GDPR & privacy engineering:
Privacy requirements, implemented in your systems.

Consent integration · Analytics · CRM & ecommerce · AI workflows

I help businesses implement the technical side of GDPR and privacy requirements across websites, analytics, CRM, ecommerce and AI workflows.
The work starts with what data your systems collect, where it goes, which tools receive it, and which controls need to be added or repaired.

What I can help with

Fix consent and tracking

You need: Consent choices to actually control analytics, advertising tags, embeds and other third-party services.

I handle:
  • Consent platforms
  • Google Consent Mode
  • GA4 and Google Ads
  • Tag Manager
  • Matomo and Umami
  • Embeds and third-party scripts

You get: A tested consent implementation where acceptance, rejection and withdrawal produce the intended behaviour across the relevant pages and visitor journeys.

Review data flows between systems

You need: A clearer picture of what personal data moves between your website, CRM, eCommerce platform and other services.

I handle:
  • Forms and lead capture
  • CRM integrations
  • Customer accounts
  • Order data
  • Marketing platforms
  • APIs and webhooks

You get: Documented data flows and the technical changes needed to reduce unnecessary data collection, restrict access or improve how information is passed between systems.

Implement privacy controls

You need: Technical requirements from your privacy adviser, DPO or internal review implemented reliably.

I handle:
  • Field restrictions
  • Access controls
  • Retention settings
  • Deletion workflows
  • Logging
  • Data minimisation

You get: Configuration and code changes that turn privacy requirements into working system behaviour rather than leaving them as policy documents.

Review AI integrations

You need: AI workflows that handle personal or potentially sensitive data in a more controlled way.

I handle:
  • Data sent to model providers
  • Prompt and response logging
  • Redaction
  • Access restrictions
  • Provider configuration
  • Human review steps

You get: A clearer and more controlled technical setup, together with documentation showing what information enters the workflow, where it goes and which safeguards are in place.

What a privacy implementation project can include

I review how consent is currently connected to analytics, advertising tools, embedded content and other third-party services. This includes checking what happens before a visitor makes a choice, after acceptance, after rejection and when consent is later withdrawn.

Where necessary, I adjust the CMP, tag manager configuration or application code so the consent signal actually controls the services it is supposed to control. I also test the implementation rather than relying on the CMP dashboard alone.

This can include Google Consent Mode, GA4, Google Ads, Meta, embedded media, chat tools and other services that load or store information in the browser.

Privacy requirements do not mean giving up useful measurement.

I can help configure analytics so the organisation still gets reliable information about how the website performs while keeping unnecessary data collection to a minimum.

Depending on the setup, this can include GA4, server-side measurement, Matomo or Umami on infrastructure controlled by the client, conversion tracking and the technical connection between analytics and advertising platforms.

I also review whether the measurement setup matches the consent model rather than treating analytics and privacy as two separate projects.

Personal data often continues far beyond the website itself.

A contact form may send data into a CRM, trigger an email platform, create an account, start an automation or pass information to another service through an API.

I review the relevant flows and implement agreed technical controls across those connections. That can include reducing the fields being collected, changing what gets transferred, limiting access, adjusting retention settings or building deletion processes that also reach connected systems.

The aim is to deal with the full workflow rather than stopping at the WordPress plugin or consent banner.

AI integrations can introduce another layer of data movement that is easy to overlook.

I can map what information is sent to model providers and connected tools, review what gets logged, and implement controls such as redaction, restricted access, shorter retention or human review where the workflow requires it.

For internal tools, this may also include separating user data from prompts, limiting which employees can access transcripts or model outputs, and documenting provider settings that matter for the organisation’s privacy review.

I do not make the legal decision about whether a specific processing activity is permitted. My role is to make sure the technical implementation reflects the decision your organisation has made.

A privacy configuration should be testable.

I verify the affected workflows after implementation, including consent states, tracking behaviour, forms, integrations and deletion or retention logic where those are part of the scope.

The handover can include documentation of which systems are involved, what data moves between them, which controls have been implemented and where further organisational or legal decisions are still required.

That gives your internal team, privacy adviser or DPO something concrete to review rather than having to reverse-engineer the implementation afterwards.

The exact scope depends on the project. You do not automatically need everything on this list.

Process

The exact scope changes, but the work usually follows the same path: understand what is happening, decide what matters, build the right thing, and leave it in a state someone can operate.

1. Understand

I start by identifying the systems in scope, what information they collect and how they communicate with each other.
That may include the website, consent platform, analytics, tag manager, CRM, ecommerce system, advertising tools, APIs and AI providers.

2. Define

If you already have requirements from a privacy adviser, DPO or internal review, I translate them into concrete implementation work.
If the technical situation is unclear, I can first document what is currently happening so the organisation has a better basis for deciding what needs to change.

3. Implement & Test

I make the required configuration or code changes and test the relevant workflows in realistic conditions.
That includes more than checking whether a banner appears. Consent, data transfer, tracking, integrations and downstream behaviour need to work together.

4. Hand over

I document what changed, which systems are involved and any remaining decisions or dependencies.
The goal is to leave you with a setup that can be reviewed and maintained later rather than one that only works as long as nobody touches it.

1. Understand The Dataflow

I start by identifying the systems in scope, what information they collect and how they communicate with each other.
That may include the website, consent platform, analytics, tag manager, CRM, ecommerce system, advertising tools, APIs and AI providers.

2. Define the technical changes

If you already have requirements from a privacy adviser, DPO or internal review, I translate them into concrete implementation work.
If the technical situation is unclear, I can first document what is currently happening so the organisation has a better basis for deciding what needs to change.

3. Build & verify

I make the required configuration or code changes and test the relevant workflows in realistic conditions.
That includes more than checking whether a banner appears. Consent, data transfer, tracking, integrations and downstream behaviour need to work together.

4. Hand over

I document what changed, which systems are involved and any remaining decisions or dependencies.
The goal is to leave you with a setup that can be reviewed and maintained later rather than one that only works as long as nobody touches it.

Want to talk through the problem first?

Have a privacy or consent problem?

Contact

Send me the website or system involved, what you already know about the issue, and which tools are connected.

You do not need to prepare a technical specification. Existing consent configurations, data-flow documentation or requirements from your privacy adviser are useful if you have them.

I can work on an existing setup or include the privacy implementation as part of a wider WordPress, ecommerce or integration project.

Not sure what you need yet?
Further reading…