Skip to content

Compliance Overview

Last updated: October 4, 2026

This page is the canonical compliance positioning page for Cybexo CMP.

Cybexo CMP currently documents support for:

  • GDPR and ePrivacy implementation patterns
  • Direct Web TCF disclosures and lifecycle, including the TCF 2.4 disclosure changes
  • IAB GPP (where enabled)
  • Google Consent Mode v2 (ad_storage, analytics_storage, ad_user_data, ad_personalization)
  • CCPA and CPRA implementation support
  • Shopify Customer Privacy API interoperability notes

See Web TCF Disclosures and Lifecycle and Google Consent Mode v2 Validation for technical validation details.

  • Collects and stores consent choices according to configured policy.
  • Exposes consent signals for web, mobile, and supported platform integrations.
  • Supports consent lifecycle actions: default, update, reopen, and change tracking.
  • Provides debugging and verification utilities for implementation audits.
  • Provide legal advice.
  • Replace legal review of jurisdiction-specific obligations.
  • Automatically fulfill data subject rights requests unless separately contracted.
  • Replace customer obligations for tag governance and vendor contract management.
Section titled “4. Regional Banner and Consent Defaults (Canonical)”

CYBEXO CMP applies the banner-delivery mode declared in the property configuration. A worldwide-TCF demonstration presents the complete TCF flow regardless of the reviewer’s location. Ordinary visitor-region routing uses a separate regional configuration; test and identify both configurations explicitly.

For dedicated visitor-region configurations, the policy is:

Region group Banner behavior Resolved Consent Mode policy User controls Framework output
EEA / UK (GDPR) Full consent banner + second-layer preferences denied for ad_storage, analytics_storage, ad_user_data, ad_personalization Accept All, Reject All, granular preferences TCF enabled (TC String generated when configured)
US regimes (CCPA / CPRA / USNat where configured) Notice/opt-out banner granted after validated policy; updates on opt-out Do Not Sell or Share, Privacy Choices, optional Continue/Allow All GPP enabled where configured
Global non-regulated regions No banner, or informational-only banner with Continue granted for all four Consent Mode keys after validated policy No consent collection controls in informational-only mode No TCF, no GPP, no consent log collection in informational-only mode

If the banner does not appear because a dedicated regional configuration determines the user is outside banner-targeted regions, Cybexo applies the configured granted Consent Mode update once the regional configuration has been validated. Direct Web starts with denied defaults while that configuration loads. A dependency failure is not an intentional no-banner case and must not produce a fabricated grant.

This applies to deployments using global defaults/data transmission controls and avoids unintended denied states when no consent UI is shown.

  • State the implementation and tested release explicitly. Direct Web TCF disclosure guidance does not qualify a CMS or native SDK release.
  • Google Consent Mode v2 requires ordering validation (default before tag execution).
  • Delivery mode and regional behavior must be documented and testable (EEA denied-by-default with banner; validated no-banner regional flows updated to the configured grant).
  • Keep screenshots and debug reports for each production domain/app release.

This document is technical guidance for configuration and verification. It is not legal advice.