The Client
A German digital marketing agency, working for a dental practice in Hamburg. The agency handles the practice's website and Google Ads and brought me in to set up conversion tracking and cookie consent on the practice's WordPress site.
Dental practices in Germany handle health data, so the agency set strict rules up front: no tracking before consent, nothing that could reveal a treatment or condition, and no remarketing or personal data in Google Ads.
The Problem
The site had tracking tools installed, but they weren't compliant and weren't measuring what the practice needed.
- The cookie banner never appeared. The site's domain wasn't authorized in Cookiebot, so no visitor ever saw the banner or could give consent.
- Tags loaded from several places. Google Site Kit and Cookiebot each tried to load Google Tag Manager, creating duplicate consent events and an unclear setup.
- URLs revealed treatments. Standard GA4 sends the full page URL and title. A visit to a page like
/zahnimplantat-hamburg/tells Google that a specific person is interested in dental implants, which can count as health data under Art. 9 GDPR. - Automatic tracking collected sensitive details. GA4's Enhanced Measurement captured internal search terms (such as “Zahnschmerzen”, toothache) and full outbound link URLs.
- The emergency link counted as a booking. Clicks on the emergency service link would have been reported to Google Ads as appointment conversions, and an event name like “urgent” would itself hint at acute pain.
- Form submissions were overcounted. The form trigger fired on every submit attempt, including ones that failed validation.
What I Did
A tracking setup where consent comes first and every piece of data is cleaned in the browser before it reaches Google.
A visitor accepts statistics in the Cookiebot banner ↓ One WordPress snippet loads Google Tag Manager ↓ GTM variables sanitize the URL, title and referrer ↓ GA4 records page views, scrolls and three generic events ↓ Google Ads imports two conversions from GA4
Consent before anything loads
I fixed the Cookiebot domain authorization so the banner appears, and loaded Google Tag Manager through a single WordPress snippet that Cookiebot blocks until the visitor accepts statistics. Without consent, the browser sends no request to Google at all. I removed the duplicate tag loading from Site Kit and Cookiebot so GTM became the only source.
URL, title and referrer sanitization
I wrote three GTM variables that rewrite what GA4 receives. They use an allowlist: only pages like the homepage, team or contact page keep their real path, every individual treatment page becomes /treatment/ with the title “Behandlung”, and any unknown page becomes /other/. Referrers are cut to the domain, and only the URL parameters needed for ad attribution (gclid, gbraid, wbraid, basic UTMs) survive. New pages the practice adds later are generalized automatically.
Generic events only
Three events with neutral names: appointment_click, contact_form_success and facebook_click. The emergency link is excluded from bookings with a text-based rule that also covers clicks on its icon, and the form event fires only when the success message appears, not on failed submissions.
Locked-down GA4
Google signals, granular location data and ads personalization are off, data retention is 2 months, and Enhanced Measurement is reduced to page views and scrolls. Site search, outbound clicks and form interactions are disabled.
Google Ads without personal data
Instead of placing an Ads tag on the site, I linked GA4 to Google Ads and imported the two key events as conversions. Ads only receives the already-sanitized data, with no Enhanced Conversions, remarketing or audiences. I also disabled Jetpack Stats, which sent visitor data to the US.
Documentation for the data protection review
A German-language document covering every tag, trigger, consent category, event parameter, suppressed field, data transfer and retention setting, so the practice's data protection officer could approve the setup before go-live.
The Stack
Everything runs on the practice's existing WordPress site; no new hosting or paid tools were added.
| Layer | Tool | Role |
|---|---|---|
| Website | WordPress (Gutenverse) | Practice website |
| Consent | Cookiebot, Google Consent Mode V2 (basic) | Banner, consent storage, blocking scripts until opt-in |
| Tag loading | WPCode | Loads GTM site-wide, gated by Cookiebot |
| Tag management | Google Tag Manager | All tags, triggers and custom JavaScript variables |
| Analytics | Google Analytics 4 | Page views, scrolls and three generic events |
| Advertising | Google Ads | Two conversions imported from GA4 |
| Reporting | Google Site Kit | Dashboard in WordPress only, no tracking code |
| Testing | GTM Preview, Tag Assistant, GA4 DebugView, browser DevTools | Verifying consent states and every outgoing value |
The Result
The practice now measures bookings and enquiries in GA4 and Google Ads while no treatment or health detail leaves the browser, and the agency received a setup its data protection officer could review line by line.
| Before | After |
|---|---|
| Cookie banner shown to 0% of visitors | Banner shown to every visitor, with a reject option |
| GTM loaded from 2 sources besides the intended one | 1 source, gated by consent |
| 9 treatment pages sent to Google under their real URLs | All 9 sent as one generic /treatment/ path |
| Search terms and outbound link URLs collected automatically | 0 search terms or link URLs sent |
| Emergency clicks would count as bookings | 0 emergency clicks in booking conversions |
| Form counted every submit attempt | Only successful submissions counted |
| No conversions in Google Ads | 2 conversions, with no Enhanced Conversions, remarketing or audiences |
- 0 requests to Google before consent, verified in GTM Preview and the browser's network panel.
- Every case tested: treatment pages, search parameters, consent accepted and rejected, emergency link, form errors.
- Delivered in 3 days, from the client's compliance requirements to the published container and the German documentation.
The agency's feedback on delivery: “Great, thank you so much.”
If your tracking has to hold up to a data protection review, get in touch.