Home / Help Center / Tracker blocking and enforcement

Privacy Setup

Tracker blocking and enforcement

Configure Growth tracker blocking rules that hold analytics and marketing tags until consent. Pro users see this as an optional upgrade step.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

June 2026

Reading time

3 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

When to use this

Tracker blocking is Step 4 of setup. On Growth, this step lets you configure enforcement modes, custom per-domain rules, deeper GTM integration, consent replay verification, and editable tracking policies. On Pro, Step 4 is shown as optional because the plan includes runtime monitoring and consent banner publishing, but not dashboard-configured tracker blocking rules. Upgrade to Growth if you need managed pre-consent blocking configuration.

Use this article when analytics still fire before consent despite a visible banner, when you migrate from another CMP, or when you need to align Google Consent Mode v2 signals with enforcement. Blocking without a published banner is ineffective because the engine needs category state.

Saving enforcement mode in the dashboard writes to your site consent record; runtime verification’s blocking check reads this state on the next visit.

Server-side tags (CAPI, server GTM) still need policy basis in your privacy notice—blocking in browser does not eliminate backend processing you operate separately.

Periodic re-audit after adding new pixels: marketing often ships tags without filing CMP tickets; monthly diff of scan tracker list versus prior month catches drift.

Step-by-step instructions

  1. Open Dashboard → Consent → Tracker blocking (or Setup Step 4). Site-scoped routes also appear under your site’s tracker-blocking page.
  2. Review detected or suggested third-party domains from scans and runtime telemetry where shown.
  3. Select an enforcement mode appropriate for your stack—strict pre-consent blocking is recommended for GA4 and ads tags.
  4. Map Google tags to Consent Mode defaults if you use GTM; update triggers so tags respect updated consent snapshots.
  5. Add custom allow/block rules for niche pixels, then save policies explicitly.
  6. Publish or sync consent configuration if the UI links blocking to published config.
  7. Visit your site without accepting marketing cookies and confirm in Network tab that blocked domains do not return 200 for tracking pixels.
  8. Accept marketing in the banner and confirm allowed tags resume (Growth replay verification automates this).
  9. Mark Step 4 complete in setup when enforcement mode is saved and runtime verification later shows blocking active.

Expected result

Before consent, analytics and marketing requests are suppressed or held per your mode. After granular accept, only approved categories load their tags. Setup Step 4 shows completed, and runtime verification reports blocking engine active.

Protection and Runtime Health views display blocked request counts over time on Growth, giving ongoing assurance—not only a one-time test.

Document enforcement mode in change tickets when marketing blames missing analytics—reviewers can confirm whether strict blocking was intentional versus misconfigured GTM consent updates.

Troubleshooting

Google Analytics still records pre-consent

Verify the GA tag fires through GTM after GDPRChecker boot. Set Consent Mode defaults to denied for analytics and ads until update. Remove duplicate hardcoded gtag installs outside GTM that bypass enforcement.

Custom rule not applied

Advanced rules require Growth. Confirm rule saved, published config refreshed, and page reloaded. Wildcard domains must match the exact request host seen in Network panel.

Blocking breaks embedded videos

Classify necessary embeds separately or allowlisted domains in custom rules. Necessary category should stay minimal—document why each exception is essential.

Step 4 is optional on Pro

Tracker blocking setup is Growth-only. Pro users see Step 4 marked optional, then continue to Step 5 · Legal Pages before Runtime Verification. Upgrade to Growth if you need dashboard-configured tracker blocking.

FAQ

What enforcement mode should I pick first?
Start strict for analytics and marketing until replay tests pass. Loosen only when legal approves specific tags as necessary and documentation exists in policy.
Does GDPRChecker replace my tag manager?
No. It coordinates consent and blocking with your existing GTM or hardcoded tags. You still manage tag definitions; GDPRChecker governs when they may fire.
What is consent replay verification?
A Growth feature that checks trackers stay blocked before consent and release after accept. Use it after changing rules or major site releases.

GDPRChecker help articles provide product guidance and do not constitute legal advice. Use them for setup and troubleshooting, and consult qualified counsel for legal interpretation.

Need hands-on verification?

Use the compliance scanner or open your dashboard to finish setup and go live.