ConsentPixel – Privacy · Verified

★★★ Built for the EU & UK market

For website owners & DPOs

Three privacy laws.
One pixel.
Zero guesswork.

GDPR consent, the ePrivacy cookie rules, and the EU AI Act don't arrive as one job — but they land on the same website. ConsentPixel handles all three from a single script, blocks every non-essential tracker until your visitor opts in, and keeps a tamper-proof, timestamped consent log your DPO can hand a regulator without flinching.

No credit card · From €8.99/mo · Or scan first — free, no account, 10 seconds

€7.1B
In GDPR fines issued since 2018 — over 60% of it since January 2023 alone
€150M
CNIL fine to a single retailer in 2025 for advertising cookies set without valid consent
1,000
UK websites reviewed by the ICO — 134 warnings from just the first 200 checked
~500/yr
Organisations the Dutch DPA now warns annually, monitoring ~10,000 sites

Why this changed in 2026

Regulators stopped reading policies. They started using your site.

The era of "we have a cookie banner, we're fine" is over. Supervisory authorities across the EU and UK now open a browser in incognito mode and watch what loads before anyone clicks accept. If a tracker fires on page load, that's a pre-consent violation — no matter what your banner says. This is exactly the failure mode ConsentPixel is built to remove.

🔍
Enforcement moved to implementation

The banner isn't the point anymore

The CNIL made it explicit: a withdrawal that's recorded but doesn't actually stop the cookies is still a violation. Regulators test whether "Reject All" is as easy as "Accept All", and whether tags truly hold until consent. Design theatre no longer passes.

📩
Complaints are systematic now

You don't have to be a household name

Privacy group noyb filed 800+ cookie complaints in 2025 with a 74% enforcement-action success rate. The Dutch DPA warns hundreds of ordinary businesses a year. SME fines routinely land in the €10,000–€100,000 range — not headline millions, but ruinous for a small operator.

🧩
Three obligations, one deadline pile-up

GDPR + ePrivacy + AI Act converge

You already owe GDPR consent and ePrivacy cookie rules. From 2 August 2026, EU AI Act Article 50 adds an AI-disclosure duty on top. Most tools make you buy and wire up three things. The sane answer is one mechanism that satisfies all three at the point the visitor already sees.

What your DPO actually needs

Not another banner. A defensible record.

When a data protection authority asks a question, they don't want to see your cookie banner — they've already seen it. They want proof: which visitor consented to what, on which version of your banner, at which timestamp, and evidence the trackers genuinely stayed off until that moment.

That's the difference between a cosmetic consent tool and a compliance system. ConsentPixel was built for the second job — because a trust brand that couldn't survive its own audit would be a contradiction.

  • Prior blocking, not just prior notice. Non-essential tags are held server-side until opt-in — the ePrivacy "prior consent" standard, enforced technically.
  • Immutable consent log. Every record is timestamped and tamper-proof. Export the full consent state, not a bare yes/no.
  • Versioned banners. If a DPA asks what disclosure was live on a given date, the answer is on record — Version 1, 2, 3…
  • Withdrawal that works. Opt-out actually stops the cookies, satisfying the CNIL's post-withdrawal standard — not just a logged preference.
  • Symmetrical choice. "Reject All" carries equal weight to "Accept All" on the first layer — no dark patterns to explain away.

One pixel · three obligations

Everything an EU website owes — covered in one place

You don't buy a GDPR tool, an ePrivacy tool, and an AI Act tool. You install one pixel, and each obligation is handled in the mechanism your visitors already interact with.

GDPR · Reg. (EU) 2016/679

Lawful consent, logged

Freely given, specific, informed, unambiguous opt-in under Article 7 — captured through a banner with equal-weight choices and no pre-ticked boxes. Every consent is stored as an auditable record.

Immutable, timestamped, exportable consent log up to 12 months
ePrivacy · Directive 2002/58/EC · Art. 82 (FR)

Cookies held before consent

The ePrivacy "prior consent" rule requires non-essential cookies to wait. ConsentPixel blocks analytics, advertising, and third-party tags on page load and releases them only after opt-in — with Google Consent Mode v2 signalling built in.

Trackers fire 0× before consent — provable in DevTools
EU AI Act · Art. 50 · from 2 Aug 2026

AI disclosure, one toggle

If your site uses an AI chatbot, AI search, or AI recommendations, Article 50(1) requires you to tell EU visitors. ConsentPixel surfaces that disclosure inside your existing banner's details panel — no separate pop-up, no developer work.

