See how Syrenis helps simplify compliance, build trust, and gain greater control over customer data. Book a Demo
Cookie Consent Management for Global Enterprises
Capture cookie consent, enforce it before a single tag fires, and prove it two years later when a regulator asks. Syrenis is a cookie management platform built for estates where one answer has to reach every domain, brand and downstream system you run, in real time.
Trusted By
What a cookie consent manager actually has to do
Four jobs, in order. Most tools do the first two.
Discovery. Scan every site and app you own for cookies, pixels and trackers, then keep that inventory current as teams add tags without telling anyone. A website audit is how you find what drifted.
Capture. Serve the banner or preference layer in the right language, with the right options for the visitor’s jurisdiction.
Enforcement. Hold non-essential scripts until valid consent exists, and revoke them the moment someone changes their mind.
Proof. Write an immutable record of every decision: what was shown, what was chosen, from where, and against which version of your notice.
Skip the fourth and you have a banner, not a consent manager. Skip the third and the banner becomes decoration. It tells the visitor their choice was applied while the tags keep firing, and the gap between the promise on screen and the behavior in the browser is exactly what a supervisory authority can measure.
Consistent Across Every Site
Apply a unified approach to cookie consent across all domains and digital properties, ensuring users see consistent experiences wherever they interact.
Built for Global Compliance
Adapt consent collection to regional requirements and frameworks, maintaining compliance across jurisdictions without adding complexity to your operations.
Control You Can Rely On
Maintain a clear, auditable record of consent and apply preferences accurately, supporting compliant data use across your digital ecosystem.
What changed in 2026
Twelve US states now require you to honor a browser signal
As of 1 January 2026, twelve states require businesses to recognize opt-out preference signals such as Global Privacy Control: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. California goes further than the rest. The site has to visibly indicate that the signal was processed rather than handling it quietly in the background.
There’s more coming. California’s AB 566, the Opt Me Out Act, was signed in October 2025. From 1 January 2027 any browser offered to Californians has to ship a built-in opt-out preference signal. The volume of GPC traffic hitting your properties is about to jump, and each of those requests is a legal instruction you have to act on before your ad tags load.
A banner can’t do this by itself. The signal arrives before any click, in an HTTP header or a JavaScript property, and something has to read it, map it to the right state law and suppress the right categories. If you read the signal after the tag has already loaded, you haven’t complied. You’ve just logged it. More on browser privacy signals.
The UK rules changed on 5 February 2026
The Data (Use and Access) Act 2025 added three exemptions to PECR, in force from 5 February 2026. Cookies used solely to collect statistics about how your service is used, with a view to improving it. Cookies used solely to remember viewing preferences, such as appearance or accessibility settings. And cookies used solely to establish a user’s location in order to provide emergency assistance.
The first two apply to website-based services only, and all three turn on that word solely. Combine an exempt purpose with anything else and consent comes straight back. You also still owe visitors clear information and a simple, free way to object, and nothing exempt can be shared with a third party for their own purposes.
Two live consequences for anyone running both markets. Your UK banner can legitimately ask for less than your EU banner now, and if it doesn’t, you’re collecting consent the law no longer requires and depressing your own analytics while you do it. Second, the exemptions are narrow enough that getting them wrong in either direction is a real risk, which is an argument for banner logic you can change centrally rather than logic hardcoded into 40 sites. Background: UK cookie law explained.
The EU is still moving
The European Commission published its Digital Omnibus package on 19 November 2025. Draft Article 88a moves consent for terminal equipment out of the ePrivacy Directive and into the GDPR, with a one-click refusal and a six month ban on asking again after someone says no. A companion Article 88b would have forced sites to honor a machine-readable browser signal.
The Council deleted 88b in its fifth compromise text of 18 June 2026 and kept 88a. Parliament hasn’t taken a position yet, and the two institutions still have to negotiate in trilogue, so none of this is settled. What it does tell you is that whatever lands will land as a deadline you don’t control, across every property you own. We broke down the proposed cookie exceptions and browser signal mandates when they were published.
