Consent changed what arrives in your reports. Most teams have not changed how they read them, so they are making budget decisions on a partial dataset presented as a complete one. We fix the measurement, the governance and the reporting, in that order.
Ethical analytics is measurement you could explain to a regulator and still act on commercially. Green Arrow Consultancy designs consent-aware measurement: Google Analytics 4 and privacy-focused alternatives, server-side tagging, tag manager governance, first-party data and event schemas tied to business decisions. We separate what was observed from what was estimated, then report it so a marketing team can use it.
Take a scenario, purely as an illustration, with numbers chosen for arithmetic rather than drawn from any study. Suppose four in ten of your visitors decline analytics cookies. The instinctive reading is that your traffic report is now a smaller version of the same picture, and you can mentally add a bit back. That reading is wrong in a way that matters.
Consent refusal is not distributed randomly. It correlates with browser, with device, with country, with age and with how technical the audience is. In our illustrative scenario, the visitors who declined might be disproportionately on Safari and iOS, disproportionately German rather than American, disproportionately the privacy-aware professional segment you sell most profitably to. So the missing 40 percent is not a haircut applied evenly. It is a hole with a shape, and the shape happens to sit over one of your best segments.
Everything downstream inherits that shape. Channel performance shifts towards whichever sources bring consenting users. Device reports quietly overstate Android. Landing page conversion rates rise on pages visited by people who click through banners quickly. A last-click attribution model built on this subset will confidently recommend moving budget, and the recommendation will be structurally biased rather than merely noisy.
They stop reporting an absolute number as truth and start reporting three things separately: what was observed, what was estimated, and what was tested. Observed data is the consented subset, and it is excellent for behaviour analysis, funnel diagnosis and user experience decisions, because the internal logic of a journey holds even on a sample. Estimated data is modelling, useful for trend and for comparing like with like over time. Tested data comes from holdouts, geo splits and incrementality experiments, and it is the only category that answers the question of what your spending actually caused.
None of this requires abandoning measurement or hiring a data science team. It requires being honest in the report about which of the three you are looking at, which is mostly a formatting decision and a discipline problem rather than a technical one.
Half of the arguments we walk into are vocabulary problems. These six terms get used loosely in vendor material and the imprecision ends up in decisions.
Most organisations end up running two of these deliberately rather than one perfectly: a consented product analytics layer for behaviour, and an aggregate layer that is always complete.
| Approach | Privacy exposure | Data completeness | Implementation cost | Defensibility |
|---|---|---|---|---|
| GA4, client-side, no consent integration | High. Tags fire before a choice is made. | Looks complete. It is not, and the gaps are invisible. | Low. It is usually what is already installed. | Poor. This is the configuration regulators have taken issue with. |
| GA4 with consent mode and modelling | Moderate. No identifiers for users who declined. | Observed subset plus modelled estimates for the rest. | Moderate. Consent platform integration and testing. | Reasonable, if the reporting distinguishes modelled from observed. |
| GA4 with server-side tagging | Moderate. You control what leaves your container. | Better than client-side: less ad-blocker and browser loss. | Higher. Infrastructure, ongoing cost and real engineering. | Good on data control. Neutral on lawful basis, which still has to exist. |
| Privacy-focused analytics, EU or self-hosted | Low. Often no cookies and no cross-site identifiers. | Aggregate and near-complete, but no user-level journeys. | Low to moderate. Migration effort plus a licence. | Strong. Short data flow, simple story, easy assessment. |
| Warehouse-first: server-side events into your own store | Low to moderate. Depends entirely on what you retain. | Highest, and you own the raw record. | Highest. Pipeline, modelling and people to run it. | Strong, provided retention and access controls are real. |
| Server logs and aggregate counters only | Lowest. No client-side identifier at all. | Traffic shape only. No funnels, no campaign detail. | Very low. | Very strong, and very limited. A floor, not a strategy. |
Assessment reflects typical implementations we audit and deploy. Your data protection position depends on your own configuration, contracts and advice, and nothing here is legal advice.
A measurement plan is a short document listing the decisions somebody makes with money, and the smallest set of events that informs each one. If an event does not appear in that mapping, we do not implement it.
