For online retailers preparing for Black Friday, consent management belongs alongside checkout reliability, stock availability and campaign readiness. Here is how to choose a platform that fits the store, and how to test the implementation before the traffic arrives.
A customer lands on a discounted product, checks the delivery date and adds it to their basket. Along the way, they may encounter an advertising pixel, an analytics tag, a product recommendation service and a customer support widget. Each has a business purpose. Each also raises a practical question: what information is being collected, and does the retailer’s handling of that information reflect the customer’s privacy choices?
That question deserves a place in the preparations for Black Friday 2026, which falls on November 27. The promotional week of November 23–29 offers a useful deadline for reviewing the entire shopping journey. Testing should also extend to Cyber Monday on November 30, particularly where a retailer changes offers, landing pages or campaign tags overnight.
A consent management platform, or CMP, can help organise the work. It can present privacy choices, record preferences and communicate those preferences to connected technologies. The right choice depends on the commerce platform, the markets served, the tracking architecture and the people responsible for maintaining it.
This shortlist examines five options: Cookiebot by Usercentrics, OneTrust, CookieYes, Termly and Complianz. Each has a different reason to earn a place in an ecommerce procurement discussion. The important buying decision is whether the chosen platform can support a demonstrably consistent experience from the first product view to the order confirmation.
The best ecommerce CMPs at a glance
The following recommendations are editorial assessments of documented capabilities and potential use cases. They are not results from a hands-on performance benchmark or a universal ranking. Product features, plan inclusions and implementation requirements should be confirmed with each provider before purchase.
| CMP | Recommended evaluation use case | Starting price (USD) | Priority for a retailer’s demonstration |
| Cookiebot CMP by Usercentrics | Stores seeking a Google-certified CMP with Google Consent Mode v2 support, plus a free plan for one domain with up to 50 subpages. | Free plan available; paid plans from approximately $8/month per domain, depending on subpage count. | Demonstrate tracker discovery, blocking and Google Consent Mode v2 signals across product pages, basket and checkout; confirm which plan covers the store. |
| OneTrust | Retail organisations coordinating multiple domains and regional rules. | Custom quote. | Demonstrate domain administration, regional configuration and consent records. |
| CookieYes | Stores wanting documented consent features across common website platforms. | Free plan available; paid plans from $10/month per domain on monthly billing. | Demonstrate GPC handling, tag controls and the selected platform integration. |
| Termly | Teams bringing consent controls and privacy documentation into one workflow. | Free plan available; Starter from $14/month per website on monthly billing. | Demonstrate how scans, policies, records and store scripts work together, and confirm which features require a higher-tier plan. |
| Complianz | WordPress-based retailers prioritising native administration. | Free plugin available; Premium Personal lists $59/year for one website. The page also displays a $54 promotional price. | Demonstrate compatibility with the store’s theme, plugins and checkout. |
Pricing checked on 8 October 2026. Prices may change. Free plans have feature or usage limits, and paid starting prices may not cover every capability discussed. Confirm billing terms, taxes, promotional rates and the required plan directly with each provider.
The most suitable CMP depends on a retailer’s operational needs, technical setup and target markets. A merchant running a single WooCommerce store will have different evaluation priorities from a retail group managing multiple brands, customer accounts and regional storefronts.
What an ecommerce consent management platform should do
The visible banner is the beginning of the evaluation. Retailers should also assess how preferences affect the technologies behind it.
A useful demonstration starts with the tracker inventory. Ask the provider to show how its scanner identifies technologies on product pages, promotional pages and other relevant parts of the store. Then establish which interactions require additional manual testing: opening a chat window, signing into an account or completing a test purchase, for example.
Next, examine enforcement. Where the chosen privacy configuration requires a script to remain inactive, the test should show that the script is controlled. Where a customer opts out of a particular use, trace the resulting change through the relevant integrations.
Finally, assess evidence and ownership. A retailer should know how to retrieve preference records, identify configuration changes and assign responsibility for new tags. A platform is more useful when its operation can be explained to both a marketing manager and a developer.
1) Cookiebot by Usercentrics: a strong candidate for automated discovery
Cookiebot CMP by Usercentrics is a Google-certified consent management platform that scans an online store for cookies and trackers, categorises them and provides automatic blocking of non-essential trackers until consent is given. It supports granular consent choices, banner customisation, Google Consent Mode v2, Microsoft UET Consent Mode and Microsoft Clarity Consent Mode. The standard Cookiebot CMP offering includes a free plan for one domain with up to 50 subpages, paid plans starting at approximately $8 per month and a 14-day Premium trial. Prices may change.
