Skip to content
← Back to Blog

What is a Consent Management Platform (CMP)? How Does It Work?

Published September 28, 2026
Osman Husain

Osman Husain

what is a consent management platform?

A consent management platform (CMP) is software that asks website and app visitors for permission to use cookies and trackers. It records each answer and tells every connected tool what data it may collect.

A CMP can also scan a site for trackers and block the ones a visitor hasn't consented to.

Users should be able to reopen their consent choices at any time and alter their preferences, which is another core CMP requirement.

The GDPR, the ePrivacy Directive, and CCPA regulations require clear consent banners displayed up front, linked to a privacy policy, and notices of how to opt out. Any deviations from this can result in regulatory action, fines, and private lawsuits.

Europe requires explicit proof of consent before any tracking pixels can fire. California, under the CCPA, requires a working opt-out from businesses that sell or share personal information. Both require records: proof of consent in Europe, and records of opt-out requests in California.

CMPs are engineered to deliver those outcomes, and enable compliance with the laws that require it. They store proof of consent, protect against wiretapping laws, and allow data access requests and deletions.

Google requires a certified CMP for companies wanting to use the Google Ads product in Europe, too. 

What is a consent management platform?

A consent management platform is the software layer between a site's visitors and its tracking tools. It decides which scripts may run for each visitor, based on individual choices, storing that record as evidence.

That makes a CMP the software side of consent management, the wider process of asking for, recording, and honoring data access permissions. CMPs handle how users move across the web: displaying the cookie banner, recording preferences, applying the signals, and storing consent logs for audits. 

CMPs come in two kinds: commercial products sold publicly (like Enzuzo), and private CMPs that publishers maintain for their own sites. In IAB Europe's 2025 compliance report, 59% of registered CMPs were commercial, and 41% were private.

A consent management platform logs and enforces choices but does not decide them. CMPs are a tool which businesses use to customize the banner, enforce geo-specific display and opt-in rules, and communicate with Gogle Tag Manager.  Two sites on the same CMP can handle consent in opposite ways, based on how they're set up.

How does a consent management platform work?

A consent management platform sets a default consent state before any other tag loads. It changes that state the moment a visitor makes a choice. Every tag that respects the CMP checks the state before it fires.

On a typical page load, the steps run in this order:

  1. The CMP's script loads first and sets a default for each purpose, such as analytics or advertising: denied until the visitor agrees, in regions that require opt-in. Google Tag Manager has a Consent Initialization trigger for this step, which always fires before all other tags, as shown in Google's documentation.
  2. CMPs establish a visitor's geographical location and applies that region's rules: an opt-in banner, an opt-out notice, or no banner at all.
  3. It shows the banner and captures the visitor's choice for each category.
  4. It updates the consent state, releases the tags the visitor allowed, and passes the choice to connected tools through standard signals.
  5.  CMPs save the choice in the visitor's browser so the banner doesn't return on every page. If the CMP keeps a consent log, it also records when the choice was made, what the visitor saw, and what they agreed to. Those are the core of what a consent record holds.
  6. It keeps a link or icon that reopens the preference center, where the visitor can change any choice, and it checks the saved choice on later visits.

Each step is a potential point of failure. The University of Michigan study of CMP deployments lists region rules among the possible platform-side causes of consent violations, alongside scanners that miss and wrongly categorize cookies.

 

cmp-3a@3x

What is a consent state?

Consent state is the set of granted or denied values, one per purpose, that a CMP holds for the current visitor. Google's version uses named consent types, such as ad_storage for advertising cookies and analytics_storage for analytics cookies. Google's tags read those values before they store anything.

A tag only follows consent state if it checks it. A pixel pasted straight into a site template never asks, and neither does a script added by a store app. Both fire whatever the visitor chose, which is one reason cookies still load after a visitor clicks Reject All.

Enzuzo's consent management platform can hold non-essential scripts until a visitor consents, using its auto-blocking script attribute or a Google Tag Manager setup, with the Enzuzo script loaded first.

What types of data does a consent management platform cover?

A consent management platform covers any information a site stores on, or reads from, a visitor's device, not just cookies. That includes other information stored on devices, and under the EDPB's guidelines, it also covers tracking pixels and software development kits (SDKs) that make a device send information, too.

