Case study · Circana

Consent management platform implementation case study: Circana

Three privacy platforms, one data and analytics business, and a set of jurisdictional requirements that do not agree with each other. What we can publish is limited. What the work involves is not a secret, so that is what this page explains.

OsanoSecuriti.aiOneTrustMulti-jurisdiction
Quick answer

Green Arrow Consultancy implemented privacy management platforms for Circana across Osano, Securiti.ai and OneTrust. Circana is a data and analytics business, so the work carried multi-jurisdiction requirements and unusually high expectations around data handling. Account detail is limited by confidentiality, so this page describes the practice: discovery, tag governance, regional rule sets and testing.

Scope of disclosure

What this page can and cannot say

Circana LLC is a data and analytics business. Green Arrow Consultancy carried out privacy management platform implementation for them across three platforms: Osano, Securiti.ai and OneTrust.

That is close to the full extent of what we are able to publish. Privacy engagements come with confidentiality agreements, and they should. A client who has just completed a discovery exercise across their estate has, by definition, a written list of things that were not right before the project started. Publishing that as a marketing asset would be a poor way to repay the trust involved in commissioning it.

So this page is written differently from a normal case study. Rather than invent account detail or dress up generalities as findings, it sets out the practitioner-level detail of what a consent management platform implementation involves across a real estate with real jurisdictional spread. If your organisation is about to run one, that is more useful than a percentage we would have had to make up.

The one public statement about the work comes from the client, quoted further down this page.

Context

The shape of the problem

Start with the client type. A data and analytics business is a harder consent environment than a consumer brand, for a structural reason: data is the product. The internal understanding of personal data is more sophisticated, the questions from legal are more precise, and the tolerance for a hand-waving answer about what a tag does is close to zero. An implementer who is used to persuading a marketing team that a banner is fine will not survive the first review.

Then add the jurisdictional spread. The European Union and the United Kingdom operate an opt-in model under the GDPR and the UK GDPR, read alongside the ePrivacy rules, which means non-essential storage and access must not happen before consent. Most United States state laws operate an opt-out model with obligations around the sale and sharing of personal information, and an expectation that the Global Privacy Control signal is honoured. Brazil, Canada, Australia, Japan and the Gulf states each add their own variations. These are not different intensities of the same rule. They are different rules, and a single global banner behaviour satisfies some of them by accident and others not at all.

And then three platforms

Running Osano, Securiti.ai and OneTrust in the same organisation is more common than vendors like to admit. Acquisitions bring contracts with them. Divisions procure independently. Migrations run in parallel while a new platform is proven. The practical consequence is that purpose categories, consent record formats and integration methods differ across parts of the estate, so the work is not one implementation repeated three times. It is three implementations plus the reconciliation between them.

The reconciliation is the interesting part. A person's choice has to mean the same thing regardless of which platform captured it, the records have to be produceable in a form that answers a regulator or a data subject request, and the categories have to map to a single internal vocabulary so that a policy written once applies everywhere.

Darren consistently demonstrated exceptional technical skill and a strong understanding of various jurisdictions’ legal requirements.

VicVP and Chief Data Privacy Officer, Circana
Vendors

Three platforms, three different strengths

We deploy and maintain all three, which is the only reason a comparison like this is worth reading rather than the one a vendor publishes about itself.

PlatformWhere it is strongestWhat to watch
OsanoFast deployment, strong automated scanning and classification, good defaults for organisations that want the platform to carry more of the workAutomated classification still needs review. A script the scanner has not seen before will land in a category by inference, not by fact
OneTrustBreadth. Consent is one module beside assessments, records of processing, data subject requests and vendor risk, which suits a wider privacy programmeBreadth costs configuration time. Deployments fail more often from unclear internal ownership than from any product limitation
Securiti.aiData discovery and mapping across systems, so the consent layer connects to where personal data actually lives rather than only to the websiteThe value depends on connecting the data sources. A website-only deployment leaves most of what you paid for unused
All threeNone of them can gate a tag that does not route through them, and all of them will report a healthy status while doing soVerify behaviour in the browser, not in the console. This applies to every consent platform on the market

Assessment based on production deployments across client estates, not on vendor documentation.

Method

What an implementation actually involves

Six stages. The configuration console appears in stage four, which surprises most people who have only been shown a vendor demonstration.

