frontend-compliance

Public on GitHub, 2026

Consent gating, analytics without PII and kids privacy as runnable TypeScript, with tests that fail if a tracker loads too early.

Context

Most of my work lives in private repositories. This is the public one, so you can read how I write code.

Problem

Writing on compliance is aimed at lawyers or infrastructure people. The person who implements it is whoever writes the component, and the failures happen on the client.

A sample of the end-to-end specs in the repository.

What I did

  1. A consent state machine and a single gate that every third-party tag has to pass through.
  2. Separate tag inventories for general and kids audiences, so kids ads fail at startup instead of in production.
  3. Normalization and SHA-256 hashing for conversion APIs, with shared event IDs for Pixel and server deduplication.
  4. Playwright specs that assert nothing fires before consent, that rejecting costs the same as accepting, and that no PII leaves in URLs or request bodies.
  5. An accessible consent dialog, checked with axe.

Outcome

  • 29 unit tests and 18 end-to-end specs, run in CI with a dependency audit.
  • Six engineering notes: consent, analytics without PII, children’s privacy, SOC 2 evidence, event deduplication and consent UI accessibility.

Source: github.com/raquel-mijares/frontend-compliance

Stack

TypeScript, Vite, Vitest, Playwright, axe-core, GitHub Actions

Want to talk about work like this?

I’m happy to go deeper on any of it, including what I’d do differently.