Enable in the portal · versioned for the audit trail
GDPR, ePrivacy & the AI Act — handled in one pixel Start the 14-day free trial. No credit card. Live on your site this afternoon.
Start free trial →

Built for EU operators

The details that survive an audit

Compliance in 2026 lives in the implementation, not the intent. These are the things a supervisory authority actually checks — built in, not bolted on.

🇪🇺

EU visitor geo-targeting

Detects EU/EEA visitors and applies the opt-in consent model automatically — while visitors elsewhere get the model appropriate to their region. One pixel, correct behaviour per jurisdiction.

🗄️

Tamper-proof consent log

Every consent and withdrawal is recorded immutably with a timestamp and banner version. Export the full log as CSV or JSON whenever your DPO — or a regulator — asks.

Audit-ready
🚫

Prior blocking of trackers

Non-essential scripts are gated until consent — the ePrivacy standard enforced in code. Open incognito DevTools and watch: nothing non-essential loads before opt-in.

⚖️

No dark patterns

"Accept All" and "Reject All" carry equal visual weight on the first layer. No hidden reject, no ambiguous wording — the exact design the CNIL and EDPB now demand.

🔄

Withdrawal that actually stops cookies

When a visitor withdraws consent, the tags stop — not just the log entry. This is the post-withdrawal standard the CNIL made explicit in its 2025 enforcement.

🔒

Privacy-first by our own design

We run Plausible, not Google Analytics. A privacy tool that surveilled its own visitors would fail its own promise — so we don't. The trust badge is cryptographically verified.

Practise what we sell
🌐

Works on every platform

WordPress, Shopify, Webflow, Wix, WooCommerce, and any site that can add a script tag. One snippet in the <head> and consent is live across every page.

🤖

EU AI Act Article 50 ready

AI-feature disclosure surfaces in your banner's details panel from a single portal toggle — no second modal, versioned for your records. Live today, ahead of the 2 August deadline.

🏛️

EU data residency

Keep consent data within the EU. Ask us about EU-region hosting for organisations with data-residency requirements or public-sector procurement rules.

On request

From exposed to compliant

Live on your site in an afternoon

No procurement cycle, no developer sprint. Four steps from a free scan to a defensible consent layer.

1

Scan your site free — see what's firing

Run the free scanner on your domain. In ten seconds you get a full inventory of the cookies, pixels, and trackers on your site — including the ones firing before consent that a DPA would flag first. No account needed.

2

Install one pixel

Add a single script tag to your <head> — about five minutes on WordPress, Shopify, or Webflow. That one snippet handles GDPR consent, ePrivacy blocking, and the AI Act disclosure across every page.

3

Configure and publish your banner

Use the visual builder to match your brand, with equal-weight Accept and Reject built in by default. Publish, and the consent layer goes live immediately. Non-essential trackers are blocked from that moment; the consent log starts filling.

4

Hand your DPO the audit trail

From then on, every consent is logged immutably with its timestamp and banner version. If a supervisory authority ever asks, the record exports in one click — proof that trackers held and consent was captured lawfully.

How ConsentPixel compares

One pixel vs. the usual stack of tools

Most EU businesses end up with a cookie tool, a separate AI-disclosure plan, and a spreadsheet pretending to be a consent log. Here's the difference.

What EU compliance needsConsentPixelTypical setup
Non-essential trackers blocked before consent✓ Enforced in codeOften notice-only
Immutable, timestamped consent log✓ Built inLimited or manual
Withdrawal actually stops the cookies✓ YesFrequently records only
Equal-weight Accept / Reject (no dark patterns)✓ DefaultVaries
EU AI Act Article 50 disclosure✓ Live now — one toggle✗ Roadmap / separate
GDPR + ePrivacy + AI Act in one pixel✓ Unified✗ Separate tools
Vendor uses privacy-first analytics itself✓ Plausible, not GAUsually Google Analytics
EU data residency option✓ On requestHigher tiers only

Ready to make your site defensible?

One pixel for GDPR, ePrivacy, and the EU AI Act — from €8.99/mo. Start your 14-day free trial and have a consent layer your DPO can stand behind, live this afternoon.

Why EU operators switch

Compliance you can actually stand behind

★★★★★

"Our DPO's first question was 'can we produce the consent record on demand?' With our old banner the honest answer was no. Now it exports in one click, timestamped and versioned. That alone justified the switch."

