Skip to content
Scan your site free

The Etalon platform

Stop tracking after opt-out.
Keep the measurement your team needs.

Privacy laws are active in 20 U.S. states. For covered businesses, honoring opt-outs is a compliance requirement. Etalon Spectra finds marketing tags that keep firing after a visitor opts out. Etalon Opt-Out Mode enforces the choice in Google Tag Manager, and Etalon engineers rebuild measurement so compliant analytics remains useful.

An initial audit takes about 60 seconds.

Questions about your stack? Talk to an engineer
EtalonInteractive example
Illustrative diagnostic

Does the choice reach the tags?

01 Ready02 Opted out03 Enforced
Visitor choiceNo opt-out sent
READY
Tag layerEnforcement not applied
OFF
Marketing tagWaiting to test behavior
UNTESTED
Measurement pathWaiting to test behavior
UNTESTED
Start with the visitor’s choice.Simulate an opt-out to follow the signal.

Illustrative behavior only. No live site is being scanned.

20 active states Works with client-side GTMServer-side GTM optional

01 / The enforcement gap

Your CMP records the choice.
Your tags need to honor it.

A consent management platform (CMP) records the visitor’s choice. Your analytics and advertising infrastructure must respond to it. Etalon tests that response.

01

Preference

Your CMP, privacy interface, or applicable browser signal records the choice.

02

Enforcement

Etalon Opt-Out Mode applies the appropriate tracking behavior inside Google Tag Manager.

Etalon audits and verifies this behavior
03

Platforms like Google Ads and Meta

Only permitted activity should reach analytics and advertising platforms.

Etalon is a technical privacy enforcement and verification platform for marketing and analytics tracking. It evaluates what actually happens against supported U.S. state privacy rules for organizations subject to those requirements.

02 / The product workflow

From the first finding
to the next verification.

An audit shows where you stand. Implementation changes the behavior. QA tests the fix before a certificate is issued.

  1. 01

    Audit

    Scan your site and observe tags, cookies, and requests around an opt-out.

    Initial scan
  2. 02

    Diagnose

    Review vendor findings, affected rules, warnings, and remediation guidance.

    Technical report
  3. 03

    Implement

    Apply Etalon Opt-Out Mode in GTM with your team or Etalon engineers.

    Enforcement framework
  4. 04

    Validate

    Run QA against the corrected implementation. Address anything that still fails.

    QA scan
  5. 05

    Certify

    A passing QA scan enables a time-bound, verifiable technical certificate.

    90-day certificate
  6. 06

    Monitor

    Re-scan as your tracking stack and supported state requirements change.

    Ongoing verification

03 / Etalon Spectra

See what still fires.
Understand why it matters.

The initial audit observes tracking before and after a tested opt-out. The report connects the request to its vendor, the evaluated rule, and the next action.

Pre-implementation audit

example.com

11 Sep 2026 · 17:03 UTC Oregon · OCPA

Illustrative report

10 tags identified

5 FAIL2 WARN3 PASS

Risk level High

Selected findings · 4 of 10 detected tags
Vendor / categoryObserved destinationRequestsVerdict
Meta PixelAdvertisingconnect.facebook.net/…/fbevents.js2FAIL
Google AdsRemarketingad.doubleclick.net/ccm/…1FAIL
Google Analytics 4Analyticsanalytics.google.com/g/collect2WARN
Google Tag ManagerContainergoogletagmanager.com/gtm.js6PASS
Finding → rule → action

Advertising request observed after opt-out

The example flags a Meta Pixel request in the post-rejection capture window with a GPC signal active.

Remediation
Review the tag’s triggers and apply the appropriate suppression when an applicable opt-out is active. Re-run QA after implementation.
Selected cookies present at the end of the rejection capture window
CookieDomainAttributed vendorExpiry
_ga.example.comGoogle Analytics 416 Oct 2027
_gcl_au.example.comGoogle Ads10 Dec 2026
IDE.doubleclick.netGoogle Ads Remarketing16 Oct 2027
cookieyes-consent.example.com—11 Sep 2027

A cookie inventory is evidence to review alongside observed requests, configuration, and the the state laws checked. A cookie’s presence alone is not a complete legal determination.

