In development, not yet available to install
The rules of the place the visitor is in.
ConsentAlly is being built to detect the visitor's country and, in the United States, the state, and to apply the consent rules configured for that place: a prior-consent banner where the preset calls for one, an opt-out model where the preset uses that, and the right language, all from one published configuration.
Jurisdiction presets at launch
- GDPR and the ePrivacy Directive for the EU and the EEA.
- UK GDPR and PECR, including the cookie exemptions of the Data (Use and Access) Act 2025.
- The Swiss Federal Act on Data Protection.
- CCPA and CPRA for California, with an opt-out model and Global Privacy Control honoured.
- A hardened preset for California that asks before anything runs at all.
Each preset will set the banner type, the default state of each category, what Global Privacy Control means and how the decision is passed on. A store will be able to enable several and set region defaults on top; the first one listed will be the fallback for a visitor no preset matches.
How detection works
The visitor's location will be read from the request at the edge, where the configuration is served, and added to the response; nothing is looked up in the browser. The consent record will store the country and the region, so a store can show which rules applied to a decision. It will store no IP address and no personal data.
Languages
The banner's curated copy will cover the languages of the EU, the EEA and the UK, and a store will be able to override any string in any of up to 30 languages.
One configuration, every region
A store will publish once. Every published version will be numbered and kept, and a store will be able to roll back to an earlier one in a single step. The dashboard will be in English.
What it cannot do
Location is the network's location. A visitor on a VPN will get the rules of the place they appear to be in.