---
title: "Capstone: design and document a consent-compliant…"
description: "Your brief Design and document a complete, consent-compliant measurement setup for a real or realistic business. The output is a Measurement Design…"
url: https://optimizeall.com/learn/privacy-first-measurement/capstone-consent-compliant-server-side-setup
updated: 2026-10-05
---

Privacy-First Measurement: Server-Side Tagging, Consent Mode and Conversion APIs · Capstone: consent-compliant server-side setup · lesson 14 of 14 · 8 min

# Capstone: design and document a consent-compliant server-side tracking setup

## Your brief

Design and document a complete, consent-compliant measurement setup for a real or realistic business. The output is a **Measurement Design Document (MDD)** that a developer can implement, a privacy lead can approve, and a marketer can rely on. Aim for 8–12 pages plus diagrams and appendices.

## Choose a scenario (or your own business)

- **A.** A Shopify-based fashion brand in the UAE selling to the GCC and UK, advertising on Meta, TikTok, Google and Snapchat.
- **B.** A B2B software company in Pakistan selling to the UK and KSA, advertising on LinkedIn and Google, with HubSpot CRM and a 45-day sales cycle.
- **C.** A private clinic group in the UK and Saudi Arabia with online booking — note the heightened sensitivity of health-related data.

## MDD template

**1. Scope and objectives**
Business goals, KPIs, platforms, regions, and what decisions the data must support.

**2. Legal and consent design**
- Tag-to-law register (from Module 1) with lawful basis per region and purpose.
- CMP choice and configuration: regions, first-layer choices, languages (Arabic/English), TCF v2.3/GPP needs, GPC handling.
- Consent Mode v2: basic or advanced per region, defaults, update logic, rationale.
- Sensitive data policy (what must never be sent — e.g., health conditions in URLs for Scenario C).

**3. Architecture**
Diagram: browser (web GTM / Google tag) → first-party server container or Google tag gateway → vendors; CRM/backend → server-side APIs; warehouse. Hosting, domain, region, monitoring.

**4. Tracking plan**
Canonical events, triggers, source of truth, parameters, values, event ID rules, platform mappings, consent purposes, owners.

**5. Server-side feeds**
For each platform (Meta CAPI, Google enhanced conversions/offline imports, TikTok Events API, LinkedIn CAPI): events, identifiers (hashed/unhashed), click-ID capture and storage, dedup keys, batching/retries, secrets management.

**6. Data minimization and security**
Fields forwarded per vendor, transformations, retention, access control, key rotation, logging without personal data.

**7. QA and monitoring**
Consent QA matrix, automated tests in CI, synthetic transactions, reconciliation bands, alerts, evidence storage.

**8. Modeled measurement and validation**
Which reports include modeled data, how you will validate (lift or geo test), clean-room opportunities.

**9. Rollout plan and RACI**
Phases, owners (Responsible, Accountable, Consulted, Informed), sign-offs.

## Worked mini-example (Scenario A, abbreviated)

- **Consent**: EU/UK opt-in; GCC Arabic/English banner with marketing consent; US GPC honored. Advanced Consent Mode for GCC after legal review; basic for EU/UK.
- **Architecture**: web GTM → `sgtm.brand.ae` on Cloud Run in a Middle East region (check availability and transfer implications); Shopify webhooks → order service → server container; BigQuery for reconciliation.
- **Feeds**: GA4 via server; Google Ads with enhanced conversions; Meta CAPI (order ID dedup); TikTok Events API; Snapchat Conversions API (check current docs).
- **Minimization**: transformation removes IP for GA4; hashed email/phone only to ad platforms and only when ad consent is granted.
- **QA**: Playwright consent suite in CI; hourly synthetic purchase; reconciliation band backend vs platforms defined per platform.
- **Validation**: Meta Conversion Lift in KSA next quarter; geo test on TikTok in UAE emirates.

## Using AI to review your MDD

```text
You are a privacy engineer and measurement lead reviewing a Measurement Design Document.
Document: {paste MDD}
Regions: {regions}. Sectors/sensitive data: {notes}.
1. List any place where data could flow to a vendor without valid consent for that purpose.
2. Check each platform feed for dedup keys, hashing rules, click-ID capture and retry handling.
3. Identify sensitive-data leakage risks (URLs, event parameters, free text).
4. Identify missing monitoring or QA scenarios.
5. List assumptions that legal counsel must confirm.
Return a table: issue | section | severity | recommended fix. Do not invent legal requirements; flag uncertainty.
```

Do not paste real personal data into AI tools; use the design document only.