Target URL
https://example.com
Scan started
11 Sep 2026 · 17:03 UTC
Duration / capture wait
43 seconds / 15 seconds
Rule set evaluated
Oregon · OCPA
GPC: HTTP / JavaScript
Applied / applied
CMP detected
CookieYes
Opt-out method
Banner interaction
CMP event confirmed
Yes
Baseline requests
295
Rejection-phase requests
234

Request counts describe observed traffic. They are not counts of legal violations.

Example content based on the audit report format. Domain anonymized.Technical findings · not legal advice

Evidence you can act on.

Scan configuration, tag inventory, cookie audit, per-tag findings, rule references, and a remediation roadmap make the result reviewable by your team.

A warning deserves review.

Some findings depend on vendor agreements and data-use configuration. WARN keeps those questions visible instead of treating every request as an automatic failure.

Scope stays visible.

Each report identifies the URL, time, signals, and laws evaluated. A single scan’s scope should not be confused with all available platform coverage.

04 / From finding to fix

Etalon Opt-Out Mode.
Put the choice into practice.

Etalon Opt-Out Mode is Etalon’s preconfigured Google Tag Manager enforcement framework for supported U.S. state privacy opt-out behavior.

Paid platform users can download the appropriate GTM configuration or template and implementation documentation for supported CMP environments.

Connect the privacy signal, configure your tags, and test the result. Your team gets an implementation starting point for state-specific enforcement.

Your team can deploy it. Ours can help.
CMP preferenceApplicable privacy signal
Inside Google Tag Manager

Etalon Opt-Out Mode

Evaluate supported state rules
Apply the appropriate tag behavior

  • Allow
  • Suppress
  • Restrict
  • Modify
  • Route

Conceptual outcomes depend on the rule, vendor, and configuration.

Architecture → implementation → verification

Three concepts.
One connected system.

Etalon enforcement layer The architecture
The Etalon enforcement layer is Etalon’s reference methodology for where privacy enforcement belongs across marketing and analytics infrastructure.
Etalon Opt-Out Mode The implementation
GTM logic and templates apply that methodology to your supported tracking environment.
Etalon The platform
Etalon Spectra audits behavior, reports findings, validates the implementation, and issues technical certification after passing QA.

Hard-coded scripts

Hard-coded, in Tag Manager, or both? Covered.

Most sites are a mix: some scripts and cookies hard-coded into the site, some tags in Google Tag Manager. Spectra flags every one that fires after a visitor says no, wherever it comes from. The fix is to strip the hard-coded scripts off the site and redeploy everything through Google Tag Manager. Your whole tracking stack then lives in one standard setup, easier to change and fully controlled by Opt-Out Mode.

05 / Your existing stack

Works with client-side GTM.
Extends when you need it.

Keep your CMP and your Google Tag Manager environment. Apply enforcement where the tracking decision is made, then verify the what actually happens.

Server-side GTM supported — not required.

Core implementation

Website

Privacy preference

CMP / privacy interface
Applicable GPC signal

Client-side Google Tag Manager

Etalon Opt-Out Mode

Enforcement before a tag sends data

Permitted platforms like Google Ads and Meta

Analytics & advertising

GA4 · Google Ads
Meta · LinkedIn · other endpoints

Optional extension
from client-side GTM
Server-side GTM

Additional enforcement and routing

Downstream platforms
after server-side checks

The direct client-side route is a complete implementation path. Add sGTM only when your architecture calls for it; testing scope depends on the configured environment.

Connect the CMP you already use.

Supported integrations

  • OneTrust
  • Cookiebot by Usercentrics
  • Usercentrics
  • Osano
  • Termly
  • CookieYes

Your CMP captures the choice. Etalon Opt-Out Mode applies it in GTM. Etalon checks what happens next.

06 / Validate the fix

An implemented fix
still needs a test.

A QA scan is the validation step after remediation. It tests applicable tracking behavior again and determines whether the implementation passes the evaluated checks.

Initial audit
Discover enforcement gaps and plan the remediation. An audit result does not issue a certificate.
QA validation
Re-test the corrected stack. Confirm the opt-out interaction and privacy signals, review per-tag verdicts, and address any remaining failures.

Certification follows a passing QA result. If QA finds unresolved issues, return to remediation and validate again.

