How Consent Management Platforms Work Behind the Scenes
Patrick Bushe
February 7, 2025 · 5 min read
Most cookie banners aren't built by the website you're visiting. They come from consent management platforms, or CMPs, such as OneTrust, Cookiebot (part of Usercentrics), Didomi and Quantcast Choice. Here's what they do after you click.
1. Showing the banner
The site adds the CMP's script to its pages. When you arrive, the script checks whether you've already made a choice, often by looking for its own cookie. If not, it shows the banner, sometimes only to visitors from regions where consent is required.
2. Recording your choice
When you accept, reject or choose specific categories, the CMP saves your decision in a cookie or local storage so the banner doesn't return on every page. Many also log consent records on their servers, because privacy laws require sites to prove consent was given.
3. Sharing it with ad vendors
Many sites use IAB Europe's Transparency and Consent Framework (TCF). The CMP encodes your choices, for each purpose and each vendor, into a compact string, often stored in a cookie named euconsent-v2. Ad tech companies read that string to decide whether they may use your data. Banners listing hundreds of "partners" are showing the TCF vendor list.
In 2024, the EU's Court of Justice ruled (case C-604/22) that this string can count as personal data, and that IAB Europe can share responsibility for how it's used.
4. Controlling tags
The CMP is supposed to stop analytics and ad scripts from loading until you consent. With Google's Consent Mode, Google tags adjust their behavior based on your choice; Google has required Consent Mode v2 for personalized ads to users in the European Economic Area since March 2024.
Why the reject button is hard to find
CMPs let site owners design the banner. Some put "Accept all" in a bright button and hide "Reject" behind "Manage options." European regulators have said rejecting should be as easy as accepting, and France's CNIL has fined large companies over this.
What goes wrong
- Tags that fire before consent because they weren't wired to the CMP.
- "Legitimate interest" switches turned on by default.
- Choices that aren't saved, so the banner keeps returning.
Making it easier
Cookie Auto-Reject clicks reject, decline or only-necessary buttons on many common CMP banners, so you don't have to hunt for them. See cookie walls and why GDPR brought cookie pop-ups.