The EU rule behind this is broad. Article 5(3) of the ePrivacy Directive requires consent before storing or accessing information on a user's device. It exempts only two cases: storage used solely to carry a communication over a network, and storage strictly necessary for a service the user explicitly asked for.

CMPs sort what their scanners find into categories, so visitors decide per purpose rather than per cookie.

Cookie categories and EU consent
Category What it covers Consent needed under EU rules?
Strictly necessary Login sessions and shopping carts No, when strictly necessary for a service the visitor requested
Functional or preferences Language, region, remembered settings, chat widgets Yes, unless strictly necessary
Analytics Visit counts, page views, traffic sources Yes, with narrow exceptions, such as France, where the CNIL exempts some audience measurement under conditions
Marketing Ad pixels, retargeting, cross-site profiles Yes

 

The strictly necessary label has to be earned, and can't be used liberally. The EDPB's cookie banner taskforce pointed to website owners' responsibility to show that the cookies they list as essential are in fact essential. Enzuzo's built-in Scan My Domain feature finds the scripts on a domain so they can be sorted into functional, analytics, marketing, and preferences categories.

Do consent management platforms work in mobile apps?

Consent management platforms can work on Android and iOS apps, but most CMPs registered with IAB Europe cover websites only. In IAB Europe's 2025 report, 65.4% of registered CMPs were exclusively for web platforms.

An app CMP ships as an SDK inside the app and shows its consent screen natively instead of as a web banner. Google's User Messaging Platform SDK works this way. Its certified CMP list shows the same web-first split: 78 entries are web-only, 31 cover web and apps, and 17 are app-only.

Apps also face a second, separate prompt on iOS. Apple's App Tracking Transparency framework requires apps to ask permission before tracking users across other companies' apps and websites. That prompt comes from the operating system, not from a CMP. Using one ad platform's data, researchers estimated that the share of trackable Apple ad traffic in US iOS apps fell from 73% to 18% after it arrived.

Which consent signals does a CMP send, and which tools read them?

A consent management platform sends consent signals in formats other tools already read, such as Google Consent Mode and the IAB's TC string. CMPs can receive signals and act upon them, to, such as Global Privacy Control, which is sent from the visitor's browser.

Consent signals a CMP sends and receives
Signal Set by What it carries Who reads it
Google Consent Mode v2 The CMP Granted or denied for ad storage, analytics storage, ad user data, and ad personalization Google tags (Ads, Analytics, Floodlight)
UET consent mode The CMP The visitor's advertising-storage choice Microsoft Advertising's UET tag
IAB TCF consent string (TC string) A registered CMP Consent and legitimate-interest choices per purpose and per registered ad-tech vendor, plus which CMP created it Ad-tech vendors registered in the framework
Global Privacy Protocol (GPP) string The CMP One string with separate sections for different jurisdictions, such as the EU TCF, a US national section, and US state sections Ad-tech vendors that support GPP
Global Privacy Control The visitor's browser A request to opt out of sale and sharing, sent as the Sec-GPC: 1 header (a W3C Working Draft) The site and its CMP

 

Missing signals cost measurement. Without Consent Mode or a TC string for visitors from the EEA, the UK, and Switzerland, Microsoft says it will stop tracking UET-based conversions and populating remarketing lists. Google ties ad personalization and audience features for EEA users to the same kind of consent signal.

Under § 7025 of California's regulations, businesses that sell or share personal information must treat opt-out preference signals like Global Privacy Control as a valid request. As of December 2025, the Future of Privacy Forum counted 12 US states that require honoring universal opt-out mechanisms. Read more in our US state privacy laws overview.

Enzuzo's consent management platform can detect a visitor's Global Privacy Control signal and implement its consent preferences.

cmp-2a@3x

How do CMPs sync consent with CRMs and other martech tools?

Consent management platforms sync consent in two ways: scripts on the page read the CMP's state through a JavaScript API, and back-end systems get the choice only when it's passed along with the data.

IAB's frameworks standardize the first part. Every TCF CMP must provide a __tcfapi function that other scripts can call and subscribe to. Its specification makes that function mandatory. The GPP specification gives GPP CMPs a __gpp function for web and in-app callers.

