Coverage
Every Law We Reach — and those we do not...yet.
Consentinel is not a rulebook with a separate branch for every law. It is one approach — Identify and hold tracking scripts until your visitor chooses, then keep the record. This page maps that approach onto the laws it answers, on both sides of the Atlantic. Where it stops, we say so here rather than in a footnote.
Read this alongside the laws themselves — that page explains what each law asks for. This one says what we actually do about it.
Current as of August 2026 · Software and documentation, not legal advice.
The Mechanism
Four Things Consentinel Does.
The laws are what those actions get pointed at.
Hold
Consentinel blocks trackers by holding them back until a visitor makes a consent choice –– When a tracker is loaded through page code Consentinel can control, it prevents the script from running before consent, so the tracker cannot set cookies, read stored identifiers, or measure the visit.
Signal
When a browser sends a “Do Not Sell My Data” signal, Consentinel treats it as an Opt-Out decision — Your visitor never needs to click the banner, the signal is Honored automatically. We store both readings separately in the log and never merge them, because they disagree about a quarter of the time.
Purge
When someone declines cookies, or changes their mind later, Consentinel clears the tracking cookies already stored on their device — Both the cookies a browser can reach plus the cookies only the server can. This is 'housekeeping' after the fact.
Record
Every consent choice gets stored securely and cannot be edited afterward: When / Choice / GPC Signal / Region / Banner Version. WE DO NOT STORE RAW IP ADDRESSES — A scrambled, or 'hashed' version replaces it. Website admins can export the consent records as a spreadsheet.
United States
Where the letters come from.
CIPA is the one a demand letter actually cites, and it is the reason the product is shaped the way it is. The opt-out rules sit beside it, not underneath it.
CIPA § 631 / § 632.7
California Invasion of Privacy Act — wiretapping
Alleged · A tracking script another company put on your site reads or records the visitor's activity in transit.
Non-essential trackers are held before they execute. For a visitor who has not consented, the tracker does not run, set an identifier, or send measurement data.
The honest edge: a tag already written into your page still has its file requested, which shows that company an IP address and the page your visitor was on. On WordPress, those tags are removed before the page is sent, so even that request never happens.
CIPA § 638.51
Pen register / trap-and-trace
Alleged · Routing and addressing data — the visitor's IP among it — is captured by a tracker without their agreement.
The same thing, applied to the network: the requests a tracker would make on its own are stopped before they're made, rather than made and then stripped of identifying details.
Same edge as above, and it matters more here because this theory is about addressing data: a loader already written into your HTML is still fetched, and that fetch carries an IP. Our crawler reports every host that reaches the network before consent, so you are told which ones rather than reassured.
CCPA / CPRA § 1798.120, § 1798.135
Opt-out of sale and sharing
Alleged · Personal information is sold or shared without an honored opt-out.
The “don’t sell my data” browser signal is honored as an opt-out automatically, without a click. A “Do Not Sell or Share My Personal Information” control is available for you to place in your footer. You have to place it — the banner won't add one for you.
CPRA reg. § 7025(c)(6)
Consent given after an opt-out signal
Alleged · A visitor with GPC enabled opens preferences and grants a category anyway — and the record contradicts what the page did.
The grant is recorded as it actually happened and flagged as an override, rather than silently rewritten to a decline. Enforcement already happened in the browser; the log's job is to describe it truthfully.
Evidence for any of the above
What a demand letter asks you to produce
Alleged · You are asked what your site did, for a specific visitor, on a specific date, under a specific configuration.
A consent log nobody can edit afterwards, tying each choice to the banner version that was live at that moment — plus, on Cloud, a check that visits your site twice in a real browser and records what loaded before consent and what changed after. Records are kept 90 days on the free plan and 24 months on paid.
Florida Digital Bill of Rights
Contractual only — no enforcement logic
Addressed in our Data Processing Addendum as controller-processor terms. There is no Florida-specific behavior in either product, and this row exists so nobody infers one.
Contractual — not a technical control
Europe, UK & Switzerland
Answered by the same mechanism, not a second product.
Prior consent is prior consent. What changes in Europe is the paperwork around it — who is the processor, where the data sits, and on what terms it crosses a border.
ePrivacy Directive Art. 5(3)
Consent before storage or access on a device
Alleged · Cookies and similar storage are set before the visitor has agreed to them.
Prior consent is enforced rather than announced: the tracker is held before it can write anything, and non-essential cookies are purged on a decline.
GDPR Art. 6 / Art. 7
Lawful basis, provable consent, withdrawal
Alleged · Consent was not freely given, not specific, not provable — or could not be withdrawn as easily as it was given.
