EU implementation scope

What the platform controls and what remains with the customer

A detailed allocation for teams preparing a Consentory deployment across EU and EEA websites.

Technical implementation scopeLast updated 19 August 2026

Consentory's technical layer

  • Discover cookies, storage and third-party network activity across representative pages.
  • Configure equal first-layer accept and reject actions plus granular purpose choices.
  • Hold managed optional scripts and iframes until the matching purpose is allowed.
  • Send Google Consent Mode v2 defaults and updates from the recorded choice.
  • Store and export pseudonymous, versioned consent records and permit later withdrawal.

Limits of automated detection

Scan results, classifications, prior-blocking detection, Consent Mode detection and readiness checks describe what the service could observe for the pages, requests, regions, devices and sessions it reached at the time of the check. They are automated aids, not an exhaustive or error-free record, and they are not a certification, audit or legal opinion.

  • Technologies that load only behind authentication, in a personalised or A/B-tested variant, in a geographic or consent state that was not reproduced, outside the crawl allowance or only for real visitor traffic can be missing from a result.
  • Classification and vendor attribution are heuristic: false positives, false negatives and unclassified items occur, and every proposed default needs customer review.
  • Bot protection, rate limiting, robots directives, authentication walls, firewall or CDN rules and third-party outages can leave a scan incomplete or make it fail.
  • A result is a snapshot and can be out of date as soon as the website, a tag manager container or a vendor changes, so retest after every release.

Customer decisions

  • Identify the controller, applicable establishments, target countries and sector-specific rules.
  • Determine purposes, lawful bases, vendors, joint-controller arrangements and international transfers.
  • Approve cookie and privacy notices, category wording, retention and data-subject request processes.
  • Classify unknown technologies and verify that tag managers, custom code and newly added vendors follow the selected purpose.
  • Decide whether IAB TCF, children's consent, sensitive-sector or national regulator requirements apply.

Country-specific considerations

GDPR provides an EU-wide data-protection framework, but national implementation of the ePrivacy rules, regulator practice, employment context, age thresholds, direct-marketing rules and enforcement expectations can differ. The customer's country matrix should cover its establishment, visitor markets, vendors and the actual processing performed.

Dependencies outside our control

Browsers, tag managers, analytics and advertising vendors, content management systems and plugins, hosting providers, CDNs, DNS and bot-protection services can change, deprecate or withdraw the interfaces, tags and consent signals the service depends on, and can suffer outages. We adapt the service where that is technically and commercially reasonable; sections 4, 19 and 20 of the Subscription Terms govern third-party changes, feature changes and events beyond reasonable control. Where a third party ignores, delays or caches a consent signal, its own agreement with the customer applies.

Release checklist

  • Scan representative public pages and authenticated journeys where authorised.
  • Resolve unclassified trackers and compare the inventory with tag-manager and vendor records.
  • Test first visit, accept all, reject all, custom choice, withdrawal and expired consent.
  • Verify keyboard, focus, screen-reader labels and EN/DE/FR text at mobile and desktop widths.
  • Confirm no optional technology runs before the applicable signal and record the release evidence.