A CRM, an email platform, or a customer data platform never sees the banner. The choice has to travel with each record or event sent to it.

How do CMPs work with tag managers?

Consent management platforms work with tag managers by setting the consent types that the tag manager checks before it fires each tag. Google's own tags, including Google Analytics, Google Ads, Floodlight, and Conversion Linker, have built-in consent checks. Every other tag's consent setting defaults to Not set, which means no extra check, so it fires automatically until someone toggles it off.

Consent signals and blocking are separate jobs. In a 2024 study of 2,230 sites using the IAB's framework, 97.8% stored and passed on the visitor's choice correctly, yet 52.3% still set tracking cookies after refusal. 

Enzuzo is a Google-certified CMP Gold Partner for Consent Mode v2. It also supports Microsoft UET Consent Mode, set up through Google Tag Manager or a custom script.

 

cmp-5b@3x

What does a CMP do for advertisers and publishers?

For advertisers and publishers, a consent management platform turns each visitor's choice into a signal that travels with every ad request. Ad-tech vendors read it to learn whether they may use that visitor's data. In Europe, that signal is usually the TC string from IAB Europe's Transparency and Consent Framework (TCF).

IAB Europe registers the CMPs that take part in the framework and audits them. Its compliance report shows 51 enforcement procedures against CMPs in 2025, up from 40 in 2024, and one CMP temporarily suspended, then reinstated.

The audits show where registered CMPs slip. In IAB Europe's 2025 audits, 80% failed the check that the banner's second layer says how long the consent string is stored. The check that the first layer explains how to withdraw consent later failed in 44%. Both are shares of audits performed, and one audit can fail both; IAB Europe doesn't publish how many audits it ran.

Google adds its own rule for publishers. Sites and apps that show personalized ads through AdSense, Ad Manager, or AdMob must use a Google-certified CMP integrated with the TCF. The rule has applied to visitors in the European Economic Area and the UK since January 16, 2024, and in Switzerland since July 31, 2024.

Traffic from a non-certified CMP may be eligible only for non-personalized or limited ads.

Enzuzo is on IAB Europe's CMP list as CMP ID 418, and on Google's list of certified CMPs for publishers, both for websites. Enzuzo supports IAB TCF v2.3, too.

GDPR and CCPA CMP requirements

EU rules require a consent management platform to hold off on non-essential tracking until a visitor agrees, and regulators expect an easy way to refuse data tracking. In other words, the banner's default setting must be opt-out, with no dark UX patterns.

California's CCPA works differently. Businesses can set the default to opt-in, but GPC must be respected, and opting out must be simple. 

Under Article 4(11) of the GDPR, consent has to be freely given, specific, informed, and unambiguous. 

CMP features EU and California rules require
CMP feature EU (GDPR and ePrivacy) California (CCPA)
Block non-essential tracking before a choice Required: consent comes first under ePrivacy Art. 5(3) Generally not required; the CCPA is built on opting out
A way to refuse, as easy as accepting Expected by regulators: a vast majority of EU authorities in the EDPB taskforce treat a banner with no reject option on any layer that has an accept button as an infringement, and the CNIL faulted a Google account flow that, before October 2023, took 2 clicks to accept personalized ads and 6 to choose generic ones Required: a banner offering only Accept All and More Information isn't symmetrical under § 7004, enforced in the Honda order
No pre-ticked boxes Required: pre-ticked boxes aren't valid consent, per the Planet49 ruling Not applicable to opt-out
Easy way to say no later Required: withdrawing must be as easy as giving consent under GDPR Art. 7(3) Required for businesses that sell or share data: at least two opt-out methods, and for online businesses one of them must be an opt-out preference signal under § 7026
Proof of each choice Required: the controller must be able to demonstrate consent under GDPR Art. 7(1) Records of consumer requests, such as opt-outs, and the responses, kept for at least 24 months under § 7101
Opt-out without verification Not applicable Required: under § 7026(d), an opt-out can't demand a verifiable request, enforced in the Ford order
A cookie banner as the only opt-out Not applicable Not enough: under § 7026(a)(4), cookie banners and cookie controls alone aren't an acceptable opt-out method
Honor opt-out preference signals such as GPC Not required by the EU texts cited here Required under § 7025 for businesses that sell or share personal information

 

A site with visitors in both places needs a CMP that applies each set of rules by region. Enzuzo can set the banner to opt-in, opt-out, or hidden by country or region, and its team recommends opt-in banners for Californian visitors.