  1. 01

    Discovery before anything else

    Crawl every property, including the subdomains nobody mentioned. Catalogue every cookie, local storage item and script. Record which are hard-coded into templates, which load through Google Tag Manager or an equivalent, and which are loaded by another vendor's script rather than by you. This inventory is the deliverable everything else depends on.

  2. 02

    Classify with legal, not for legal

    Purpose categories are a legal judgement expressed as a technical configuration. Strictly necessary, functional, analytics and marketing are the common four, and the argument is always about which analytics count as strictly necessary. Get the decision written down and signed, because it will be questioned later by someone who was not in the room.

  3. 03

    Build regional rule sets

    Opt-in behaviour for the EU and UK. Opt-out behaviour with Global Privacy Control handling for US states that require it. Region detection that fails safe, so an unresolved location gets the stricter treatment rather than the looser one. Then decide, deliberately, whether to apply the strictest regime everywhere and accept the commercial cost.

  4. 04

    Re-point every gated tag

    This is the unglamorous middle of the project. Tags move out of templates and into the consent-aware path. Trigger conditions in the tag manager become consent-dependent. Server-side tagging, where it is in use, needs its own treatment because the consent decision has to travel with the request.

  5. 05

    Wire the record and the withdrawal path

    Consent has to be recorded with enough context to prove what was shown and what was chosen, and there has to be a working route for someone to change their mind later. A preference link that does not actually revoke anything is a common and serious defect.

  6. 06

    Test, then re-test after the next release

    Verification is covered below. The point to establish at implementation time is that this is a recurring check with an owner and a calendar entry, not a sign-off.

Governance

Tag governance, the part that decides the outcome

A consent platform is a mechanism. Tag governance is the discipline that keeps the mechanism connected to reality.

Interoperability

Consent signals and where they travel

A banner is the visible five per cent. These are the mechanisms that decide whether the choice a person made has any effect.

Global Privacy Control
A browser-level signal expressing an opt-out of sale and sharing. Several US state regimes treat it as a valid request, which means it has to be read and acted on server-side as well as reflected in the banner state, rather than merely displayed back to the user.
Google consent mode
A signalling layer that tells Google tags whether analytics and advertising storage are permitted. Configured correctly it changes tag behaviour rather than simply blocking the tag, which matters for measurement continuity. Configured carelessly it becomes a way of collecting data while appearing not to.
IAB Transparency and Consent Framework
The advertising industry's string-based framework for passing consent state to demand partners. Relevant where a site carries programmatic advertising, largely irrelevant where it does not, and frequently enabled by default when it should not be.
Consent records
The proof layer. What was shown, when, which version of the notice, what was chosen and by which identifier. This is what turns a compliance claim into an evidenced one, and it is the part most often left at vendor defaults.
Cross-domain and cross-platform propagation
Where an estate spans several domains, or several consent platforms, a choice made on one property should not have to be repeated on the next. Getting this right is partly configuration and partly a decision about how far a single consent legitimately extends.
Verification

How you prove it works

Every consent platform ships a compliance dashboard, and every one of them will tell you the implementation is healthy while a hard-coded pixel fires on page load. The dashboard reports on what the platform knows about. The browser reports on what actually happened. Only one of those is evidence.

The verification we run is deliberately low-technology. Open the site in a clean browser profile with the network panel recording. Load the page and do nothing. Record every request that leaves before any consent interaction, and every cookie and storage item written. Reject all, reload, record again. Accept all, reload, record again. Then withdraw consent through the preference link and confirm that what was set is actually cleared and that the tags stop.

Then repeat it where the rules differ

Region detection is a common failure point, and it cannot be tested from one country. The behaviour a German visitor gets, the behaviour a California visitor gets and the behaviour an unresolved location gets are three different tests. On multi-region estates we run them from the relevant locations rather than trusting a geolocation override in the platform's preview mode, because the override and the live path are not always the same code.

What good looks like at the end

Before consent, nothing but strictly necessary requests. After rejection, still nothing. After acceptance, only the tags in the inventory and nothing that is not. On withdrawal, storage cleared and collection stopped. A consent record for each of those states that a privacy team can retrieve without asking an agency. And a re-scan in the calendar, because the next content release will change something.