LM
Lena M.Head of Digital · Munich · e-commerce
★★★★★

"I was paying €340/month for ten Cookiebot domains. They doubled my price with one email. I moved to ConsentPixel, kept the same compliance standard, and cut the bill by more than half — with the AI Act disclosure included."

DK
Daniel K.Web studio owner · Amsterdam
★★★★★

"The thing that sold me was that they don't run Google Analytics on their own site. A privacy vendor that tracks you is a red flag. This one practises what it sells — and the reject button carries the same weight as accept, out of the box."

SB
Sofia B.DPO · Lisbon · SaaS

EU compliance questions

What EU owners and DPOs ask first

Does ConsentPixel actually block trackers before consent, or just show a banner?
It blocks. Non-essential scripts — analytics, advertising, third-party tags — are gated and do not execute until a visitor opts in. This is the ePrivacy "prior consent" standard enforced technically, and you can verify it yourself: open your site in an incognito window with DevTools on the Network tab and confirm nothing non-essential loads before you click accept. A banner that merely notifies while cookies fire underneath is the exact failure regulators are now penalising.Not legal advice; consult your counsel or DPO for your specific situation.
We're a small business, not a tech giant. Are we really at risk?
Enforcement is no longer reserved for large platforms. The Dutch DPA warns around 500 organisations a year and monitors roughly 10,000 sites; the UK ICO reviewed the top 1,000 UK websites and issued 134 warnings from just the first 200. Privacy group noyb filed over 800 cookie complaints in 2025 with a 74% enforcement-action rate. Fines for small and mid-sized businesses commonly fall in the €10,000–€100,000 range — rarely headline news, but serious for a small operator. The trend is toward volume, and ordinary business websites are squarely in scope.Not legal advice.
How is this different from Cookiebot, OneTrust, or the CMP I already have?
Three practical differences. First, ConsentPixel unifies GDPR consent, ePrivacy blocking, and EU AI Act Article 50 disclosure in a single pixel — most setups need separate tools. Second, the consent log is immutable and exportable, built for the moment a DPA asks for proof rather than as an afterthought. Third, we use privacy-first analytics (Plausible) on our own site rather than Google Analytics — a small thing that signals the whole approach. On price, EU operators moving from per-domain CMP pricing typically find our plans meaningfully lower.
Does the EU AI Act Article 50 requirement apply to my website?
Article 50(1) applies if your site uses an AI system that interacts directly with EU visitors — an AI chatbot, AI-powered search, AI recommendations, or AI-assisted support. From 2 August 2026 you must disclose that to EU visitors. ConsentPixel surfaces this disclosure inside your existing consent banner's details panel from a single portal toggle, so you satisfy it without a separate pop-up or developer work. If you don't use any AI-powered features, this obligation may not apply to you today — but the toggle is there the moment you add one.Not legal advice; consult counsel for your specific use case.
Can I produce a consent record if a supervisory authority investigates?
Yes — that's a core design goal. Every consent and withdrawal is stored as an immutable, timestamped record tied to the banner version that was live at the time. You can export the full consent state (not just a yes/no flag) as CSV or JSON at any time. If a data protection authority asks what disclosure was in place on a specific date and which visitors consented to what, the answer is on record rather than reconstructed after the fact.
Does withdrawal of consent actually stop the cookies?
Yes. When a visitor withdraws consent, the associated tags stop firing — not merely a preference logged while cookies continue. This matters because regulators have made the distinction explicit: a withdrawal that's correctly recorded but doesn't halt the tracking is still treated as a violation. ConsentPixel enforces the stop, so your recorded state and your actual behaviour match.Not legal advice.
Can we keep our consent data inside the EU?
EU data residency is available on request. If your organisation has data-residency requirements — common in the public sector, healthcare, or regulated industries — talk to us about EU-region hosting for your consent data. We'll walk you through the setup before you commit.
How long does it take to get compliant?
An afternoon for most sites. Installing the pixel is one script tag in your site's header — about five minutes on WordPress, Shopify, or Webflow. Configuring and publishing the banner takes a few more. From publish, trackers are blocked and the consent log begins immediately. The free scan beforehand takes ten seconds and needs no account, so you can see your current exposure before you change anything.

Give your DPO a consent record that holds up

Install one pixel and cover GDPR, ePrivacy, and the EU AI Act in your first session. Or scan your site first to see exactly what's firing — free, no account.

No credit card · From €8.99/mo · EU data residency available

Google CMP Partner IAB TCF 2.3 GDPR · ePrivacy · EU AI Act Privacy-first — we run Plausible, not GA
Scroll to Top