Services · Consent

Cookie consent management for a whole estate, not one banner

We have rolled consent out across multi-brand, multi-language website portfolios, and the pattern is always the same. The banner takes a week. The tags take a quarter. Almost every site we audit is already setting trackers before anybody has clicked anything.

Osano · OneTrust · Securiti.ai200+ managed websitesMulti-region
Quick answer

Cookie consent management is the work of making a website load only the tracking a visitor has lawfully agreed to, in the way their jurisdiction requires. A consent management platform such as Osano or OneTrust supplies the banner and the consent record, but compliance depends on tag governance, a cookie audit, correct regional templates and testing. We run this across whole multi-brand estates.

Definitions

What a CMP does, and what it does not do

The distinction matters because most procurement buys the first definition and assumes the second.

What a consent management platform gives you
A banner and preference centre, a category model, a durable consent record, a geolocation ruleset deciding which template a visitor sees, a signal other scripts can read, and usually a scanner. Osano, OneTrust and Securiti.ai are the three we deploy most often, and for Circana we implemented privacy management across all three.
What it does not give you
It does not stop a script hard-coded into the page template, know what your cookies are for, decide your lawful basis, fix a tag manager container firing on page view regardless of consent state, or tell you the pixel your agency added last March is still there. That is human work, and it is where the risk lives.
The consent signal and the consent record
The platform publishes a state, per category, per visitor, and everything downstream reads it: tag manager, Google Consent Mode, server-side endpoints, embedded widgets, custom scripts. It also stores proof of what was shown, what was chosen and when. That record is the artefact a regulator asks for, and the one most teams have never tried to export for a named individual until the day they need it.
First

The audit that has to come first

Four steps, about two weeks on a normal estate, and reliably at least one surprise.

  1. 01

    Crawl every template, not every page

    Homepage, category, product, article, form, checkout, search results, error page, and anything behind a login. Scanners follow links. They do not fill in forms, complete a purchase or log in, so a pure scan misses the tags that only fire deep in a journey.

  2. 02

    Scan from each region you serve

    A site often loads a different tag set for a visitor in Frankfurt than for one in Chicago, deliberately or because a regional team added something. We test through proxies in the countries that matter.

  3. 03

    Compare before and after consent

    The important artefact is the delta: what fires on load with no interaction, what fires after Accept All, and what fires after a granular rejection. If the first and third lists are not much shorter than the second, the implementation is decorative.

  4. 04

    Name the controller, then delete before you categorise

    A cookie name is not an answer. Somebody has to say which vendor sets it, what it does and which purpose it serves. Every estate we audit also carries trackers from campaigns that ended years ago and vendors nobody holds a contract with. Removing those is faster and safer than writing a category description for something you do not use.

The real work

Tag governance is the actual project

The single most common finding in our audits is trackers firing before consent on a site with a correctly licensed consent platform installed. That is rarely a platform failure. It can only govern what routes through it, and plenty of things stopped routing through it years ago.

The culprits are predictable. A marketing pixel pasted into the theme header because it was urgent. A WordPress or Shopify plugin injecting its own analytics. An embedded video, map or chat widget setting cookies the moment the iframe loads. A regional team running its own Google Tag Manager container. A vendor script that silently added a third party call in an update. A trigger set to All Pages with no consent condition, because that is the default and nobody changed it.

What fixing it involves

Consolidating tags into governed containers. Rebuilding hard-coded scripts as consent-conditional tags. Wrapping embeds so the third party is not contacted until the category is granted, usually with a click-to-load placeholder. Making consent initialisation run first on the page. Then re-testing, because something always survives the first pass.

Where server-side tagging helps, and where it does not

Moving tag execution to a server-side container gives you a control point, removes third party scripts from the browser and improves Core Web Vitals. What it does not do is create a lawful basis. Data sent server-side is still personal data and still needs consent where consent is required. We build these configurations as part of our ethical analytics work, and the consent check happens before the hop, not after it.

Geography

How consent differs by region

One estate, three behaviours. The geolocation ruleset decides which a visitor gets, and it is worth testing rather than assuming.

