Consent Management Platform (CMP): What It Is and How It Works
Learn what a consent management platform (CMP) is, how it collects and stores cookie consent, and how to choose one that keeps your website compliant.
A consent management platform (CMP) is the software layer that sits between your website and your visitors' personal data, collecting and enforcing their cookie choices. If your site uses analytics, advertising pixels, or embedded media and receives traffic from the EU, UK, or California, a CMP is how you turn legal consent requirements into something that actually runs in the browser. This guide explains what a CMP does, when the law effectively requires one, and how to choose and configure one correctly. It is educational information, not legal advice, so consult a qualified attorney for guidance specific to your business.
What Is a Consent Management Platform (CMP)?
A consent management platform is software that displays a consent banner, records each visitor's choices, blocks non-essential cookies and trackers until consent is given, and stores auditable proof of every decision. The banner is only the visible part. The real work happens underneath: script blocking, signal passing, and record keeping.
A complete CMP handles four jobs:
- Collection: Presents a banner or preference center where visitors accept, reject, or customize cookie categories.
- Enforcement: Prevents non-essential cookies and tracking scripts from firing until the visitor opts in.
- Signaling: Passes the visitor's choices to third-party tools such as Google Analytics, Meta Pixel, and ad networks so they respect the decision.
- Record keeping: Stores a timestamped log of who consented to what, which you need if a regulator asks for proof.
You will see the phrase written both ways: consent management platform CMP and CMP consent management platform. They mean the same thing. Some vendors also use "consent management provider," particularly in the advertising ecosystem, where the IAB maintains a list of registered CMPs for its Transparency and Consent Framework.
Why a CMP Consent Management Platform Matters Legally
No regulation contains the sentence "you must install a CMP." What the law requires is a set of behaviors that are practically impossible to deliver manually on a modern website.
The ePrivacy Directive and GDPR
Article 5(3) of the ePrivacy Directive requires prior informed consent before storing or accessing information on a user's device, except for cookies that are strictly necessary to deliver a service the user requested. The General Data Protection Regulation (GDPR) then defines what valid consent looks like: Article 4(11) requires it to be freely given, specific, informed, and unambiguous, and Article 7(1) puts the burden of proof on you to demonstrate that consent was given.
That combination creates three technical obligations:
- Block first, ask second. Non-essential cookies must not fire before the visitor opts in. A banner that loads Google Analytics while asking for permission fails this test.
- Offer real choices. Under Article 7(3) of the GDPR, withdrawing consent must be as easy as giving it. Regulators including CNIL in France have fined companies specifically for making "reject" harder than "accept"; Google was fined 150 million EUR and Facebook 60 million EUR in 2022 on exactly this point.
- Keep evidence. If a data protection authority investigates, you need timestamped records showing what each visitor was told and what they chose.
Penalties are serious. GDPR fines reach up to 20 million EUR or 4% of global annual turnover under Article 83, and ePrivacy penalties vary by EU member state on top of that.
CCPA, CPRA, and other laws
The California Consumer Privacy Act (CCPA), as amended by the CPRA, uses an opt-out model rather than opt-in. Businesses that sell or share personal information must honor "Do Not Sell or Share My Personal Information" requests and, under the CPRA regulations, opt-out preference signals such as Global Privacy Control (GPC). A CMP with geo-targeting can show EU visitors an opt-in banner and California visitors an opt-out link from the same installation. Similar consent or opt-out duties now exist in laws from Brazil's LGPD to state laws in Virginia, Colorado, and Connecticut.
How a CMP Works: The Consent Lifecycle
Understanding the lifecycle helps you evaluate whether a given CMP actually does its job or just paints a banner on the page.
- Scan: The CMP (or a companion scanner) crawls your site to find cookies, scripts, and third-party services, then sorts them into categories such as necessary, analytics, marketing, and preferences.
- Block: On each page load, the CMP script runs before other tags and holds back everything non-essential.
