Author –
Date Published –
Consent, cookies and marketing entropy: why good intentions are not enough
Most companies are not deliberately ignoring privacy rules, they’re usually making an effort. The problem is that consent and tracking are typically dealt with late, implemented in a hurry, and then allowed to deteriorate as the marketing stack changes around them.
That is bad for compliance. It is also bad for measurement.
Ahead of our recent webinar on tracking and attribution, we audited 23 UK websites submitted by attendees, most of them in financial services and B2B. Four of them (22%) looked broadly compliant.
That was not a formal legal assessment, and 23 sites is not a representative sample of the UK internet. It is worth being clear about one thing, though: these sites were submitted by people who had signed up to a webinar about consent and tracking. They were, by definition, the ones paying attention. Whatever 22% represents, it is closer to a ceiling than an average.
What was more interesting was why so many of them were getting it wrong.
Almost all of them had a consent banner, and almost all were using a recognised consent management platform. Somebody had thought about privacy and had gone to the trouble of buying software to address it. Yet 78% still failed.
That is the finding worth sitting with. The consent management platform was near-universal, and it was not the thing controlling what happened on the site.
Tracking used to make this easier to ignore. Someone clicked an advert, a cookie was placed, they returned and filled in a form, and the numbers lined up well enough for everyone to nod at the report and move on. It was never as accurate as we liked to pretend, but it was simpler.
Now there are
- Consent requirements
- Browser restrictions
- Multiple devices
- Longer buying journeys
- Platform modelling
- and users who quite reasonably do not want to be followed around the internet because they once looked at a mortgage calculator.
The data has not vanished, but the certainty has. Which means the gap between what a consent banner claims and what a website actually does is no longer a technicality. It is the difference between reporting you can defend and reporting you cannot.
“Have we sorted the cookies?”
Consent and tracking tend to appear rather late in a website project.
The design has been approved. The copy has been through seven rounds of amendments. Senior people have devoted surprising amounts of energy to the choice of hero image. The launch date is fixed.
Then somebody asks the question.
A banner is added, a few categories are selected, and the site goes live. Initially, everything may be reasonably tidy. Then marketing entropy sets in.
A new agency adds a Meta Pixel. Google Ads conversion tracking is introduced. The CRM team installs another script. Somebody experiments with a form platform. A supplier pastes code directly into the website because getting access to Google Tag Manager would apparently require six emails, two meetings, multiple sign-offs and an impact assessment.
Six months later, the consent banner still describes a simple, orderly system. Behind it sits a rather less orderly collection of tags, pixels, scripts and half-abandoned conversion actions.
Nobody has necessarily done anything malicious. The setup has simply drifted.
A consent banner is not a force field. It is only useful if it controls what actually happens on the site.
When the consent banner becomes decorative
A consent management platform should do several things. It should capture the user’s choice, communicate that choice to the rest of the technology stack, and ensure tags behave accordingly. It should also make rejecting non-essential tracking straightforward. “Accept all” in a large friendly button, with “manage your preferences” tucked away near the terms and conditions, is not a real choice, and regulators have been saying so for years.
One site in our sample illustrates the pattern almost perfectly. A wealth manager, well-known consent platform, categories configured sensibly, and a banner that recorded a rejection accurately and stored it correctly. Google Tag Manager then fired the advertising pixel anyway, because it had been given its instructions two years earlier and nobody had revisited them. The consent platform’s own dashboard reported the implementation as complete. Everybody involved had done their part. Nobody owned the join between them.
The common failure modes are mundane:
- Consent categories do not correspond to the tags actually on the site.
- Advertising or analytics storage begins before the visitor has agreed.
- The banner records a rejection and the tag manager proceeds regardless.
- New tags are added without anyone checking the consent configuration.
- Consent Mode is partly configured, which can be worse than not configuring it at all, because it looks finished.
- Nobody retests after the website changes.
There is real nuance here, and it is worth stating plainly, because it is where confident but wrong conclusions get drawn. A tag appearing to fire before consent is not automatically evidence of non-compliance. With an advanced consent setup configured properly, platforms may legitimately send restricted, cookieless signals before the visitor chooses. That is a different thing from setting advertising cookies or transmitting identifiable data regardless of what the visitor selected.
