Skip to main content
Promotional banner for the pentest readiness checklist
CMPs Under the Hood: A Security Engineer's Configuration ReferenceLaws and Regulations
5 min readFor Marketing Technology Teams

CMPs Under the Hood: A Security Engineer's Configuration Reference

Scope: What This Guide Covers

This guide explains how Consent Management Platforms (CMPs) enforce privacy law requirements at the technical level. You'll learn the specific requirements CMPs must meet, how they integrate with tag managers and ad-tech stacks, and common deployment issues. If you're configuring a CMP, auditing one, or explaining to stakeholders why "just add the snippet" isn't enough, bookmark this page.

Key Concepts and Definitions

A Consent Management Platform sits between your site's visitors and your tracking stack. It sets a default consent state before any other tag loads, captures each visitor's choice, updates that state, and signals the result to every connected tool.

Consent state is the set of granted-or-denied values the CMP holds for the current visitor. Google's implementation uses named types: ad_storage for advertising cookies, analytics_storage for analytics cookies, ad_user_data for user data sent to Google, and ad_personalization for ad personalization. Your tags check these values before storing anything.

Consent signals are the formats other tools read: Google Consent Mode v2, Microsoft UET Consent Mode, IAB's TC string, and the GPP string. A tag only respects consent if it checks the signal. A pixel pasted directly into your template never asks.

Terminal Equipment Access is the EU legal term for storing or reading information on a visitor's device. Article 5(3) of the ePrivacy Directive requires Prior Consent before access, with two narrow exemptions: storage used solely to carry a communication, and storage strictly necessary for a service the visitor explicitly requested.

The Load Sequence That Matters

On a typical page load, the CMP script must run first. It sets the default state for each purpose (denied in opt-in regions), detects the visitor's location, shows the banner, captures the choice, updates the state, releases allowed tags, and saves the choice in the browser. Google Tag Manager's Consent Initialization trigger fires before all other tags for this reason.

Each step is a potential failure point. The University of Michigan's study of CMP deployments lists region rules among the platform-side causes of consent violations, alongside scanners that miss cookies and wrongly categorize them.

Requirements Breakdown

GDPR (Articles 4(11), 6(1)(a), 7)

  • Valid Consent requires a Clear Affirmative Action before Terminal Equipment Access.
  • The CMP must record when the choice was made, what the visitor saw, and what they agreed to.
  • Visitors must be able to withdraw consent as easily as they gave it.
  • Equal Prominence: reject and accept options must carry the same visual weight.

ePrivacy Directive (Article 5(3))

  • Prior Consent required before storing or accessing information on the user's device.
  • Exemptions: communication carriage and storage strictly necessary for a service the visitor requested.
  • The "strictly necessary" label must be earned, not assumed.

CCPA (§ 1798.135)

  • Businesses that sell or share personal information must provide a working opt-out mechanism.
  • Under § 7025 of California's regulations, you must treat Global Privacy Control as a valid request.
  • You must maintain records of opt-out requests.

TCF v2.3 v2.3

  • Every registered CMP must provide a __tcfapi JavaScript function that other scripts can call.
  • Google requires a certified CMP for companies using Google Ads in Europe.
  • In IAB Europe's 2025 compliance report, 59% of registered CMPs were commercial, 41% were private.

Implementation Guidance

Tag Manager Integration

Your CMP sets consent types that Google Tag Manager checks before firing each tag. Google's own tags (Analytics, Ads, Floodlight, Conversion Linker) have built-in consent checks. Every other tag defaults to "Not set," meaning no check, so it fires automatically until you configure it.

In a 2024 study of 2,230 sites using IAB's framework, 97.8% passed the visitor's choice correctly, yet 52.3% still set tracking cookies after refusal. Consent signals and blocking are separate jobs.

Cookie Categorization

Your CMP scanner sorts what it finds into categories. Here's what requires consent under EU rules:

  • Essential Cookies: Login sessions, shopping carts (no consent needed when strictly necessary).
  • Functional: Language, region, chat widgets (consent required unless strictly necessary).
  • Analytics: Visit counts, page views, traffic sources (consent required, with narrow exceptions like France's CNIL exemption for some audience measurement).
  • Marketing: Ad pixels, retargeting, cross-site profiles (always requires consent).

The EDPB's Consent Notice taskforce pointed to website owners' responsibility to prove that cookies labeled essential are in fact essential.

Signal Compatibility

Your CMP must send signals in formats your stack already reads:

  • Google Consent Mode v2 for Google tags.
  • UET Consent Mode for Microsoft Advertising.
  • TC string for ad-tech vendors registered in IAB's framework.
  • GPP string with jurisdiction-specific sections.
  • Global Privacy Control reception (sent as Sec-GPC: 1 header).

Missing signals cost measurement. Without Consent Mode or a TC string for EEA, UK, and Swiss visitors, Microsoft stops tracking UET-based conversions and populating remarketing lists.

Common Pitfalls

In IAB Europe's 2025 audits, 80% of CMPs failed the check that the banner's second layer states how long the consent string is stored. The check that the first layer explains Withdrawal of Consent failed in 44%.

Other failure modes:

  • CMP script loads after tags have already fired.
  • Scanner misses scripts added by store apps or plugins.
  • Region detection applies wrong ruleset.
  • "Not set" tags bypass consent checks entirely.
  • Consent state updates but blocked scripts remain cached.
  • No mechanism to reopen preference center.

Quick Reference Table

Requirement Regulation Technical Implementation
Consent before tracking GDPR Art. 6(1)(a) CMP sets default to denied; updates on choice
Terminal Equipment Access ePrivacy Dir. Art. 5(3) CMP blocks storage/access until consent
Opt-out mechanism CCPA § 1798.135 CMP honors Global Privacy Control signal
Consent records GDPR Art. 7(1) CMP logs timestamp, banner version, choices
Withdrawal as easy as grant GDPR Art. 7(3) Persistent link to preference center
Equal Prominence EDPB Guidelines Accept/reject buttons same size, color weight
Certified CMP for Google Ads Google policy IAB-registered CMP with valid TC string
__tcfapi function TCF v2.3 spec Mandatory JavaScript API for registered CMPs

Your CMP is only as compliant as your configuration. The platform provides the mechanism; you're responsible for the rules it enforces.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like