For WooCommerce stores running on WordPress, merchants can install the official Cookiebot plugin, connect their Cookiebot account using their Domain Group ID and configure the banner without coding. Shopify merchants can install the dedicated Cookiebot CMP app and follow its guided setup, also without coding skills. The Shopify app operates independently of an existing Cookiebot account and has its own plans and pricing.
Those capabilities make Cookiebot a reasonable candidate for retailers that want to organise tracker discovery and consent configuration around an automated service. The ecommerce evaluation should nevertheless reach beyond a standard homepage installation.
Ask the provider or implementation partner to demonstrate a product visit, a privacy choice, a basket update and a completed test order. Check how the implementation handles promotional landing pages, embedded services and the store’s advertising tags.
For a Shopify merchant, confirm the exact scope of the app and the configuration required for the merchant’s checkout and pixel arrangements. For WordPress, include the live theme and relevant plugins in the test environment.
Best-fit consideration: retailers seeking automated cookie and tracker discovery, established platform integrations and Global Privacy Control (GPC) support for US audiences. Cookiebot CMP detects browser GPC signals and triggers an automated opt-out, helping retailers honour preferences against the sale or sharing of personal data. Confirm plan scope, scan coverage, regional configuration and support arrangements against the store’s requirements.
2) OneTrust: a candidate for coordinated retail administration
OneTrust Cookie Consent documents tracker discovery, regional banner configuration, deployment across domains, scheduled scans and a consent transaction database. Its product information also describes scanning behind logins and tools for controlling trackers through blocking and tag-manager integrations.
These features make it a sensible platform to evaluate where several retail websites need coordinated administration. That recommendation is an assessment of the documented feature set, rather than a claim that every large retailer needs the same system.
The demonstration should reflect the organisation’s structure. Ask how a central privacy team can establish rules, how individual store teams manage local requirements and how changes are recorded. Include customer account areas and any separate storefront domains within the proposed scope.
Procurement should also establish which capabilities belong to the quoted package, who performs deployment and how ongoing support is delivered. The most useful proposal connects the software to named responsibilities within the retail organisation.
Best-fit consideration: retail groups evaluating coordinated domain and regional management. Request a demonstration using the intended operating model and a clearly scoped implementation proposal.
3) CookieYes: consent management with plans based on traffic and scan coverage
CookieYes offers automated cookie scanning and categorisation, configurable consent banners, script blocking and exportable consent logs. It supports Google Consent Mode v2, Microsoft UET Consent Mode and Global Privacy Control (GPC), with installation options for WordPress, Shopify and Wix. Its banner tools include a preference-revisit widget so visitors can change or withdraw consent.
For retailers, the main distinction between CookieYes subscriptions is the combination of traffic allowances, scanning coverage and banner controls. The free plan covers 5,000 pageviews per month and 100 pages per scan. Basic starts at $10 per month per domain on monthly billing, increasing those limits to 100,000 pageviews and 600 pages per scan, with additional pageview charges above the included allowance.
Higher tiers add capabilities relevant to larger stores: Pro includes geo-targeting and monthly scheduled scans, while Ultimate includes weekly scheduled scans, unlimited pageviews and removal of CookieYes branding. These differences matter for retailers with expanding product catalogues, seasonal traffic peaks or regional banner requirements. Prices and plan inclusions may change.
Best-fit consideration: merchants using common ecommerce platforms who want scanning, consent controls and records in one service, and whose catalogue size and traffic fit the selected plan’s allowances.
4) Termly: a candidate for consent and documentation workflows
Termly’s consent management platform documents cookie scanning, configurable banners, script blocking, preference records and regional consent rules. It also offers policy tools and describes keeping a cookie policy updated through scheduled scans.
This makes Termly worth evaluating where the same team coordinates privacy documentation and website consent controls. The operational advantage to investigate is whether the team can maintain a clear relationship between its published explanations and the technologies running on the store.
Ask for a demonstration that begins with a scan and follows through to categorisation, policy publication and script control. Check how a new marketing tool would be reviewed and reflected in the relevant documentation.