Regulators already priced the mistakes
In January 2022 France’s CNIL fined Google 150 million euros and Facebook Ireland 60 million euros, 210 million between them, over one design decision. Accepting cookies took a single click. Refusing them took several.
The EDPB’s Cookie Banner Taskforce adopted its report on 17 January 2023. Three findings still catch enterprise sites out. Pre-ticked accept boxes aren’t valid consent, including on the second layer where teams assume nobody looks. A refuse option buried as a text link inside a paragraph lacks the prominence a real choice requires. And withdrawing consent has to be as easy to find as giving it was, which rules out the pattern where the only way back is a link in the footer of the privacy policy.
In August 2022 the California Attorney General settled with Sephora for 1.2 million dollars, in part for failing to process opt-out requests sent through Global Privacy Control. That case is still the reference point for what honoring the signal means in practice.
Recognized by GartnerĀ® as a Consent Management Leader
Recognized by leading analysts such as GartnerĀ® and KuppingerCole, Syrenis is the highest-performing Consent Management Platform on the market in terms of configurability, flexibility and speed.
āFully customizable, Syrenis has developed a deep and rich feature set across all four service categories, especially where integration is concerned, equally handling data from legacy systems through data loader functions and complex CRM APIs.āā
Cookie Management Features
Flexible Banners
Create and customize cookie banners with full control over language, design and behavior, optimizing consent rates while meeting global regulatory requirements.
Granular Controls
Give users clear, detailed choices over cookie categories and data usage, supporting compliant consent while improving transparency and user trust.
Cookie Auditing
Automatically scan for cookies and trackers, maintaining an up-to-date inventory and clear visibility over data collection across your websites and applications.
Simplified Recording
Access clear, auditable records of cookie consent activity across your digital properties, supporting internal reporting, regulatory requirements, and ongoing compliance monitoring.
Automatic Regulatory Updates
When regulations change, banner behavior updates automatically, with no manual monitoring and no manual reconfiguration.
Single Global Script Deployment
One embed script, every region, every regulation. A single script implementation serves the correct banner globally.
Geo-Aware Banner Behavior
Global deployment in 40+ languages without manual translation. The correct consent experience is always served for every region.
Brand Governance With Brand Consistency
Maintain consent and preference governance without sacrificing brand identity.
Built for estates that outgrew a banner tool
One script, one record, one place to change the rules when a regulator moves. That is the difference between a cookie banner and a cookie consent management platform.
One record across every brand
A visitor who consents on one property in your group shouldn’t be asked again on another, and consent given on a subdomain should carry to the parent where the same identity applies. Cross-domain consent handling and a shared record are what make that work. Most banner tools don’t offer either.
Signals read before tags fire
Opt-out preference signals are processed ahead of your advertising and analytics tags, mapped to the right state law, so the categories that should be suppressed never load in the first place.
Records you can hand to a regulator
Every decision is stored with notice version, timestamp and jurisdiction, in a form that can’t be edited after the fact. That’s the first thing a supervisory authority asks for.
Where enterprise cookie consent usually breaks
Three failure modes come up again and again on complex estates.
Drift
Marketing adds a tag through Google Tag Manager, nobody maps it to a consent category, and it fires for everyone. Automated scanning catches this. A quarterly manual review doesn’t.
Fragmentation after an acquisition
Two brands, two banners, two consent databases, one legal entity holding the risk. Consolidating consent records is slow, unglamorous work, and it’s why a lot of privacy teams inherit a compliance problem they didn’t create.
The withdrawal path
Plenty of enterprise sites capture consent cleanly and then bury the way back five clicks deep. The EDPB called this out directly and suggested a persistent hovering icon or a standardized visible link. A line at the bottom of the privacy policy isn’t that.
Seven questions to put to any vendor on your shortlist
Does consent propagate, or just get stored?
Ask what happens in your CRM, CDP, email platform and ad accounts within 60 seconds of a visitor withdrawing consent. If the answer involves a nightly export, that gap is your exposure window.
How does it handle one identity across several domains?
A customer who accepts on your main site and lands on your support subdomain shouldn’t be asked again. Cross-domain and cross-brand consent is where most tools quietly reset the record.
