Coverage

Every Law We Reach — and those we do not...yet.

Consentinel is not a rulebook with a separate branch for every law. It is one approach — Identify and hold tracking scripts until your visitor chooses, then keep the record. This page maps that approach onto the laws it answers, on both sides of the Atlantic. Where it stops, we say so here rather than in a footnote.

Read this alongside the laws themselves — that page explains what each law asks for. This one says what we actually do about it.

Current as of August 2026 · Software and documentation, not legal advice.

The Mechanism

Four Things Consentinel Does.
The laws are what those actions get pointed at.

01
Hold

Consentinel blocks trackers by holding them back until a visitor makes a consent choice –– When a tracker is loaded through page code Consentinel can control, it prevents the script from running before consent, so the tracker cannot set cookies, read stored identifiers, or measure the visit.

02
Signal

When a browser sends a “Do Not Sell My Data” signal, Consentinel treats it as an Opt-Out decision — Your visitor never needs to click the banner, the signal is Honored automatically. We store both readings separately in the log and never merge them, because they disagree about a quarter of the time.

03
Purge

When someone declines cookies, or changes their mind later, Consentinel clears the tracking cookies already stored on their device — Both the cookies a browser can reach plus the cookies only the server can. This is 'housekeeping' after the fact.

04
Record

Every consent choice gets stored securely and cannot be edited afterward: When / Choice / GPC Signal / Region / Banner Version. WE DO NOT STORE RAW IP ADDRESSES — A scrambled, or 'hashed' version replaces it. Website admins can export the consent records as a spreadsheet.

United States

Where the letters come from.

CIPA is the one a demand letter actually cites, and it is the reason the product is shaped the way it is. The opt-out rules sit beside it, not underneath it.

CIPA § 631 / § 632.7

California Invasion of Privacy Act — wiretapping

Both

Alleged · A tracking script another company put on your site reads or records the visitor's activity in transit.

Non-essential trackers are held before they execute. For a visitor who has not consented, the tracker does not run, set an identifier, or send measurement data.

The honest edge: a tag already written into your page still has its file requested, which shows that company an IP address and the page your visitor was on. On WordPress, those tags are removed before the page is sent, so even that request never happens.

CIPA § 638.51

Pen register / trap-and-trace

Both

Alleged · Routing and addressing data — the visitor's IP among it — is captured by a tracker without their agreement.

The same thing, applied to the network: the requests a tracker would make on its own are stopped before they're made, rather than made and then stripped of identifying details.

Same edge as above, and it matters more here because this theory is about addressing data: a loader already written into your HTML is still fetched, and that fetch carries an IP. Our crawler reports every host that reaches the network before consent, so you are told which ones rather than reassured.

CCPA / CPRA § 1798.120, § 1798.135

Opt-out of sale and sharing

Both

Alleged · Personal information is sold or shared without an honored opt-out.

The “don’t sell my data” browser signal is honored as an opt-out automatically, without a click. A “Do Not Sell or Share My Personal Information” control is available for you to place in your footer. You have to place it — the banner won't add one for you.

CPRA reg. § 7025(c)(6)

Consent given after an opt-out signal

Cloud

Alleged · A visitor with GPC enabled opens preferences and grants a category anyway — and the record contradicts what the page did.

The grant is recorded as it actually happened and flagged as an override, rather than silently rewritten to a decline. Enforcement already happened in the browser; the log's job is to describe it truthfully.

Evidence for any of the above

What a demand letter asks you to produce

Both

Alleged · You are asked what your site did, for a specific visitor, on a specific date, under a specific configuration.

A consent log nobody can edit afterwards, tying each choice to the banner version that was live at that moment — plus, on Cloud, a check that visits your site twice in a real browser and records what loaded before consent and what changed after. Records are kept 90 days on the free plan and 24 months on paid.

Florida Digital Bill of Rights

Contractual only — no enforcement logic

Cloud

Addressed in our Data Processing Addendum as controller-processor terms. There is no Florida-specific behavior in either product, and this row exists so nobody infers one.

Contractual — not a technical control

Europe, UK & Switzerland

Answered by the same mechanism, not a second product.

Prior consent is prior consent. What changes in Europe is the paperwork around it — who is the processor, where the data sits, and on what terms it crosses a border.

ePrivacy Directive Art. 5(3)

Consent before storage or access on a device

Both

Alleged · Cookies and similar storage are set before the visitor has agreed to them.

Prior consent is enforced rather than announced: the tracker is held before it can write anything, and non-essential cookies are purged on a decline.