Other laws change the settings again. Quebec's Law 25 and Canada's PIPEDA set their own consent rules, covered in the Law 25 guide and the PIPEDA guide. 

How is a CMP implemented on a website?

CMPs are usually implemented in one of three ways: a script tag placed first in the page head, a tag manager template, or a plugin for the site's content management system.

How a CMP gets installed
Method How it works What it can block Where it breaks
Script in the page head The CMP's script loads before anything else and holds back scripts until consent Scripts in the page, if the CMP loads first and auto-blocking is on Scripts that load before the CMP, or ones it can't identify
Tag manager template The CMP runs inside the tag manager and sets consent types that tags check Tags inside the tag manager that have consent checks Tags left on Not set, and anything outside the tag manager
CMS or store plugin A plugin installs the CMP script on every page of a Shopify, WordPress, or Webflow site Same as the script method, installed without code Scripts added by other apps or plugins that load first

 

After install, setup follows the same order on every method. The site gets scanned, cookies get sorted into categories, rules get set by region, Google and Microsoft signals are setup if required, and the real workflow starts. 

The Michigan study also lists possible client-side causes of consent failures, such as developers embedding the CMP's script incorrectly and cookies nobody categorized. 

Testing should include the banner itself: it's part of the page, so it has to work with a keyboard and a screen reader like any other page element. A CMP also has to give people a way back into their settings once the banner closes.

 

cmp-4a@3x 

Is a consent management platform mandatory?

CMPs aren't explicitly named under EU law or California's rules, but their outcomes and purpose are. Those include consent before tracking in the EU, a working opt-out in California, and clear audit trails of consent preferences.  

For publishers, skipping a certified CMP in Europe means Google may serve only non-personalized or limited ads to visitors in Europe.

Under ePrivacy Article 5(3), a site can skip consent for technology that's strictly necessary for a service the visitor explicitly asked for. Examples include a shopping cart or a login session. A site that runs only strictly necessary cookies has nothing to ask permission for, so it doesn't need a consent banner under EU rules.

Everything else needs a way to collect and prove consent. Each new script, region, or ad platform adds rules that a CMP applies automatically and a developer would otherwise have to maintain.

Under EU rules, company size doesn't matter for consent compliance. The rules apply to all.

Sites that skip consent risk regulator ire and private lawsuits.  

Still unconvinced? The consent management benefits guide covers how your business gains goodwill by investing in privacy compliance.

 

cmp-6a@3x

What does a CMP do that a cookie banner or tag manager can't?

A consent management platform does three jobs a cookie banner and a tag manager can't do on their own: it collects and records each visitor's choice, turns that choice into signals every tag manager can process, and lets visitors change preferences later.

A cookie banner is only the visual front end; it cannot record or store consent choices independently. 

CMP vs cookie banner, tag manager, and preference center
Tool What it does What it doesn't do on its own
Cookie banner Shows the notice and the accept and reject buttons Block scripts, keep consent records, or send consent signals
Tag manager (such as Google Tag Manager) Loads tags and can check consent state before firing each one Ask visitors for consent or record their choice
Preference center The settings page where people revisit cookie choices and, in many setups, communication preferences Block trackers or send ad signals, unless a CMP runs behind it
Consent management platform Collects each choice, keeps the consent log, and tells every connected tag whether it may run Control scripts that never check consent state

 

The main difference between a consent manager and a cookie banner is that displaying a banner alone looks like consent. That's not the full picture.

California's regulations say as much: cookie banners and cookie controls aren't by themselves an acceptable way to opt out of the sale or sharing of personal information. 

The consent management platform market

Analyst estimates put the consent management market, software and services combined, at about $1.0 billion in 2025. Grand View Research projects $1.2 billion in 2026 and $2.8 billion by 2033, growing at 13.1% annually, with North America the biggest by market size.

The closest public count of the consent management platform industry is IAB Europe's CMP registry, which listed 194 active CMPs on September 24, 2026. 

