Skip to main content

DPO workspace

One stop for measured compliance evidence

We are not a CMP — we do not deploy your cookie banner or edit vendor categories inside OneTrust. We are the independent verification and evidence layer DPOs, agencies, and privacy teams use alongside their CMP.

Why not run the banner ourselves? CMPs are consent management systems — legal records, UI, and vendor taxonomy. ConsentSignals is consent verification — network measurement, drift detection, and audit artefacts. Combining both avoids vendor lock-in and matches how regulators test sites.

What you get in one scan

  • Measured CMP effectiveness (8-session consent matrix)
  • Consent Mode Enforcement — Google Consent Mode v2 + TCF 2.3 on the wire
  • Granular & closed-loop leak signals (Essential-only, Analytics-only, Withdrawal, GPC, Returning user)
  • Observed vendor / subprocessor inventory from network data
  • GTM-before-CMP and server-side tracking hints
  • Multi-page audits (checkout, account, key flows)
  • EU geo profiles (IE, DE, FR, NL, ES, IT, UK)
  • Child-audience classification + COPPA 2025 signals
  • Six-framework regulatory mapping + signed PDF
  • Scheduled CMP health checks + drift webhooks (Pro)

Early-access modulesBeta

First-to-market readiness signals — visible in every child-privacy scan (HEAA, wallet) or as a dedicated audit (EAA). Indicators only; not certification.

Typical DPO workflow

1

Keep your CMP

OneTrust, Cookiebot, Didomi, or Usercentrics continues to run your banner, store consent records, and manage vendor categories.

2

Scan with ConsentSignals

We run a 8-session consent matrix (Accept All, Reject / Disagree All, Essential-only, Analytics-only, Withdraw marketing (Accept then revoke), GPC/DNT signal, Returning user (Reject cookies), and a passive baseline), flag GTM order issues, build an observed vendor inventory, and map findings to statute provisions.

3

Reconcile & remediate

Compare observed domains to your CMP vendor list. Export tracker CSV for import workflows. Fix tag order, re-scan, schedule daily CMP health checks.

4

Evidence for counsel

Download HMAC-signed PDFs for board packs, client deliverables, and regulatory inquiry prep — indicators only, not legal verdicts.

Honest limits

  • ×We are not a CMP — we do not install banners, store consent records, or host vendor lists
  • ×Server-side / CAPI tracking invisible to browser sessions (we may hint; we do not replace CAPI)
  • ×Geo-gated CMP banners and tag sets — each scan uses one region profile
  • ×A/B or multivariate experiments — headless Chromium typically sees one variant
  • ×Shadow pixels inside widgets the CMP authorised
  • ×Every possible per-category toggle a human might choose (we approximate Essential-only, Analytics-only, and post-Accept withdrawal)
  • ×CMP consent-log timestamps without a read-only API or export upload
  • ×DSAR / subject-access portals, EUDI wallet relying-party flows, or consumer parental-control apps
  • ×Legal verdicts — evidence for your DPO and counsel only