We have rolled consent out across multi-brand, multi-language website portfolios, and the pattern is always the same. The banner takes a week. The tags take a quarter. Almost every site we audit is already setting trackers before anybody has clicked anything.
Cookie consent management is the work of making a website load only the tracking a visitor has lawfully agreed to, in the way their jurisdiction requires. A consent management platform such as Osano or OneTrust supplies the banner and the consent record, but compliance depends on tag governance, a cookie audit, correct regional templates and testing. We run this across whole multi-brand estates.
The distinction matters because most procurement buys the first definition and assumes the second.
Four steps, about two weeks on a normal estate, and reliably at least one surprise.
Homepage, category, product, article, form, checkout, search results, error page, and anything behind a login. Scanners follow links. They do not fill in forms, complete a purchase or log in, so a pure scan misses the tags that only fire deep in a journey.
A site often loads a different tag set for a visitor in Frankfurt than for one in Chicago, deliberately or because a regional team added something. We test through proxies in the countries that matter.
The important artefact is the delta: what fires on load with no interaction, what fires after Accept All, and what fires after a granular rejection. If the first and third lists are not much shorter than the second, the implementation is decorative.
A cookie name is not an answer. Somebody has to say which vendor sets it, what it does and which purpose it serves. Every estate we audit also carries trackers from campaigns that ended years ago and vendors nobody holds a contract with. Removing those is faster and safer than writing a category description for something you do not use.
The single most common finding in our audits is trackers firing before consent on a site with a correctly licensed consent platform installed. That is rarely a platform failure. It can only govern what routes through it, and plenty of things stopped routing through it years ago.
The culprits are predictable. A marketing pixel pasted into the theme header because it was urgent. A WordPress or Shopify plugin injecting its own analytics. An embedded video, map or chat widget setting cookies the moment the iframe loads. A regional team running its own Google Tag Manager container. A vendor script that silently added a third party call in an update. A trigger set to All Pages with no consent condition, because that is the default and nobody changed it.
Consolidating tags into governed containers. Rebuilding hard-coded scripts as consent-conditional tags. Wrapping embeds so the third party is not contacted until the category is granted, usually with a click-to-load placeholder. Making consent initialisation run first on the page. Then re-testing, because something always survives the first pass.
Moving tag execution to a server-side container gives you a control point, removes third party scripts from the browser and improves Core Web Vitals. What it does not do is create a lawful basis. Data sent server-side is still personal data and still needs consent where consent is required. We build these configurations as part of our ethical analytics work, and the consent check happens before the hop, not after it.
One estate, three behaviours. The geolocation ruleset decides which a visitor gets, and it is worth testing rather than assuming.
| EU and UK | Most US states | Opt-out and notice-only jurisdictions | |
|---|---|---|---|
| Default state | Non-essential tracking off until consent is given | Tracking generally permitted until the consumer objects | Tracking permitted, with notice and a route to object |
| What the banner must offer | A genuine choice, with rejecting as easy as accepting | A clear opt-out for sale, sharing and targeted advertising | Notice and an opt-out path, often with no Accept All control at all |
| Browser signals | No general requirement to honour a browser signal | Several states require universal opt-out signals to be honoured automatically | Varies, and usually not mandated |
| Sensitive data | Special category data needs explicit consent | Sensitive data typically needs opt-in even in an opt-out state | Varies, commonly opt-in |
| Effect on your data | Measured volumes fall, and modelling recovers part of the gap | Volumes largely hold, but suppression lists must be respected | Volumes hold, and the banner is informational rather than gating |
A general operating summary, not legal advice. Obligations depend on your processing and your territories, and the US position changes as more states legislate.
Google Consent Mode tells Google tags what a visitor agreed to, rather than simply blocking the tag. Version 2 added ad_user_data and ad_personalization to the existing analytics_storage and ad_storage flags, and made sending them a condition of remarketing audiences and full conversion measurement for European Economic Area and UK traffic. A consent gap stopped being a legal abstraction and started showing up as broken audiences in an advertising account.
There are two shapes. Basic mode blocks Google tags entirely until consent is given. Advanced mode loads them in a restricted state sending cookieless pings, letting Google model some unconsented traffic. Advanced recovers more measurement, and a request leaves the browser before consent. Take that choice deliberately and document it.
If you sell advertising inventory or work with programmatic vendors in Europe, you probably need a TCF-registered platform so consent strings pass down the supply chain in a form partners recognise. A brand site running its own marketing tags usually does not, and deploying it where it is not needed adds vendor lists hundreds of entries long to the banner.
A consented Google Analytics 4 setup with consent mode and sensible retention still answers the questions most businesses ask. The habit that breaks is comparing a post-consent period with a pre-consent one and reading the difference as a performance drop, so we rebase measurement at launch.
A banner is a user interface component and gets the same standard as everything else, a point our accessibility practice makes loudly.
Darren's practical mind makes him really effective at cutting through complexity to find the most suitable solution.
Consent rate is the share of visitors accepting some or all non-essential categories. It varies enormously by country, device, traffic source and how much the visitor wanted to be on your site. Anyone quoting a target number without asking about those variables is guessing.