The retailer should separately validate its GPC requirements and the exact store integration, rather than relying on a general description of privacy-law support. Privacy notices should also be reviewed against the merchant’s actual practices and applicable obligations.
Best-fit consideration: teams looking to bring consent administration and privacy documentation into a shared workflow. Confirm the required technical controls and document-review responsibilities before deployment.
5) Complianz: a candidate for native WordPress administration
Complianz for WordPress describes a native privacy suite with a configuration wizard, customisation and integration with plugins and themes. The company separately offers a Shopify app, so retailers should evaluate the appropriate product rather than assume identical capabilities across platforms.
For a WooCommerce store, the WordPress approach is worth considering where the website team wants consent administration within its existing environment. The useful test is compatibility with the store as operated: its theme, extensions, performance settings and purchase journey.
Ask the implementation team to show the handling of embedded content and marketing scripts, and how privacy preferences remain effective during checkout. Establish which requirements are covered by the chosen edition, including regional behaviour, records and opt-out signals.
Also agree how plugin updates and store changes will be tested. Native administration can fit an existing workflow, but the retailer still needs an owner for configuration and verification.
Best-fit consideration: WordPress retailers prioritising a native consent-management workflow. Evaluate the required edition and compatibility with the complete WooCommerce installation.
US privacy requirements: start with the applicable rules
For a US-focused store, a privacy review should distinguish between notices, consent requirements and opt-out rights. Treating them as one interchangeable banner setting makes it harder to establish whether the implementation serves its intended purpose.
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives consumers rights that include opting out of the sale or sharing of personal information. California’s Attorney General explains that covered businesses must honour a valid GPC signal. The law has applicability criteria; selling online does not, by itself, establish that every merchant is covered. California’s CCPA guidance provides the starting point for that assessment.
For retailers, the practical recommendation is to create a requirements document before configuring the CMP. Identify the relevant jurisdictions, the processing purposes, the technologies involved and the behaviour required for each privacy choice. Have qualified counsel resolve legal applicability and interpretation where necessary.
Then give developers a testable specification. “Support US privacy” is too broad to serve as an acceptance test. “Apply the required opt-out handling to these data flows, preserve it across these pages and produce this evidence” is a requirement a team can verify.
GPC needs a behavioural test
Global Privacy Control communicates a browser-level privacy preference. A retailer evaluating support should inspect the resulting data handling, alongside any customer-facing indication required by applicable rules.
Use separate browser sessions for the test. In one, enable GPC before visiting the store. In another, submit the relevant manual opt-out. Compare the behaviour specified for each, including what happens when the visitor moves from a product page into checkout.
Record the test conditions, the configuration and the outcome. If a preference is connected to an identifiable customer account, include that account behaviour in the requirements review. The aim is to establish exactly what the implementation does, without assuming that a displayed status proves every downstream action.
Keep CIPA separate from the cookie-banner discussion
The California Invasion of Privacy Act, or CIPA, is another issue for a retailer’s legal and technical review. Cookiebot’s retail checkout explainer discusses website-tracking concerns involving checkout technologies and chat widgets.
These concerns should be assessed against the actual service, data flow and current law. The presence of a pixel, chat service or replay tool does not by itself establish unlawful conduct, and installing a CMP cannot guarantee an outcome in a legal dispute.
A constructive review asks what each tool receives, when the transfer happens, who receives it and what disclosure or authorisation is appropriate. Include services that process conversations or interactions without relying on a conventional cookie.
That creates a useful bridge between legal advice and engineering work: a defined question about a defined technology, supported by observations from the store.
Checkout should have its own acceptance test
Retailers should explicitly include checkout in CMP acceptance testing. The implementation team needs to establish whether the shopping journey crosses a separate domain, a hosted service or another environment with its own controls.
Map the route from the campaign landing page to the order confirmation. At each stage, identify which organisation operates the page, which technologies receive information and how the relevant preference reaches them.
Include guest checkout and signed-in checkout. Where used, test accelerated payment options, discount-code interactions, support widgets and post-purchase pages. For external services, establish the retailer’s responsibilities and the controls available rather than assuming its website banner governs the provider’s entire system.
The acceptance criterion should be specific: the customer can complete the intended purchase, the required privacy choices remain effective and the team can explain the relevant data transfers. Save the results alongside the deployment record.
Consent and measurement: investigate the numbers before explaining them
Marketing teams should understand what a privacy configuration permits their measurement tools to observe. A reduction in recorded events needs investigation before it is described as weaker demand or declining campaign performance.