Can one script serve different rules by region?
Geo-aware behavior from a single deployment, or a separate implementation per market and a change request every time a law moves.
What does the audit record actually contain?
Notice version, timestamp, jurisdiction, the choice itself, and proof the entry can’t be edited later. Ask to see one.
Does it read GPC and other opt-out signals before tags fire?
Reading the signal after the tag has loaded isn’t compliance.
How many integrations, and who maintains them?
Building and owning your own connectors is a hidden headcount cost that shows up in year two.
Who else runs it at your scale, in your regulatory footprint?
Ask for the reference call.
350+ Integrations
View all
Enhance Your Cookie Management Strategy Further
Preference Management
Give customers control over how their data is used and build trust through every interaction. Centralize preferences, enable seamless updates across channels, and build richer, consented customer profiles over time.
Risk & Policy
Stay ahead of evolving regulations with centralized control over policies, notices, and data subject rights. Identify risk, respond faster, and maintain full auditability across jurisdictions.
Cookie consent manager vs consent management platform
The terms get used interchangeably. The difference matters when you write the requirements document.
| Cookie consent manager | Consent and preference platform | |
|---|---|---|
| Scope | Cookies, pixels and trackers on web properties | Cookies plus channel, marketing and data-use preferences across every touchpoint |
| Identity | Usually anonymous, device level | Anonymous and known customers, resolved to one profile |
| Systems | Website and tag manager | CRM, CDP, service desk, email, mobile apps, call center |
| Record | Cookie consent log | Full consent and preference history per person |
| Bought by | Web and marketing ops | Privacy, legal and marketing together |
If your requirement stops at the website, a cookie consent manager covers it. If a customer can also update their marketing preferences during a call with your service team, and that has to reconcile with what they clicked on your banner, you need the platform. Syrenis does both, which is why the cookie layer and the preference center share one record instead of two.
Drive Growth With Compliance
Syrenis gives privacy leaders the control and visibility to manage consent across complex, global environments. With modern privacy UX at its core, it unifies systems, applies preferences in real time, and turns compliance into a revenue enabler.
Enterprise Scale
Designed for global demand, our platform delivers fast, reliable performance across regions and high-volume environments. Maintain consistent consent and preference management at scale, without compromise.
Head of Compliance
Lexis Nexis
Global Compliance
Manage evolving privacy regulations with confidence. Apply the right policies based on location, ensure accurate consent capture, and maintain a clear, immutable, auditable view of compliance across frameworks such as CCPA and GDPR.
Service Delivery Manager
Media
Real-time orchestration
Keep systems and teams aligned with real-time updates across your entire ecosystem. As preferences change, theyāre applied instantly, ensuring consistent, compliant data usage across every channel.
Head of Technical Privacy & Governance
Retail
Frequently Asked Questions
What is cookie consent?
Cookie consent is a visitor’s permission for a site to store or read cookies and similar tracking on their device. Cookie consent management is the system around it: capturing the answer, enforcing it before non-essential tags load, storing a record that stands up to audit, and applying any change the visitor makes afterwards. Capture on its own isn’t management.
Do I need a cookie banner on my website?
In the EU, yes, for anything non-essential. The ePrivacy Directive requires prior consent before non-essential cookies are set. In the UK the answer changed on 5 February 2026, when the Data (Use and Access) Act 2025 exempted three narrow categories from consent: statistics used to improve the service, remembering viewing preferences, and location for emergency assistance. You still have to tell people and give them a free way to object, so you still need a notice layer. You may need to ask for less than you did last year. See UK cookie law explained.
What are the different types of cookies?
Cookies are usually grouped into strictly necessary, performance, functional and targeting. The categories matter because they’re the unit of enforcement. Whatever a visitor rejects has to map to a set of scripts that then don’t load, which is why an unmapped tag added through a tag manager is the most common way a compliant setup quietly stops being compliant.
How should a cookie banner be implemented?
