# Consent management platform (CMP)

Source: https://ordergroup.co/glossary/consent-management/
Last updated: 2026-10-10

> Consent management (CMP) in a lending or fintech app: GDPR and ePrivacy rules, SDKs off until consent, withdrawal, records and what the backend stores.

[Fintech](https://ordergroup.co/glossary/fintech/)
5 min read

# Consent management platform (CMP)

Also known as: CMP, consent management, consent management platform

Definition

A consent management platform (CMP) is software that asks users for consent, records each decision per purpose, and tells the app or website which tools may run. In the EU it implements the consent rules of the GDPR and of Article 5(3) of the ePrivacy Directive.

Cite this entry

Text
"Consent management platform (CMP)". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/consent-management/
HTML
`<a href="https://ordergroup.co/glossary/consent-management/">Consent management platform (CMP)</a> - Order Group`

Reviewed by [Mateusz Widenka](https://ordergroup.co/authors/mateusz-widenka/), Head of Delivery
Last reviewed 10 October 2026

## How consent management works

The GDPR defines consent in Article 4(11) as "any freely given, specific, informed and unambiguous indication of the data subject's wishes" given "by a statement or by a clear affirmative action". Article 7 adds four conditions. The controller must be able to prove that consent was given. A consent request mixed with other matters must be clearly separate from them. The user may withdraw at any time, and withdrawing must be as easy as giving consent. Under Article 7(4), tying a service to consent for processing it does not need weighs heavily against consent being freely given.

The ePrivacy Directive (2002/58/EC) adds a second rule. Article 5(3) allows storing information on a user's device, or reading information already stored there, only with consent, unless it is strictly necessary to transmit a communication or to provide a service the user explicitly requested. The European Data Protection Board says in Guidelines 2/2023 that this applies whether or not the information is personal data, and that client-side code which instructs the device to send information counts as gaining access. Analytics, crash reporting and attribution SDKs in a mobile app fall into that category.

A consent management platform sits between these rules and the code. It shows the choice, stores the decision for each purpose or tool, and exposes the decision to the app, which starts a tool only when it is allowed to run. A lending app usually holds two more kinds of permission. Marketing consents per channel (e-mail, SMS, phone calls, push) live in the lender's own system, next to the customer record. Operating system permissions, such as push notifications or Apple's App Tracking Transparency prompt on iOS, are granted on the phone and are separate from consent in the legal sense.

## What consent management means for your software

Most SDKs start collecting the moment the app launches. Analytics libraries send automatic events, such as the first open of the app or the start of a session, before any screen appears. Showing a banner is not enough: automatic collection has to be switched off in the native configuration of each platform and switched on in code only after the app has read the decision. Check each platform separately, because a configuration file that works on Android may be ignored on iOS, where the same flags go into the app's property list file.

According to the EDPB, once consent is withdrawn the controller must stop the processing based on it, and delete the data if no other legal basis remains. In the app a consent change should therefore stop the SDK in the current session, not at the next launch.

No answer means no consent. If the CMP fails to load or never reports a decision, every tool that depends on consent stays off. Treat that branch as a normal path and test it.

Defaults must be empty. Guidelines 05/2020 state that pre-ticked opt-in boxes are invalid under the GDPR. A checkbox that ticks itself because of a state bug makes the consent invalid, so it deserves a regression test.

Proving consent under Article 7(1) takes a record for each consent: its name, the version of its text, its status and the time of each change. Keep information notices out of the consent list: an information clause only informs the customer and needs no agreement.

Writing the specification?

Add Consent management platform (CMP) to your requirements checklist

Collect the terms your project touches and get their system requirements in one e-mail, ready for an RFP.

Consent rules and what they require from a lending app
RuleSourceWhat the system needs

Consent is an affirmative act; pre-ticked boxes are invalidGDPR Art. 4(11); EDPB Guidelines 05/2020Empty defaults covered by a regression testController can prove consentGDPR Art. 7(1)Record per consent: name, text version, status, time of changeWithdrawal as easy as giving consentGDPR Art. 7(3)Consent screen in the profile; SDK stops in the current sessionDevice storage and access need consent unless strictly necessaryePrivacy Art. 5(3); Polish PKE Art. 399SDKs off natively at launch, switched on after the CMP decisionService not conditional on consent it does not needGDPR Art. 7(4)Loan application that can be completed without marketing or analytics consentCommercial information sent with terminal equipment or automated calling systems needs prior consentPolish PKE Art. 398Separate marketing consents per channel in the core system

## Rules and regulation

The GDPR has applied since May 25, 2018. Article 5(3) of the ePrivacy Directive is applied through national law, so a lender in Poland follows the Electronic Communications Law (Prawo komunikacji elektronicznej, PKE) of July 12, 2024, in force since November 10, 2024. Article 399 transposes Article 5(3): storing or reading information on the user's device requires prior information and consent, except where it is necessary for transmission or for a service the user requested. Article 398 bans the use of automated calling systems and telecommunications terminal equipment, in particular through interpersonal communication services, to send commercial information, including direct marketing, unless the user has consented beforehand. Consent may be given by providing an e-mail address for receiving commercial information at that address. Article 400 applies the data protection rules to obtaining that consent.

