For your legal team
One page for a lawyer who does not practice privacy. What we do, what stays yours, and why there is nothing to redline.
The technical problem, in one paragraph
A consent banner is a statement to a visitor about what will and will not happen if they decline. Whether that statement is true is a question about configuration: which tags the tag manager is holding back, whether the consent signal reaches them, and whether an opt-out signal sent by the browser is honored. A banner can be present, correctly worded, and still not do what it says, because the part that enforces it sits in a different system from the part that displays it.
That is the whole of our subject matter. We make the enforcement match the statement, and we hand you a dated record of what changed and what was tested.
Where the lanes divide
Your counsel owns every legal position. We do the technical work and hand you the evidence of what changed. We do not tell you whether you are compliant, we do not estimate your exposure, and we do not predict how any claim would be decided.
What we can tell you precisely is what was configured, what was tested, and what fired or was blocked in each consent state. That is a factual record of a system's behavior on a given date. What it means for your obligations is your call, and we do not have a view we would ask you to rely on.
What exactly your client is approving
One design document, in writing, before the build starts. It states the banner and preference center configuration, the tag categories, the geolocation rules, and the sites in scope. Approving it starts the clock and fixes the scope. Nothing outside it gets built, and nothing inside it changes without a new approval.
What is included
- Configuration in your own platform tenant
- Standard scope, built from templates we have run before
- A design document you approve before the build starts
- Testing per consent state, shared with you before go-live
- Configuration documentation at handover
- Standard terms, accepted at checkout
What is not
- Platform license costs, which you buy directly from OneTrust
- Custom development beyond what the platform does natively
- Rebuilding or re-tagging your website code
- Third-party tracking you do not control
- Migration of records from another platform
- Legal positions, which stay with your counsel
What we do not touch
Your site code. Your CMS. Your DNS. Your production publish. Somebody on your side with publish rights merges to production, which keeps the change under your control and means no third party can alter your live site. Tags hardcoded outside the tag manager, or living in an agency's own container, are outside the implementation. We list them for you rather than change them.
What the evidence does and does not demonstrate
You receive test results per consent state, plus a confirmatory test after go-live. They demonstrate what the configuration did on the pages tested, on the date tested. They do not demonstrate the absence of tracking elsewhere: anything hardcoded into templates, anything running server side, and any site on another container are outside what the test can see.
Consent work also carries a graded baseline, A+ to F, for the sites in scope. The grade describes how the configuration is set up. Your legal position is a separate question for your counsel.
Why the terms are not negotiable, and what redlining costs
There is a master agreement and there is a statement of work. Both are standard, and both are accepted at checkout. What we remove is the negotiation, not the agreement.
The price and the timeline depend on that. Standard terms are what make a fixed fee and a two-week build possible, so a request to change them is not an objection to overcome, it is a signal that the engagement needs custom scoping at a higher price. If that is where you land, everything already paid is credited toward the custom engagement, so raising it costs your client nothing but time.
Not published here yet
Four things belong on this page and none of them should be written before it can be sourced. Each is with counsel:
- A primary-source citation and a review date for the technical problem stated above
- The master agreement and the statement of work, in full and readable before checkout
- A substantiation line for every published figure: source, method and period. Denominators live here, never on the marketing pages
- What the automation touches, whether client data trains anything, which decisions a senior practitioner signs off, and who is accountable
Reviewing this before it is complete? Ask us directly and we will answer in writing.