How consent management works
Three separate things have to line up. A visitor is asked what they allow, usually through a banner. Their answer is stored, normally in a cookie on their own device. And every tag on the site — your analytics, your advertising pixels, your chat widget — has to check that stored answer before it fires. Most sites do the first two and quietly skip the third, which is the part that actually changes anything.
A consent platform sits between the visitor and your tags. Tag Manager, for example, can hold a tag back until a consent signal arrives, and Meta’s own tools can be told whether a given page view is permitted to build an audience. The categories are usually split between strictly necessary items, which keep the site working, and everything else, which needs an explicit yes.
What counts as valid consent varies by market. Rules in the European Union and the United Kingdom are strict about asking first and making refusal as easy as acceptance, while other markets ask less. If you sell to buyers abroad, the strictest market your visitors sit in is the one that sets your standard.
Why consent management matters
The obvious reason is legal exposure, and it is real. The practical reason is that consent decides how much data your analytics and tracking setup ever sees. A refusal is not a lost visitor; it is a visitor who buys without ever appearing in your reports, which makes every channel look worse than it is and pushes budget towards whichever platform happens to claim credit most confidently.
It also protects you from a quieter risk: a site that promises one thing in its privacy policy and does another in its tag manager. That mismatch is the version of this problem that causes trouble.
Common mistakes with consent management
The commonest is a banner that changes nothing. Tags fire on page load regardless of the answer, and the banner becomes decoration with a legal risk attached. A close second is a pre-ticked box or a design where accepting is one click and refusing takes several — a pattern regulators in strict markets treat as no consent at all.
Then there is the privacy policy that lists cookies the site does not set and omits the ones it does. Copying a template from another site is how that happens. The policy must describe the site you actually run.
How to act on it
Audit before you write anything: load your own site with the browser’s network panel open and list every third party it contacts. That list, not a template, is what the banner and the policy must cover.
Wire the tags to the stored answer through your tag manager rather than trusting each vendor’s own script, so there is one place to check. Then test both paths — accept and refuse — and confirm that refusing genuinely stops the requests. Finally, expect gaps in reporting and plan for them, rather than treating the shortfall as a tracking fault to be chased.