GDPR and ePrivacy: how OptinStack maps on
By OptinStack Team - Jun 28, 2026 - 1 min read
This article explains how OptinStack's features map onto the requirements of the GDPR and the ePrivacy Directive. It is written as a disclosure of what the platform does, not as compliance advice for your specific situation.
This is not legal advice. Whether OptinStack is sufficient for your obligations depends on your jurisdictions, the trackers you use, and your data flows. High-risk sections should be reviewed by a qualified advisor.
How OptinStack maps onto GDPR and ePrivacy
| Requirement | OptinStack behavior |
|---|---|
| Valid consent before non-essential storage or access | Pre-consent blocking gates trackers until the visitor accepts the relevant category. |
| Consent must be as easy to withdraw as to give | The preferences dialog lets visitors change or reset any category at any time. |
| Granular control over categories | Four fixed categories (necessary, analytics, marketing, preferences) each toggled independently. |
| Records of consent for accountability | Each choice is synced to the server with a timestamp and the GPC signal, and can be exported. |
Recommended banner mode
For audiences covered by the GDPR and ePrivacy, use the opt-in banner mode. Optional categories start as denied and trackers stay blocked until the visitor accepts.
Related articles
Basic vs Advanced Google Consent Mode
Compare Basic and Advanced Google Consent Mode, including tag loading, cookieless pings, GTM settings, verification, and when each mode makes sense.
Brand the banner and preferences dialog
Brand the banner and preferences dialog using dedicated tokens injected into the Shadow DOM.
Set up Google Consent Mode v2
Map OptinStack's four consent categories onto Google Consent Mode v2 and keep them in sync as visitors choose.
How helpful was this article?