Not just purchase. Purchase with margin band, new versus returning, discount applied and fulfilment method, because those are the dimensions a commercial decision is actually made on.
A form submission counts a keystroke. A qualified enquiry is one your sales team accepted, which means the definition has to come back from the CRM rather than being decided in the tag manager.
The highest-signal, least-read report in most analytics accounts. It is a list, in your customers' own words, of things they expected you to sell or explain and could not find.
For long sales cycles, the useful event is a step completed: specification chosen, quote configured, document downloaded. Time on page measures neither interest nor confusion, and cannot tell them apart.
Closed-won, churned, refunded. Without a return path from the CRM or billing, marketing optimises towards leads it will never learn were worthless.
Every report should be able to say what share of its underlying traffic consented. This one change converts arguments about whether the numbers are wrong into a factual conversation about coverage.
Every ungoverned container we inherit got that way honestly. An agency needed access, a contractor added a pixel, a developer built a temporary trigger for a launch, and nothing was ever removed. This is the cheapest work in analytics and it is almost never anybody's job.
There is no correct analytics platform, only a correct answer for your situation, and the situation has three inputs: what decisions the business makes with the data, what your data protection position tolerates, and who is going to operate it on a Tuesday afternoon when something breaks.
GA4 earns its place when you spend meaningfully on Google advertising, when you want the raw event export into a warehouse without paying for a pipeline, or when the people who will use it already know it. The export in particular is undersold: it turns GA4 from a reporting tool into a source of records you can join to your own data. Where it needs care is the data protection story. Several European supervisory authorities issued decisions against implementations of the previous generation of Google Analytics on international transfer grounds, which pushed a lot of organisations towards server-side configurations and regional controls. If that history is going to appear in your own assessment, we would rather you had the configuration and the documentation ready before it does.
If your team looks at traffic, sources, top pages and conversions, and nothing more, then Matomo, Plausible, Fathom or Piwik PRO will give you those numbers with a far shorter data flow, frequently without cookies, sometimes without a consent prompt for analytics at all depending on the configuration and your regulator's position. The reporting is aggregate and you lose user-level journey analysis. For a large share of organisations that is a trade worth making, and it makes the data protection assessment considerably shorter.
First-party identity is where measurement meets privacy engineering properly. Logged-in identifiers, hashed email matching, server-side conversion forwarding and CRM audience building are all technically straightforward and all legally consequential. The rules we work to are simple. Identity is only resolved where there is a lawful basis and a notice a reasonable person would recognise. Hashing is not anonymisation, and anyone who tells you otherwise is selling something. Marketing identifiers stay out of the analytics dataset unless there is a documented reason for them to be there. And every downstream destination is listed in the record of processing before the first event is forwarded, not after a data subject access request arrives.
When we move a client between platforms we run both in parallel for a full reporting cycle, reconcile the differences, and write down why they differ, because they always do. Then we archive the old data in a form somebody can still query in three years. Analytics migrations fail on the history, not on the tags.
Darren consistently demonstrated exceptional technical skill and a strong understanding of various jurisdictions' legal requirements.
A monthly analytics report that runs to forty pages of screenshots is not a report, it is an alibi. The test of a good one is whether a marketing manager can read it in five minutes and come away knowing what changed, why, and what they should do differently. That structure is short: the three numbers the business steers on, what moved and the most likely cause, what was tested and what it showed, and one recommendation with an owner.
It also has to be honest about coverage. Every figure in our reports carries its consent context, so a conversation about a dip in organic conversions starts with whether consent rates moved rather than ending there three weeks later. The single most useful line in a monthly report is often the one that says the underlying sample changed.
We also build the commentary layer with AI. Green Arrow Consultancy runs an analytics reporting assistant in production: it takes dashboard exports and turns them into written commentary for clients, drafting the narrative around what moved and what is worth attention, with a human reviewing before anything is sent. A generalised version of it is one of the live demonstrations on this site, at Neuro Insight, and the approach behind it is described under AI consulting. It does not decide anything. It removes the four hours a month an analyst spends retyping what the chart already shows, which is time better spent on the experiment that produces the next month's chart.
