Consent management is the most European software category there is. iubenda is Italian. Usercentrics is German. Cookiebot is Danish, now owned by Usercentrics. Didomi and Axeptio are French. Complianz is Dutch. consentmanager is German.

The American players — OneTrust, Osano, Termly — are the exception rather than the rule. Europe wrote the law, so Europe built the tools.

But here is the thing worth more than any of the above: whether your banner actually blocks scripts before consent. A German CMP that fires Google Analytics on page load is exactly as non-compliant as an American one. Jurisdiction is the tiebreaker, not the criterion.

You have probably already switched

Every other page in our European alternatives series asks you to migrate away from an American incumbent. This one mostly does not, because the category never had one.

GDPR and the ePrivacy rules created the consent management market in Europe, and European companies built the products first. A business running iubenda, Cookiebot or Complianz has an entirely European consent stack and almost certainly never framed it that way.

Which makes this page shorter than it might have been. If you are already on one of the EU platforms below, this category is done — go spend the effort on email marketing or analytics, where there is a real transfer to remove.

Where each major CMP is based

PlatformHeadquartersStatusTransfer mechanism needed
iubendaBologna, ItalyEUNone
UsercentricsMunich, GermanyEUNone
CookiebotDenmark (Usercentrics-owned)EUNone
DidomiParis, FranceEUNone
AxeptioFranceEUNone
ComplianzNetherlandsEUNone
consentmanagerGermanyEUNone
CookieYesMilton Keynes, UKAdequate third countryNone — adequacy
EnzuzoToronto, CanadaAdequate third countryNone — adequacy
TermlyUnited StatesThird countryDPF or SCCs
OsanoAustin, United StatesThird countryDPF or SCCs
OneTrustAtlanta, United StatesThird countryDPF or SCCs
A note on our own recommendations. We rate CookieYes highly and it is UK-registered, not EU. The UK holds an adequacy decision renewed in December 2025, so this creates no transfer problem — but if your reason for reading this page is strict EU jurisdiction, iubenda is the one of our top picks that actually satisfies it. We would rather say that plainly than quietly let the distinction slide.

The EU-headquartered options

iubenda — Italy

Bologna-based, and the most complete European option for a small business: consent banner, lawyer-maintained privacy and cookie policies, and consent records in a single subscription. The policies update automatically as law changes, which is the part that ages badly when you write documents once.

If you want EU jurisdiction and one vendor for both consent and legal documents, this is the answer. Our full iubenda review covers where it is weaker — per-site pricing adds up across a portfolio, and there is more configuration than a first-time buyer expects.

Best EU-headquartered pick

iubenda

Italian, EU-hosted, lawyer-maintained policies and a banner that genuinely blocks scripts before consent. The strongest option if EU jurisdiction is a hard requirement rather than a preference.

Usercentrics and Cookiebot — Germany and Denmark

Usercentrics, founded in Munich in 2017, acquired the Danish Cookiebot in 2021 and now sells both. Together they are the enterprise-leaning European choice, strong on granular consent configuration, IAB TCF support and audit-grade consent logging.

Cookiebot's automatic cookie scanning is the feature small sites notice most — it crawls your site and generates the cookie declaration rather than asking you to maintain it by hand. Pricing scales with pages and subdomains, which can surprise larger sites.

Didomi and Axeptio — France

Didomi is the French enterprise player, focused on consent and preference management across web, apps and connected TV, and common among publishers and large media groups. Axeptio takes the opposite approach — a deliberately friendly, conversational banner design aimed at smaller businesses that resent how hostile consent UI usually looks.

Complianz — Netherlands

A Dutch WordPress-native plugin with a strong following, built around a configuration wizard that maps your actual plugins and services to consent categories. If you are on WordPress and want something that lives inside the CMS rather than as an injected third-party script, it is the natural fit. See our WordPress GDPR guide for how it compares in context.

consentmanager — Germany

Berlin-based, TCF-certified, and priced for mid-market sites. Less well known internationally than Usercentrics but a solid German option with strong multi-language support.

The adequate-third-country options

Two of the tools we recommend elsewhere on this site sit just outside the EU, and both are unproblematic from a transfer perspective.

