Products

First-party consent manager

A consent manager served from your own domain that actually gates traffic. Accept, reject, and no answer are all honoured, in the browser and on the server, from one choice.

What it is

DataCops includes its own first-party consent manager, built to the IAB TCF v2.2 standard. It is served from your own subdomain, and it does not just record a choice, it enforces it. When a visitor in an opt-in region says no, no identity is kept and nothing marketing-related is sent, in the browser and on the server, from one banner. Every consent choice is logged, so you can show when and how consent was given (GDPR Article 7(1)).

Why third-party banners go blind

A traditional consent manager loads from a third-party domain. Ad blockers and privacy browsers like Brave often block those domains. So the banner never loads for some of your visitors, and you have no record of how consent was handled for them.

The DataCops consent manager is first-party. It loads from your own domain, the same way the rest of DataCops does, so it is much less likely to be stripped.

The compliance gap

There are two common answers to the consent problem in the market, and neither one solves it.

The track-nothing approach

Privacy-first tools keep no visitor identity at all, so they identify nobody. That is compliant, but not useful for marketing. With no identity, you cannot attribute a click to a sale, and you have nothing meaningful to send back to an ad platform.

The platform blind spot

Now take a site that set up consent properly. A visitor clicks reject. Many tools then stop collecting entirely, and the rejected visitor becomes a zero. The marketer who did consent properly ends up with two gaps: visitors who block the script, and visitors who declined.

DataCops takes a third path, built in layers: count visits in aggregate without identifying anyone, identify only with consent, and hold that line on the server as well as in the browser.

Three outcomes, all enforced

The consent manager produces three outcomes, and all three are enforced.

  • Accept. The visitor can be identified and marketing events can be sent. A durable first-party id is only issued when the session also passes the fraud check.
  • Reject. The visitor is not identified, no durable cookie is issued, and marketing events are not sent to ad platforms. Each skipped send is written to the audit log.
  • No banner required. Consent gating is geo-conditional by design. Outside the regions that require opt-in, DataCops collects normally and the banner does not need to block anything.

What it means for your European traffic

Europe is where consent matters most. In the EU and the UK, you cannot send marketing data about a visitor until they have opted in. Most tools either send it anyway and take on the legal risk, or stop collecting and lose the visitor. DataCops does neither.

Here is what happens to a European visitor, step by step.

  • They see the banner. In opt-in regions, consent starts as no, and nothing marketing-related is sent until they actively agree.
  • Google tags follow the same choice. The consent manager feeds Google Consent Mode v2 through TCF, so Google's own tags respect the visitor's answer.
  • Fraud protection still runs. The security checks that spot bots, VPNs, and fraud do not need marketing consent, so junk traffic is still filtered.
  • Nothing is lost on a late yes. If a marketing event happens before a European visitor answers, it is held, not thrown away. When they accept, the held events are released and delivered. If they later withdraw, DataCops handles the withdrawal on the server too.

One choice, two systems

A single consent choice controls two separate systems at once: your browser-side tags, like Google's own scripts, and DataCops' server-side sending to ad platforms. There is no second place to keep in sync.

A bot cannot consent

A consent signal from a bot is meaningless. So the consent manager works with fraud detection: a session flagged as a bot is not issued a durable id and is not sent to ad platforms, whatever it clicked on the banner. The same IP and behaviour signals that power fraud detection make that call.

Compliant by default

Because DataCops runs its own consent manager, its own IP service, and the IAB TCF v2.2 framework together, consent is handled at the system level rather than stitched together from separate vendors. The security checks run on a legitimate-interest basis, and marketing only moves with a real yes where one is required.

Deletion requests

When a person asks for their data to be removed, that request has to be honoured. Because a visitor's identity in DataCops is held on the server and kept per merchant, there is one place to remove it. See DSAR automation for how requests are handled.

Was this page helpful?