/

/

Consent

Consent

/

/

Does your tracking hold up when your client advertises in five markets?

Does your tracking hold up when your client advertises in five markets?

Consent

Consent

Does your tracking hold up when your client advertises in five markets?

Does your tracking hold up when your client advertises in five markets?

Rhobin

Rhobin

July 31, 2026

July 31, 2026

7 min read

7 min read

Usually not, because there is no single rule to satisfy: inside the EU the cookie rule is a directive implemented country by country, the UK now exempts analytics aimed at improving a service under two conditions, and most US markets run an opt-out model that leans on a browser signal rather than on your banner. One setup can still serve five markets, but only if the decision is configured per market instead of assumed.

Usually not, because there is no single rule to satisfy: inside the EU the cookie rule is a directive implemented country by country, the UK now exempts analytics aimed at improving a service under two conditions, and most US markets run an opt-out model that leans on a browser signal rather than on your banner. One setup can still serve five markets, but only if the decision is configured per market instead of assumed.

The symptom

On paper it is one account. One tag setup, one consent banner, one GA4 property, and a client selling in the Netherlands, Germany, the UK, Norway and the United States. The monthly report is where it stops behaving like one: volume that does not line up with spend per market, one country's leads stepping down overnight without a release, another where the ad platform claims far more conversions than analytics can show.

The first read is usually a tagging bug, so somebody spends half a day in the container and finds nothing broken. Because nothing is. The setup does the same thing in every market. What changes at the border is the rule it has to satisfy, and how much a browser may store before the visitor has answered anything.

Agencies bring this to Archon Labs regularly, and it is rarely a bug. On a single-market account, 15-30% of conversions going uncaptured is the baseline most teams already live with. Add four markets to the same setup and that gap stops being one number. It becomes a different number per country, for different reasons.

Why does one setup behave differently per market?

Because there is no single rule to satisfy. There are three layers, and they do not share a map.

Inside the EU, the binding text is national

The European rule that governs storing anything on a visitor's device is a directive, not a regulation. Article 5(3) of the ePrivacy Directive permits storing or accessing information in terminal equipment only "on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information", with carve-outs only for transmission and for what is "strictly necessary" to deliver the service the user asked for. A directive binds member states to legislate it, so the text your client is held to is Dutch, German or Norwegian.

Norway shows what that costs. Its rule sits in section 3-15 of the Electronic Communications Act, which forbids storing or gaining access to information in a user's equipment without informing them what is processed, for what purpose and by whom, and without their consent. Datatilsynet, the Norwegian regulator, states that consent has to meet the GDPR's requirements, a standard that applies there from 1 January 2025. An agency running the same banner in Oslo as in Amsterdam changed nothing in 2025. The obligation moved underneath it.

The UK moved in the other direction

Britain is where "the EU rule, roughly" now costs you. The Data (Use and Access) Act 2025 rewrote regulation 6 of the UK's PECR so the prohibition reads "Subject to Schedule A1", and that schedule carries the exceptions. Paragraph 5 covers storage whose "sole purpose" is collecting statistical information about how the service or website is used "with a view to making improvements". That is analytics, and under that paragraph it does not need PECR consent.

The gate is narrower than the headline. Sole purpose means the same data cannot also feed advertising, and the paragraph attaches two conditions: "clear and comprehensive information about the purpose of the storage or access", and "a simple means of objecting, free of charge, to the storage or access" that the user has not used. So the UK is not a banner-free market, just one where the mechanism can be an objection route rather than a request, and where nothing about ads changed.

The United States runs a different mechanism, not a softer version

In most US markets the default is not permission before collection but the ability to opt out afterwards, and part of that duty is carried by a browser signal rather than your banner. The California Attorney General says of the Global Privacy Control that "under law, it must be honored by covered businesses as a valid consumer request to stop the sale or sharing of personal information". The Colorado Attorney General states that "beginning July 1, 2024, businesses falling within the CPA's application thresholds must allow Consumers to opt-out" through a universal opt-out mechanism.

For a measurement setup that is an inversion. A market with a quiet banner can still be dropping signals, because a share of visitors arrive with a browser-level preference already set, and a setup that never reads it is not acting on it. Sensitive data categories are where the exceptions live, and that is counsel's call, not the tag setup's.

The ad platforms draw a second map

Google's EU user consent policy applies to "end users in the European Economic Area, the UK and Switzerland". It requires consent for "the use of cookies or other local storage where legally required" and for "the collection, sharing, and use of personal data for personalization of ads", plus identification of "each party that may collect, receive, or use end users' personal data". That map is contractual and does not trace the legal one: the UK exception does not release UK ad traffic from it, and Switzerland sits inside it while sitting outside the EEA. A setup has to satisfy both at once.

What good looks like

One architecture, configured per market, instead of five setups or one blunt setup. Google's tags accept default consent states scoped by region, "according to ISO 3166-2", where "the one with a more specific region will take effect". That is what lets one implementation behave differently in Oslo, Manchester and Denver without becoming five things to maintain, and the signals behind it are worth understanding before you scope the work.

Three things then have to be true per market. It is clear what may be collected before the visitor answers. The signals that market requires are read and acted on. And someone can show the client, per country, what was measured and what was refused. The last one turns a compliance conversation into a reporting conversation, which is the version a client can act on.

That is the work Archon Consent exists to do: implement the per-market decision, keep consent state and measurement consistent across markets, and hand it over documented so local teams can see what applies where. What it does not do is decide the legal position. Where the honest answer is "it depends", it depends on where the visitor is, which platform receives the data, and what the client's legal advisers will sign.

It also does not make the numbers whole. A refusal in a strict market is a legitimate answer that permanently removes those events, so roughly 95% of events is the realistic ceiling on any setup, and it stays a ceiling rather than a promise. What a server-side setup done properly moves is the baseline, 15-40% more conversions recovered than the account measures today, mostly in the markets nobody has examined closely.

FAQ

Can we not just apply the strictest rule everywhere?

You can, and plenty of agencies do, because it is defensible and simple to maintain. It also has a bill. In markets where consent is not required before collection you are asking for permission you did not need, and you lose the share that says no. That is a trade-off to make deliberately, and it helps to know what a banner costs in data first.

Does the UK change mean our UK clients can drop the banner?

No, and that is the expensive reading. The exception covers storage whose sole purpose is statistics for improving the service, so the moment the same data feeds advertising it falls outside the gate. It also carries two conditions: information about the purpose, and a simple free way to object that the user has not used. Google's policy still covers UK end users regardless.

Do we need a cookie banner for the US market?

That is a question for the client's lawyers, and the model is different rather than absent. California requires covered businesses to honour the Global Privacy Control as a valid opt-out, and Colorado has required in-scope controllers to accept a universal opt-out mechanism since 1 July 2024, with GPC currently the only recognised one. What is actionable for you is whether the setup reads those signals at all.

Our client has local legal teams in three of the five markets. Where does that leave us?

In a better position than the accounts that have none. They own the legal basis per market. Your job is to tell them exactly what the setup stores and sends and to whom, so their decision rests on facts, then to implement it without rounding to the strictest or loosest market. Start with the market where spend is high and the numbers diverge most from the client's own backend.

If you want to know which of your client's markets is quietly under-measured, that is one of the first things we map in a free tracking audit.

ArchonLabs

Marketing intelligence agencies run for their clients.

© 2026 Archon LabsPrivacyTermsBehind your agency, not in front of it.