- Prompt: The visitor sees the banner with accept, reject, and customize options presented with equal prominence.
- Record: The choice is stored with a timestamp, the categories selected, and the banner version shown.
- Execute: Consented scripts are released; rejected ones stay blocked. Consent signals go out to downstream tools.
- Persist and refresh: The choice is remembered on return visits, remains changeable at any time, and is re-requested when your cookie usage changes or the consent expires.
Step one is where most manual setups quietly fail. Sites add a tag manager container, a chat widget, or an embedded video months after configuring the banner, and those new trackers fire without consent. This is why scanning cannot be a one-time task; your cookie inventory changes whenever your marketing stack does.
Core Features Every CMP Needs
When comparing vendors, treat the following as non-negotiable:
- Prior blocking of all non-essential cookies and scripts, verified in the browser, not just claimed in marketing copy.
- Granular categories so visitors can accept analytics but reject marketing, as required by the "specific" element of GDPR Article 4(11).
- Equal accept and reject options on the first banner layer.
- Consent records with timestamps, exportable if a regulator asks.
- A persistent preference center (usually a footer link) where visitors can change or withdraw consent, satisfying Article 7(3).
- Automatic cookie scanning on a schedule, so new trackers are caught and categorized.
- Consent signal integrations, at minimum Google Consent Mode v2 and ideally IAB TCF v2.2 if you run programmatic ads.
- Geo-targeting to show the right banner behavior per jurisdiction.
- Multi-language banners matched to your audience.
A cookie consent banner that lacks prior blocking or record keeping is decoration, not compliance.
CMP and Google Consent Mode v2
Since March 2024, Google requires Consent Mode v2 for websites using Google advertising features with European Economic Area and UK traffic. Without it, remarketing audiences stop filling and ad personalization degrades.
Consent Mode v2 defines four signals your CMP must send:
- ad_storage: whether advertising cookies may be stored.
- analytics_storage: whether analytics cookies may be stored.
- ad_user_data: whether user data may be sent to Google for advertising.
- ad_personalization: whether data may be used for personalized ads.
The CMP maps its banner categories to these signals and updates them the moment a visitor makes a choice. If you run Google Ads or GA4, verify that any CMP you shortlist is a Google-certified CMP partner, because Google now requires certification for Consent Mode integration with its ad products. For setup details, see the Google Consent Mode v2 guide.
Choosing a Consent Management Platform (CMP) for Your Site
The right choice depends on traffic volume, ad stack complexity, and how often your site changes.
Questions to ask before comparing vendors
- Where are your visitors? EU and UK traffic requires opt-in behavior; California requires opt-out handling and GPC support.
- Do you run programmatic advertising? If yes, you need IAB TCF v2.2 support and Google certification. If you only run analytics, you do not.
- How often does your site change? Frequent changes demand automatic rescans, not annual manual audits.
- How many monthly visitors do you have? Most CMPs price by banner views or sessions.
- Do you need the banner in multiple languages?
What CMPs cost
Pricing follows a consistent pattern across the market:
| Tier | Typical price | What you get |
|---|---|---|
| Free | $0 | Basic banner, capped monthly views, manual scanning |
| Entry | $10 to $15/mo per site | Higher view limits, scheduled scans, consent records |
| Professional | $20 to $50/mo per site | Unlimited or high view caps, geo-targeting, branding removal |
| Enterprise | Custom | Multiple domains, SLAs, advanced integrations |
As a concrete example, TermsBox includes its consent banner free for up to 5,000 monthly views with manual scans, while its paid tiers ($12/mo Starter, $25/mo Pro, per website) add scheduled scanning, higher view limits, and geo-targeted consent. Comparable entry pricing exists across the category, so weigh the scanning and integration features rather than the sticker price alone.
Cookie Policy Generator
Create a cookie policy for GDPR compliance. Create yours in minutes with TermsBox.
