Privacy & Consent (CMP)

Inlay checks for visitor consent before running an ad auction or firing any tracking pixel on your site. In the EEA, UK, and Switzerland this means an ad only serves once a valid consent signal exists — no CMP, or a declined one, means Inlay serves nothing for that impression rather than guessing.

What is a CMP?

A Consent Management Platform (CMP) is the cookie/consent banner software running on your site. A CMP that implements the IAB Transparency & Consent Framework (TCF) 2.2 exposes a standard window.__tcfapi interface that any ad tech vendor, including Inlay, can read to check what a visitor has consented to.

Inlay doesn't provide or require a specific CMP. Any TCF 2.2-certified CMP already on your page is picked up automatically — there's nothing extra to configure on the Inlay side once one is installed.

Behavior in the EEA, UK & Switzerland

For a visitor Inlay determines is in the EEA, UK, or Switzerland — based on your CMP's own signal, the visitor's network location, or the page's declared language — Inlay requires two things to be true before it will run the auction for that impression:

  • Purpose 1 — Store and/or access information on a device
  • Purpose 2 — Use limited data to select advertising

Both must be explicitly granted through your CMP. Otherwise:

SituationWhat happens
No CMP installed on the pageNo ad is served for that impression. Nothing renders in the slot.
CMP present, visitor declinesSame as above — no ad, no auction, no tracking pixel fires.
CMP present, visitor grants Purpose 1 + 2Ad serves normally.
CMP present and reports GDPR doesn't apply to this visitorAd serves normally — no consent is required in that case.
Inlay never treats a missing CMP as evidence that GDPR doesn't apply. If Inlay can't confirm consent one way or the other for an EEA/UK/Swiss visitor, it holds the impression rather than serving it. There is currently no reduced-data “contextual” fallback for this case — most demand partners require a valid consent signal to bid on this inventory at all.

Behavior for US privacy signals (GPC)

Separately from the EU/TCF check above, Inlay also honors Global Privacy Control (GPC)— a browser or extension-level signal that a growing number of US states (including California, Colorado, and Connecticut) treat as a valid, legally binding opt-out request. If a visitor's browser sends a GPC signal, Inlay does not run the auction or fire trackers for that impression, regardless of the visitor's location.

This is currently a conservative default rather than a fine-tuned regional policy — Inlay holds the impression outright instead of attempting a reduced-data fallback. This may become less restrictive over time as our broader US privacy compliance work concludes.

Everywhere else

Outside the EEA, UK, Switzerland, and without a GPC signal, none of the above applies — Inlay serves the auction exactly as it always has. You do not need a CMP to monetize traffic that isn't covered by GDPR/UK-GDPR/Swiss-FADP or a GPC opt-out.

Setting up a CMP

If a meaningful share of your traffic is in the EEA, UK, or Switzerland, adding a TCF 2.2-certified CMP to your site directly improves how much of that traffic Inlay can monetize. Any certified CMP works — Inlay reads the standard __tcfapi interface, not a vendor-specific integration.

Once installed, no changes are needed on the Inlay side. The embed script picks up the CMP's consent signal automatically on the next page load.

FAQ

Will this reduce my ad revenue?
Only for EEA/UK/Swiss traffic without a working CMP, or for visitors sending a GPC opt-out signal. Traffic outside those cases is unaffected.

Do I need to use a specific CMP?
No. Any CMP that implements IAB TCF 2.2 works — Inlay reads the standard __tcfapi interface.

What if none of my traffic is in the EU?
Then this doesn't affect you day-to-day — the GPC check still applies to any visitor whose browser sends that signal, but the EU/TCF check simply never triggers for traffic outside the EEA/UK/Switzerland.