GDPR Art. 6 / Art. 7

Lawful basis, provable consent, withdrawal

Both

Alleged · Consent was not freely given, not specific, not provable — or could not be withdrawn as easily as it was given.

Opt-in by default with per-category choice. Dismissing the banner does not grant consent — a design decision, not an oversight. Withdrawal is a first-class method in the log, alongside accept, decline and preferences.

GDPR Art. 28 · Chapter V

Processor obligations and international transfer

Cloud

A published DPA with processor terms, a named subprocessor list with 30 days' notice of change, and the EU Standard Contractual Clauses (Module 2, controller to processor) for transfers to the US. The WordPress plugin used locally sends us nothing, so no processor relationship arises at all — the DPA says so in its second section.

Contractual — not a technical control

UK GDPR · Swiss revFADP

Treated as EEA, deliberately

Cloud

Both are classified alongside the EEA in the consent log rather than given their own weaker branch. Treating a UK or Swiss visitor as anything else would under-protect them for no benefit to anyone.

Where we stop

Where Our Coverage Stops. (for now..)

A coverage matrix with no blanks in it is a brochure. These are the blanks. You should read them before you buy, not after something arrives in the post.

We're not on the European advertising framework list

There's an industry framework that gates a specific list used for programmatic advertising in Europe. We're not on it and we're not currently trying to be. If your revenue depends on European programmatic ads, that's a real gap — and you should know it before you buy, not after.

No per-state engine outside California

Our own law page lists nineteen states with comprehensive privacy laws on the books, and neither product contains a rule written to any of them. Where those laws recognize a universal opt-out signal, honoring GPC is the mechanism that answers them — and we honor GPC everywhere, for every visitor. But that is one signal doing general work, not per-state coverage, and we would rather say so than let the table imply otherwise.

The nineteen, with effective dates

Do Not Sell is not the same as cookie clearing

On a California opt-out we deny the consent signals and clear cookies. If your site is advertising-heavy and genuinely depends on sale-or-share mechanics, ask your counsel what a complete Do-Not-Sell posture requires for your business. Cookie clearing is hygiene. We will not sell it as more than that.

Outside Europe and the US, we don't record where your visitor is

A visitor from Brazil or Canada is treated exactly like everyone else — they get the same protection as everyone else — but the log records their region as unknown rather than guessing at a law we have not built for. LGPD, PIPEDA and the rest are not addressed.

We don't handle data subject requests

Access, deletion and correction requests — DSARs — are not part of Consentinel, and tools that bundle them with consent will do that job better. The reason is structural rather than a missing feature: your visitors' consent records hold a salted, truncated hash of an IP and no name, no email and no account, so we genuinely cannot look a person up on request. What we can do is hand you every record for your site, exportable and timestamped, and our processing agreement sets out the assistance we owe you.

What the DPA commits us to

Some platforms have a limit no consent tool can pass

On Wix, the platform's own marketing tags cannot be blocked in the visitor's browser by anyone, and on Shopify we measured a Meta Pixel sending data before consent, through Shopify's own sandbox, on a textbook install. The controls above describe what we do; what your platform allows is a separate question, and we publish those measurements too.

See the platform measurements

Most of these are something you can act on

What we can't block from inside your page, you can often remove at its source. A font loaded by a style file stops being an outside request once you host the font yourself. A script your CDN or host adds is a switch in their settings. Tracking that happens server-to-server is yours — you set it up, so you can scope it down, delay it until after consent, or turn it off. We tell you which ones are running, on which pages, and when we saw them. Doing something about each one is your call, but at least it's a call you get to make.

One posture, everywhere

We don't guess where your visitor is.

Plenty of consent tools geolocate the visitor and relax the rules for the ones they decide are outside Europe. We built that, and then we withdrew it — because a full-page cache stores one copy of the page for everyone, so the first visitor after a cache purge can freeze their own country into the HTML that every subsequent visitor receives. One American warming the cache would have put every European on the weaker setting, with trackers firing before consent and nothing anywhere reporting a fault.

So every visitor gets the strict setting: nothing runs until they choose. It costs a little measurement in places that would have permitted more, and it means the posture you tested is the posture everyone gets.

What to do with this page

If you're evaluating us: read the gaps first. They're the part that decides whether we fit.

If you already use us: the four things above are what your account is doing right now. The record they produce is in your dashboard, and exports as a spreadsheet.

If you're advising someone else: this page plus the per-platform measurements is the honest picture. Neither is a legal opinion.

Consentinel provides software and documentation, not legal advice. Nothing on this page creates an attorney-client relationship or guarantees compliance with any law, and the statutes described here change. What it does describe is what the software does — and the fastest way to find out what your own site does is to scan it.

Scan your site free