That is the standard we hold implementations to, on this engagement and on every other. The general service is described under cookie consent management, and the broader programme work under privacy consulting. Green Arrow Consultancy is a member of the International Association of Privacy Professionals and is registered with the Information Commissioner's Office under ZA822868.

Questions

Frequently asked questions

More on platforms, migrations and ongoing operation in the full FAQ.

Why would one organisation run more than one consent platform?

Rarely by design. It usually happens through acquisition, where the acquired business brings its own platform and contract, or through divisional autonomy, where two parts of a group procured separately. It can also be deliberate during a migration, when a new platform is being proven on part of the estate before the old one is switched off. Whatever the cause, the practical requirement is the same: the consent decision a person makes has to be honoured consistently, whichever platform served the notice.

How long does a consent management platform implementation take?

For a single site with a clean tag setup, days. For a real estate with inherited tags, several properties and multiple jurisdictions, the configuration is not the long part. Discovery is. Crawling the estate, cataloguing cookies and scripts, tracing which are hard-coded and which run through a tag manager, and agreeing purpose categories with legal is where the time goes. Budget the majority of the programme for work that happens before anyone opens the platform console.

Which consent platform do you recommend?

It depends on the estate, not on the vendor. Osano is quick to deploy, has strong automated scanning and suits organisations that want the platform to do more of the classification work. OneTrust is the broadest and is usually the answer where consent is only one module of a larger privacy programme with assessments, records of processing and vendor risk. Securiti.ai is strongest where data discovery and mapping across systems matter as much as the banner. We deploy and maintain all three, and the right answer is a property of your estate rather than of the vendor list.

What is the difference between a cookie banner and a consent management platform?

A banner is a user interface. A consent management platform is the banner plus a cookie and script inventory, per-region rule sets, a consent record with proof of when and how it was captured, an interface for people to change or withdraw their choice, and a signalling mechanism that other technologies read. Organisations that buy a banner and skip the rest tend to discover the gap during an audit or a data subject request.

How do you handle US state privacy laws alongside GDPR?

With separate rule sets rather than one global behaviour. The EU and UK model is opt-in: non-essential tags must not fire before consent. Most US state laws, including the California framework, are opt-out, with obligations around sale and sharing of personal information and honouring the Global Privacy Control browser signal. Applying the strictest regime everywhere is a defensible choice, and it is a commercial decision the client should make consciously rather than one an implementer should make quietly.

What is the most common implementation mistake you find?

Tags that bypass the mechanism. A consent platform can only gate what is routed through it. If a pixel is hard-coded into a page template, or a vendor script loads another vendor script that the inventory never captured, the banner will look correct and the behaviour will not be. This is why post-implementation testing with a network inspector, before and after consent, matters more than the platform's own compliance dashboard.

Do you migrate organisations between consent platforms?

Yes, and it is a distinct piece of work from a first implementation. A migration has to preserve existing consent records where the legal basis allows, keep both platforms from serving notices at once during cutover, re-map purpose categories that rarely align neatly between vendors, and re-point every gated tag. Doing it market by market rather than all at once is almost always the safer route.

What can you tell us about the Circana engagement specifically?

Less than we would like to. The engagement was privacy management platform implementation across Osano, Securiti.ai and OneTrust for Circana LLC, a data and analytics business, and Vic, its VP and Chief Data Privacy Officer, has publicly described the work in terms of technical skill and an understanding of various jurisdictions' legal requirements. Beyond that, the detail sits under confidentiality, which is normal for privacy engagements and is the reason the rest of this page describes the general practice rather than the account.

Who should own consent internally once implementation is finished?

Someone with authority over tag deployment, not only over policy. The failure mode we see most often is a privacy or legal owner who is accountable for compliance but has no control over what marketing adds to the tag manager. Pair the accountable owner with a change route through the tag manager, and give them a periodic re-scan so drift is found by them rather than by a regulator.

Written and reviewed by the Green Arrow Consultancy team, led by Darren Tyler, founder and chief executive.

Green Arrow Consultancy Ltd, Cardiff, Wales. Company number 12491770. ICO registration ZA822868. Member of the International Association of Privacy Professionals. Last reviewed .

Find out what your banner is actually doing

We will load your site in a clean profile, record what fires before consent, after rejection and after acceptance, and send you the list. It takes us a morning and it is usually the most informative thing a privacy team reads that quarter.