
Open the visual model ↗
A claim, a packet, and a legal conclusion are different things
The useful distinction in the imported privacy research is between observable technical behaviour, contractual promises, and a legal interpretation of both. A product can promise limited processing while its default configuration calls other parties. A network trace can show a request without establishing the recipient’s full retention or reuse practice.
Keep these evidence types in separate fields. Record the observed component and version, the relevant contract clause, the unresolved question, and who can answer it. “Yes, by default” is not an adequate explanation of a setting.
Two data paths to put on paper
For a direct contextual placement, map the page request, ad decision, creative delivery, any impression beacon, optional frequency control, click redirect, landing page, and aggregate report. A simple placement can acquire third parties through externally hosted creative or an advertiser-supplied pixel.
For a programmatic path, add the consent manager, wrapper, identity components, supply-side partners, demand-side recipients, ad server, creative hosts, measurement services, and synchronisation calls. Document which requests happen before a choice, after rejection, after acceptance, and after withdrawal. These are templates to inspect, not a statement that every vendor behaves identically.
| Field | What to capture |
|---|---|
| Component and endpoint | Product, configuration version, hostname, and responsible entity |
| Purpose | Selection, delivery, measurement, fraud prevention, or another defined use |
| Information | Identifiers, URL and query string, IP handling, device details, consent signal |
| Storage and transmission | Browser keys, recipient chain, retention, onward use |
| Choice state | Absent, accepted, rejected, withdrawn, or applicable opt-out signal |
| Evidence | Dated capture, vendor documentation, contract reference, unresolved legal question |
Ask for evidence that survives a configuration change
The research questionnaire covers identity, roles, technical behaviour, data handling, youth and sensitive contexts, supply-chain quality, and marketing claims. Use those families to assign an owner and an unanswered-question log. The following is a reusable review checklist, not an invitation to contact vendors automatically.
- Which legal entities process information, for which purposes, and under which claimed roles?
- Which cookies, browser keys, endpoints, identity techniques, and fourth parties are used?
- What happens with absent, malformed, rejected, or withdrawn consent and relevant opt-out signals?
- Can query strings or sensitive page context be removed before transmission?
- What are the retention, deletion, access, transfer, and subprocessor terms?
- Which per-page youth or sensitive-context controls propagate downstream?
- How can a creative, advertiser, or demand partner be blocked, and how is propagation tested?
- What evidence supports claims about anonymity, consent, or privacy, and what audit rights exist?
Make the acceptance test match the promise
Use a clean browser profile and capture the normal and failure paths. Compare the observed endpoints with the inventory rather than only the consent-manager vendor list. Repeat after a material release, a new partner, or a purpose change.
Treat contractual review and technical testing as complementary. Retain evidence safely with a defined deletion schedule; an ad-operations investigation should not become an unbounded store of reader data. The implementation and review work remains to be done for any live service.
Sources & limits
Flow maps and checklists are proposed review methods. No vendor configuration or live data flow has been audited by this article.
Adapted from supplied research. See the evidence and review method. Section source notes identify supporting references; operational suggestions remain editorial judgment.
- ICO: Guidance on storage and access technologies
Primary guidance · Source updated 29 April 2026 · Primary source checked · 15 September 2026 - ICO: How do the rules apply to online advertising?
Primary guidance · Publication date not stated · Primary source checked · 15 September 2026 - EDPB Guidelines 2/2023: Technical scope of Article 5(3)
Primary guidance · Source published 16 October 2024 · Primary source checked · 15 September 2026
Source claims and editorial judgments remain separate. Send a correction with the passage and supporting evidence.


