Purpose at entry
Why is the record needed, which fields are necessary, what choice is offered, and what should happen when a person refuses?
Data trail
A real record may pass through a browser, API, application database, analytics property, email service, support export, log, backup, and staff device. Map that route before deciding what the product can honestly tell a user.
Why is the record needed, which fields are necessary, what choice is offered, and what should happen when a person refuses?
Which roles, processors, AI tools, integrations, and support staff can see or change it? Where are permissions broader than the task?
Find vendor storage, subprocessors, logs, exports, backups, remote access, transfers, and manual workarounds outside the main database.
Define retention, deletion, closure, correction, access requests, backup aging, incident decisions, communications, and proof of completion.
Consent field test
Check which tags load before a selection, what a refusal changes, whether preferences can be reopened, how a withdrawal propagates, and what evidence remains. Norway's current rules and the actual technologies need a fresh applicability review; the Norwegian Data Protection Authority is an official starting point.
This site uses one Norway GA4 property to separate its traffic and direct-contact click events.
A separate property does not settle notice, consent, retention, transfer, user-right, or vendor-duty questions.
Advertising, profiling, and additional non-essential tracking are not silently included in the engineering scope.
Bring the vendor list, access roles, exports, and backup behavior—not only the public privacy copy.