🎯 pack: adtech-privacy-pack

Run tracking pixels without the VPPA class-action.

Loading the Meta Pixel, GA4, TikTok pixel, or session-replay (FullStory / Hotjar / LogRocket)? GreatCTO auto-attaches adtech-privacy-pack for the US web-tracking litigation surface: VPPA (video viewing + $2,500/violation), CIPA wiretap / pen-register (session replay), Washington MHMDA consumer-health data, state sale/share + Global Privacy Control, and FTC §5 policy-vs-reality.

Auto-attach signals

Detected by CLI when:

meta pixel · fbevents · ga4 · tiktok pixel · session replay · fullstory · hotjar · VPPA · CIPA · MHMDA

The pack rides on top of your base archetype (web-service, ai-system, fintech, …) — it doesn't replace it. Auto-injects reviewer agents into the pipeline + opens human gates listed below.

Reviewer agents activated

2 specialists added to the pipeline.

01 · adtech-privacy-reviewer

VPPA + CIPA wiretap/pen-register + MHMDA + state sale/share + GPC + FTC §5

02 · us-privacy-reviewer

CCPA/CPRA sale-share + universal opt-out / GPC

Human gates introduced

1 new gate type on top of gate:plan + gate:ship.

GateOwnerTrigger
gate:tracking-consentsecurity-officerno third-party tag fires before consent
Required artefacts before senior-dev claims tasks

6 concrete deliverables.

EVAL suite required

1 golden-set scenarios shipped as templates.

Each EVAL has ≥5 test cases, pass threshold, regression interpretation, cross-refs to TM + gates. Run via your existing test framework.

Regulatory surface covered

6 standards / regulations addressed.

VPPA (18 U.S.C. §2710) CIPA (Cal. Penal Code §631 / §638.51) Washington My Health My Data Act Nevada SB370 CCPA / CPRA FTC Act §5
FAQ

Common questions about adtech-privacy-pack.

When does adtech-privacy-pack auto-attach?
When the CLI detects these signals in your repo: meta pixel · fbevents · ga4 · tiktok pixel · session replay · fullstory · hotjar · VPPA · CIPA · MHMDA. Override anytime by editing packs: in PROJECT.md.
What human gates does adtech-privacy-pack introduce?
gate:tracking-consent (security-officer). These layer on top of the standard plan/ship gates.
What if my project doesn't match these signals exactly?
You can manually add the pack name to PROJECT.md or run /migrate to re-run detection with updated rules.
30 seconds

Drop GreatCTO into any repo — adtech-privacy-pack attaches automatically.

$ npx great-cto init
no signup·runs locally·pay your own API