CMP List
A CMP List generally refers to a compilation of Consent Management Platforms, which are software tools that help websites and apps collect, manage, and store user consent for processing personal data. Such a list may be used to compare or select vendors that support cookie and consent compliance. The available evidence describes what a Consent Management Platform is but does not detail the specific structure, maintainer, or authority behind any particular 'CMP List,' so those aspects are out of scope here.
In the context of cookie consent management, a 'CMP List' typically denotes a catalog or register of Consent Management Platforms (CMPs), the software solutions that facilitate the collection, management, and storage of user consent for the processing of personal data on websites and mobile applications. CMPs are commonly deployed to support compliance with data privacy obligations, though a tool's inclusion on any list does not itself guarantee legal compliance, which depends on configuration and jurisdiction-specific requirements (for example, the opt-in consent standards typical of EU/UK frameworks versus opt-out models under certain US state laws). The evidence provided does not identify a specific governing body, framework (such as an IAB TCF registered-CMP list), or eligibility criteria for any particular 'CMP List'; where such a list is maintained by a specific framework or authority, its scope and requirements should be confirmed against that source directly. This distinction is noted because contested or framework-specific interpretations are not resolvable from the evidence packet.
Why it matters
Selecting a Consent Management Platform is one of the more consequential technical decisions an organization makes when operationalizing cookie and consent compliance, and a CMP List, understood as a compilation of available platforms, can serve as a starting point for comparing vendors. Because CMPs are the software layer through which user consent is collected, managed, and stored across websites and apps, the choice of platform affects how consent signals are captured, how records are retained, and how well the deployment can be aligned with jurisdiction-specific requirements.
It is important to treat any CMP List as a reference for vendor evaluation rather than as a compliance assurance. Inclusion of a platform on a list does not, by itself, establish that a given deployment is lawful. Compliance generally depends on how the CMP is configured, the categories of cookies and technologies in use, and the applicable legal regime, for example, the opt-in consent standards typical of EU and UK frameworks versus the opt-out models common under certain US state privacy laws. A well-regarded tool configured incorrectly can still produce non-compliant outcomes.
The evidence available describes what a Consent Management Platform is but does not identify a specific governing body, framework, or eligibility criteria behind any particular 'CMP List.' Where a list is maintained by a specific framework or authority, such as a registered-CMP list under a particular consent framework, its scope, criteria, and legal significance should be confirmed directly against that source rather than assumed.
Who it's relevant to
Inside CMP
Common questions
Answers to the questions practitioners most commonly ask about CMP.
