A consent management platform (CMP) captures, enforces and proves cookie consent across every regulation you operate under.
Most privacy laws require a lawful basis before you process someone’s personal data, and for cookies and trackers that basis is usually consent. A consent management platform is the system that makes that consent real: it asks the visitor, holds back tracking until they answer, remembers the choice, and proves it later.
The term is often shortened to CMP, and you may also hear it called a consent manager, a cookie consent manager or consent management software. Whatever the name, the job is the same: turn a legal requirement into something your website actually enforces and can defend in an audit.
See how this maps to specific laws on our compliance hub, browse the consent management solutions built for your role and industry, or check what fires on your own site with the free cookie scanner.
Six jobs every real CMP has to do, not just show a banner.
Show a compliant consent banner and capture a clear, freely given choice per purpose, before any non-essential cookie or tracker runs.
Hold analytics, ads and third-party scripts until the visitor agrees, so nothing fires without a lawful basis. This is what separates a real CMP from a banner that only records a choice after the fact.
Detect where each visitor is and apply the correct legal basis and banner behaviour automatically, from opt-in (GDPR) to opt-out (CCPA) to India's DPDPA.
Give visitors an always-available way to review and withdraw consent, and re-block trackers the moment they do.
Pass consent signals to Google tags via Consent Mode v2 and respect Global Privacy Control, so measurement and compliance stay aligned.
Store a tamper-evident record of who consented to what, when, and under which policy version, so you can answer a regulator or auditor with evidence.
A short checklist for choosing a CMP you will not have to replace.
The platform must block non-essential trackers before consent. A banner that only logs a choice after scripts already fired does not make you compliant.
One platform should handle GDPR, UK GDPR, CCPA/CPRA, DPDPA, LGPD and more, with the right behaviour per jurisdiction, not a separate tool per law.
Look for versioned consent receipts and tamper-evident records you can export, not just a count of clicks.
The platform should discover the cookies and trackers on your site and flag what runs before consent, so your banner reflects reality.
A single script tag, plus WordPress, Shopify and Google Tag Manager integrations, so you are live in minutes without an engineering sprint.
Region rules and banner content you edit from a dashboard, so legal changes do not need a deployment.
Everything above, in one platform built for evidence rather than just a banner.
Capture provable consent, block trackers before they fire, and prove it across every regulation. Free to start.