Adequacy is a real legal status, not a technicality. Personal data flows to these countries on the same footing as within the EU. The one caveat is that adequacy decisions are periodically reviewed and can be withdrawn — which is the same structural risk as the US framework, at considerably lower temperature.

What matters more than jurisdiction

If you take one thing from this page, take this.

A banner that does not block is non-compliant regardless of where the vendor is incorporated. The most common failure in European privacy law is a consent notice that appears while Google Analytics has already fired. An EU-headquartered CMP configured badly fails exactly as hard as a US one.

The criteria that actually decide compliance, in order:

  1. Does it block non-essential scripts before consent? Not "does it show a notice". Test it with devtools and a fresh browser profile.
  2. Is rejecting as easy as accepting? Equal prominence. France's CNIL fined Google €150 million and Facebook €60 million in 2022 primarily over this.
  3. Does it keep consent records? You must be able to demonstrate consent. That means logs, with timestamps and what was shown.
  4. Does it support Google Consent Mode v2? Required in practice if you run Ads or GA4 on EEA traffic — see our guide.
  5. Can visitors withdraw consent later? A persistent link back to preferences.
  6. Then, and only then: where is the vendor based.

Our cookie consent tool comparison applies exactly this test, which is why the ranking there is not sorted by nationality.

What a CMP actually processes

Worth understanding, because it explains why jurisdiction ranks lower here than in other categories.

A consent platform typically stores a consent record — a timestamp, the choices made, the banner version shown, and usually a truncated or hashed IP address or a random identifier to tie the record to a returning visitor. That is personal data, so it needs a lawful basis and a data processing agreement. It is also a thin slice compared with what your email platform or office suite holds.

The practical implication: a US-based CMP is a smaller transfer exposure than a US-based CRM, and a smaller one again than a US-based office suite. If you are prioritising, this is not the category where the sovereignty argument pays off most — which is exactly what our priority ordering reflects.

How to choose

Your situationPick
EU jurisdiction is a hard requirementiubenda or Usercentrics
You want consent and legal policies from one vendoriubenda
Fastest setup, best free tierCookieYes (UK)
WordPress, want it inside the CMSComplianz (NL)
Shopify storeEnzuzo (CA)
Publisher needing IAB TCF at scaleDidomi or Usercentrics
You mainly serve US traffic and CCPATermly (US)

Frequently asked questions

Which consent management platforms are European?

Most of the significant ones. iubenda is Italian, Usercentrics is German, Cookiebot is Danish and now part of Usercentrics, Didomi and Axeptio are French, Complianz is Dutch and consentmanager is German. The main US players are OneTrust, Osano and Termly. Consent management is one of the few software categories where European vendors lead rather than follow.

Does my consent platform need to be EU-based?

No. A CMP processes consent records and some identifiers on your behalf, and a US or UK provider with a data processing agreement and a valid transfer mechanism is lawful. An EU provider simply removes the transfer from your records. Whether the banner actually blocks scripts before consent matters far more than where the vendor is incorporated.

Is CookieYes a European company?

CookieYes Limited is registered in the United Kingdom, in Milton Keynes, with a team working across the UK and India. The UK is not in the EU but holds a European Commission adequacy decision, so transfers to it need no standard contractual clauses. It is accurate to call it UK-based rather than EU-based.

Is Cookiebot still a Danish company?

Cookiebot was founded in Denmark and was acquired by the Munich-based company Usercentrics in 2021. It is still sold as Cookiebot by Usercentrics. Either way the ownership stays within the EU, so the transfer position is unchanged.

What matters more than where a CMP is based?

Whether it genuinely blocks non-essential scripts before consent is given. A banner that displays a notice while Google Analytics already fired is the single most commonly enforced failure in European privacy law, and it is equally broken whether the vendor is in Munich or Atlanta.

Is OneTrust a European company?

No. OneTrust is headquartered in Atlanta in the United States, though it has a substantial European presence and is widely used by European enterprises. Like other US processors it relies on Data Privacy Framework certification or standard contractual clauses for transfers.

Does switching CMP require new consent from visitors?

In practice yes, because consent records are stored by the platform and are rarely portable between vendors. Visitors will see the banner again after a switch. That is a minor annoyance rather than a compliance problem — and it is a good moment to check the new banner blocks properly before the first visitor arrives.

Related reading