EU and UKMost US statesOpt-out and notice-only jurisdictions
Default stateNon-essential tracking off until consent is givenTracking generally permitted until the consumer objectsTracking permitted, with notice and a route to object
What the banner must offerA genuine choice, with rejecting as easy as acceptingA clear opt-out for sale, sharing and targeted advertisingNotice and an opt-out path, often with no Accept All control at all
Browser signalsNo general requirement to honour a browser signalSeveral states require universal opt-out signals to be honoured automaticallyVaries, and usually not mandated
Sensitive dataSpecial category data needs explicit consentSensitive data typically needs opt-in even in an opt-out stateVaries, commonly opt-in
Effect on your dataMeasured volumes fall, and modelling recovers part of the gapVolumes largely hold, but suppression lists must be respectedVolumes hold, and the banner is informational rather than gating

A general operating summary, not legal advice. Obligations depend on your processing and your territories, and the US position changes as more states legislate.

Plumbing

Consent Mode v2, TCF and the ad stack

Google Consent Mode tells Google tags what a visitor agreed to, rather than simply blocking the tag. Version 2 added ad_user_data and ad_personalization to the existing analytics_storage and ad_storage flags, and made sending them a condition of remarketing audiences and full conversion measurement for European Economic Area and UK traffic. A consent gap stopped being a legal abstraction and started showing up as broken audiences in an advertising account.

There are two shapes. Basic mode blocks Google tags entirely until consent is given. Advanced mode loads them in a restricted state sending cookieless pings, letting Google model some unconsented traffic. Advanced recovers more measurement, and a request leaves the browser before consent. Take that choice deliberately and document it.

The Transparency and Consent Framework

If you sell advertising inventory or work with programmatic vendors in Europe, you probably need a TCF-registered platform so consent strings pass down the supply chain in a form partners recognise. A brand site running its own marketing tags usually does not, and deploying it where it is not needed adds vendor lists hundreds of entries long to the banner.

A consented Google Analytics 4 setup with consent mode and sensible retention still answers the questions most businesses ask. The habit that breaks is comparing a post-consent period with a pre-consent one and reading the difference as a performance drop, so we rebase measurement at launch.

Darren's practical mind makes him really effective at cutting through complexity to find the most suitable solution.

NicoloSenior Brand Manager, Energizer Holdings
Numbers

Consent rate, and what honestly moves it

Consent rate is the share of visitors accepting some or all non-essential categories. It varies enormously by country, device, traffic source and how much the visitor wanted to be on your site. Anyone quoting a target number without asking about those variables is guessing.

What genuinely moves it, in rough order of effect: how fast the banner appears and how quickly it can be dismissed, how many words it contains, whether categories are in plain language or vendor jargon, how long the vendor list is, and whether it looks like part of the site or a legal notice bolted on. Cutting a two hundred vendor TCF list from a site that does not need TCF is usually the largest single improvement available.

What we will not do is dark patterns. Colour-weighting accept against a greyed-out reject, hiding rejection behind a second screen, confirmshaming copy, a deliberately tedious preference centre. They lift the rate briefly. They are also what European regulators keep issuing findings about, and the consent they produce is not valid, so the data collected under it is not safely usable.

Some data loss is simply the correct outcome. Server-side measurement of first party events, consent mode modelling and better use of your own customer data recover more than banner trickery does, and carry none of the same risk.

Maintenance

What breaks after launch

Failure modes we see repeatedly. All of them are caught by a rescan and a monitoring routine, which is why consent is a retained service rather than a project with an end date.

A new tag arrives ungoverned

A campaign, an agency or a regional team adds a script directly to a template. It fires on load, the consent platform cannot see it, and nobody notices until the next scan.

A vendor changes their script

An update adds a new domain or a new cookie. Your categorisation is now wrong and your cookie notice is out of date, through no action of yours.

The geolocation rules drift

A template update, a new jurisdiction, or a rule edited during an unrelated task. Regional behaviour changes silently and only shows up in a proxy test.

A consent-conditional tag gets loosened

Somebody debugging a conversion issue sets a trigger to fire regardless of consent, and the temporary change is still there four months later.

The cookie notice stops matching reality

Accurate at launch, and twelve months of estate changes later it describes a website that no longer exists. The same goes for a consent rate that shifts by double digits after a copy edit and reads as a traffic change because nobody was monitoring it.