Generate NowRed flags to avoid
- Banners with no reject button on the first layer.
- "Consent" solutions that only hide the banner while cookies fire anyway.
- No exportable consent log.
- No update path for regulatory changes such as Consent Mode v2, which stranded many sites on non-compliant setups in 2024.
Connecting Your CMP to Your Cookie Policy
A CMP and a cookie policy are two halves of the same obligation. The banner collects consent; the policy delivers the "informed" part of informed consent by disclosing what each cookie does, who sets it, and how long it lasts.
Keep them synchronized:
- Every cookie category in the banner should be explained in the policy.
- When a scan finds new trackers, both the banner configuration and the policy need updating.
- The banner and preference center should link directly to the policy.
You can create the document side with a cookie policy generator and pair it with your banner configuration. If you are still deciding what the policy itself must contain, the guide on what a cookie policy is covers the required disclosures in detail.
Common CMP Implementation Mistakes
Even with good software, configuration errors undermine compliance. These are the failures regulators and auditors find most often:
- Scripts loaded outside the CMP. A developer hardcodes a pixel in the page template, bypassing the blocking layer. Audit with browser DevTools: open a private window, reject all cookies, and check which requests still fire.
- Tag manager misconfiguration. Google Tag Manager tags must be gated by consent triggers or built-in consent checks; a container that fires everything on page load defeats the CMP.
- Cookie walls. Blocking all site access unless the visitor accepts marketing cookies conflicts with "freely given" consent under GDPR Article 4(11). The EDPB's guidelines on consent (05/2020) reject this pattern in most cases.
- Pre-ticked boxes. The CJEU's Planet49 ruling (Case C-673/17, 2019) confirmed that pre-checked consent boxes are invalid.
- Ignoring returning-visitor changes. If a visitor withdraws consent, previously set cookies for that category should be deleted or invalidated, not merely stopped going forward.
- One banner for the whole world. Showing EU-style opt-in to United States visitors is legal but costs consent rates, while showing US-style notice-only banners to EU visitors is a violation. Geo-targeting solves both.
Test after every marketing tool you add, not just at launch.
Frequently Asked Questions
What is a consent management platform (CMP)?
A consent management platform (CMP) is software that displays a cookie banner, collects visitor consent choices, blocks non-essential cookies until consent is given, and stores proof of every consent decision. It helps websites comply with laws like the GDPR and the ePrivacy Directive.
Do I legally need a CMP for my website?
No law names CMPs specifically, but if you use non-essential cookies and have visitors from the EU or UK, Article 5(3) of the ePrivacy Directive and the GDPR require prior opt-in consent that you can prove. A CMP is the practical way to meet those requirements, which is why regulators expect to see one in place.
What is the difference between a CMP and a cookie banner?
A cookie banner is only the visible notice; a CMP is the full system behind it. The CMP blocks cookies before consent, records each choice with a timestamp, passes consent signals to tools like Google Analytics, and lets visitors change their mind later. A banner without these functions does not make you compliant.
Is a free CMP good enough for compliance?
Often yes, for smaller sites. Free tiers such as TermsBox's (5,000 banner views per month) include the core requirements: prior blocking, granular choices, and consent records. You typically pay when you need higher traffic volumes, geo-targeted behavior, or automatic rescans of your site.
How does a CMP work with Google Consent Mode v2?
The CMP translates each visitor's choices into consent signals (ad_storage, analytics_storage, ad_user_data, and ad_personalization) and sends them to Google tags. Since March 2024, Google requires Consent Mode v2 signals from EEA and UK traffic to use ad personalization and remarketing features.
How long should a CMP store consent records?
The GDPR sets no fixed period, but you must retain proof of consent for as long as you rely on it, under the accountability principle in Article 5(2). In practice most organizations keep records for the life of the consent plus a limitation period; CNIL guidance suggests re-asking for consent at least every 13 months.