QA verification reportIllustrative result
QA PASSED

Validation complete.

3Tags evaluated
0Fail
0Warn
Opt-out interaction
Confirmed
GPC: HTTP / JavaScript
Confirmed / confirmed
Per-tag results
3 passed
Next step
Issue technical certificate

Separate illustrative QA scan. This is not a before-and-after result for the audit example.

07 / Verifiable technical certification

Evidence with a scope,
a date, and a way to verify it.

A successful QA scan can issue an Etalon Compliance Certificate valid for 90 days. It documents the domain, the state laws checked, validation time, and expiration.

A unique certificate ID, verification URL, and QR code connect the issued document to Etalon’s verification system.

  1. Open the verification URL or scan the certificate’s QR code.
  2. Match the certificate ID, domain, and evaluated scope.
  3. Check the validation status and expiry against the verification record.

The certificate attests to the technical state observed by Etalon at validation. It is not a legal opinion or a guarantee of the organization’s overall legal compliance.

ETALON DATA LLCExample only

Etalon

Etalon Compliance
Certificate

Etalon Certified Illustrative status

Example Companyexample.com

Evaluated scope
Oregon · OCPA
Tracking-layer opt-out checks
Issued
Valid through
Certificate ID
ETL-2026-8F3A91C2
QR code linking to the illustrative certificate record on this page
Verify the recordOpen example verification

This demo QR opens the example below. It is not a live certificate.

Technical validation at the time of scan.
Etalon is not a law firm and does not provide legal advice.

Example verification record

ETL-2026-8F3A91C2 · example.com

Illustrative status: Etalon Certified. Scope: Oregon OCPA tracking-layer checks. Issued 11 September 2026, 17:01 UTC; expires 10 December 2026, 17:01 UTC.

This is a demonstration record, not an issued Etalon Compliance Certificate or a lookup against the production verification system.

08 / Continuous verification

Your stack changes.
Your evidence should keep up.

New tags, vendor updates, CMP changes, redesigns, and new state rules can change tracking behavior. Scheduled re-scans help surface drift between certifications.

Starting point

Certified implementation

A dated record of the validated state.

Change happens

Re-scan the stack

Review changed tags, vendors, signals, and rules.

Issue detected

Remediate and re-run QA.

Validation passes

Issue or renew technical certification.

An audit re-scan does not automatically renew a certificate. Fresh QA validation is required for re-certification. Scan scheduling depends on your plan.

09 / U.S. state coverage

One enforcement architecture.
State-specific validation.

The engine covers supported state privacy rules for tracking across 20 active states. Etalon monitors legislation, rule changes, and enforcement dates, updates the engine, and adds coverage as new laws take effect.

See every state and corresponding law
20active states
4upcoming states

Upcoming: Oklahoma, Louisiana, Alabama, and Vermont.

Coverage as of 9 September 2026. Statutory thresholds, scope, and exemptions vary. Florida’s law has a narrower scope; California’s CCPA and CPRA are grouped as one state.

EU, UK and Google Consent Mode

EU visitors. Google's consent rules. Same scan.

GDPR (EU and UK)

In the EU and UK, tracking needs consent before it starts. Spectra loads your site as an EU or UK visitor and flags every non-essential cookie and script that fires before a choice is made, or after the visitor clicks Reject. Covers GDPR and the ePrivacy rules, plus UK GDPR and PECR.

Google Consent Mode v2

Google requires Consent Mode v2 for ad measurement and remarketing on EU and UK traffic. Spectra checks that your Google tags receive the right consent signals (ad_storage, analytics_storage, ad_user_data and ad_personalization) before and after every choice, and flags a setup that sends the wrong ones.

11 / Implementation support

Your team can implement it.
Or ours can.

Use the platform and Etalon Opt-Out Mode with your own GTM expertise. When you need help, Etalon engineers can configure enforcement, remediate the stack, validate the result, and document the handoff.

Engineering, scoped to your environment.

  • GTM configuration and CMP integration
  • Etalon Opt-Out Mode deployment and tracking architecture review
  • GA4, Google Ads, Meta, and LinkedIn tracking configuration
  • Server-side GTM where appropriate
  • QA validation, documentation, and technical handoff

Scope depends on containers, domains, tags and vendors, CMP configuration, server-side architecture, and existing technical debt.

