Humans of Martech
Avsnitt

235: Why consent banners, tags and privacy policies never match, with Stéphane Hamel

Dela

What's up everyone, today we have the pleasure of sitting down with Stéphane Hamel, Founder and Product Architect at MANTIS.

  • (00:00) - Intro
  • (01:07) - In This Episode
  • (04:07) - How To Audit Which Trackers Are Firing On Your Website
  • (07:00) - Why Nobody On Your Team Owns The Tags Firing On Your Site
  • (11:22) - Why Your Consent Banner Does Not Match What Your Site Actually Does
  • (16:45) - Does Server Side Tagging Actually Improve Privacy Governance
  • (22:30) - Why Loading A Third Party Script Is Already A Privacy Risk
  • (27:30) - What Happens When You File A Privacy Complaint In Canada
  • (36:42) - Why AI Output Is Useless Without Domain Expertise
  • (41:58) - Is AI Removing The Training Path For Junior Marketers
  • (44:16) - When Vibe Coding Works And When It Falls Apart
  • (47:56) - Why Marketing And IT Still Fight Over Who Maintains The Stack
  • (52:02) - How To Decide Which Projects Deserve Your Energy


Summary: Stéphane Hamel built the first web analytics QA tool back in 2006, watched an ad blocker quietly borrow his logic, and spent the next 20 years learning that tracking got harder to see every year while the industry got better at documenting it. Now he's building MANTIS, a privacy observability platform that watches what a website actually does instead of what its policy claims. Along the way he audited his own credit bureau account after a breach, found trackers from companies that no longer exist sitting on the page displaying his credit file, and spent 2 years fighting to get them removed. He also coined the term vegetative AI, sold his house and furniture after one good vacation in the Rockies, and will tell you your consent banner is a receipt for a transaction nobody actually agreed to. Wait until you hear what a third party script collects before it fires a single tag.

About Stéphane Hamel

Stéphane Hamel is the founder and product architect of MANTIS, a privacy observability platform built to show what a website actually does at runtime rather than what its policy claims. He's spent 35 years across the full arc of digital analytics, building WASP in 2006 as the first web analytics quality assurance tool, publishing the Digital Analytics Maturity Model in 2009, and creating Da Vinci Tools, which was later acquired by Supermetrics.

He teaches MBA and EMBA students at Université Laval and advises privacy tech startups including Supermetrics, Caden, and Masthead Data. He's currently writing his first book on digital analytics concepts, and having been a victim of 2 of Canada's largest data breaches, he treats privacy as a trust problem rather than a legal one.

How To Audit Which Trackers Are Firing On Your Website

Open the network tab on your own company's homepage and count the outbound requests. Most marketers who try this land somewhere between 40 and 100 calls going to domains nobody on the current team approved. In 2006 that number was small enough to check by hand, and the only question worth asking was whether your analytics tag fired on the right page at the right moment.

That's the question Stéphane built WASP to answer. He was on the technical side back then, implementing trackers on client websites, and nobody in the room was talking about privacy or where any of this data ended up. The tool checked whether tags fired when they were supposed to and whether they collected the right information. It was quality assurance work, and it was the first tool of its kind.

That shift wasn't academic. Stéphane got hit by data leaks more than once, watched fraud follow, and spent 35 years consulting and teaching through every generation of the tracking stack. MANTIS is what came out the other side, and it asks a very different question than WASP did.

The new question has 3 parts:

What is actually loading on this website in terms of trackers, Whether any of those trackers fire without consent, What kind of data each one collects once it does

The hard part is the chain. Websites include third party scripts that load other scripts, a pattern Stéphane calls piggybacking, and every hop moves further from anything a marketer ever approved. Fingerprinting rides along in the same traffic. By the time a script 4 hops deep does something it shouldn't, nobody on the marketing team can name what triggered it or say where the data went.

So MANTIS is built for people who don't read network waterfalls for a living. Marketers, decision makers, privacy specialists, and the technical folks stuck doing QA on tags all need to see the same picture, and right now they each see a different slice of it. The industry spent 20 years getting very good at deploying tags and almost no time getting good at watching them. That gap is why most privacy programs audit documents instead of traffic, and why the documents keep passing while the traffic keeps failing.

Key takeaway: Run your own homepage through a network inspector before you click anything on the consent banner, and write down every third party domain that already received a request. Compare that list against the vendor list your consent management platform declares. Any domain in the first list that's missing from the second is a gap you own right now.

Why Nobody On Your Team Owns The Tags Firing On Your Site

Anyone can inspect a page now. Right click, open the debug console, watch the calls go out live. That was exotic in 2006 and it's table stakes today, which raises a reasonable objection to the whole category of tag surfacing tools. If the browser already shows you everything, what's left to build?

Stéphane's answer is that the console shows you the calls and tells you nothing about who authorized them. Working with technical people for 35 years, he's watched the gap widen. The traffic is visible. The accountability is gone.

There's a story from the WASP years he still turns over. Someone messaged him saying the tool should block the tags it found. He said no, that's not the purpose, the purpose is quality assurance. Shortly after, ad blockers took off, and he found some of his own logic sitting inside one of the very first ones. He had no way to prove it and no means to enforce anything. He was one guy solving his own problem, and the industry took the idea somewhere he hadn't intended.

20 years on, the reason tags go unowned has less to do with technology than with how many people handle a single pixel on its way to production. Stéphane walks through the cast:

The marketer, who asks for something and moves on, The software engineer, or the data engineer, depending on which fancy name the org uses this year, Legal, who reviews the words and doesn't get the technical constraints, The consent management platform vendor, whose position is that they provide a tool and don't provide legal advice

That's 4 groups, and not one of them can describe the whole system. That's before you count the agency your marketing lead handed tag manager access to, the one that said trust us, we know what we're doing, we're just going to put a tag on your website. Then somebody runs an audit 2 years later and finds tags firing that nobody recognizes.

Here's the part that should bother you more than it probably does. Every single tag is a privacy risk and a security risk at the same time. The moment you put third party JavaScript on your site, you've given someone else write access to your users' browsers, and that script can change tomorrow without telling you. It might start recording keystrokes. It might start fingerprinting. Stéphane notes that vendors coming out of the US tend to be particularly greedy about collection, and none of that requires a new contract or a new conversation.

What MANTIS does about it is draw a timeline. You got consent at t...

Podden och tillhörande omslagsbild på den här sidan tillhör Phil Gamache. Innehållet i podden är skapat av Phil Gamache och inte av, eller tillsammans med, Poddtoppen.