Consent Management
In short
Consent management means collecting, storing and managing your website visitors' consent, for example for analytics and marketing cookies.
Also known as: consent banner, cookie banner, cookie consent banner, CMP, consent management platform
Consent management covers everything needed to collect, document and technically enforce your website visitors' consent to data processing. You usually see it as a cookie banner; behind it there's typically a consent management platform (CMP).
What a CMP does
- Ask: The banner asks for consent, usually split into categories like ‘necessary’, ‘statistics’ and ‘marketing’.
- Store: The choice is logged with a timestamp so you can prove it.
- Control: Tracking scripts like the Meta Pixel or Google tags only load once the matching category is approved.
- Allow withdrawal: Visitors must be able to change their choice later.
Why consent management changes tracking
In the EU, the GDPR and the ePrivacy rules generally require consent for marketing and analytics cookies. If a visitor declines, those scripts must not run. For you, that means the ad account only sees part of your real conversions. Many US states now have their own privacy laws as well, typically with opt-out rather than opt-in rules.
Example
Your landing page gets 1,000 visitors from Meta ads, and 40 of them become leads. If 60% accept marketing consent, the browser pixel sees only about 24 leads on average. The cost per lead in the ad account looks much higher than it really is – and the algorithm has fewer signals to learn from.
Consent management in lead generation
Because consent shrinks your data, it pays to also capture leads from your CRM or forms instead of relying on browser events alone. Clarify with your privacy advisor which data you share with ad platforms and on what legal basis.
With lead tracking in LeadMetrics, the lifetime of a session depends on consent: 90 days with consent, 1 day without.
Common mistakes
- Loading scripts before consent: The banner is there, but the pixel still fires immediately.
- Hiding the reject option: An ‘accept all’ button without an equally easy way to decline is legally risky in the EU.
- Wrong categories: Putting a marketing tag under ‘necessary’ doesn't get around consent – it just makes your setup vulnerable.
Note: This article is not legal advice.
Ready for better tracking?
Frequently asked questions
Guides on this topic
Related terms
All termsGDPR · General Data Protection Regulation
The GDPR (General Data Protection Regulation) is the EU law protecting personal data. Since May 2018 it applies to anyone processing data of people in the EU.
First-Party Cookies
First-party cookies are set by the domain you are currently visiting. They store things like logins, shopping carts or tracking IDs for that same website.
Third-Party Cookies
Third-party cookies are set by a different domain than the one you visit, such as an ad network, and let that domain track users across many websites.
Conversion Tracking
Conversion tracking records which users complete a desired action after clicking an ad – such as submitting a form, booking a call or buying.
Server-Side Tracking
Server-side tracking sends tracking data to ad and analytics platforms from a server instead of the browser – more robust and under your control.
App Tracking Transparency
App Tracking Transparency (ATT) is Apple's rule since iOS 14.5: apps must ask users before tracking them across other companies' apps and websites.