Opt-in by default with per-category choice. Dismissing the banner does not grant consent — a design decision, not an oversight. Withdrawal is a first-class method in the log, alongside accept, decline and preferences.
GDPR Art. 28 · Chapter V
Processor obligations and international transfer
A published DPA with processor terms, a named subprocessor list with 30 days' notice of change, and the EU Standard Contractual Clauses (Module 2, controller to processor) for transfers to the US. The WordPress plugin used locally sends us nothing, so no processor relationship arises at all — the DPA says so in its second section.
Contractual — not a technical control
UK GDPR · Swiss revFADP
Treated as EEA, deliberately
Both are classified alongside the EEA in the consent log rather than given their own weaker branch. Treating a UK or Swiss visitor as anything else would under-protect them for no benefit to anyone.
Where we stop
Where Our Coverage Stops. (for now..)
A coverage matrix with no blanks in it is a brochure. These are the blanks. You should read them before you buy, not after something arrives in the post.
We're not on the European advertising framework list
There's an industry framework that gates a specific list used for programmatic advertising in Europe. We're not on it and we're not currently trying to be. If your revenue depends on European programmatic ads, that's a real gap — and you should know it before you buy, not after.
No per-state engine outside California
Our own law page lists nineteen states with comprehensive privacy laws on the books, and neither product contains a rule written to any of them. Where those laws recognize a universal opt-out signal, honoring GPC is the mechanism that answers them — and we honor GPC everywhere, for every visitor. But that is one signal doing general work, not per-state coverage, and we would rather say so than let the table imply otherwise.
The nineteen, with effective datesDo Not Sell is not the same as cookie clearing
On a California opt-out we deny the consent signals and clear cookies. If your site is advertising-heavy and genuinely depends on sale-or-share mechanics, ask your counsel what a complete Do-Not-Sell posture requires for your business. Cookie clearing is hygiene. We will not sell it as more than that.
Outside Europe and the US, we don't record where your visitor is
A visitor from Brazil or Canada is treated exactly like everyone else — they get the same protection as everyone else — but the log records their region as unknown rather than guessing at a law we have not built for. LGPD, PIPEDA and the rest are not addressed.
We don't handle data subject requests
Access, deletion and correction requests — DSARs — are not part of Consentinel, and tools that bundle them with consent will do that job better. The reason is structural rather than a missing feature: your visitors' consent records hold a salted, truncated hash of an IP and no name, no email and no account, so we genuinely cannot look a person up on request. What we can do is hand you every record for your site, exportable and timestamped, and our processing agreement sets out the assistance we owe you.
What the DPA commits us toSome platforms have a limit no consent tool can pass
On Wix, the platform's own marketing tags cannot be blocked in the visitor's browser by anyone, and on Shopify we measured a Meta Pixel sending data before consent, through Shopify's own sandbox, on a textbook install. The controls above describe what we do; what your platform allows is a separate question, and we publish those measurements too.
See the platform measurementsMost of these are something you can act on
What we can't block from inside your page, you can often remove at its source. A font loaded by a style file stops being an outside request once you host the font yourself. A script your CDN or host adds is a switch in their settings. Tracking that happens server-to-server is yours — you set it up, so you can scope it down, delay it until after consent, or turn it off. We tell you which ones are running, on which pages, and when we saw them. Doing something about each one is your call, but at least it's a call you get to make.
One posture, everywhere
We don't guess where your visitor is.
Plenty of consent tools geolocate the visitor and relax the rules for the ones they decide are outside Europe. We built that, and then we withdrew it — because a full-page cache stores one copy of the page for everyone, so the first visitor after a cache purge can freeze their own country into the HTML that every subsequent visitor receives. One American warming the cache would have put every European on the weaker setting, with trackers firing before consent and nothing anywhere reporting a fault.
So every visitor gets the strict setting: nothing runs until they choose. It costs a little measurement in places that would have permitted more, and it means the posture you tested is the posture everyone gets.
What to do with this page
If you're evaluating us: read the gaps first. They're the part that decides whether we fit.
If you already use us: the four things above are what your account is doing right now. The record they produce is in your dashboard, and exports as a spreadsheet.
If you're advising someone else: this page plus the per-platform measurements is the honest picture. Neither is a legal opinion.
Consentinel provides software and documentation, not legal advice. Nothing on this page creates an attorney-client relationship or guarantees compliance with any law, and the statutes described here change. What it does describe is what the software does — and the fastest way to find out what your own site does is to scan it.
Scan your site free