## Assessment rubric

| Criterion | Excellent |
|---|---|
| Lawfulness | Every purpose mapped to a basis per region; consent enforced client- and server-side |
| Architecture | First-party, minimal, monitored, secure |
| Accuracy | Dedup, IDs, values, currencies and click IDs designed end to end |
| Coverage | Server feeds for each ad platform; offline/CRM loops where relevant |
| QA | Automated consent tests, synthetic transactions, reconciliation, evidence |
| Honesty | Modeled data labeled; validation plan with lift/geo tests |

## Video lecture: Capstone: design and document a consent-compliant server-side tracking setup

Lecture coming soon · 14 chapters · about 8 minutes. Read the full transcript below.

1. Capstone
2. Why it matters
3. Scenarios
4. Sections 1–2
5. Sections 3–4
6. Simple example: one feed spec
7. Sections 5–6
8. Sections 7–9
9. Example: Scenario A (abbreviated)
10. AI as reviewer
11. Rubric
12. Mistakes + try this now
13. Watch me do it: MDD QA section (illustrative)
14. Your next step

## Lecture transcript

### Capstone

This is your capstone. You're going to design and document a complete measurement setup that's accurate, consent-compliant and ready to build. The output is a measurement design document that a developer can implement, a privacy lead can approve, and a marketer can trust. In this lecture I'll walk you through the scenarios, the nine-section template, an abbreviated example, an AI review prompt and the rubric.

### Why it matters

Why does this capstone matter? Because measurement setups are usually built piece by piece, by different people, over years, and nobody can explain the whole thing. A written design changes that. Here's an analogy. A building's wiring diagram doesn't make the lights brighter, but it means any electrician can fix a fault safely, and an inspector can approve the building. Your measurement design document is the wiring diagram for your data. It lets developers build, privacy leads approve, and marketers trust the numbers.

### Scenarios

Pick a scenario, or use your own business. Option A, a Shopify fashion brand in the UAE selling across the Gulf and the UK, advertising on Meta, TikTok, Google and Snapchat. Option B, a Pakistani software company selling to the UK and Saudi Arabia via LinkedIn and Google, with a CRM and a forty-five-day sales cycle. Option C, a private clinic group in the UK and Saudi Arabia with online booking, where health-related data needs extra care.

### Sections 1–2

Sections one and two. Scope and objectives: the goals, KPIs, platforms, regions and decisions the data must support. Then legal and consent design, the heart of a compliant setup: your tag-to-law register, the consent platform configuration by region and language, whether you need TCF or GPP, how you honor Global Privacy Control, basic or advanced Consent Mode per region with the reasoning, and a sensitive data policy listing what must never be sent.

### Sections 3–4

Sections three and four. The architecture: a diagram showing the browser, your first-party server container or tag gateway, each vendor, your CRM and backend feeding server APIs, and your warehouse, plus hosting, domain, region and monitoring. Then the tracking plan: canonical events, triggers, the source of truth, parameters, values, event ID rules, platform mappings, consent purposes and owners.

### Simple example: one feed spec

Here's a simple worked example of one section done well: the Meta feed for scenario A. Events: purchase and add payment info. Source of truth: the Shopify order webhook for purchase. Identifiers: hashed email and phone from the order, external ID from the customer ID, IP and user agent from the original browser request, f b p and f b c captured by the server container. Dedup key: order underscore the order number, also passed to the Pixel. Consent: only sent when advertising consent is granted, read from the CMP state stored with the order. Retries: up to three with backoff, same event ID. Secrets: access token in the cloud secret manager, rotated quarterly.

### Sections 5–6

Sections five and six. Server-side feeds: for each platform, the events, identifiers and whether they're hashed, how click IDs are captured and stored, dedup keys, batching and retries, and how secrets are managed. Then data minimization and security: exactly which fields each vendor receives, transformations, retention, access control, key rotation, and logging that avoids personal data.

### Sections 7–9

Sections seven to nine. QA and monitoring: your consent matrix, automated tests in the deployment pipeline, synthetic transactions, reconciliation bands and alerts, and where evidence is stored. Modeled measurement: which reports include modeled data and how you'll validate with a lift or geo test. And the rollout plan, with phases and a RACI, who's responsible, accountable, consulted and informed, plus sign-offs.

