1. Compliance-and-Standards
  • Getting-Started
    • CYBEXO Developer Documentation
    • Quickstart (5 to 10 Minutes)
    • Documentation Overview
    • Concepts and Glossary
  • Compliance-and-Standards
    • Compliance Overview
    • IAB TCF v2.3 Support
    • Google Consent Mode v2 Validation
    • TCF API Validation
    • Audit Checklist (Pre-Launch)
  • Web-and-CMS-Integrations
    • CYBEXO CMP SDK – Web & GTM Setup
    • Integrate CYBEXO CMP with Webflow and Wix
    • Integrate CYBEXO CMP with WordPress
    • Integrate CYBEXO CMP with Drupal
    • Integrate CYBEXO CMP with Shopify
    • Google Tag Manager (GTM) Template Guide
  • Mobile-SDKs
    • CYBEXO CMP SDK - iOS Setup
    • iOS SDK API Reference
    • CYBEXO CMP SDK - Android Setup
    • Android SDK API Reference
    • App Attribution Partner (AAP) Integrations
  • Developer-Reference
    • Web JS API Reference
    • Consent Event Schema
    • Deployment and Environments
    • CYBEXO Debug Tool
    • Troubleshooting Playbook
    • Performance and Best Practices
    • Accessibility and UX Guidelines
    • Localization Workflow
    • Migration Guide
  • Security-and-Privacy
    • Security Overview
    • Privacy Architecture
    • Data and Logging Transparency
    • Subprocessors
    • CSP and Network Allowlist
  • Enterprise-and-Legal
    • DPA and Legal Pack
    • RFP Feature Matrix
    • Status and Reliability
    • Support and Escalation
    • CYBEXO CMP SDK – Commercial Licence
  • Operations
    • Changelog and Version Policy
  1. Compliance-and-Standards

Compliance Overview

Last updated: April 26, 2026
This page is the canonical compliance positioning page for Cybexo CMP.

1. Supported Standards and Frameworks#

Cybexo CMP currently documents support for:
GDPR and ePrivacy implementation patterns
IAB TCF v2.3
IAB GPP (where enabled)
Google Consent Mode v2 (ad_storage, analytics_storage, ad_user_data, ad_personalization)
CCPA and CPRA implementation support
Shopify Customer Privacy API interoperability notes
See IAB TCF v2.3 Support and Google Consent Mode v2 Validation for technical validation details.

2. What Cybexo CMP Does#

Collects and stores consent choices according to configured policy.
Exposes consent signals for web, mobile, and supported platform integrations.
Supports consent lifecycle actions: default, update, reopen, and change tracking.
Provides debugging and verification utilities for implementation audits.

3. What Cybexo CMP Does Not Do#

Provide legal advice.
Replace legal review of jurisdiction-specific obligations.
Automatically fulfill data subject rights requests unless separately contracted.
Replace customer obligations for tag governance and vendor contract management.

4. Regional Banner and Consent Defaults (Canonical)#

Cybexo CMP applies region-aware behavior to align banner UX, framework output, and Consent Mode defaults.
Region groupBanner behaviorConsent Mode defaultUser controlsFramework output
EEA / UK (GDPR)Full consent banner + second-layer preferencesdenied for ad_storage, analytics_storage, ad_user_data, ad_personalizationAccept All, Reject All, granular preferencesTCF enabled (TC String generated when configured)
US regimes (CCPA / CPRA / USNat where configured)Notice/opt-out bannergranted by default; updates on opt-outDo Not Sell or Share, Privacy Choices, optional Continue/Allow AllGPP enabled where configured
Global non-regulated regionsNo banner, or informational-only banner with Continuegranted for all four Consent Mode keysNo consent collection controls in informational-only modeNo TCF, no GPP, no consent log collection in informational-only mode

4.1 Google Partner Program Requirement (No-Banner Cases)#

If the banner does not appear because the user is outside banner-targeted regions, Cybexo keeps measurement intact by granting Consent Mode defaults in those no-banner cases.
This applies to deployments using global defaults/data transmission controls and avoids unintended denied states when no consent UI is shown.

5. Audit Positioning Notes#

IAB TCF v2.3 support should always be stated explicitly.
Google Consent Mode v2 requires ordering validation (default before tag execution).
Regional behavior must be documented and testable (EEA denied-by-default with banner, non-banner regions granted-by-default).
Keep screenshots and debug reports for each production domain/app release.

6. Legal Notice#

This document is technical guidance for configuration and verification. It is not legal advice.
Previous
Concepts and Glossary
Next
IAB TCF v2.3 Support