12 / Scope and responsibility

Where the platform stops,
and your legal team starts.

Technical verification is one part of privacy compliance. Legal applicability and organizational obligations require a separate legal and governance assessment.

Etalon’s technical scope

  • Observed tags, cookies, and network behavior
  • GTM enforcement through Etalon Opt-Out Mode
  • Supported CMP and privacy-signal integration
  • Technical findings, remediation, and QA validation
  • Time-bound technical certificates and re-scans

Your legal and privacy team’s scope

  • Legal interpretation, applicability, and exemptions
  • Policies, disclosures, and consumer notices
  • Vendor contracts and data-use agreements
  • Rights-request procedures and sensitive-data obligations
  • Organizational legal compliance and governance

13 / Spectra FAQ

The details behind
the workflow.

Answers for marketing, engineering, privacy, and legal teams.

Ask about your stack

The platform and scanner

What is Etalon?

Etalon is a technical privacy enforcement and verification platform for marketing and analytics tracking. It audits observed website behavior against supported U.S. state rules, reports enforcement gaps, validates remediation, and can issue time-bound technical certification after a passing QA scan.

What does Etalon Spectra actually test?

It observes tags, cookies, network requests, and vendor behavior around tested privacy opt-outs. The report records the CMP interaction, applicable privacy signals, and the state laws checked so your team can see what occurred during the capture window. A result applies to the recorded scan scope and conditions.

How is an audit scan different from a QA scan?

An initial audit discovers gaps and provides findings to guide implementation. QA is a separate scan after remediation: it rechecks the corrected behavior and determines whether the evaluated checks pass. A passing QA scan enables certification; an initial audit does not issue a certificate.

Does an audit scan modify my website?

The audit observes and interacts with your website’s privacy interface in a scan session. It does not deploy Etalon Opt-Out Mode or change your published GTM configuration. Your team or Etalon engineers perform implementation as a separate step.

What appears in the compliance report?

The report includes the target URL, scan time and configuration, laws evaluated, tag inventory, vendor platforms like Google Ads and Meta, request counts, PASS/WARN/FAIL findings, cookie inventory, rule references, and a remediation roadmap. Warnings can identify behavior that needs manual review of configuration or vendor agreements. Report access depends on the platform plan.

Enforcement and integrations

What is Etalon Opt-Out Mode?

Etalon Opt-Out Mode is Etalon’s preconfigured Google Tag Manager enforcement framework for supported U.S. state privacy opt-out behavior. Paid platform users can download the appropriate configuration or template and implementation documentation. It must be configured for the tracking environment and validated after deployment.

How do the Etalon enforcement layer, Etalon Opt-Out Mode, and Etalon relate?

The Etalon enforcement layer is Etalon’s reference architecture for where privacy enforcement belongs in the tracking stack. Etalon Opt-Out Mode implements that methodology through GTM logic and templates. Etalon is the platform that audits and verifies the resulting behavior.

Can I use normal client-side Google Tag Manager?

Yes. Etalon works with standard client-side Google Tag Manager environments. Etalon Opt-Out Mode can enforce tracking behavior there. Server-side GTM is supported but is not required, and you do not need to migrate to server-side tagging simply to use the platform.

Does Etalon also support server-side GTM?

Yes. Etalon can support and validate server-side Google Tag Manager environments when configured. The server-side extension adds enforcement and routing for downstream platforms where your architecture needs it. The implementation and validation scope should reflect the actual client-side and server-side setup.

Does Etalon replace my CMP or cookie banner?

No. Your CMP or privacy interface captures the visitor’s preference. Etalon Opt-Out Mode connects that preference to GTM enforcement. Etalon then observes and verifies the tracking behavior. These components have different responsibilities and work together.

Which CMPs does Etalon integrate with?

The supported integration list includes OneTrust, Cookiebot, Usercentrics, Osano, Termly, and CookieYes. The appropriate Etalon Opt-Out Mode configuration connects the supported CMP environment to your GTM implementation.

Can Etalon work without a CMP?