### Example: Scenario A (abbreviated)

Here's an abbreviated example for scenario A. Opt-in for EU and UK visitors, an Arabic and English banner in the Gulf with marketing consent, and Global Privacy Control honored for US visitors. Advanced Consent Mode for the Gulf after legal review, basic for Europe. A server container on a first-party subdomain in a Middle East cloud region. Shopify webhooks feed the order service. Server feeds to GA4, Google Ads with enhanced conversions, Meta, TikTok and Snapchat. Hashed identifiers only go to ad platforms when ad consent is granted. And validation through a Meta lift study and a TikTok geo test.

### AI as reviewer

Use AI as a reviewer. The lesson's prompt asks a model, acting as a privacy engineer and measurement lead, to find any place data could reach a vendor without valid consent, check each feed's dedup, hashing, click IDs and retries, spot sensitive data leaks in URLs or parameters, identify missing QA scenarios, and list assumptions your legal counsel must confirm, in a table with severity and fixes. Never paste real personal data. Review the design, not the customers.

### Rubric

Score yourself on six criteria. Lawfulness: every purpose mapped to a basis per region, with consent enforced client-side and server-side. Architecture: first-party, minimal, monitored, secure. Accuracy: dedup, IDs, values, currencies and click IDs designed end to end. Coverage: server feeds for each platform and offline loops. QA: automated tests, synthetic transactions, reconciliation and evidence. And honesty: modeled data labeled, with a validation plan.

### Mistakes + try this now

Common capstone mistakes. Architecture diagrams with no consent checks drawn on them. Tracking plans with event names but no ID rules. Feed sections that say we'll use CAPI, with no identifiers, dedup or retries. No sensitive data policy, especially in health scenarios. And no plan to validate modeled numbers. Try this now: before writing prose, draw your architecture diagram and mark every point where consent is checked with a small lock icon. If any data path to an ad platform has no lock, you've found the most important gap in your design.

### Watch me do it: MDD QA section (illustrative)

Watch me do it. Let's draft the QA section of an illustrative measurement design document for scenario B, the Pakistani software company selling to the UK and Saudi Arabia. First, the consent matrix: two region profiles, UK and Saudi Arabia, three choices each, accept all, reject all, analytics only, and for each cell, which tags fire client-side and which forwards happen server-side. Six rows, written in a table. Second, automation: a Playwright test for the UK reject-all row runs on every deployment and fails the release if any request to LinkedIn, Google Ads or Meta appears. Third, the synthetic conversion: every six hours a test lead is submitted with a test flag; the CRM routes it to a test pipeline stage, and the server sends a test LinkedIn and Google conversion that we verify arrived, without polluting real data. Fourth, reconciliation: weekly, CRM SQLs versus LinkedIn and Google reported conversions, with bands. Fifth, evidence: every release stores the test report and a HAR file in a dated folder. Sixth, ownership: the growth engineer owns the suite, the privacy lead reviews quarterly. That's a QA section a regulator or client would respect.

### Your next step

That's the course. You now understand the real state of tracking, the laws that govern it, consent management and Consent Mode, GA4 and server-side tagging, every major conversion API, data quality and QA, first-party data strategy, and modeled measurement. Your next step: write your measurement design document, run the AI review, fix what it finds, and you'll have a blueprint any team would be glad to build.

## Key takeaways

- The capstone output is a Measurement Design Document developers, privacy leads and marketers can all use.
- Start from legal and consent design, then architecture, tracking plan and server-side feeds.
- Build minimization, security, QA and monitoring into the design, not after launch.
- Label modeled data and plan validation with lift or geo tests.
- Use AI to review the design, never with real personal data.

## Try it

Produce the Measurement Design Document for one scenario using the template, including an architecture diagram, tracking plan, consent QA matrix and validation plan; run the AI review prompt and address the findings.

- [Previous: Modeled conversions, aggregated measurement and data clean rooms](https://optimizeall.com/learn/privacy-first-measurement/modelled-conversions-and-clean-rooms)
- [All lessons of Privacy-First Measurement: Server-Side Tagging, Consent Mode and Conversion APIs](https://optimizeall.com/learn/privacy-first-measurement)
