Accessibility settings

Text size

100%

Fintech 5 min read

Consent management platform (CMP)

Also known as: CMP, consent management, consent management platform

Definition

A consent management platform (CMP) is software that asks users for consent, records each decision per purpose, and tells the app or website which tools may run. In the EU it implements the consent rules of the GDPR and of Article 5(3) of the ePrivacy Directive.

Cite this entry

Text

"Consent management platform (CMP)". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/consent-management/

HTML

<a href="https://ordergroup.co/glossary/consent-management/">Consent management platform (CMP)</a> - Order Group
Consent rules and what they require from a lending app
RuleSourceWhat the system needs
Consent is an affirmative act; pre-ticked boxes are invalidGDPR Art. 4(11); EDPB Guidelines 05/2020Empty defaults covered by a regression test
Controller can prove consentGDPR Art. 7(1)Record per consent: name, text version, status, time of change
Withdrawal as easy as giving consentGDPR Art. 7(3)Consent screen in the profile; SDK stops in the current session
Device storage and access need consent unless strictly necessaryePrivacy Art. 5(3); Polish PKE Art. 399SDKs off natively at launch, switched on after the CMP decision
Service not conditional on consent it does not needGDPR Art. 7(4)Loan application that can be completed without marketing or analytics consent
Commercial information sent with terminal equipment or automated calling systems needs prior consentPolish PKE Art. 398Separate marketing consents per channel in the core system

Rules and regulation

The GDPR has applied since May 25, 2018. Article 5(3) of the ePrivacy Directive is applied through national law, so a lender in Poland follows the Electronic Communications Law (Prawo komunikacji elektronicznej, PKE) of July 12, 2024, in force since November 10, 2024. Article 399 transposes Article 5(3): storing or reading information on the user's device requires prior information and consent, except where it is necessary for transmission or for a service the user requested. Article 398 bans the use of automated calling systems and telecommunications terminal equipment, in particular through interpersonal communication services, to send commercial information, including direct marketing, unless the user has consented beforehand. Consent may be given by providing an e-mail address for receiving commercial information at that address. Article 400 applies the data protection rules to obtaining that consent.

The EDPB's Guidelines 05/2020 on consent, adopted on May 4, 2020, explain granularity per purpose, pre-ticked boxes, cookie walls and withdrawal. Its Guidelines 2/2023, adopted in final form on October 7, 2024, set out which techniques fall under Article 5(3). They build on Opinion 9/2014 of the Article 29 Working Party, which had already placed device fingerprinting within Article 5(3), and they cover unique identifiers, tracking pixels and code that runs on the device. In November 2025 the European Commission proposed a Digital Omnibus that would, among other things, change the GDPR and the consent rules for storing and reading information on devices. As of October 2026 the proposal is still being negotiated, so the rules above apply.

From our projects

The app we have built for AvaFin Poland since January 2026 handles App Tracking Transparency on iOS, a CMP that decides about each SDK separately, and the consents stored in AvaFin's system. In September 2026, following requirements from AvaFin's legal team, we switched Firebase Analytics and Crashlytics off natively on both platforms. They are switched on only after the app reads the CMP decision. Because the crash reporting setting persists, crashes at startup are reported for consenting users from the second launch. On iOS the flags went into the app's property list file, because the shared configuration file was not read there. When the customer withdraws consent, the AppsFlyer attribution SDK stops sending data in the same session and resumes when consent is given again. If the CMP never reports a decision, everything that depends on consent stays off.

The consents in AvaFin's system are versioned records grouped into marketing consents (e-mail, SMS, phone and the customer panel) and app consents (analytics and push marketing). A separate consent for marketing push notifications was added in August 2026, and switching push on now triggers the system permission dialog. The same month the information clause was removed from the list of consents.

In Aasa24, the lending app we have developed for Aasa Polska since May 2023, analytics starts only after consent. In November 2024 the single phone marketing consent was split into separate SMS and phone call consents. In August 2026 the app got new marketing consents for partners on the last step of the application, and customers can now manage their marketing consents in the customer profile.

Sources

  1. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 4(11) and 7 - EUR-Lex
  2. Directive 2002/58/EC on privacy and electronic communications (ePrivacy Directive), Article 5(3) - EUR-Lex
  3. Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1 - European Data Protection Board
  4. Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive, version 2.0 - European Data Protection Board
  5. EDPB-EDPS Joint Opinion 2/2026 on the Digital Omnibus proposal - European Data Protection Board
  6. Ustawa z dnia 12 lipca 2024 r. - Prawo komunikacji elektronicznej (Dz.U. 2024 poz. 1221), art. 398-400 - Sejm RP

FAQ

Mateusz Widenka
Mateusz Widenka
Head of Delivery
Talk to an engineer
  • Analytics and attribution SDKs read or store information on the device and are not needed for the service the customer asked for, so under Article 5(3) of the ePrivacy Directive they wait for consent. In AvaFin's app crash reporting also waits for consent, following the client's legal team.

  • Withdrawal must be as easy as giving consent (GDPR Article 7(3)), and processing based on it must stop. In the app that means stopping the SDK in the current session.

  • No. They are operating system permissions. The app still needs consent in the legal sense, recorded in the CMP or in the lender's system, and the two have to agree.

  • No. The EDPB states that pre-ticked opt-in boxes are invalid under the GDPR, so every consent starts empty and needs an action from the customer.

Building a system that depends on Consent management platform (CMP)?

See how we build software for this domain, with case studies and the stack we use.

Requirements checklist

For each term we send the definition and what it requires from your software. Free, no sales call needed.

Your checklist is empty. Use the plus next to a term to add it.

    Order Group sp. z o.o. (Warsaw) uses your e-mail to send the checklist (Art. 6(1)(b) GDPR) and keeps a record of the request (Art. 6(1)(f) GDPR). Marketing consent is optional and can be withdrawn at any time. Read the Privacy Policy