Skip to main content

Consent management and adding tools to our websites

Our websites use Usercentrics to ask visitors for consent. Visitors choose which categories of services they accept. A service is any tool on the website that processes visitor data, like an analytic…

Clemens Siebenhaar
Updated by Clemens Siebenhaar

Our websites use Usercentrics to ask visitors for consent. Visitors choose which categories of services they accept. A service is any tool on the website that processes visitor data, like an analytics tool or an advertising pixel. A service only loads when its category is accepted.

Consent is about more than cookies. It covers what a service does with visitor data, also when it doesn't set any cookies.

Several of our websites share one consent setup, including the Academy LMS and the customer portals.

We use three categories. They are the same on every website.

Category

What it covers

Examples

Essential

Needed for the website to work. Always active.

Google Tag Manager, fonts

Functional

Measuring and improving the website

Google Analytics 4

Marketing

Advertising platforms and conversion tracking for ads

Google Ads, Meta Pixel, Microsoft Advertising

Visitors accept or decline a whole category, not single tools. If someone accepts Marketing, all marketing tools can load.

You need a new tool on the website

Send a message to clemens.siebenhaar@sdworx.com with the name of the tool, the websites where you need it and what you want to use it for.

Adding a tool takes more than adding a script. We need to:

  1. Add the tool to Usercentrics in the right category. If Usercentrics doesn't know the tool yet, we ask their support to add it to their catalog.
  2. Add the tag to Google Tag Manager (GTM), so it only loads after consent.
  3. Allow the tool's domains in the Content Security Policy (CSP) of the website. The CSP is a list of domains the browser may load content from. Without the entry, the browser blocks the tool.

Changes are collected and published together. Each time we add, remove or switch off a tool, visitors who already answered the consent banner see it again. That's why we don't publish every change on its own. We decide when to publish in the weekly MT Update.

Please don't add scripts directly to a page or a form. They bypass the consent check.

Old OneTrust code

Before Usercentrics we used OneTrust. Old pages and forms can still contain code like this:

<script type="text/plain" class="optanon-category-C0002">...</script>

This code never runs anymore. OneTrust used to switch it on after consent. Usercentrics doesn't. If a form contains this code, it doesn't track anything.

If you find it, replace it. For Account Engagement forms, use the code from Account Engagement form key event tracking. Copied forms keep the code of the original, so check them as well.

For GTM users

Use the trigger of the tool. Each tool has a trigger Activate - <Tool> and a variable Consent Status - <Tool>. There are also triggers per category, like Activate - Functional Services. Use the one for the tool. When we publish changes in Usercentrics, the consent for a category becomes invalid until the visitor answers the banner again. The consent for each tool stays valid. Tags on a category trigger stop for returning visitors, tags on the tool trigger keep running.

The variable must match the name in Usercentrics exactly. Consent Status - Hotjar reads the key Hotjar. If the name doesn't match, the variable returns false and the tag never fires. GTM shows no error. After adding a tool, check in Preview mode that the variable returns true after you accept the category.

Google tags work differently. GA4 and the other Google tags don't use an Activate trigger. They fire on Initialization and use Consent Mode. Before consent they send data without cookies. After consent they work as usual. Don't move them to an Activate trigger.

Load order: The tag ALL - Set default consent and the Usercentrics template run on Consent Initialization, before every other tag. Keep it that way. Otherwise a tag can fire before the consent check.

How did we do?

Channel groupings in Google Analytics and Salesforce

Contact