Marketing Privacy Compliance Checklist: Notices, Consent, Vendors, and Rights Requests

By ·

Sixteen phases for the privacy work a consumer brand's marketing stack actually generates, ordered by risk reduction per dollar rather than by statute. Phase one is a three-pass tag inventory including a network capture, because the tag manager tells you what marketing thinks is running and the capture tells you what is running. Early phases handle the four fixes that remove most litigation exposure in six weeks - session replay, consent gating, URL restructuring, and sensitive-page tag suppression. Later phases build the sale-and-share analysis, the recipient register, the contract terms that follow from it, the notice set including the financial incentive notice, the rights request workflow with verification and appeals, the marketing-channel consent records that decide TCPA cases, retention automation, and assessments. The last phase installs tag change control, which is what keeps the whole thing from decaying. One invented matter, Fernvale Wellness, runs throughout.

IP and Technology > Privacy Data Security | Checklist | Published 15 October 2023 - Updated 26 September 2025 | Casey Scott McKay - marksy.us

Summary. Sixteen phases for the privacy work a consumer brand's marketing stack actually generates, ordered by risk reduction per dollar rather than by statute. Phase one is a three-pass tag inventory including a network capture, because the tag manager tells you what marketing thinks is running and the capture tells you what is running. Early phases handle the four fixes that remove most litigation exposure in six weeks — session replay, consent gating, URL restructuring, and sensitive-page tag suppression. Later phases build the sale-and-share analysis, the recipient register, the contract terms that follow from it, the notice set including the financial incentive notice, the rights request workflow with verification and appeals, the marketing-channel consent records that decide TCPA cases, retention automation, and assessments. The last phase installs tag change control, which is what keeps the whole thing from decaying. One invented matter, Fernvale Wellness, runs throughout.

Keywords: tag inventory · network capture audit · url sensitivity review · session replay removal · consent gating · global privacy control · sale and share analysis · service provider recategorization · processor contract terms · privacy notice rewrite · just-in-time notice · financial incentive notice · rights request workflow · verification and appeals · tcpa consent record · can-spam opt-out testing · coppa assessment · biometric consent · retention automation · tag change control


What this checklist is for

This is the working document for the privacy obligations a marketing stack creates. It does not re-teach the law. If you cannot say in one sentence why a supplement company can be sued under the Video Privacy Protection Act, read The Data Behind the Marketing first. The reasoning behind each box — why the network capture beats the tag manager export, why URLs are legal artifacts, why the sale-and-share analysis precedes the contracts — is in Building a Privacy Compliance Program for a Consumer Brand. This document tells you what to do, in order.

Who should use it. In-house counsel at a consumer brand with no privacy engineer; outside counsel scoping a remediation; a general counsel who has just received a demand letter about a pixel; and anyone who has been told the company is "CCPA compliant" and wants to verify it.

What you'll need before you start. Administrative access to the tag manager; a browser with developer tools; the mobile app dependency manifests; the vendor contract file; the current privacy notice with its version history; the SMS and email platform consent exports; the loyalty program terms; and engineering time, because roughly half of this is engineering work.

The worked matter. Fernvale Wellness — direct-to-consumer supplements and at-home diagnostic kits, $70 million revenue, a video content library, a product-recommendation quiz, a loyalty program, an SMS program, and aggressive retargeting. The audit finds 31 production tags of which marketing can identify 19; a conversion pixel firing on /quiz/results/thyroid-support; site-wide session replay including checkout; a consent banner that loads after the tags; a 2021 privacy notice that omits three vendors; no Global Privacy Control; SMS consent records with no disclosure text; and three vendor contracts with no processor terms.

| Phase | What you accomplish | Typical elapsed time | |---|---|---| | 1 | Three-pass tag inventory | 2-4 weeks | | 2 | The week-one emergency fixes | 1 week | | 3 | URL sensitivity review and restructuring | 3-6 weeks | | 4 | Consent architecture that gates | 1-2 weeks | | 5 | Universal opt-out signals | 1 week | | 6 | Sale-and-share analysis and recipient register | 4-8 weeks | | 7 | Vendor contract remediation | 6-12 weeks | | 8 | Notice rewrite and just-in-time notices | 4 weeks | | 9 | Financial incentive notice | 1 week | | 10 | Rights request workflow | 8 weeks | | 11 | Marketing channel consent records | 4 weeks | | 12 | Special categories: children, biometrics, health, video | 3-6 weeks | | 13 | Retention, deletion, and de-identification | 8 weeks | | 14 | Data protection assessments | 4 weeks | | 15 | Incident playbook | 2 weeks | | 16 | Tag change control and quarterly audit | ongoing |


