I Tested 7 GDPR Consent Platforms With a Real Website — Most Failed
Two months ago, I needed a consent management platform for a multi-country ecommerce project. I assumed they all worked. I was wrong.
I built a GDPR scanner — a headless browser that visits a site, monitors network requests, and answers three questions:
- Are trackers firing before the user interacts with the consent banner?
- Is the “Reject All” button actually accessible?
- After clicking reject, do trackers stay blocked?
I tested the 7 most popular CMPs against the same test site with 14 real trackers. Three passed. Four failed — one so badly I’m surprised they’re still in business.
The test site
A Next.js marketing page with Google Analytics 4, Facebook Pixel, Hotjar, LinkedIn Insight Tag, TikTok Pixel, HubSpot, Intercom, Segment CDN, Amplitude, FullStory, Rollbar, Sentry, Microsoft Clarity, and Twitter Pixel — all hardcoded into <head>.
No CMP pre-configuration. Each was installed following its own setup wizard. Then I ran the scanner in incognito from a German IP.
What I found
Usercentrics — 8/10 (Passed)
Usercentrics blocked everything before consent. No requests. No cookies. No local storage. The reject button was slightly smaller than the accept button, which is a dark pattern under the DSA, but from a pure blocking perspective, it was perfect.
After rejecting, the scanner confirmed zero tracking activity across all 14 trackers. The rejection was stored and persisted across page refreshes.
I’d use this for an enterprise client. The €15/month starting price is high for small sites, but it’s legally defensible in the one way that matters: trackers don’t fire without consent.
OneTrust — 8/10 (Passed)
Same as Usercentrics, but with a better reject button — equal size, equal contrast, one click. The enterprise pricing (€50+/month) makes it overkill for most projects, but the free tier covers basic cookie consent. I wouldn’t pay for it, but I wouldn’t worry about fines either.
Klaro — 8/10 (Passed)
Open source. Free. Works. The UI looks like it was designed by a backend developer — functional, ugly, zero friction. If you’re a solo founder or a small team, install this and stop thinking about consent. It handles the blocking correctly and doesn’t cost anything.
This is what I’d recommend to 80% of the people who ask me. I’d rather have a slightly ugly free tool that actually works than a polished paid tool that silently leaks data.
Cookiebot — 7/10 (Failed one check)
Cookiebot’s blocker was solid post-consent, but GA4 fired before I touched the banner. It was a single request — the analytics.js loader — but under GDPR, one unauthorized tracking request is the same legal exposure as a hundred.
The fix is straightforward: you need to manually configure Google Consent Mode v2 to default to denied. I wrote a separate guide on this because it tripped me up for a week →
Didomi — 7/10 (Failed one check)
Blocked everything except one request to the Segment CDN. This is a known issue in Didomi’s own documentation — Segment loads scripts before Didomi’s blocker initializes. If you use Segment, you need to manually add cdn.segment.com to Didomi’s custom domain blocklist.
This is the kind of bug that would never appear in a vendor’s own testing. They test with their own setup, not yours. Unless you’re running your own scanner against your actual site, you won’t know it’s broken.
Osano — 5/10 (Failed one critical check)
Strong blocking, but the “Reject All” button is hidden behind a “More Options” menu. This is the exact pattern that got a French publisher fined in 2024 (CNIL decision 2024-047). The CNIL ruled that requiring an extra click to refuse constitutes an obstacle to free consent.
Technically good product, legally risky decision. I wouldn’t recommend it for EU-only traffic.
CookieYes — 4/10 (Failed three checks)
The worst performer. GA4 fired, Hotjar loaded, and Facebook Pixel was still tracking after I clicked “Reject All.” The reject button design is actually good — equal size, clear label — but the blocking is terrible.
CookieYes is popular because it’s cheap ($10/month) and well-marketed. It’s also a compliance trap. I would not trust this with a client’s legal exposure.
The comparison
| CMP | Blocks before consent | Reject button | Blocks after rejection | Price | Real-world score |
|---|---|---|---|---|---|
| Usercentrics | ✅ | ⚠ Slightly smaller | ✅ | €15/mo | 8/10 |
| OneTrust | ✅ | ✅ | ✅ | Free tier, €50+/mo | 8/10 |
| Klaro | ✅ | ✅ | ✅ | Free | 8/10 |
| Cookiebot | ❌ GA4 leaked | ✅ | ✅ | €12/mo | 7/10 |
| Didomi | ⚠ Segment bypass | ✅ | ✅ | Custom | 7/10 |
| Osano | ✅ | ❌ Hidden reject | ✅ | $49/mo | 5/10 |
| CookieYes | ❌ Multiple leaks | ✅ | ❌ FBP still firing | $10/mo | 4/10 |
How to not get this wrong
The biggest lesson from this testing isn’t about which CMP is best. It’s this: you don’t know if your CMP is working until you test it with real trackers on your actual site.
Every CMP works differently depending on your stack. What passes with vanilla HTML might fail with Next.js hydration. What works with gtag might break with GTM. The only way to be sure is to scan your site yourself.
I built the scanner I used for this comparison. It’s free, open source, and takes ~15 seconds to run. If you run it and your CMP passes, you’ve got something no vendor’s marketing page can give you: proof that it actually works on your specific site.
If you’re building something with AI features, you have additional obligations under the EU AI Act beyond cookie consent. I broke down what that actually means for software companies →