Blog Privacy
September 23, 2026

The Consent Compliance Paradox: Why Having a CMP Isn't the Same as Having Consent

Ivan Tsarynny
Ivan Tsarynny

Here’s a question I’ve started asking privacy and security leaders in almost every conversation: if I asked you right now to list every script collecting data on your website, could you do it? If I then asked how many of those scripts are overwriting consent preferences, would you know?

Most people pause. Some laugh. A few say yes with real confidence. But when we run the audit, the answer is almost always more complicated than they expected. And that gap between what people believe is happening across their digital properties and what’s actually happening is the problem DXComply is built to solve.

The Confidence Gap Is Real, and It’s Measurable

We recently commissioned Censuswide to run an independent survey of 800 privacy, security, and governance, risk, and compliance (GRC) leaders, and the results put a number on something I’ve been hearing anecdotally for years. Consent management platforms (CMPs) have become close to universal, with 98.1% of organizations having deployed one or planning to deploy one. If you judged the industry by adoption alone, you’d think consent was a solved problem.

It isn’t. Only 24% of organizations told us they continuously verify that their consent controls are actually enforced. Everyone else is relying on a one-time test during implementation, a vendor’s assurance, or simply a belief that things still work the way they were configured months or years ago.

That’s the paradox at the heart of this: organizations have consent infrastructure, but they have little visibility into whether the code running underneath it honors it. A banner can be perfectly configured and still not tell you anything true about what happens the moment a visitor clicks Reject All.

DXComply consent audit after a visitor clicks Reject All: three essential scripts load and four optional ones (GA4, Meta Pixel, Google Ads, Intercom) are blocked.
DXComply checks every consent choice against what loads. Accept All: every script runs. Reject All: only the essential ones should.

Most organizations don’t realize that a consent failure and a script problem are the same problem. They treat consent as a banner and a legal question. They treat scripts as a marketing and engineering question. In reality, nearly every consent failure we’ve found traces back to a script doing something the organization didn’t know it was doing.

The clearest evidence of that disconnect is a single contradiction sitting right in our survey data. Among organizations using a CMP, 66% said they feel somewhat or very confident that their platform blocks scripts before consent is given. But only 8% said they believe every script on their website is fully authorized.

Read those two numbers side by side and you can see the whole problem. Two-thirds of CMP users trust their platform. Fewer than one in ten trust their own script inventory. That’s not a technology gap. That’s a visibility gap. DXComply closes it by showing teams what is happening on their sites and apps, prioritizing the risks that matter most, and giving them a clear path to remediation.

The rest of the data tells the same story from a different angle. Nearly nine in ten organizations (89%) have experienced a vendor changing its data collection practices without telling them. More than half (60.6%) said they discover unauthorized or undocumented scripts on their own websites at least occasionally, with some saying it happens constantly. And in a separate live poll we ran with the International Association of Privacy Professionals (IAPP), which reached a different audience than our survey, only 14% of respondents said they continuously audit CMP behavior with dedicated tooling. Everyone else is checking in periodically and hoping nothing has changed since the last review.

Why a Point-in-Time Audit Was Never Going to Be Enough

This is where a lot of privacy programs get the mental model wrong. Consent is treated like a project you finish: configure the banner, run a test, file the documentation, move on. But the website underneath that banner is never finished. Marketing launches a new campaign. A vendor pushes an SDK update. Engineering ships a page redesign. Every one of those routine changes can quietly alter what a script does with a visitor’s choice, and none of them shows up as a change to the consent program on paper.

That’s why a single point-in-time audit, even a thorough one, only tells you the truth for as long as nothing changes. And on a modern website, something is always changing. Organizations in our survey run an average of 34 third-party technologies across their digital properties. Each one is a separate piece of code that can be updated by someone outside your organization, on their own schedule, with no obligation to tell you. Auditing that environment once a quarter is like taking a single photograph of a river and calling it a map.

Continuous auditing belongs at the core of a consent program. It gives teams an accurate view of consent behavior in an environment that changes daily, so they aren’t relying on controls that were checked once and trusted indefinitely.

Our live audits back up the survey. Across 168 consent audits we conducted on 92 real websites, 93% of those websites failed to fully honor the Global Privacy Control (GPC) signal. On most of the sites we looked at, scripts kept loading and collecting data after a visitor explicitly said no.

And it’s the pattern we see with customers, over and over. Teams come to us confident in their consent program, and within the first assessment, they’re looking at a list of vendors, cookies, and scripts they didn’t know were on their pages, or cookies miscategorized as strictly necessary that let a tracker keep running after a visitor rejected it. The problem usually wasn’t intent. It was a lack of continuous visibility into what was happening, and of a way to prioritize and remediate the risks that visibility uncovered.

What We’re Delivering to Close the Gap

This is why the latest version of DXComply centers on two ideas. First, consent compliance has to be continuous, and it has to be grounded in what scripts do, not what a platform records. Second, asking privacy teams to file a ticket and wait for a code change just to understand consent behavior across their digital properties has always been backwards. DXComply audits websites and mobile apps without requiring teams to write code or instrument their applications.

  • Continuous internal and external consent auditing. DXComply tests live pages both externally, the way a visitor experiences them, and internally, tracing script behavior underneath the page, under every consent state: default, Accept All, Reject All, and GPC. There’s nothing to install and nothing for engineering to instrument, and it runs continuously rather than as a one-time check.
  • Compliance posture reporting by regulation and framework. Teams can see where they stand against GDPR, CCPA/CPRA, HIPAA, and more than 70 other regulations and frameworks, from one continuous audit rather than a separate manual review for each one.
  • Risk-based remediation prioritization. Every finding is scored by materiality and risk, so privacy, engineering, and legal teams can focus first on the issues that create the greatest compliance exposure instead of working through a flat list.
  • Remediation workflows built for how teams already work. Findings route directly into Slack, Jira, ServiceNow, Teams, Splunk, Datadog, and PagerDuty, with the vendor, the trigger, and the destination attached, so there’s no translation step between finding a problem and assigning it.
  • Cross-border data flow mapping. DXComply traces where data travels, independent of where a vendor claims to be registered, which matters more every year as data transfer rules multiply.
  • Preserved, exportable evidence. Every finding carries dated session recordings and reasoning logs, so what you hand to counsel or a regulator is defensible, not a summary you have to reconstruct after the fact.

Together, these capabilities are what continuous consent auditing at scale looks like: uncovering compliance gaps, prioritizing remediation based on risk, routing issues to the teams that can fix them, and preserving the evidence to demonstrate what happened. Finding more problems is only the start. The goal is to help teams address the right problems faster, strengthen their compliance posture, and reduce exposure to regulatory fines and litigation.

Where This Is Heading

Better policies and more thorough documentation won’t win the next era of privacy compliance. Regulators are moving toward evaluating actual behavior, not stated intent, and our research shows organizations know it. In our survey, 91.7% expect their investment in digital privacy to increase over the next year, and 97.1% are actively evaluating automation to help them keep up.

Neither the size of a compliance team nor the thickness of its documentation will decide who does well in that next phase. The organizations that succeed will be the ones that can continuously see what their digital properties are doing with the choices visitors make, understand which gaps create the greatest risk, and act before those gaps become larger compliance problems. That’s the problem we started Feroot to solve, and it’s the one we keep building toward with every release of DXComply.

A CMP Records the Choice. DXComply Verifies What Happens Next.

Continuously audit consent behavior across websites and mobile apps, prioritize compliance gaps based on risk, and give teams the evidence and remediation path they need to take action.

Explore DXComply