Scanning your connection...
Back to Glossary
Legal

What is Consent Management?

Systems and processes for collecting, recording, and managing user consent for data collection and processing, required by GDPR and similar laws.

Consent management became critical after GDPR made freely-given, specific, informed consent a legal requirement.

Requirements Under GDPR

  • Consent must be freely given (not forced)
  • Must be specific to each purpose
  • User must be informed of what they're consenting to
  • Must be as easy to withdraw as to give
  • Pre-ticked boxes are not valid consent

Consent Management Platforms (CMPs)

  • OneTrust, Cookiebot, Osano, TrustArc
  • These generate the cookie consent banners you see everywhere

The Problem

  • Most consent banners are designed to manipulate users into accepting
  • "Dark patterns": making "Accept All" prominent while hiding "Reject"
  • Many implementations are technically non-compliant
  • GDPR enforcement has been slow against abusive consent patterns

The Privacy Perspective

Consent management as currently implemented is largely theater. Real privacy comes from services that don't collect unnecessary data in the first place (privacy by design), not from consent banners that trick users into "agreeing" to surveillance.

Related Terms

Have more questions?

Use our guided flow to get the right next privacy step for Consent Management.

Open Guided Flow