The last piece is cadence. Weekly numbers for the things that can be acted on weekly, monthly narrative for the things that move slowly, and a quarterly session where somebody is allowed to say a channel is not working. Reports that arrive on a schedule nobody chose get filed unread, and an unread report is an expensive way to comply with a habit.
Consent, lawful basis and cookie categorisation are covered in more depth under consent management and in the full FAQ.
Ethical analytics is measurement designed so that the data you hold, the way you collected it and the purposes you use it for would all survive being read out loud to the person it came from, or to a regulator. In practice that means collecting the minimum that answers a real business question, honouring the consent signal everywhere rather than only in the banner, keeping identifiers out of analytics unless you have a lawful basis and a notice that says so, and being straight in your reporting about what is observed and what is estimated.
You get less raw event volume and better decisions. Most reporting stacks collect far more than anyone uses: dozens of automatically captured events nobody has ever queried, sitting alongside three or four numbers that actually drive spending decisions. The loss that matters is coverage of visitors who declined, and that is handled with modelling, server-side aggregation and a reporting frame that stops pretending partial data is complete data. Teams usually find they lose detail they were not using and gain confidence in the numbers they were.
Consent mode is Google's mechanism for keeping tags on the page while changing their behaviour according to the consent signal: with the advanced implementation, cookieless pings are sent for users who declined, carrying no identifiers. Modelling then estimates the behaviour of that unconsented traffic from patterns observed among consented users. It is an estimate. It is useful for trend and for comparing campaigns, it is not a record of what an individual did, it requires enough observed traffic to run at all, and it should never be presented in a board pack as if it were counted.
No, and this is the most expensive misunderstanding in the field. Server-side tagging moves where tags execute, from the visitor's browser into a container you run. That gives you control over what is forwarded to which vendor, better data quality, less client-side script and longer-lived first-party cookies. It does not create a lawful basis. If you forward personal data to an advertising platform without consent, doing it from a server rather than a browser changes nothing about the legal analysis, and the fact that it is harder for a visitor to observe is not a defence.
Sometimes. The honest test is whether you need what GA4 gives you: the free tier, the BigQuery export, the advertising integrations and an enormous pool of people who already know it. If you do not run paid media through Google properties, if your data protection position on international transfers is strained, or if your team never opens anything beyond sessions and conversions, a privacy-focused alternative such as Matomo, Plausible, Fathom or Piwik PRO is usually simpler, quieter and easier to explain in a data protection impact assessment. We have deployed both. We will tell you which one your situation actually calls for.
Stop treating attribution as accounting and start treating it as evidence. Last-click reports built on a consented subset will systematically flatter whichever channels correlate with consenting users. The workable approach is a layered one: platform reporting for in-channel optimisation, consented analytics for journey and behaviour analysis, and a periodic holdout test or media mix analysis for the question of what the spend is genuinely producing. Where the numbers disagree, the experiment wins.
One named person, with everybody else in a workspace that cannot publish. Almost every ungoverned container we inherit got that way honestly: an agency needed access for a campaign, a contractor added a pixel, a developer built a temporary trigger, and nobody ever removed any of it. We install a tag inventory with an owner and a consent category per tag, a publish approval, a naming convention and a quarterly review. It is unglamorous and it is the single highest-return piece of analytics work we do.
Yes, for the visitors who agreed to it, and that is a smaller and more valuable audience than the one you were addressing before. What has to change is the plumbing: advertising tags fire on a consent signal rather than on page load, conversion values are forwarded from a container you control, and audience lists are built from first-party data you can account for. We build this alongside the consent platform rather than as a workaround for it.
An implementation audit is fixed price and takes two to three weeks: container review, tag inventory, consent behaviour testing, event schema and a prioritised findings list. Build work is quoted per workstream, and server-side tagging carries an ongoing infrastructure cost you should budget separately. Reporting and monthly commentary run as a retainer. If your problem is that nobody trusts the numbers, the audit alone usually resolves it.
We will tell you what your container is really firing, where the consent signal is being ignored, and which of your reported numbers you should stop quoting in meetings.