TrackLead
←All articles

The Tracking Readiness Checklist for iOS, GDPR, and Cookie Updates

2 min read

Between iOS privacy changes, GDPR enforcement, and the slow decline of third-party cookies, "is our tracking still compliant and accurate" is a question every agency should be able to answer without a scramble. Use this checklist to find out where you actually stand.

This is part of our series for tracking and data specialists. See the full overview here: Server-Side Tracking for Tracking & Data Specialists.

Why this matters right now

None of these three pressures, iOS tracking prevention, GDPR enforcement, and cookie restrictions, are new, but they compound. A setup that technically survives one of them can still fail against the combination of all three.

That failure usually shows up as a client asking why their numbers do not match, not as a clear error message.

The checklist

  1. Consent Mode v2 is implemented correctly, with default and updated states configured before any tags fire.

  2. Server-side tracking is in place for any client with meaningful ad spend riding on conversion data.

  3. First-party cookies are used wherever possible, instead of relying on third-party cookies that browsers increasingly restrict.

  4. Event deduplication is configured between client-side and server-side tags, so the same conversion is not counted twice.

  5. A clear, current record exists of every platform each client is sending data to, so nothing gets missed during an audit.

  6. Someone is actually monitoring each client's tracking on an ongoing basis, not just checking it at setup.

  7. Data retention settings in GA4 and other platforms match the client's actual compliance requirements, not just the platform default.

  8. A documented process exists for what happens when a platform, such as GA4, Meta, or Google Ads, changes its API or requirements.

  9. Every conversion event has a locked-down, standardized schema, rather than being configured slightly differently across clients.

  10. Someone can explain, in plain language, exactly what data is collected and where it goes, if a client or regulator asks.

If you failed more than two or three of these

That is common, and it is worth treating as a priority list rather than a source of panic. Start with server-side tracking and Consent Mode, since those two items address the largest share of the accuracy and compliance gap at once.

This checklist is meant as a practical starting point, not legal advice. Specific compliance questions should go to a client's legal counsel.

Where TrackLead fits

Most of these items are hard to maintain manually across a growing client list. Not because any single one is complicated, but because doing it consistently, for every client, every time, is tedious.

TrackLead automates the server-side setup and consent configuration pieces of this list directly. Its monitoring covers the ongoing check that most agencies skip once things seem to be working.