So the useful question is not “did a tag fire?”
It is “what was sent, what was stored, and did the system honour the choice the visitor made?”
That is where a lot of implementations come unstuck. The consent banner works perfectly well in its own admin panel. Google Tag Manager carries on with the programme it was given three years ago. From the visitor’s point of view, they said no. From the website’s point of view, they submitted some non-binding feedback.
Worth noting where the obligations actually sit, since this is commonly muddled: in the UK, the rules on storing and accessing information on someone’s device come from PECR, not UK GDPR, and consent under PECR has to meet the UK GDPR standard. The Data (Use and Access) Act 2025 has introduced a small number of exceptions for genuinely low-risk purposes. It has not changed the position for advertising and marketing tags, which is where almost all of the risk lives anyway.
In financial services, this is about trust
The issue matters in every sector but it matters more in financial services, because financial services companies sell trust before they sell anything else.
Customers are being asked to share information about their income, savings, debts, pensions, businesses and future plans. They may be making decisions that shape the next thirty years of their life. The relationship needs to feel open from the first click, not from the point at which somebody signs something.
Most customers will never know or care about the distinctions between cookies, browser storage, advertising pixels and pseudonymous identifiers. They will care if they make a clear choice and later discover it was ignored.
That produces an odd contradiction. A financial brand can spend a great deal of money presenting itself as prudent, responsible and customer-focused, while its website quietly behaves in a way that is none of those things. The technical problem may be small. The effect on trust is not proportionate to the size of the technical problem.
For a financial services business, consent is not solely a matter for legal, compliance or the web team. It is part of the customer experience, and part of the brand promise.
Compliance and measurement are on the same side
Privacy and marketing measurement are still too often treated as opposing forces. Marketing wants more data. Compliance wants less. Both retreat to their corners and communicate through increasingly cautious emails.
This is a false fight, and it is an expensive one.
Poor consent implementation does not only create legal and reputational risk. It degrades the data. When tags fire inconsistently, when consent categories do not match the technology, and when platforms receive unreliable signals, the reports become genuinely harder to interpret. Google Analytics says one thing. Google Ads says another. Meta has a third view. The CRM contains a fourth, assuming somebody has updated it.
Fixing the consent layer gives you a clean starting point. It establishes what can be collected, when, and how it may be used. It improves the quality of the signals reaching your analytics and advertising platforms. And it makes the differences between reports explicable rather than embarrassing.
The result will not be perfect data. Perfect data is largely something software vendors promise during sales demonstrations. But it can be useful, defensible data – and being able to explain your numbers to a compliance committee is worth more in this sector than a marginally prettier dashboard.
Why the numbers refuse to agree
GA4 does not tell the whole story. Neither does Google Ads, Meta, LinkedIn, the call-tracking platform or the monthly dashboard.
They are all looking at the customer journey from different positions, applying different rules.
Consent is one of those rules, and it is the one most often left out of the explanation. A visitor who declines analytics is largely absent from GA4. The same visitor may still be represented in Google Ads through modelled conversions. Two platforms, two sets of rules, and a divergence that exists by design rather than by fault. If you do not know what your consent rates are and how each platform responds to them, you cannot explain your own reporting – and the gap gets attributed to whichever agency is in the room.
The rest follows from the same principle. Some conversions are directly observed and others are modelled. Platforms use different attribution windows. A prospect may research on one device, return on another, telephone the office, and eventually convert offline through an adviser.
The numbers will not agree. This does not make the systems useless. It means they answer different questions.
Google Ads can help optimise campaigns. GA4 can show broader patterns of website behaviour. Call tracking can distinguish a meaningful conversation from a missed call. The CRM can tell you whether an enquiry became a qualified opportunity, an application or a sale.
The objective is not to force every platform to produce the same total. It is to know what each number means, and whether it is good enough to support the decision in front of you.
The conversion is not always the conversion
One of the easiest ways to waste a paid media budget is to optimise towards the simplest thing to measure.
Someone fills in a form, so the advertising platform records a conversion. Unfortunately, the form contains nonsense. Or the person is outside the target market. Or they wanted customer support. Or the application is declined at the next stage.
