One script tag per site. Consentfolio runs a banner your visitors won't hate, blocks trackers until they say yes, and keeps the records to prove it, for every domain you look after.
Try it below. Every choice writes a timestamped record, exactly like on a real site.
One line in the <head>. Works with any CMS, framework, or hand-rolled site.
It holds your analytics, ads and embeds until there's a yes, shows an equal-prominence accept and reject, and sends Consent Mode v2 signals to Google, with no extra wiring.
Consentfolio stores every choice with a timestamp and proof ID. Export and hand them over whenever an audit, a client or a regulator asks.
Every feature ships on every plan, with no gates or add-ons.
Analytics, ads and embeds stay off until there's a yes, so nothing non-essential fires before consent.
Every choice stored with a timestamp and proof ID. Exportable as CSV, tamper-evident, regulator-ready.
Works with GA4 and Google Ads out of the box. The four v2 signals are sent automatically.
Prior blocking, an equal-prominence reject button and provable records: the things the ICO checks.
One flat price per site, banded by monthly users. No page-view tiers that jump when a campaign lands.
Move a domain to a client's card without touching the tag. You keep admin control; they get the invoice.
On £24 and £49 plans, one project covers up to three domains with a shared banner and one consent choice that follows visitors between them.
EU and UK visitors see an opt-in banner; US visitors see a CCPA opt-out notice with a Do Not Sell control. GPC honoured automatically, IAB GPP US National string emitted.
Keyboard-navigable, screen-reader friendly, equal-prominence accept and reject. No dark patterns, no cookie walls.
Built for the person who looks after twenty sites. Add a client, style the banner to their brand, group their domains into one project, and stop thinking about it.
No feature gates and no surprise upgrade emails. You pay per domain, banded by that domain's monthly users. Every plan gets everything.
Remove your old banner, add one line. No plugin, no migration project.
No page-view tiers that jump the bill when a client's campaign lands.
Export every consent record, any time, as CSV.
A cookie consent manager is software that asks your visitors for permission before non-essential cookies run, then records that choice. It is also called a consent management platform, or CMP. A good one does four jobs: it collects valid consent, it blocks tracking scripts until a visitor agrees, it keeps a record you can show a regulator, and it forwards the choice to your marketing and analytics tags. Consentfolio does all four from a single script tag, so you set it up once and leave it running.
Consent management sits at the centre of privacy compliance. Each visit gets a clear choice, Consentfolio logs it, and your tags follow it. The log is your proof when a regulator asks.
A cookie consent banner is required whenever your website sets non-essential cookies, which covers analytics, advertising and most embedded content. Under the GDPR, the UK PECR and the EU ePrivacy Directive, third-party cookies need explicit prior consent, so the banner has to appear and block those cookies before they run. The banner also informs users about the cookies in use and gives them a real choice. A cookie consent banner complies with the GDPR when it requests consent clearly, blocks tracking cookies until consent is given, and lets a visitor reject as easily as accept. A site that sets only strictly necessary cookies can skip the banner, though that is rare once analytics or ads are in play.
A growing set of privacy regulations shapes cookie consent, and the model differs by region. They share one aim: giving people control over their own data. Global privacy compliance means matching the rule to each visitor.
| Regulation | Region | What it requires |
|---|---|---|
| GDPR | EU | Prior opt-in consent for non-essential cookies; data protection by design |
| UK PECR and UK GDPR | United Kingdom | Prior consent for non-essential cookies; an equal-prominence reject option |
| ePrivacy Directive | EU | The rule behind cookie consent for storage and access on a device |
| CCPA and CPRA | California | Clear disclosures about data collection and an opt-out of sale or sharing |
| LGPD | Brazil | A lawful basis and control over personal data |
| POPIA | South Africa | Consent and protection of personal information |
| PIPEDA | Canada | Consent for the collection and use of personal data |
| Digital Markets Act | EU | Transparency duties for large "gatekeeper" digital services |
The EU and the UK use an opt-in model: nothing non-essential runs until the visitor agrees. California and several US states, including Virginia, lean on an opt-out model, where tracking may run until the visitor asks you to stop. Other regimes, from Japan to South Korea, add their own duties. The CCPA and CPRA both require disclosures, and the EU Digital Markets Act emphasises transparency for the largest platforms. If you serve visitors under several of these regimes, applying the stricter opt-in standard keeps you covered across borders.