Etalon Opt-Out Mode can work without a CMP when the implementation receives the appropriate privacy preferences or applicable signals through another supported route. Your team still needs to configure and validate that route. Whether a particular privacy interface satisfies your organization’s legal obligations is a question for your legal team.

Does Etalon replace Google Consent Mode v2?

No. Consent Mode communicates consent states to Google tags and products. Etalon Opt-Out Mode applies Etalon’s additional state-specific enforcement logic across the supported tracking environment. They can coexist; neither a consent-state setting nor a banner alone proves that the entire stack behaves as intended.

How does Global Privacy Control fit into the platform?

Global Privacy Control (GPC) is a browser signal for communicating a privacy preference. Etalon’s report can record its HTTP and JavaScript presence during a scan and evaluate the observed tracking response against supported applicable rules. Requirements vary by state; the platform’s current coverage should guide implementation, rather than an old fixed list of GPC states.

Read the GPC technical specification.

QA and technical certification

What happens if QA still finds an issue?

Review the remaining findings, correct the implementation, and run QA again. Certification follows a passing QA result. A failed validation is an action item for remediation, not a certificate of compliance.

What does a Etalon Compliance Certificate verify?

It records the technical state observed by Etalon for a domain and the the state laws checked at the time of successful QA validation. It does not certify every aspect of an organization’s legal compliance, replace legal counsel, or guarantee future tracking behavior.

How long does certification remain valid?

Certificates are valid for 90 days from issuance. Fresh QA validation is required for re-certification. The issue and expiration dates remain part of the record so a certificate is not treated as permanent evidence.

How is a certificate verified?

Use the issued certificate’s verification URL or QR code to open Etalon’s verification record, then match the unique certificate ID, domain, scope, status, and expiry. The certificate shown on this page is an illustration; its link and QR code open a demonstration record, not the production verification system.

What if my tracking stack changes after certification?

A certificate describes the validated state at a particular time. Re-scan after material changes to tags, vendors, CMP configuration, or the site. If the audit finds a gap, remediate and re-run QA. Scheduled audit scans help monitor changes but do not automatically renew certification.

Coverage, data, and responsibilities

Which U.S. state laws does Etalon cover?

The current coverage register lists 20 active states and their corresponding laws, with four upcoming states listed separately. A scan report identifies which rules were actually evaluated in that run. Statutory thresholds, exemptions, and scope vary, so available state coverage does not mean every law applies to every organization.

View active and upcoming state coverage.

What happens when a new state law takes effect?

Etalon monitors legislation, rule changes, and enforcement dates, updates the engine, and adds state coverage as new laws become active. Upcoming coverage is distinguished from active coverage in the state register.

Does a scan collect data from my visitors’ sessions?

The scanner runs in a Etalon-controlled browser session rather than monitoring your visitors’ sessions. Its report records technical tracking information such as vendors, tag behavior, cookies, and network platforms like Google Ads and Meta. That scan-session evidence is different from collecting your visitors’ browsing histories or customer records.

Do I need to give Etalon GTM access for an audit?

The initial website audit observes the site from a browser and does not require a GTM deployment. Installing Etalon Opt-Out Mode is a separate implementation step that requires appropriate access to the GTM environment, whether performed by your team or Etalon engineers.

Does Etalon provide legal advice or guarantee legal compliance?

No. Etalon LLC is not a law firm and does not provide legal advice. The platform handles technical enforcement and verification. Legal interpretation, statutory applicability, policies, disclosures, contracts, rights-request procedures, and overall organizational legal compliance remain with your legal and privacy team.

Implementation

Can our own team implement the remediation?

Yes. Teams with GTM and privacy engineering expertise can configure the downloaded Etalon Opt-Out Mode template, connect their supported CMP or privacy-signal route, remediate the relevant tags, and use QA to validate the result. The template and documentation support implementation; they do not remove the need to configure and test your environment.

What if we do not have in-house GTM expertise?

Etalon engineers can scope and perform implementation and remediation, including GTM configuration, CMP integration, Etalon Opt-Out Mode deployment, optional server-side work, QA, and technical handoff. Scope depends on your domains, containers, vendors, CMP setup, and existing architecture.

Start with the evidence

See what your tracking stack does after opt-out.

Run a free scan Talk to an engineer

About 60 seconds to your initial audit.