Privacy-First Measurement: Server-Side Tagging, Consent Mode and Conversion APIsCapstone: consent-compliant server-side setup · Lesson 14 of 14

Capstone: design and document a consent-compliant server-side tracking setup

Article · 8 min · 8 min lecture

Video lecture

Capstone: design and document a consent-compliant server-side tracking setup

14 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 14

Capstone

  • A Measurement Design Document
  • Scenarios
  • Nine-section template
  • Example, AI review, rubric

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Your brief

Design and document a complete, consent-compliant measurement setup for a real or realistic business. The output is a Measurement Design Document (MDD) that a developer can implement, a privacy lead can approve, and a marketer can rely on. Aim for 8–12 pages plus diagrams and appendices.

Choose a scenario (or your own business)

  • A. A Shopify-based fashion brand in the UAE selling to the GCC and UK, advertising on Meta, TikTok, Google and Snapchat.
  • B. A B2B software company in Pakistan selling to the UK and KSA, advertising on LinkedIn and Google, with HubSpot CRM and a 45-day sales cycle.
  • C. A private clinic group in the UK and Saudi Arabia with online booking — note the heightened sensitivity of health-related data.

MDD template

1. Scope and objectives Business goals, KPIs, platforms, regions, and what decisions the data must support.

2. Legal and consent design

  • Tag-to-law register (from Module 1) with lawful basis per region and purpose.
  • CMP choice and configuration: regions, first-layer choices, languages (Arabic/English), TCF v2.3/GPP needs, GPC handling.
  • Consent Mode v2: basic or advanced per region, defaults, update logic, rationale.
  • Sensitive data policy (what must never be sent — e.g., health conditions in URLs for Scenario C).

3. Architecture Diagram: browser (web GTM / Google tag) → first-party server container or Google tag gateway → vendors; CRM/backend → server-side APIs; warehouse. Hosting, domain, region, monitoring.

4. Tracking plan Canonical events, triggers, source of truth, parameters, values, event ID rules, platform mappings, consent purposes, owners.

5. Server-side feeds For each platform (Meta CAPI, Google enhanced conversions/offline imports, TikTok Events API, LinkedIn CAPI): events, identifiers (hashed/unhashed), click-ID capture and storage, dedup keys, batching/retries, secrets management.

6. Data minimization and security Fields forwarded per vendor, transformations, retention, access control, key rotation, logging without personal data.

7. QA and monitoring Consent QA matrix, automated tests in CI, synthetic transactions, reconciliation bands, alerts, evidence storage.

8. Modeled measurement and validation Which reports include modeled data, how you will validate (lift or geo test), clean-room opportunities.

9. Rollout plan and RACI Phases, owners (Responsible, Accountable, Consulted, Informed), sign-offs.

Worked mini-example (Scenario A, abbreviated)

  • Consent: EU/UK opt-in; GCC Arabic/English banner with marketing consent; US GPC honored. Advanced Consent Mode for GCC after legal review; basic for EU/UK.
  • Architecture: web GTM → sgtm.brand.ae on Cloud Run in a Middle East region (check availability and transfer implications); Shopify webhooks → order service → server container; BigQuery for reconciliation.
  • Feeds: GA4 via server; Google Ads with enhanced conversions; Meta CAPI (order ID dedup); TikTok Events API; Snapchat Conversions API (check current docs).
  • Minimization: transformation removes IP for GA4; hashed email/phone only to ad platforms and only when ad consent is granted.
  • QA: Playwright consent suite in CI; hourly synthetic purchase; reconciliation band backend vs platforms defined per platform.
  • Validation: Meta Conversion Lift in KSA next quarter; geo test on TikTok in UAE emirates.

Using AI to review your MDD

You are a privacy engineer and measurement lead reviewing a Measurement Design Document.
Document: {paste MDD}
Regions: {regions}. Sectors/sensitive data: {notes}.
1. List any place where data could flow to a vendor without valid consent for that purpose.
2. Check each platform feed for dedup keys, hashing rules, click-ID capture and retry handling.
3. Identify sensitive-data leakage risks (URLs, event parameters, free text).
4. Identify missing monitoring or QA scenarios.
5. List assumptions that legal counsel must confirm.
Return a table: issue | section | severity | recommended fix. Do not invent legal requirements; flag uncertainty.

Do not paste real personal data into AI tools; use the design document only.

Assessment rubric

CriterionExcellent
LawfulnessEvery purpose mapped to a basis per region; consent enforced client- and server-side
ArchitectureFirst-party, minimal, monitored, secure
AccuracyDedup, IDs, values, currencies and click IDs designed end to end
CoverageServer feeds for each ad platform; offline/CRM loops where relevant
QAAutomated consent tests, synthetic transactions, reconciliation, evidence
HonestyModeled data labeled; validation plan with lift/geo tests

Key takeaways

  • The capstone output is a Measurement Design Document developers, privacy leads and marketers can all use.
  • Start from legal and consent design, then architecture, tracking plan and server-side feeds.
  • Build minimization, security, QA and monitoring into the design, not after launch.
  • Label modeled data and plan validation with lift or geo tests.
  • Use AI to review the design, never with real personal data.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. In a clinic group's MDD, which item deserves special attention?
  2. What should the MDD's server-side feed section specify for each platform?
  3. What is the right way to use AI in reviewing the MDD?

Put it into practice

Produce the Measurement Design Document for one scenario using the template, including an architecture diagram, tracking plan, consent QA matrix and validation plan; run the AI review prompt and address the findings.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.