Consentfolio blocks non-essential scripts until a visitor consents, records every choice, and sends Google Consent Mode v2 signals to your Google tags. Script blocking holds analytics, advertising and embed tags until there is a yes, so tracking technologies such as cookies, tags, trackers, pixels and beacons stay dormant. Consentfolio stores every choice as a consent record: a timestamped, exportable log that proves compliance if the ICO or a client asks. Those consent logs also let you answer a data subject access request. The banner is built to WCAG 2.2, so it works for keyboard and screen-reader users.
One project can cover more than one domain. On £24 and £49 plans, a project takes its main domain plus up to two additional domains and shares a single banner and one consent choice across all of them. When a visitor accepts on the marketing site and clicks through to the shop, the shop already knows their choice and shows nothing; the preferences modal discloses the covered domains so consent is informed. The scope is per project, not per organisation, so one agency running several clients keeps each client's consent decisions separate.
You add Consentfolio with one script tag in your site's head, and it works on any platform. That includes WordPress, Shopify, Wix, Squarespace and Joomla, as well as a hand-built site. It sits alongside Google Tag Manager, which manages your scripts and tags, and it does not need a plugin. Paste the tag, declare your cookies from a template, and the banner is live in minutes.
Google Consent Mode v2 tells Google's tags whether a visitor has consented, and Consentfolio sends those signals automatically. It sets the four signals, analytics_storage, ad_storage, ad_user_data and ad_personalization, to denied by default, then updates them the moment a visitor chooses. Consent Mode v2 supports Google Analytics 4 and Google Ads, and this signal forwarding means your measurement respects consent without extra tagging. Read the Google Consent Mode v2 guide for the detail.
Opt-in consent means non-essential cookies stay off until the visitor agrees, and it is the standard across the EU and the UK. Opt-out consent means tracking can run until the visitor objects, which is closer to the California model. Consentfolio is built for the opt-in standard: it blocks first, then asks, and records the answer. A cookie policy tells visitors what cookies your site uses and why, and your banner links to it. Together, the policy and the consent logs answer the two questions a regulator asks: did you inform people, and can you prove they agreed.
Yes. The banner collects real prior consent, non-essential scripts stay blocked until a visitor opts in, and every choice is stored as a timestamped record. You remain the data controller, and we give you the tooling and the proof.
Out of the box. The tag sends the v2 signals (ad_storage, analytics_storage, ad_user_data, ad_personalization) automatically, so GA4 and Google Ads behave correctly without extra GTM wiring.
One site and its subdomains, so client.co.uk, www and shop.client.co.uk are all one domain. Each domain is priced by its own monthly users. On £24 and £49 plans, one project can also cover up to two additional domains, and a visitor's consent choice follows them across those domains via link clicks; direct visits to another domain prompt once.
Yes, on £24 and £49 plans. A project can cover its main domain plus up to two more (a marketing site, a shop and an app, say) with a single banner and one consent choice that follows visitors as they click between them. Paste the same install snippet on every domain and add the extras in the banner customiser's Cross-domain consent card. Direct visits to another domain prompt once. £9 plans stay single-domain.
Yes. Hand a domain off to a client's card, and the tag on their site never changes. You keep admin control of the setup if you want it.
The banner keeps running until the end of your billing period, and you can export your consent records as CSV at any time. They belong to you.
Not yet. You declare your cookies from ready-made templates in the dashboard rather than relying on an automatic scan. If a scanner is essential for you, our Cookiebot comparison covers that trade-off.
Whenever your site sets non-essential cookies, such as analytics, advertising or embedded content. Under the GDPR, UK PECR and the ePrivacy Directive, third-party cookies need explicit prior consent, so the banner must appear and block them until the visitor agrees.
The GDPR and UK PECR require prior opt-in consent in the EU and UK, with the ePrivacy Directive behind them. The CCPA and CPRA require disclosures and an opt-out in California, and LGPD, POPIA and PIPEDA apply in Brazil, South Africa and Canada. Global privacy compliance means matching the rule to each visitor.
You control the banner's colours, position and buttons to match your brand, with an equal-prominence accept and reject. The banner varies by region automatically: EU and UK visitors see the opt-in banner, US visitors see the CCPA opt-out notice with a Do Not Sell control. It serves a single language today.
Yes. For US visitors, Consentfolio reads navigator.globalPrivacyControl and auto-applies the opt-out if it is set, shows a visible confirmation, and records it. It emits the IAB GPP US National (usnat) string through the standard window.__gpp CMP API, so US ad-tech can read the visitor's opt-out state.
Add your first domain in the time it takes a kettle to boil. From £9 a month.