At scale

Running consent across two hundred sites

Configuring consent on one website is a task. Doing it across a brand portfolio in a dozen languages and several regulatory regimes is a different discipline. Our managed portfolio passed two hundred websites in 2022, spanning brands whose regional teams all publish independently.

At that scale you need a standard: one reference configuration with agreed categories, copy, design and regional rules. Then a deviation register recording every site allowed to differ and why, because there will always be legitimate exceptions and the failure mode is forty undocumented ones. Changes go out as releases against the standard, tested on a sample of templates rather than only the homepage of the largest brand.

Monitoring is the part that pays for itself

With one site you notice when the banner breaks. With two hundred you do not, unless something is watching: scheduled rescans, alerting on new cookies and unrecognised domains, checks that the consent script is still initialising first, and a periodic proxy test from each major region. The point is to find a failure within a day rather than at the next annual audit.

Consent is one layer of a privacy programme

A perfect banner on an estate with no record of processing, no retention rules and no supplier register is a very visible part of an incomplete job. Consent lands best inside a wider privacy programme, and increasingly has to account for AI features creating processing after the consent model was designed. Our website management practice is usually the delivery route, because the team that can change two hundred sites already maintains them.

Questions

Frequently asked questions

Definitions of the terms used here are in the glossary, and broader questions are answered in the FAQ.

Does installing a consent management platform make us compliant?

No. A platform gives you a banner, a preference centre, a consent record and a signal other scripts can read. Compliance depends on whether your tags obey that signal, whether the categories describe what the cookies really do, whether the regional behaviour is right, and whether anyone maintains it. We regularly audit sites with a licensed platform and trackers firing before a visitor clicks anything.

Which consent platform should we use?

Osano, OneTrust and Securiti.ai are the three we deploy most often, and for Circana we implemented privacy management across all three. The choice usually follows what the rest of the privacy programme runs on rather than the banner itself. If you already own a broad privacy suite, use its consent module. Any of them can be configured badly.

What is a cookie audit and why does it come first?

It is an automated scan plus a manual review establishing what your site actually sets: every cookie, pixel, tag, local storage entry and third party call, on every template, in every region, before and after consent. It comes first because you cannot categorise what you have not found, and because scans miss anything that only fires on a checkout, a gated form or a logged-in page.

What did Google Consent Mode v2 change?

It made consent signalling a prerequisite for advertising features rather than an optional refinement. Version 2 added ad_user_data and ad_personalization to the existing analytics and advertising storage flags, and advertisers serving the European Economic Area and the UK must send them for remarketing audiences and conversion measurement to keep working. It forced a lot of organisations to fix consent plumbing, because the consequence became commercial rather than only legal.

Why do tags fire before consent on so many sites?

Because tags accumulate faster than governance does. A campaign pastes a pixel into the theme. A plugin injects its own script. An embedded video or chat widget sets cookies on load. A regional team runs its own container. A vendor script quietly adds a third party call. None of it is visible from the consent platform, which is why consent work is really tag governance with a banner attached.

Will a banner reduce our analytics data?

Yes, in opt-in regions, and anyone who says otherwise is selling something. Honest measurement means comparing like with like after launch, then using consent mode modelling and server-side configuration to recover what can lawfully be recovered. The bigger risk is the opposite one: a misconfigured banner blocking tags it should not, silently, on one template, for months.

Why does one of our regions not show an Accept All button?

Because platforms serve different templates by visitor location, and in jurisdictions with an opt-out or notice-only regime the standard template deliberately omits an Accept All control. It is not a misconfiguration, and in most platforms it cannot be overridden without changing the jurisdiction rules the template derives from. We test regional behaviour through proxies rather than assuming.

Written and reviewed by the Green Arrow Consultancy team, led by Darren Tyler, founder and chief executive.

Green Arrow Consultancy Ltd, Cardiff, Wales. Company number 12491770. ICO registration ZA822868. Member of the International Association of Privacy Professionals. Last reviewed .

Start with a cookie audit

Send us one domain or two hundred. We will scan them, show you what fires before consent, and tell you whether the fix is a configuration change or a quarter of tag governance.