Skip to content
CookieTosser

Consent management platforms explained

Published September 27, 2026

Almost every cookie banner on the web today is generated by a consent management platform (CMP) — third-party software the site installed rather than something it built itself. Understanding what a CMP actually does, and what it only promises to do, explains why two sites can have banners that look nearly identical and behave completely differently underneath.

What a CMP does

A CMP is a script the site loads, usually before anything else, that:

  1. Shows the banner and records whatever choice the visitor makes.
  2. Reads that choice back on every later page view, so the visitor isn't asked again.
  3. Exposes the choice as a signal — typically the window.dataLayer or gtag('consent', 'update', …) calls used by Google's tools, or a TCF consent string (below) for the ad industry more broadly — that other scripts on the page are supposed to check before they run.
  4. Optionally holds back other tags itself, if it's configured to control the order scripts load in, rather than merely reporting a choice for other scripts to act on voluntarily.

That fourth point is the crux of the whole topic, and it's a configuration choice, not something a CMP guarantees automatically. A CMP installed to display a compliant-looking banner is a different, much smaller thing than a CMP installed to gate every tracking script until it's answered — see how to stop loading trackers before consent for the difference in practice. A site can install a CMP purely for the banner and its record-keeping, while every advertising and analytics tag on the page loads exactly as it would with no CMP at all. That gap is exactly what shows up when a scan finds trackers loading before any interaction with a banner that otherwise looks properly built.

The IAB's Transparency and Consent Framework (TCF)

The Transparency and Consent Framework (TCF), maintained by IAB Europe, is a shared standard the online advertising industry built so that hundreds of ad-tech vendors on a page don't each need their own separate consent conversation with the visitor. When a visitor makes a choice, the CMP encodes it into a compact "TC string" that records which purposes (like ad personalization) and which of thousands of registered vendors the visitor consented to. Any TCF-compliant vendor on the page can read that string and decide whether it's allowed to run.

TCF has itself drawn regulatory scrutiny. Belgium's data protection authority found problems with how the framework handled the TC string, and the Court of Justice of the EU weighed in on the case in 2024, addressing whether the string counts as personal data and how responsibility is shared between IAB Europe and the businesses using the framework. The current version of the standard, TCF 2.2 (2023), responded to some of that criticism: it dropped "legitimate interest" as a legal basis for personalised advertising and content, and it requires CMPs to show how many vendors are asking for consent and to make withdrawing consent as easy as giving it.

TCF only governs vendors that participate in it. A site can (and often does) also run non-TCF scripts — its own analytics, a chat widget, an A/B testing tool — that never check the TC string at all, because nothing requires them to.

Google Consent Mode v2

Consent Mode is Google's own mechanism for its tags (Google Analytics, Google Ads, the Google tag) to adjust behavior based on a visitor's consent choice, communicated via gtag('consent', 'update', …) calls with signals including ad_storage, analytics_storage, and — added in version 2 — ad_user_data and ad_personalization. Google requires the v2 signals for sites that want to keep using personalized advertising and remarketing features for visitors in the EEA.

It comes in two modes, and the difference matters a lot for what actually loads before consent:

  • Basic Consent Mode: Google's tags don't load at all until the visitor responds to the banner. Nothing is set, nothing pings out, until there's an answer either way. This is the more privacy-protective default, at the cost of Google getting no data at all — not even anonymized signals — for a visit that never gets an answer.
  • Advanced Consent Mode: Google's tags load immediately, before any consent choice, but send cookieless pings — requests with no cookie attached — when consent for storage is denied. Google uses these pings to statistically model the conversions and traffic it can no longer measure directly, without setting the identifiers it would otherwise use.

The distinction is exactly the kind of thing a before-consent scan like this site's is built to see: in Basic mode, a Google tag genuinely doesn't fire before an answer. In Advanced mode, a request to Google fires before any answer, every time — it just doesn't carry a cookie. Whether that counts as the kind of "storage or access" the ePrivacy Directive requires consent for is a real point of debate, since a cookieless ping is still an outbound request disclosing that a specific page was visited, at a minimum, to a specific advertising company, before the visitor said yes.

Why a banner isn't proof of anything by itself

Put together, none of this changes the same basic fact from how to check what a site loads: the only way to know what a specific site does before consent is to look. A CMP, TCF membership, and Google Consent Mode all describe mechanisms available to hold tags back — none of them describe what a given site actually configured. A well-known CMP's logo in the footer is evidence the site cared enough to install one; it isn't evidence of how it was set up. Look up a site's own report to see what our monthly scan actually found loading before any click, or check yourself with your browser's tools.

Related guides