requests and Meta test events before/reject/allow/withdraw, including a late-loading script.

TikTok Pixel

Purpose
Advertising and attribution
Consent category
Marketing
Installation and configuration
Enter the Pixel ID; remove copies installed in theme code, plugins, apps or GTM.
Before consent / initial rejection
The managed pixel is withheld.
After approval
Loads the pixel and grants consent.
Later withdrawal and limits
Sends the vendor revoke signal, including when a script finishes loading after withdrawal. Server-side events are separate.
How to verify
Check TikTok script requests and test events in every state; confirm a single installation.

Klaviyo

Purpose
Signup forms and behavioral marketing
Consent category
Marketing tracking; forms remain available
Installation and configuration
Use the public site ID, never a private API key. Remove independently installed Klaviyo scripts and review first-party identification features.
Before consent / initial rejection
Loads Klaviyo onsite forms with the documented __kla_off tracking opt-out set synchronously before the loader.
After approval
Removes the adapter-owned opt-out cookie when Marketing is allowed.
Later withdrawal and limits
Restores tracking opt-out while preserving forms. Other-domain cookies, identity workers and app-side tracking require account-specific validation.
How to verify
Prove forms still open and submit with Marketing off, while behavioral tracking does not fire. Repeat allow/revoke/reload on your actual account.

Google Tag Manager

Purpose
Container for independently controlled tags
Consent category
Per-tag consent, not one blanket tracking category
Installation and configuration
Enter a container ID. Set consent requirements on GA4, Meta, TikTok and every other tag inside the container.
Before consent / initial rejection
Loads the container with denied Google Consent Mode defaults established before tags run.
After approval
Sends consent updates from the selected categories.
Later withdrawal and limits
Sends updated denied states. Tags that ignore consent or advanced-mode cookieless behavior require manual review.
How to verify
Use GTM Preview plus the browser Network panel. Verify every individual tag, duplicates and non-Google consent checks.

Custom scripts and purposes

Purpose
Site-specific optional functionality
Consent category
Any enabled optional category
Installation and configuration
Add a named HTTPS script and purpose in the editor, or use an inert script declaration. Custom categories use stable custom_ keys and independent stored decisions.
Before consent / initial rejection
No loader is created before its own purpose is granted.
After approval
The configured script is created only after evidence is acknowledged.
Later withdrawal and limits
The element is removed and the page reloads for already-running generic code. The adapter cannot erase third-party cookies or stop server-side processes.
How to verify
Prove a custom purpose does not grant Functional, Analytics, Marketing or Media; test blocked grants, withdrawal, reload and expired policy state.

Media, social widgets and tracking pixels

YouTube, Vimeo, Spotify, SoundCloud, Maps and vendor-provided social iframe URLs use the same inert-frame declaration. The runtime shows a placeholder, grants only the relevant category and restores the source after a later regrant. Images/pixels can use the same data attributes; remove src and srcset from their original HTML.

Inert frame

<iframe title="Product video"
  data-strongprivacy-category="media"
  data-strongprivacy-src="https://www.youtube-nocookie.com/embed/VIDEO_ID"
></iframe>

For Instagram, Facebook, TikTok or X widgets that require both markup and a vendor script, wrap the complete trusted vendor snippet in a template. Nothing in the template is loaded until the category is allowed. Script-based widgets reload the page on withdrawal; test the exact vendor embed format on your site.

Script-based widget

<template title="Social post" data-strongprivacy-category="media">
  <!-- Insert your vendor’s complete reviewed embed markup and script here. -->
</template>

Only use reviewed vendor embed URLs and markup

StrongPrivacy is installed directly in the page, not inside an iframe. The iframe examples here are third-party media being controlled. Do not put untrusted visitor HTML into widget templates. Content-provider restrictions, CSP and cross-origin frame policies still apply.

Provider references

These are integration capabilities, not a legal determination or vendor certification. Keep a site-specific acceptance record and review provider changes.