UK Manufacturer Refutes 7 Scan Claims, Finds 2 Leaks

Organization

A UK flooring manufacturer, engaged through its web agency (anonymized)

Industry

Manufacturing, Residential and Commercial Flooring

Services Used

Consent Audit (OneTrust, Google Tag Manager, GA4, Convert Experiences, Azure Application Insights)

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

This is some text inside of a div block.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

This is some text inside of a div block.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

This is some text inside of a div block.

About

The client is a UK flooring manufacturer with residential and commercial sites, engaged through its web agency. A third-party compliance scanner issued a report listing consent-rule violations and asked the agency to act on them. Acting would have meant developer time across the site template, the tag manager, and the consent platform. Before committing the time, the agency asked for an independent audit: is the scan right, and if not, what is actually wrong?

Challenges

  • A third-party scanner reported the site was breaching consent rules, with multiple violations claimed across the site template, tag manager, and consent platform.
  • Acting on the scan would have required developer effort across three owners (website dev team, GTM owner, CMP owner) before anyone knew which fixes were actually needed.
  • The scan report's claims had not been tested against captured evidence: real consent states, tag behaviour, or network requests.
  • The team could not tell whether the consent framework was fundamentally broken, or whether only a few things were actually leaking.
  • Switching off GA4 advanced consent mode on the scanner's recommendation would have cost the client its conversion data for visitors who declined.
  • A scanner, auditor, or regulator could challenge the set-up again. The client needed documented proof of what was actually working.

Goals

  • Test every claim in the scan report against captured evidence before any developer time was committed.
  • Validate the end-to-end consent framework: OneTrust banner, tag manager gating, GA4 consent mode, and behavioural modelling.
  • Identify any real leaks and attribute each one to the correct owner.
  • Keep GA4 advanced consent mode with behavioural modelling on, since it was already working.
  • Deliver a written validation report the client can show a scanner, an auditor, or a regulator.
  • Produce a prioritised fix list split by owner, so each team only gets its items.

Solution/Approach

  • Captured evidence for every claim in the scan report: consent state, tag behaviour before and after the user's choice, and network requests on each page.
  • Validated the consent framework end to end: OneTrust banner, tag manager gating, GA4 consent mode, and behavioural modelling.
  • Tested each of the scanner's claims against the captured evidence. Seven did not survive it.
  • Traced the two real leaks (Convert Experiences and Azure Application Insights) to hard-coded tags in the site template, outside the tag manager, where no tag audit normally looks.
  • Documented each leak as a finding with the owning team and the exact template file it lives in.
  • Delivered an Advanced Consent Mode audit and validation report with a 12-item prioritised fix list.
  • Split the fix list across three owners: website dev team (the two template tags), GTM owner (container items), CMP owner (OneTrust configuration and final sign-off comparison).
  • Every item on the list carries its own evidence and priority.

Results

  • 7 of the scanner's claims refuted against captured evidence, so no developer time was spent on them.
  • 2 real consent leaks identified, both hard-coded in the site template outside the tag manager.
  • 12-item prioritised fix list delivered, split across 3 owners (website dev team, GTM owner, CMP owner), with evidence and priority on every item.
  • GA4 advanced consent mode with behavioural modelling confirmed working. The audit kept the client's conversion data intact. The scan would have had the client switch it off.
  • The consent framework (OneTrust banner, tag manager gating, GA4 consent mode) validated end to end, with documented evidence.
  • The client now holds a written validation of its consent set-up to show a scanner vendor, an auditor, or a regulator.
Related Case Studies

Results That Speak for Themselves.

Migrating 9,000+ pages across 12 languages

Successful migration of 9,000+ pages across 12+ languages, with no critical downtime.

80% CPR reduction and 3x ROI over 6 years

Multi-channel strategy driving 50%+ monthly registration growth.

35% cost reduction while scaling SEO delivery globally

Ogilvy needed to scale SEO delivery across multiple markets without expanding headcount. Mavlers Agency stepped in as their invisible production partner.