Most leadership teams I meet still think of tracking as a technical detail that IT or the agency handles. That was true five years ago. Today, with Consent Mode v2 and a cookie landscape where a growing share of visitors decline tracking cookies, the tracking architecture is a direct determinant of how accurate your marketing decisions are—and therefore a leadership responsibility, not just a technical matter.
Why Client-Side Tracking Alone No Longer Holds Up
Traditional client-side tracking (a pixel or script running in the user's browser) depends on the browser allowing it to run and the user granting consent. Browser restrictions (Safari's ITP, Firefox's tracking protection) and a growing number of users actively declining cookies under Consent Mode mean a significant share of your real traffic and conversions never get measured correctly—not because they didn't happen, but because the measurement method couldn't see them.
The consequence isn't just "a bit less data." It's systematic undermeasurement of specific channels and segments (typically mobile, Safari users, and privacy-conscious segments), which skews your attribution and optimization decisions in exactly the same way as the last-click problem—just at a technical level instead of a methodological one.
What Consent Mode v2 Actually Requires
Google requires Consent Mode v2 implementation to use full functionality in Google Ads and Analytics for EU traffic. Without a correctly implemented Consent Mode, you lose access to important remarketing and optimization features—not as a future risk, but as a current limitation for accounts that haven't updated their setup.
Server-Side Tracking as the Fix—The Governance Angle
Server-side tracking moves data handling from the user's browser to a server you control (typically via Google Tag Manager Server-side or an equivalent container). It provides three governance-relevant benefits: Better data quality—data sent server-side is less exposed to ad-blockers and browser restrictions, giving a more accurate picture of actual performance. Greater control over data—you decide exactly which data gets forwarded to which third parties, instead of a third-party pixel having free access to everything happening on your site. A stronger compliance position—server-side architecture makes it markedly easier to document and prove how personal data is processed, relevant both for GDPR and for upcoming regulation.
What Leadership Should Concretely Require of the Setup
You don't need to understand the technology. You need to require answers to five questions from your agency or internal team: What share of our conversions are measured server-side versus client-side today? Is Consent Mode v2 correctly implemented, and when was it last tested? Which data gets sent to which third parties, and is it documented? What happens to measurement when a user declines cookies—do we fall back on modeling, or do we lose the data point entirely? Who is responsible for keeping the CMP (Cookieinformation or similar) and consent signals synchronized with tracking as the platforms update their requirements?
If your team or agency can't clearly answer these five questions, you have a governance gap, regardless of how well your campaigns perform on paper.
The Practical Architecture (in Brief)
A modern, compliant tracking architecture typically consists of a CMP (Consent Management Platform, e.g., Cookieinformation) integrated with Google Tag Manager, a server-side GTM container that receives and forwards data based on the user's actual consent, and a first-party data strategy where as much of the valuable data as possible (leads, conversions, customer identity) is captured and owned by you rather than depending on third-party cookies that disappear over time.
Why This Is Strategic, Not Just Technical
An organization with solid server-side tracking and correct Consent Mode implementation simply measures more accurately than competitors still running pure client-side tracking. That means better bid optimization (the platforms have more real data points to optimize on), more reliable reporting to the board, and a stronger position if a regulator ever raises questions about your data handling.
This isn't a project you do once and forget. Consent requirements and platform requirements change continuously—it requires a quarterly governance check, not a one-time implementation expected to hold for years.