Glossary
Terms and acronyms used in ConsentIQ reports and dashboards.
Tracking & Analytics
GA4
Google Analytics 4
Google's current web analytics platform. Requires Consent Mode v2 for EEA traffic. Succeeded Universal Analytics (UA), which was sunset July 2024.
GTM
Google Tag Manager
A tag management system that deploys and manages tracking scripts (GA4, Meta Pixel, etc.) without editing website code. Consent prerequisites for each tag are configured in GTM.
sGTM
Server-side Google Tag Manager
A server-hosted GTM container. Data is sent to a server before being forwarded to third-party vendors, instead of firing tags directly in the visitor's browser.
UA
Universal Analytics
Google's previous analytics platform, sunset July 2024. Tags still present after the sunset date no longer process data but indicate incomplete migration.
AA
Adobe Analytics
Adobe's enterprise analytics platform (part of Adobe Experience Cloud). Uses AppMeasurement or the Adobe Web SDK for data collection.
CM360
Campaign Manager 360
Google's ad server (formerly DoubleClick Campaign Manager). Uses Floodlight tags to track ad conversions and audience data across campaigns.
Consent Technology
CMP
Consent Management Platform
Software that presents a consent banner to visitors and records their choices. Examples include OneTrust, Cookiebot, CookieYes, Usercentrics, and iubenda.
TCF
Transparency and Consent Framework
An IAB standard for passing consent signals between CMPs, publishers, and advertising technology vendors. Required by many programmatic advertising systems.
IAB
Interactive Advertising Bureau
Industry body that publishes the TCF standard and advertising technology guidelines used across the programmatic advertising ecosystem.
GPC
Global Privacy Control
A browser signal that communicates a user's preference not to have their data sold or shared. Must be honoured under CCPA/CPRA and some US state privacy laws including NHPA.
SRI
Subresource Integrity
A browser security feature that verifies a third-party script has not been tampered with, using a cryptographic hash in the
integrity attribute. Guards against supply-chain attacks.
PII
Personally Identifiable Information
Any data that can identify an individual — name, email address, phone number, IP address, or device identifiers. Sending PII to analytics platforms without consent is a direct GDPR violation.
DOM
Document Object Model
The in-memory representation of a web page's HTML structure as seen by a browser. ConsentIQ uses DOM inspection to detect consent banners, dark patterns, and tag behaviour.
Privacy Regulations
GDPR
General Data Protection Regulation
EU law governing collection and processing of personal data. Applies to any organisation processing data of EU/EEA residents. Fines up to €20M or 4% of global annual turnover.
PECR
Privacy and Electronic Communications Regulations
UK regulations governing the use of cookies and similar technologies. Requires prior consent before setting non-essential cookies. Enforced by the ICO.
CCPA
California Consumer Privacy Act
California privacy law giving consumers rights over their personal data, including the right to opt out of the sale of personal information. Enforced by the California Attorney General and CPPA.
CPRA
California Privacy Rights Act
2023 amendment to the CCPA that created the California Privacy Protection Agency (CPPA) and added consumer rights around sensitive personal information.
CTDPA
Connecticut Data Privacy Act
Connecticut's comprehensive privacy law. Penalties up to $5,000 per wilful violation. The cure period ended January 2025, meaning violations are now immediately actionable.
NHPA
New Hampshire Privacy Act
New Hampshire's privacy law, effective January 2025. Requires businesses to honour the Global Privacy Control (GPC) browser signal as a valid opt-out.
EEA
European Economic Area
The 27 EU member states plus Norway, Iceland, and Liechtenstein. GDPR applies to personal data of EEA residents regardless of where the processing organisation is located.
SCCs
Standard Contractual Clauses
Pre-approved EU/UK contract clauses used to legitimise transfers of personal data to countries without an adequacy decision (e.g. the United States).
DSAR
Data Subject Access Request
A formal request by an individual to access the personal data an organisation holds about them. GDPR gives individuals the right to submit DSARs and requires a response within 30 days.
ROPA
Records of Processing Activities
A document required under GDPR Art. 30 that lists all personal data processing activities carried out by an organisation, including purposes, legal bases, and retention periods.
Regulators & Bodies
ICO
Information Commissioner's Office
The UK's data protection regulator, responsible for enforcing UK GDPR and PECR. Issues fines and enforcement notices for cookie consent violations.
CNIL
Commission Nationale de l'Informatique et des Libertés
France's data protection authority, known for active enforcement of cookie consent requirements. Has issued significant fines for Meta Pixel and cookie banner dark patterns.
EDPB
European Data Protection Board
The EU body that coordinates GDPR enforcement across member states and issues binding guidelines on topics including consent, dark patterns, and cookies.
FTC
Federal Trade Commission
US federal agency with authority to enforce privacy and data security under its unfair or deceptive practices mandate. Increasingly active on dark patterns and undisclosed data sharing.
DPA
Data Protection Authority
The national or regional regulatory body responsible for enforcing data protection law. Each EU country has its own DPA (e.g. ICO in the UK, CNIL in France, BfDI in Germany).
Check Identifiers
Each check in a ConsentIQ audit is assigned an ID with a prefix indicating its module. The number indicates the specific check within that module.
CHK
Consent module checks
CHK-001 to CHK-027 cover the consent audit: GTM loading, Consent Mode, banner behaviour, privacy policy checks, and consent pattern analysis. Core module — always scored.
GA4
GA4 module checks
GA4-001 to GA4-014 cover the Google Analytics 4 audit: tag presence, consent compliance, Consent Mode parameters, duplicate tags, and PII detection. Core module — always scored.
GTM
GTM Container module checks
GTM-001 to GTM-017 cover GTM container governance: consent prerequisites, paused tags, trigger conflicts, container size, debug mode, and security issues. Core module — always scored.
AA
Adobe Analytics module checks
AA-001 to AA-010 cover the Adobe Analytics audit. Optional module — only scored when Adobe Analytics is detected on the page.
FL
Floodlight / CM360 module checks
FL-001 to FL-007 cover Campaign Manager 360 Floodlight tags: consent compliance, duplicate activities, page targeting, and PII in URLs. Optional module — only scored when Floodlight tags are detected.
SP
Social Pixels module checks
SP-001 to SP-010 cover social advertising pixels: Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, and Pinterest Tag. Optional module — only scored when social pixels are detected.
CKS
Cookie Security module checks
CKS-001 to CKS-010 cover cookie attributes: Secure flag, HttpOnly flag, SameSite, expiry duration, HTTPS enforcement, and domain scope. Optional module — scored when any cookies are present.
This glossary covers the key terms used in ConsentIQ reports and dashboards. For detailed technical information on any specific check, refer to the finding detail in your audit report.