Compliance Overview
Last updated: October 4, 2026
This page is the canonical compliance positioning page for Cybexo CMP.
1. Supported Standards and Frameworks
Section titled “1. Supported Standards and Frameworks”Cybexo CMP currently documents support for:
- GDPR and ePrivacy implementation patterns
- Direct Web TCF disclosures and lifecycle, including the TCF 2.4 disclosure changes
- IAB GPP (where enabled)
- Google Consent Mode v2 (
ad_storage,analytics_storage,ad_user_data,ad_personalization) - CCPA and CPRA implementation support
- Shopify Customer Privacy API interoperability notes
See Web TCF Disclosures and Lifecycle and Google Consent Mode v2 Validation for technical validation details.
2. What Cybexo CMP Does
Section titled “2. What Cybexo CMP Does”- Collects and stores consent choices according to configured policy.
- Exposes consent signals for web, mobile, and supported platform integrations.
- Supports consent lifecycle actions: default, update, reopen, and change tracking.
- Provides debugging and verification utilities for implementation audits.
3. What Cybexo CMP Does Not Do
Section titled “3. What Cybexo CMP Does Not Do”- Provide legal advice.
- Replace legal review of jurisdiction-specific obligations.
- Automatically fulfill data subject rights requests unless separately contracted.
- Replace customer obligations for tag governance and vendor contract management.
4. Regional Banner and Consent Defaults (Canonical)
Section titled “4. Regional Banner and Consent Defaults (Canonical)”CYBEXO CMP applies the banner-delivery mode declared in the property configuration. A worldwide-TCF demonstration presents the complete TCF flow regardless of the reviewer’s location. Ordinary visitor-region routing uses a separate regional configuration; test and identify both configurations explicitly.
For dedicated visitor-region configurations, the policy is:
| Region group | Banner behavior | Resolved Consent Mode policy | User controls | Framework output |
|---|---|---|---|---|
| EEA / UK (GDPR) | Full consent banner + second-layer preferences | denied for ad_storage, analytics_storage, ad_user_data, ad_personalization |
Accept All, Reject All, granular preferences | TCF enabled (TC String generated when configured) |
| US regimes (CCPA / CPRA / USNat where configured) | Notice/opt-out banner | granted after validated policy; updates on opt-out |
Do Not Sell or Share, Privacy Choices, optional Continue/Allow All | GPP enabled where configured |
| Global non-regulated regions | No banner, or informational-only banner with Continue | granted for all four Consent Mode keys after validated policy |
No consent collection controls in informational-only mode | No TCF, no GPP, no consent log collection in informational-only mode |
4.1 No-banner cases
Section titled “4.1 No-banner cases”If the banner does not appear because a dedicated regional configuration determines the user is outside banner-targeted regions, Cybexo applies the configured granted Consent Mode update once the regional configuration has been validated. Direct Web starts with denied defaults while that configuration loads. A dependency failure is not an intentional no-banner case and must not produce a fabricated grant.
This applies to deployments using global defaults/data transmission controls and avoids unintended denied states when no consent UI is shown.
5. Audit Positioning Notes
Section titled “5. Audit Positioning Notes”- State the implementation and tested release explicitly. Direct Web TCF disclosure guidance does not qualify a CMS or native SDK release.
- Google Consent Mode v2 requires ordering validation (default before tag execution).
- Delivery mode and regional behavior must be documented and testable (EEA denied-by-default with banner; validated no-banner regional flows updated to the configured grant).
- Keep screenshots and debug reports for each production domain/app release.
6. Legal Notice
Section titled “6. Legal Notice”This document is technical guidance for configuration and verification. It is not legal advice.