GDPR & privacy engineering:
Privacy requirements, implemented in your systems.
Consent integration · Analytics · CRM & ecommerce · AI workflows
I help businesses implement the technical side of GDPR and privacy requirements across websites, analytics, CRM, ecommerce and AI workflows.
The work starts with what data your systems collect, where it goes, which tools receive it, and which controls need to be added or repaired.

What I can help with
Fix consent and tracking
You need: Consent choices to actually control analytics, advertising tags, embeds and other third-party services.
I handle:You get: A tested consent implementation where acceptance, rejection and withdrawal produce the intended behaviour across the relevant pages and visitor journeys.
Review data flows between systems
You need: A clearer picture of what personal data moves between your website, CRM, eCommerce platform and other services.
I handle:You get: Documented data flows and the technical changes needed to reduce unnecessary data collection, restrict access or improve how information is passed between systems.
Implement privacy controls
You need: Technical requirements from your privacy adviser, DPO or internal review implemented reliably.
I handle:You get: Configuration and code changes that turn privacy requirements into working system behaviour rather than leaving them as policy documents.
Review AI integrations
You need: AI workflows that handle personal or potentially sensitive data in a more controlled way.
I handle:You get: A clearer and more controlled technical setup, together with documentation showing what information enters the workflow, where it goes and which safeguards are in place.
What a privacy implementation project can include
I review how consent is currently connected to analytics, advertising tools, embedded content and other third-party services. This includes checking what happens before a visitor makes a choice, after acceptance, after rejection and when consent is later withdrawn.
Where necessary, I adjust the CMP, tag manager configuration or application code so the consent signal actually controls the services it is supposed to control. I also test the implementation rather than relying on the CMP dashboard alone.
This can include Google Consent Mode, GA4, Google Ads, Meta, embedded media, chat tools and other services that load or store information in the browser.
Privacy requirements do not mean giving up useful measurement.
I can help configure analytics so the organisation still gets reliable information about how the website performs while keeping unnecessary data collection to a minimum.
Depending on the setup, this can include GA4, server-side measurement, Matomo or Umami on infrastructure controlled by the client, conversion tracking and the technical connection between analytics and advertising platforms.
I also review whether the measurement setup matches the consent model rather than treating analytics and privacy as two separate projects.
Personal data often continues far beyond the website itself.
A contact form may send data into a CRM, trigger an email platform, create an account, start an automation or pass information to another service through an API.
I review the relevant flows and implement agreed technical controls across those connections. That can include reducing the fields being collected, changing what gets transferred, limiting access, adjusting retention settings or building deletion processes that also reach connected systems.
The aim is to deal with the full workflow rather than stopping at the WordPress plugin or consent banner.
AI integrations can introduce another layer of data movement that is easy to overlook.
I can map what information is sent to model providers and connected tools, review what gets logged, and implement controls such as redaction, restricted access, shorter retention or human review where the workflow requires it.
For internal tools, this may also include separating user data from prompts, limiting which employees can access transcripts or model outputs, and documenting provider settings that matter for the organisation’s privacy review.
I do not make the legal decision about whether a specific processing activity is permitted. My role is to make sure the technical implementation reflects the decision your organisation has made.
A privacy configuration should be testable.
I verify the affected workflows after implementation, including consent states, tracking behaviour, forms, integrations and deletion or retention logic where those are part of the scope.
The handover can include documentation of which systems are involved, what data moves between them, which controls have been implemented and where further organisational or legal decisions are still required.
That gives your internal team, privacy adviser or DPO something concrete to review rather than having to reverse-engineer the implementation afterwards.
Process
The exact scope changes, but the work usually follows the same path: understand what is happening, decide what matters, build the right thing, and leave it in a state someone can operate.
1. Understand
I start by identifying the systems in scope, what information they collect and how they communicate with each other.
That may include the website, consent platform, analytics, tag manager, CRM, ecommerce system, advertising tools, APIs and AI providers.
2. Define
If you already have requirements from a privacy adviser, DPO or internal review, I translate them into concrete implementation work.
If the technical situation is unclear, I can first document what is currently happening so the organisation has a better basis for deciding what needs to change.
3. Implement & Test
I make the required configuration or code changes and test the relevant workflows in realistic conditions.
That includes more than checking whether a banner appears. Consent, data transfer, tracking, integrations and downstream behaviour need to work together.
4. Hand over
I document what changed, which systems are involved and any remaining decisions or dependencies.
The goal is to leave you with a setup that can be reviewed and maintained later rather than one that only works as long as nobody touches it.
1. Understand The Dataflow
I start by identifying the systems in scope, what information they collect and how they communicate with each other.
That may include the website, consent platform, analytics, tag manager, CRM, ecommerce system, advertising tools, APIs and AI providers.
2. Define the technical changes
If you already have requirements from a privacy adviser, DPO or internal review, I translate them into concrete implementation work.
If the technical situation is unclear, I can first document what is currently happening so the organisation has a better basis for deciding what needs to change.
3. Build & verify
I make the required configuration or code changes and test the relevant workflows in realistic conditions.
That includes more than checking whether a banner appears. Consent, data transfer, tracking, integrations and downstream behaviour need to work together.
4. Hand over
I document what changed, which systems are involved and any remaining decisions or dependencies.
The goal is to leave you with a setup that can be reviewed and maintained later rather than one that only works as long as nobody touches it.
Want to talk through the problem first?
Have a privacy or consent problem?
Contact
Send me the website or system involved, what you already know about the issue, and which tools are connected.
You do not need to prepare a technical specification. Existing consent configurations, data-flow documentation or requirements from your privacy adviser are useful if you have them.
I can work on an existing setup or include the privacy implementation as part of a wider WordPress, ecommerce or integration project.
Not sure what you need yet?
Further reading…
-
A user consents to analytics, but their ad blocker still blocks GA4. What can you do?
A visitor accepts analytics in your consent banner. Your consent platform records that choice correctly. GA4 is now allowed to run. And the visitor’s ad blocker blocks it anyway. This is not unusual. Consent systems and ad blockers solve different problems, and they usually do not communicate with each other. Your consent platform knows the…
-
Consent Mode v2 for Malta and EU websites: what it changes in reporting
Understand Consent Mode v2, tag timing and consent-state testing, with real integration examples and technical setup from €250 excluding VAT.
-
GA4 vs Matomo vs Umami: how much analytics does a small business actually need?
GA4 and Matomo solve overlapping but different measurement problems. Choose from the decisions, privacy posture, data ownership, integrations, and operating capacity your business actually has.