The EDPB's Guidelines 05/2020 on consent, adopted on May 4, 2020, explain granularity per purpose, pre-ticked boxes, cookie walls and withdrawal. Its Guidelines 2/2023, adopted in final form on October 7, 2024, set out which techniques fall under Article 5(3). They build on Opinion 9/2014 of the Article 29 Working Party, which had already placed device fingerprinting within Article 5(3), and they cover unique identifiers, tracking pixels and code that runs on the device. In November 2025 the European Commission proposed a Digital Omnibus that would, among other things, change the GDPR and the consent rules for storing and reading information on devices. As of October 2026 the proposal is still being negotiated, so the rules above apply.

## From our projects

The app we have built for AvaFin Poland since January 2026 handles App Tracking Transparency on iOS, a CMP that decides about each SDK separately, and the consents stored in AvaFin's system. In September 2026, following requirements from AvaFin's legal team, we switched Firebase Analytics and Crashlytics off natively on both platforms. They are switched on only after the app reads the CMP decision. Because the crash reporting setting persists, crashes at startup are reported for consenting users from the second launch. On iOS the flags went into the app's property list file, because the shared configuration file was not read there. When the customer withdraws consent, the AppsFlyer attribution SDK stops sending data in the same session and resumes when consent is given again. If the CMP never reports a decision, everything that depends on consent stays off.

The consents in AvaFin's system are versioned records grouped into marketing consents (e-mail, SMS, phone and the customer panel) and app consents (analytics and push marketing). A separate consent for marketing push notifications was added in August 2026, and switching push on now triggers the system permission dialog. The same month the information clause was removed from the list of consents.

In Aasa24, the lending app we have developed for Aasa Polska since May 2023, analytics starts only after consent. In November 2024 the single phone marketing consent was split into separate SMS and phone call consents. In August 2026 the app got new marketing consents for partners on the last step of the application, and customers can now manage their marketing consents in the customer profile.

## Related terms

- [Data anonymization](https://ordergroup.co/glossary/data-anonymization/)

Data anonymization is processing personal data so that no one can identify the person by any means reasonably likely to be used. Anonymous data falls outside the GDPR; pseudonymized data, which can be re-linked with separately kept information, remains personal data under the GDPR.
- [Device fingerprinting](https://ordergroup.co/glossary/device-fingerprinting/)

Device fingerprinting is the collection of technical attributes of a phone or browser to recognize the same device across sessions. Lending apps use it for fraud checks at login, registration and the loan application. In the EU it falls under the GDPR and Article 5(3) of the ePrivacy Directive.
- [Open banking](https://ordergroup.co/glossary/open-banking/)

Open banking is regulated third-party access to a customer's payment account, with the customer's consent. In the EU it rests on PSD2, which defines account information services (AIS) and payment initiation services (PIS).

## Sources

1. [Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 4(11) and 7](https://eur-lex.europa.eu/eli/reg/2016/679/oj) - EUR-Lex
2. [Directive 2002/58/EC on privacy and electronic communications (ePrivacy Directive), Article 5(3)](https://eur-lex.europa.eu/eli/dir/2002/58/oj) - EUR-Lex
3. [Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-052020-consent-under-regulation-2016679_en) - European Data Protection Board
4. [Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive, version 2.0](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en) - European Data Protection Board
5. [EDPB-EDPS Joint Opinion 2/2026 on the Digital Omnibus proposal](https://www.edpb.europa.eu/system/files/documents/2026-02/edpb_edps_jointopinion_202602_digitalomnibus_en.pdf) - European Data Protection Board
6. [Ustawa z dnia 12 lipca 2024 r. - Prawo komunikacji elektronicznej (Dz.U. 2024 poz. 1221), art. 398-400](https://api.sejm.gov.pl/eli/acts/DU/2024/1221/text.pdf) - Sejm RP

Mateusz Widenka reviewed this entry. Ask how it applies to your project.

[Ask an engineer](https://ordergroup.co/contact-us/)

## FAQ

![Mateusz Widenka](https://ordergroup.co/media/images/T02DHCC1Z-U039G6G3JS1-8e7d2cd80ccb-512.format-webp.webp)

Mateusz Widenka

Head of Delivery

[Talk to an engineer](https://ordergroup.co/contact-us/)

### Do analytics and crash reporting SDKs in a mobile app need consent?

Analytics and attribution SDKs read or store information on the device and are not needed for the service the customer asked for, so under Article 5(3) of the ePrivacy Directive they wait for consent. In AvaFin's app crash reporting also waits for consent, following the client's legal team.

### How quickly does withdrawing consent have to take effect?

Withdrawal must be as easy as giving consent (GDPR Article 7(3)), and processing based on it must stop. In the app that means stopping the SDK in the current session.

### Is an iOS tracking prompt or a push permission the same as consent?

No. They are operating system permissions. The app still needs consent in the legal sense, recorded in the CMP or in the lender's system, and the two have to agree.

### Can a consent checkbox be ticked by default?

No. The EDPB states that pre-ticked opt-in boxes are invalid under the GDPR, so every consent starts empty and needs an action from the customer.

Building a system that depends on Consent management platform (CMP)?

See how we build software for this domain, with case studies and the stack we use.

[See Fintech Software Development Services](https://ordergroup.co/fintech-software-development/)

Requirements checklist

For each term we send the definition and what it requires from your software. Free, no sales call needed.
Your checklist is empty. Use the plus next to a term to add it.