The advertising platform celebrates. The sales team remains unmoved.
Good measurement follows the journey towards a genuine business outcome. For a financial services business, that means distinguishing between an initial enquiry, a qualified lead, an appointment, an application, an approval, and a funded account or completed mortgage. The further you can connect marketing activity to those outcomes, the more useful your optimisation becomes.
This is also the point at which the consent foundation stops being an abstract compliance concern and starts costing money. Feeding qualified outcomes back to advertising platforms – offline conversion imports, enhanced conversions, CRM-based audiences – depends on a lawful basis and a consent record you can actually rely on. Get the foundation wrong and the most commercially valuable measurement available to you is the first thing you cannot safely do. Firms in this position tend to discover it late, usually in the same week somebody asks why the cost per funded account cannot be reported.
None of which means sending every field in the CRM to every advertising platform. Consent, lawful use, data minimisation and security still apply. It means deciding which outcomes have real commercial value, and designing the measurement around those. A completed contact form is evidence that somebody completed a contact form. It is not evidence that the campaign worked.
It usually does not take a grand transformation programme
Most businesses do not need to replace every platform, rebuild the website, and establish a cross-functional steering group with its own branded PowerPoint template.
You need an honest audit and a clear order of work.
Look at the consent platform, Google Tag Manager, the analytics properties, the advertising tags, the conversion events, the call tracking and the CRM connections. Then sort what you find into three groups.
- Compliance risks: consent choices being ignored, non-essential storage beginning too early, misleading banner behaviour.
- Measurement faults: duplicate events, broken conversions, missing identifiers, inconsistent tracking.
- Commercial opportunities: lead qualification, offline conversion imports, better call measurement, optimisation towards real outcomes.
Then fix the consent foundation, fix the measurement, and use the improved data to make better decisions. In that order. Improving your measurement on top of a consent layer you do not trust just gets you to the wrong answer faster.
If you want a sense of where you stand before commissioning anything, there are five questions worth putting to whoever looks after your website and your tracking. They are deliberately simple, and the answers are revealing.
- If a visitor rejects everything, which specific tags stop firing? Ask for the list, not the reassurance.
- Do the consent categories in our banner correspond to the tags actually on our site, or to the categories the platform shipped with?
- When advertising or analytics storage is denied, what do the affected tags do – nothing at all, or something restricted? Does everyone involved understand the difference?
- When a new tag is added, at what point does somebody check its consent configuration?
- Who last verified this against the live site, rather than against the consent platform’s dashboard, and when?
The honest answer to several of these is often “we would need to check.” That is a perfectly good answer, provided somebody then checks. The answer to avoid is a confident one that turns out to rest on a screenshot of an admin panel.
And whatever the current state, retest it. A consent implementation is not something to complete once and then admire from a safe distance. It needs checking whenever the site, the tag manager, the analytics setup, the CRM or the advertising stack changes – which, in most organisations, is roughly always. Otherwise marketing entropy simply starts again.
Better data, not more data
The aim is not to recreate the old world of unrestricted tracking, nor to collect every available signal because the technology permits it.
Customers are entitled to understand what is happening and to make a meaningful choice. Financial services businesses in particular should be comfortable explaining what they collect and why. If you would not want to explain a piece of your tracking to a customer, that is useful information about the tracking.
There is a commercial argument too, and it is the stronger one. A well-run, consent-aware measurement setup produces cleaner signals, more credible reporting, and a much better basis for optimisation. Connecting marketing activity to CRM outcomes lets you focus on qualified leads, applications, funded accounts, revenue and retained value, rather than decorative dashboard metrics.
The objective is not perfect attribution. We are unlikely to get that back, assuming we ever really had it.
The objective is a measurement system that is honest about its limitations, respects the customer’s choice, and is useful enough to support a real decision.
That is a less exciting promise. It is also a much more useful one.
We audit consent and measurement implementations for financial services and regulated businesses – testing what actually happens on the live site, not what the dashboard claims, and returning a prioritised list of compliance risks, measurement faults and commercial opportunities. If you would like to know which side of that 22% you are on, get in touch.



