Consent Management Build for EU and US Traffic

Camille DelacroixProNew0 orders on this service
Ad Compliance and Legal · Consent management implementation

Consent built from your tags outward: purpose taxonomy, firing matrix, TCF v2.2 and GPP in one banner, and a consent record you can produce later.

About this service

The common failure is a banner Google accepts and CNIL does not. Since 16 January 2024 Google has required a certified consent management platform integrated with the Transparency and Consent Framework for European Economic Area and UK traffic on Ad Manager, AdSense and AdMob. Certification checks that your strings are well formed. It does not check that refusing is as easy as accepting, which is the point CNIL fined Google and Facebook 150 and 60 million euros over in January 2022, and it is still the first thing an inspector looks at. How I build it: The taxonomy comes before the tool. I write the purpose list from your actual tags rather than from the framework's generic labels, then a firing matrix: every tag, against every purpose, against every region, with the states in which it must not fire. That matrix is the specification, the QA script, and the document that settles arguments between marketing and engineering six months later. Choosing between Didomi, Sirdata, Axeptio, Usercentrics or OneTrust happens after it and takes an afternoon, because by then the requirements are written down. Framework details that decide the design: Version 2.2 has been mandatory since 20 November 2023 and removed legitimate interest from the personalised advertising purposes, so those are consent or nothing, and any vendor sheet still showing legitimate interest for purpose 4 is out of date. The first layer has to state the vendor count and describe purposes in plain language. Google's additional consent string carries its ad technology providers sitting outside the framework. For United States traffic the Global Privacy Platform sections carry the signal instead, and the two have to coexist inside one banner without the geo logic turning into folklore that nobody can read. Proof: Consent that cannot be produced later did not happen. I specify the record: the string, the timestamp, the banner version and a hash of its text, the purposes and vendors as resolved at that moment, and a lookup by user identifier so an access request can be answered without pulling an engineer off a sprint. CNIL's guidance on lifetimes lives in the same place, meaning identifiers at thirteen months, associated data at twenty-five, and a refusal that is remembered rather than re-asked on the next page view. Consent or pay: I will build a paywall alternative for a publisher with a genuine equivalent offer and a price defensible against the criteria in EDPB Opinion 08/2024. For everyone else the answer is no, and the reason is that the version described to me on most first calls is a fee set to make refusal irrational, which is the same defect as a hidden refuse button with an invoice attached to it. Not included: The cookie inventory feeding the taxonomy, which is separate work and should come first. In-app consent, which follows a different framework and different store rules. Rewriting your privacy notice, although the purposes I define have to match it and I will point out precisely where they do not. Who should not book this: Anyone whose success measure is consent rate. I have raised acceptance by deleting three purposes nobody could explain and by shortening the first layer, and I have also handed over builds where acceptance fell and the client was better off for it. If the brief is to tune the interface until people give in, that work is available elsewhere, and it is the work regulators are currently pricing.

Scope

Target market
Worldwide, United Kingdom, Germany, France
Working language
English, French
Industry
Ecommerce and DTC, Automotive, Media and publishing, Agencies and consultants
Engagement model
One-off project
Turnaround
1 month or more
Seller type
Fractional executive

What the seller needs from you

  1. 1Do you have a current cookie and vendor inventory?
  2. 2Which regions carry material traffic, and which regulators have already contacted you?
  3. 3What is your current banner, and who owns it internally?
  4. 4Do you monetise through Google Ad Manager, AdSense or AdMob?
  5. 5Where must the consent record be queryable from?

Asked at checkout. Delivery time starts once you answer, not when you pay.

Reviews

No reviews on this service yet.

Reviews appear only after an order completes, and both sides review each other. Nothing here is seeded or bought.

Other sellers offering consent management implementation

See all →

Starting at €9,000