Phase 1 — Three-pass tag inventory


Phase 2 — The week-one emergency fixes


Phase 3 — URL sensitivity review and restructuring


Phase 4 — Consent architecture that gates


Phase 5 — Universal opt-out signals


Phase 6 — Sale-and-share analysis and recipient register


Phase 7 — Vendor contract remediation


Phase 8 — Notice rewrite and just-in-time notices


Phase 9 — Financial incentive notice


Phase 10 — Rights request workflow


Phase 11 — Marketing channel consent records


Phase 12 — Special categories


Phase 13 — Retention, deletion, and de-identification


Phase 14 — Data protection assessments


Phase 15 — Incident playbook


Phase 16 — Tag change control and quarterly audit


Phase 6A — The other doors data comes in through

Pixels get the attention. Most of a brand's data arrives through channels the marketing team designed as engagement, and each carries its own obligations.

Phase 16A — The quarterly and annual calendar

Everything above decays on a predictable schedule. Put the maintenance on a calendar owned by a named person and it survives; leave it to judgment and it does not.

Quarterly.

Annually.

On every material change.


Key Authorities at a Glance

| Authority | What it provides | Phase | |---|---|---| | 15 U.S.C. § 45 | Deception, unfairness, dark patterns | 4 | | 18 U.S.C. § 2710 | Video Privacy Protection Act | 2, 12 | | 18 U.S.C. §§ 2510-2523 | Federal Wiretap Act | 2 | | Cal. Penal Code §§ 630-638 | CIPA | 2 | | Cal. Civ. Code §§ 1798.100-1798.199.100 | Rights, notices, contracts, opt-outs | 5-10 | | Cal. Civ. Code § 1798.140 | Sale and share definitions | 6 | | Colo. Rev. Stat. § 6-1-1301 | Universal opt-out | 5 | | Conn. Gen. Stat. § 42-515 | Appeals | 10 | | Va. Code § 59.1-575 | Rights and assessments | 10, 14 | | Tex. Bus. & Com. Code § 541.001 | Texas comprehensive statute | 8 | | Wash. Rev. Code ch. 19.373 | Consumer health data; private right of action | 12 | | 740 ILCS 14 | BIPA | 12 | | Rosenbach v. Six Flags Entm't Corp., 129 N.E.3d 1197 (Ill. 2019) | No actual injury required | 12 | | Cothron v. White Castle Sys., Inc., 216 N.E.3d 918 (Ill. 2023) | Per-scan accrual | 12 | | Tex. Bus. & Com. Code § 503.001 | Texas biometric statute | 12 | | 15 U.S.C. §§ 6501-6506 | COPPA | 12 | | 16 C.F.R. Part 312 | COPPA Rule | 12 | | 47 U.S.C. § 227 | TCPA | 11 | | 47 C.F.R. § 64.1200 | TCPA rules | 11 | | Facebook, Inc. v. Duguid, 592 U.S. 395 (2021) | Autodialer definition | 11 | | 15 U.S.C. § 7704 | CAN-SPAM | 11 | | 16 C.F.R. Part 316 | CAN-SPAM Rule | 11 | | 16 C.F.R. Part 310 | Telemarketing Sales Rule | 11 | | 16 C.F.R. Part 318 | Health Breach Notification Rule | 12, 15 | | 16 C.F.R. Part 425 | Negative option and cancellation | 11 | | 15 U.S.C. § 1681 | FCRA, background screening | 12 | | TransUnion LLC v. Ramirez, 594 U.S. 413 (2021) | Concrete harm and standing | 1 | | Regulation (EU) 2016/679 | GDPR, where EU users are in scope | 4 |

The five things people get wrong

Trusting the tag manager export. It lists what marketing knows about. The network capture lists what is running, and the gap is where the exposure lives.

Writing the privacy notice first. A notice drafted before the inventory is a more precise description of something unverified, and an inaccurate notice is a deception problem on top of the underlying one.

Treating the banner as the fix. A banner that appears while the tags are already firing provides no defense and adds a second violation, because it tells the user something untrue.

Ignoring the URL. Every tag on a page receives the page path. A path that names a condition transmits that condition to every third party, regardless of what any tag was configured to send.

Skipping tag change control. Everything in this checklist decays without it, because each new tag is added by a reasonable person solving a reasonable problem.

Related Documents

Articles

Guides

Checklists

Toolkits


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Trademark and copyright outcomes turn on specific facts. Marksy is not a law firm.

Read this article on Marksy