What genuinely moves it, in rough order of effect: how fast the banner appears and how quickly it can be dismissed, how many words it contains, whether categories are in plain language or vendor jargon, how long the vendor list is, and whether it looks like part of the site or a legal notice bolted on. Cutting a two hundred vendor TCF list from a site that does not need TCF is usually the largest single improvement available.
What we will not do is dark patterns. Colour-weighting accept against a greyed-out reject, hiding rejection behind a second screen, confirmshaming copy, a deliberately tedious preference centre. They lift the rate briefly. They are also what European regulators keep issuing findings about, and the consent they produce is not valid, so the data collected under it is not safely usable.
Some data loss is simply the correct outcome. Server-side measurement of first party events, consent mode modelling and better use of your own customer data recover more than banner trickery does, and carry none of the same risk.
Failure modes we see repeatedly. All of them are caught by a rescan and a monitoring routine, which is why consent is a retained service rather than a project with an end date.
A campaign, an agency or a regional team adds a script directly to a template. It fires on load, the consent platform cannot see it, and nobody notices until the next scan.
An update adds a new domain or a new cookie. Your categorisation is now wrong and your cookie notice is out of date, through no action of yours.
A template update, a new jurisdiction, or a rule edited during an unrelated task. Regional behaviour changes silently and only shows up in a proxy test.
Somebody debugging a conversion issue sets a trigger to fire regardless of consent, and the temporary change is still there four months later.
Accurate at launch, and twelve months of estate changes later it describes a website that no longer exists. The same goes for a consent rate that shifts by double digits after a copy edit and reads as a traffic change because nobody was monitoring it.
Configuring consent on one website is a task. Doing it across a brand portfolio in a dozen languages and several regulatory regimes is a different discipline. Our managed portfolio passed two hundred websites in 2022, spanning brands whose regional teams all publish independently.
At that scale you need a standard: one reference configuration with agreed categories, copy, design and regional rules. Then a deviation register recording every site allowed to differ and why, because there will always be legitimate exceptions and the failure mode is forty undocumented ones. Changes go out as releases against the standard, tested on a sample of templates rather than only the homepage of the largest brand.
With one site you notice when the banner breaks. With two hundred you do not, unless something is watching: scheduled rescans, alerting on new cookies and unrecognised domains, checks that the consent script is still initialising first, and a periodic proxy test from each major region. The point is to find a failure within a day rather than at the next annual audit.
A perfect banner on an estate with no record of processing, no retention rules and no supplier register is a very visible part of an incomplete job. Consent lands best inside a wider privacy programme, and increasingly has to account for AI features creating processing after the consent model was designed. Our website management practice is usually the delivery route, because the team that can change two hundred sites already maintains them.
Definitions of the terms used here are in the glossary, and broader questions are answered in the FAQ.
No. A platform gives you a banner, a preference centre, a consent record and a signal other scripts can read. Compliance depends on whether your tags obey that signal, whether the categories describe what the cookies really do, whether the regional behaviour is right, and whether anyone maintains it. We regularly audit sites with a licensed platform and trackers firing before a visitor clicks anything.
Osano, OneTrust and Securiti.ai are the three we deploy most often, and for Circana we implemented privacy management across all three. The choice usually follows what the rest of the privacy programme runs on rather than the banner itself. If you already own a broad privacy suite, use its consent module. Any of them can be configured badly.
It is an automated scan plus a manual review establishing what your site actually sets: every cookie, pixel, tag, local storage entry and third party call, on every template, in every region, before and after consent. It comes first because you cannot categorise what you have not found, and because scans miss anything that only fires on a checkout, a gated form or a logged-in page.
It made consent signalling a prerequisite for advertising features rather than an optional refinement. Version 2 added ad_user_data and ad_personalization to the existing analytics and advertising storage flags, and advertisers serving the European Economic Area and the UK must send them for remarketing audiences and conversion measurement to keep working. It forced a lot of organisations to fix consent plumbing, because the consequence became commercial rather than only legal.
Because tags accumulate faster than governance does. A campaign pastes a pixel into the theme. A plugin injects its own script. An embedded video or chat widget sets cookies on load. A regional team runs its own container. A vendor script quietly adds a third party call. None of it is visible from the consent platform, which is why consent work is really tag governance with a banner attached.
Yes, in opt-in regions, and anyone who says otherwise is selling something. Honest measurement means comparing like with like after launch, then using consent mode modelling and server-side configuration to recover what can lawfully be recovered. The bigger risk is the opposite one: a misconfigured banner blocking tags it should not, silently, on one template, for months.
Because platforms serve different templates by visitor location, and in jurisdictions with an opt-out or notice-only regime the standard template deliberately omits an Accept All control. It is not a misconfiguration, and in most platforms it cannot be overridden without changing the jurisdiction rules the template derives from. We test regional behaviour through proxies rather than assuming.
Send us one domain or two hundred. We will scan them, show you what fires before consent, and tell you whether the fix is a configuration change or a quarter of tag governance.