119 of them were commercial CMPs. Of those 194, 129 were registered only for web-based consent.

Choosing the right consent management platform

Businesses usually choose a consent management platform by checking how well it delivers on cookie classification, tracking, audit trails, and analytics.

The best consent management platforms:

  • Hold non-essential scripts until a visitor agrees, rather than showing a banner over tags that already fired.
  • Apply opt-in, opt-out, or no banner by region, so EU and California visitors each get the right rules.
  • Offer a reject option that takes no more effort than accepting, with banners that are easy to customize.
  • Send the right signals a website is configured for, such as Google Consent Mode v2 and Microsoft UET consent mode, and honor Global Privacy Control where state law requires it.
  • Scan the site and sort what they find into categories, so new scripts don't slip through uncategorized.
  • Keep a consent log that shows when each choice was made and what the visitor saw.
  • Install in a few simple steps either by a <head> script, tag manager template, or CMS plugin
  • Display accurate analytics showing consented vs unconsented traffic

The best CMPs guide puts nine leading platforms through checks like these, with prices and a pick for each use case. Large and multi-brand sites can start with the enterprise CMPs guide, and the CMP pricing overview.

Enzuzo's CMP offers a strong balance between price and functionality, making it ideal for mid-market businesses. Want to learn more? Book an advisory call with a consent expert

Frequently asked questions

What does CMP stand for?

CMP stands for consent management platform. It's the software behind a site's cookie banner that records each visitor's choice and tells the site's tags what data they can collect. The letters mean other things in unrelated fields, including medicine. On a website's privacy settings or in ad-tech documentation, CMP means the consent tool.

Can a CMP show different banners in different countries?

A consent management platform can show different banners by country, based on geo-specific rules. The CMP applies that region's rules, such as an opt-in banner for visitors in the EU. For California, a site can default to opt-in, if it respects Global Privacy Control. Where no law applies, it does not need to show a banner.

Is a free CMP enough for a small website?

A free CMP is enough for many small websites if it blocks trackers before consent, logs each choice, and supports the regions the site's visitors come from. Traffic and domain limits usually apply on free CMPs;  Enzuzo's Free plan covers 1 domain and 5,000 monthly visitors, with basic consent logs.

How can a business tell if its CMP is actually blocking tags?

Network requests are the best way to check if your CMP is working. Any analytics or ad requests after rejecting cookies means a CMP hasn't passed on the right consent signals and isn't doing its job. 

What is a TC string?

A TC string is the encoded record of a visitor's consent choices that a registered CMP creates under IAB Europe's Transparency and Consent Framework. It lists which purposes and which registered ad-tech vendors the visitor allowed. The string travels with ad requests so each vendor can check it.

Can a company build its own consent management platform?

A company can build its own consent management platform, and many publishers do. In 2025, 41% of the CMPs registered with IAB Europe were private CMPs run by a publisher for its own sites. However, building one in-house means maintaining the scanner, the regional banner rules, and the right cookie categorization. A CMP that creates TC strings also needs IAB Europe registration and has to pass its audits.

Which team usually manages a consent management platform?

A consent management platform is usually shared across three groups. Privacy or legal staff set the rules, marketing or the web team configures the banner and categories, and developers install the script and connect the tag manager. On a small site, one person often does all three jobs.

What happens to consent when a visitor clears their cookies?

When a visitor clears their cookies, the choice saved in the browser disappears, so the CMP shows the banner again on the next visit. The earlier choice survives only in the consent log, if the CMP keeps one. A saved choice also stays on one device and one domain. Carrying it further takes a login or a shared setup across domains, which multi-domain consent covers.

Osman Husain

Osman Husain

Osman is the content lead at Enzuzo. He has a background in data privacy management via a two-year role at ExpressVPN and extensive freelance work with cybersecurity and blockchain companies. Osman also holds an MBA from the Toronto Metropolitan University.

LinkedIn →
logo_Constellation1_Light
logo_Mate_Light
logo_PCC_Light
logo_Aspen_Light
logo_Yale_Light
logo_BrightStar_Light

Start managing consent
the easy way.

Free forever plan available. No credit card required.

★ 4.6/5 on G2 | Trusted by 30,000+ businesses worldwide