Visible, readable, and offering accept, reject and customize with equal weight. Non-essential cookies stay blocked until valid consent exists. The EDPB’s Cookie Banner Taskforce report of 17 January 2023 named the patterns authorities treat as non-compliant: pre-ticked boxes, including on the second layer, and a refuse option hidden as a text link inside a paragraph. France’s CNIL fined Google 150 million euros and Facebook Ireland 60 million euros in January 2022 over exactly this, because accepting took one click and refusing took several. More on symmetry in cookie banners.
What is prior consent vs implied consent?
Prior consent requires users to actively opt in before cookies are set, as required under GDPR cookie consent rules. Implied consent assumes agreement through user actions such as continued browsing, and it’s no longer compliant in most regions for non-essential cookies.
How do I manage cookie preferences?
Preferences have to be as easy to change as they were to give. The EDPB has been explicit that withdrawal must be as accessible as consent was, and suggested a persistent hovering icon or a standardized visible link. A link at the bottom of the privacy policy doesn’t meet that. Whatever the visitor changes then has to reach the systems holding their data, not just the cookie table.
What is the ePrivacy Directive?
The EU rule, often called the cookie law, that governs cookies and similar technologies and works alongside GDPR. It may not govern them for much longer. The Commission’s Digital Omnibus proposal of 19 November 2025 would move consent for terminal equipment into the GDPR itself under a new Article 88a. The Council kept 88a in its compromise text of 18 June 2026 and deleted the companion Article 88b, which would have required sites to honor browser signals. Parliament hasn’t voted, so nothing is final.
Can users reject cookies easily?
Yes. Regulations require that rejecting cookies is as easy as accepting them. A compliant banner gives clear options to refuse non-essential cookies without friction, at the same level of prominence as accept.
How often should consent be refreshed?
There’s no single figure, and the anchors that exist point different ways. France’s CNIL tells sites to limit tracker lifetime to 13 months. The EU’s draft Article 88a would stop you re-prompting a visitor who refused for six months. Refresh sooner than either if your cookie usage materially changes. The practical answer is that the renewal period has to be configurable per jurisdiction rather than set once globally.
What happens if I don't comply with cookie laws?
Enforcement is active and expensive. France’s CNIL issued 150 million euros against Google and 60 million against Facebook Ireland in January 2022 over how hard refusal was made. In August 2022 the California Attorney General settled with Sephora for 1.2 million dollars, in part for failing to process opt-out requests sent through Global Privacy Control. The EDPB’s January 2023 taskforce report sets out the design practices authorities across the EU treat as non-compliant.
Does a cookie consent manager have to honor Global Privacy Control?
In the twelve US states that require recognition of universal opt-out mechanisms as of 1 January 2026, yes. The signal has to be read and acted on before advertising and analytics tags fire, and California expects the site to show the visitor that the request was processed. The California Attorney General’s 1.2 million dollar settlement with Sephora in August 2022 turned on this point.
Can one cookie consent manager cover multiple brands and domains?
It should. A visitor who consents on one property in your group shouldn’t be asked again on another, and consent given on a subdomain should carry to the parent where the same identity applies. That needs cross-domain consent handling and a shared record. A lot of banner tools have neither.
Did the UK change its cookie rules in 2026?
Yes. The Data (Use and Access) Act 2025 added three exemptions to PECR, in force from 5 February 2026: statistics collected solely to improve the service, remembering viewing preferences, and location solely for emergency assistance. The first two apply to website-based services. All three require clear information and a simple free way to object, none can be shared with third parties for their own purposes, and all three turn on the word solely. UK banners built before February 2026 are asking for consent the law no longer requires.
Will the EU Digital Omnibus change cookie consent rules?
Very likely, though not yet. The Commission proposed on 19 November 2025 to move terminal equipment consent into the GDPR under Article 88a, with one-click refusal and a six month pause before you can ask a refusing visitor again. Article 88b would have required sites to honor machine-readable browser signals. The Council deleted 88b on 18 June 2026 and kept 88a. It still has to clear Parliament and trilogues.
Still have questions? Contact our compliance experts.
Ready to see Syrenis in action?
Book a demo to see how Syrenis can help you achieve compliance and centralize consent management.