Google distinguishes between basic and advanced Consent Mode. Its technical documentation explains that basic mode blocks Google tags until the relevant interaction and consent, while advanced mode can send measurements without cookies when consent is denied. The implementation choice therefore affects data transmission; a denied storage state does not automatically mean no request is sent.
Retailers should have that choice reviewed against their requirements. Consent Mode support is a technical capability, not a legal guarantee or a promise to recover every missing conversion.
As an operational check, compare advertising and analytics reports with order-system records over a defined period. Investigate differences in definitions, attribution windows, duplicate events and consent behaviour. Order records can help establish completed transactions, but they do not automatically establish which advertisement caused a purchase.
The objective is explainable measurement. A useful reporting process can identify what is directly observed, what is modelled and what remains uncertain.
AI shopping tools belong in the privacy inventory
If a store uses an AI shopping assistant, include it in the same inventory and review process as other customer-facing services. Focus on the information it receives and the purposes for which that information is used.
Ask whether conversations are retained, whether the service can access account or order information, which provider processes the data and whether additional uses need separate controls. Define the permitted scope before connecting the assistant to customer systems.
Cookiebot’s discussion of AI shopping assistants provides context for this review. Its separate Digital Trust Report commentary discusses consumer attitudes to AI and privacy. Such material can inform questions, but a retailer should evaluate its own services rather than infer customer behaviour or financial outcomes from general findings.
For the customer experience, make the assistant’s role understandable. Explain relevant data use where the interaction occurs, and align that explanation with the privacy documentation. A conventional cookie choice should not be treated as blanket permission for every possible use of an AI conversation.
A practical consent checklist for Black Friday week
Before November 23, complete a baseline audit and resolve any material questions about scope. During the promotional week, concentrate on verifying changes and responding to observed issues.
1) Inventory campaign technologies. Include store apps, tag-manager entries, embedded services and relevant server-side transfers. Name an owner for each.
2) Test fresh visits. Arrive through the homepage, product pages and campaign links. Verify behaviour before and after the relevant privacy choice.
3) Test browser opt-out signals. Enable GPC before arrival and check the required handling throughout the journey.
4) Complete test purchases. Include guest and account journeys, payment options and order confirmations within the agreed scope.
5) Check mobile usability. Confirm that shoppers can read the choices, operate the controls and revisit preferences without obstructed navigation.
6) Review interactive services. Open chat and other widgets to establish whether they introduce additional data flows.
7) Trace server-side handling. Where data moves through backend systems, verify the relevant controls there as well.
8) Save evidence and assign ownership. Retain dated test results, configuration details and a contact for urgent review.
Cookiebot’s Retail Consent Audit Guide landing page describes a downloadable resource covering banner checks, GPC testing, checkout, widgets and referral handling. Teams considering it should review the access form and the resource’s scope. The public description is not a substitute for testing their own store.
For the November 23–29 campaign, establish a simple change rule: anyone adding a tag, widget or landing page must identify the privacy checks needed before release. Extend that rule into Cyber Monday. A named reviewer and a repeatable test are more useful than a last-minute assumption that the original setup still applies.
How to choose the right CMP for your store
Begin with the platform and the requirements document. Shortlist providers that can support the intended architecture, then request a demonstration based on the actual purchase journey.
Evaluate cost against the full proposed scope: domains, usage allowances, scanning, records, regional settings, implementation and support. Ask how seasonal traffic affects billing and what happens if an allowance is exceeded. Obtain written answers rather than infer them from an entry-level price.
Also examine the maintenance process. Who reviews scan results? Who approves categories? Who configures a newly added advertising service? Who checks the store after a theme, app or checkout change? A technically capable product needs a workable operating arrangement.
Cookiebot merits consideration for automated discovery and integrations; OneTrust for coordinated domain and regional administration; CookieYes for its documented feature mix across common platforms; Termly for consent and documentation workflows; and Complianz for native WordPress administration. These are starting points for evaluation, not substitutes for an implementation test.
The strongest Black Friday preparation ends with evidence. The store team knows which technologies operate across the journey, what the applicable privacy choices mean and how those choices affect data handling. It can complete a purchase test, retrieve the relevant records and identify the person responsible for the next change.
That is the standard a retail CMP should help the business meet: an understandable customer experience and a consent implementation the people running the store can verify.



