What is a consent management platform (CMP)?
A consent management platform runs your cookie banner, blocks tracking until visitors choose and keeps proof. What it does, what it can't, how to choose.
A consent management platform (CMP) is the software that asks your visitors whether they accept cookies and similar tracking, holds back everything that needs consent until they answer, and keeps a record of what they chose. Many also produce the cookie list your policy needs and pass the choice on to tools like Google Analytics. The banner is the part you see; the CMP is the machinery behind it.
The term is not just vendor jargon. France's CNIL uses it in its cookie recommendation, where it suggests that the successive configurations of a CMP can be kept, time-stamped, by the company that provides it, as one way to prove consent was collected properly.
Why sites need one
In the EU, Article 5(3) of the ePrivacy Directive only allows a site to store or read information on a visitor's device with their consent, unless it is strictly necessary for a service they asked for or used solely to transmit a communication. The GDPR then defines what consent is: "freely given, specific, informed and unambiguous", given "by a statement or by a clear affirmative action". The UK has an equivalent rule in PECR.
On a site with a tag manager, an analytics tool, an ad pixel and a couple of embedded videos, meeting that rule by hand is close to impossible. That is the job a CMP takes on.
What a CMP does
It shows the choice. A banner that offers Accept and Reject at the same level, plus a way to choose by category. When the EDPB's cookie banner taskforce surveyed Europe's regulators, "a vast majority" considered it an infringement when a layer of the banner has an accept button but no option to refuse. The same report confirms that pre-ticked boxes do not produce valid consent.
It blocks before consent. Cookies and scripts that need consent have to wait until the visitor opts in. Cookies placed without consent were the reason for the CNIL's €150 million fine against SHEIN in 2025, and our look at what regulators actually punish shows how often it comes up.
It records the decision. Under Article 7(1) of the GDPR, "the controller shall be able to demonstrate that the data subject has consented". A CMP stores what each visitor chose and when.
It lets visitors change their mind. Article 7(3) adds: "It shall be as easy to withdraw as to give consent." In practice that means a link or icon that reopens the choice on any page.
It explains the cookies. Consent only counts if it is informed, so the banner and the cookie policy have to say which cookies the site uses and why. Which of them need consent at all is a question of purpose, covered in which cookies need consent.
It passes the choice on. Other tools need to know what the visitor decided:
| Signal | What it carries | Who expects it |
|---|---|---|
| Google Consent Mode | Four consent types: ad_storage, analytics_storage, ad_user_data and ad_personalization | Google tags. For visitors in the EEA, Google says you "must collect consent" and share consent signals to keep using its measurement, ad personalisation and remarketing features (Google) |
| Global Privacy Control (GPC) | A browser signal asking sites not to sell or share the visitor's data | California's Attorney General says it "must be honored by covered businesses as a valid consumer request" (OAG) |
| IAB Europe's TCF | A standard consent string for advertising vendors | Google requires a Google-certified CMP integrated with the TCF for personalised ads through AdSense, Ad Manager or AdMob in the EEA, the UK and Switzerland (Google) |
Consent Mode does not ask the visitor anything. Google's documentation expects you to obtain the choice through a banner, your own solution or a CMP first, then pass it on.
What a CMP does not do
For a European site that uses analytics or advertising, a CMP is the practical way to meet the rule. It is not sufficient on its own, and a vendor that tells you otherwise is overselling.
- It does not make you compliant. A CMP configured with Reject tucked away, or with a marketing cookie filed as necessary, collects consent that is not valid.
- It only controls what it knows about. A script pasted straight into a template or a tag added by a marketer next quarter can sit outside it. And it decides whether a tag runs, not what the tag does once it runs: in the Apoteket case, the consent gate worked, and the Meta Pixel still sent the names, addresses and purchases of customers who had accepted marketing cookies to Meta.
- It does not see your servers. Data your backend sends to an ad platform never passes through the banner.
- It does not decide for you. Which cookies are necessary, which legal basis applies to the processing that follows, and what your privacy notice says remain your calls.
How to choose one
| Question | Why it matters |
|---|---|
| Does it block before consent? | Test it: open a private window, open DevTools and look at the cookies before you touch the banner. Our cookie checker does the same for a single URL. |
| Is Reject on the first layer, as easy as Accept? | Most European regulators treat a missing reject option as an infringement, as above. |
| Does it find your cookies for you? | A cookie list kept by hand goes stale the next time someone adds a tag. |
| Which laws does it handle? | The EU and UK expect opt-in. US state laws such as the CCPA expect an opt-out and honouring GPC. |
| Which signals do you need? | Consent Mode v2 if you use Google Ads or Analytics; the TCF if you sell personalised ads through Google's publisher products. |
| Where are consent records stored? | They hold IP addresses and choices, which is personal data. |
| What does it cost your pages? | Every visitor loads the script before anything else. |
We keep side-by-side comparisons of Katla and other CMPs, with each competitor's facts taken from its own public pages, on our compare pages.
Tip
Before comparing features, check the one thing every CMP claims: load your own site in a private window and see whether any analytics or advertising cookie is already there before you click anything.
Where Katla fits
Katla is a CMP, and here is plainly what it does today. It has two consent modes, GDPR
(opt-in) and US State Laws (CCPA, opt-out), and Auto picks between them by the visitor's
timezone. Accept, Reject and Customise sit together on the first layer, with nothing
pre-selected. In GDPR mode, the cookie guard blocks non-functional cookies before consent and
deletes any set before it ran, and scripts tagged with data-katla-category wait until their
category is accepted.
It sends Google Consent Mode v2 signals and honours GPC (not Do Not Track). Consent records keep the latest decision per visitor, with its categories, time and a truncated IP address, and everything is hosted in the EU, in Frankfurt. Katla also scans your site, classifies each cookie with AI and generates the cookie policy from what it found, in 13 languages.
It does not support the IAB TCF. If you need personalised ads through AdSense or Ad Manager for European visitors, you need a TCF-certified CMP, and Katla is not one.
This post explains what consent management platforms do. It is not legal advice.