Design an Enterprise Cookie & Consent Management Platform (CMP)
A Consent Management Platform (CMP)βsuch as OneTrust, Didomi, or Usercentricsβis a mission-critical compliance system that governs data privacy for enterprise websites and mobile apps. Under global privacy frameworks (GDPR in the EU, CCPA/CPRA in California, LGPD in Brazil), websites are legally prohibited from executing tracking scripts or dropping non-essential cookies without prior consent. The platform must evaluate regional legal policies at the CDN Edge in under 10 milliseconds, dynamically block third-party scripts, encode standardized IAB TCF v2.2 consent strings, and generate tamper-evident cryptographic audit trails to withstand regulatory audits.
1. Understanding the Problem
Functional Requirements
- Geo-Targeted Policy Evaluation: Automatically determine which legal jurisdiction applies based on user Geo-IP (e.g., EU requires strict opt-in prior consent; California requires opt-out; other regions require standard notification).
- Dynamic Script & Cookie Blocking: Intercept and block third-party analytics and marketing scripts (Google Analytics, Meta Pixel, TikTok) until user consent is granted.
- Standardized Consent Encoding (IAB TCF v2.2): Encode user consent into standardized binary strings (TC Strings) for advertising tech vendors.
- Cross-Domain Consent Sharing: Synchronize user consent across related subdomains and properties (e.g.
*.brand.com). - Tamper-Evident Audit Trail: Maintain an immutable, legally verifiable log of consent receipts (timestamp, IP, categories accepted, policy version) for up to 5 years.
Non-Functional Requirements
- Ultra-Low Edge Latency: Evaluating whether to show a banner must resolve in at the CDN edge so it does not degrade Core Web Vitals (Largest Contentful Paint - LCP).
- Extreme Availability: uptime. If the consent service fails, it must fail safe according to regional laws (e.g., default to blocking in EU, default to allowing in US).
- High Concurrency: Handle 100,000+ Requests per Second (QPS) across thousands of customer websites.
- Data Integrity & Non-Repudiation: Consent receipts must be mathematically tamper-proof using cryptographic hashing.
Capacity Estimations & Sizing (5 Years)
- Scale:
- Daily Global Pageviews Evaluated: 1 Billion pageviews/day.
- Peak Evaluation QPS: 50,000 to 100,000 QPS.
- Daily Consent Mutations (user clicks "Accept" or changes preferences): 50 Million actions/day 600 writes/second average.
- Storage Calculations (5-Year Audit Log):
- 50M consent records/day 365 days 5 years .
- Audit Record Size:
consent_id(UUID),user_pseudonym_id(UUID),geo_country(2B),policy_version(4B),purposes_accepted_bitmask(8B),sha256_signature(32B),timestamp(8B) 128 bytes. - Total Storage: .
- Easily stored in an append-only analytical store like ClickHouse, BigQuery, or Amazon QLDB!
2. The Set Up
Defining Core Entities
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β REGULATORY_POLICY β
ββββββββββββββββββββ¬βββββββββββββββ¬βββββββββββββββββββββββ€
β policy_id β VARCHAR(32) β PRIMARY KEY β
β jurisdiction β VARCHAR(16) β "EU_GDPR", "US_CCPA" β
β country_codes β ARRAY[CHAR(2)β ISO 3166 Country Listβ
β consent_model β ENUM β OPT_IN, OPT_OUT, INFOβ
β banner_required β BOOLEAN β Display UI Flag β
β vendor_framework β ENUM β IAB_TCF_V2, CUSTOM β
β policy_version β INT β Legal Rev Number β
ββββββββββββββββββββ΄βββββββββββββββ΄βββββββββββββββββββββββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β CONSENT_RECEIPT β
ββββββββββββββββββββ¬βββββββββββββββ¬βββββββββββββββββββββββ€
β receipt_id β UUID β PRIMARY KEY β
β user_token β UUID β 1st-party cookie ID β
β domain β VARCHAR(128) β "shop.example.com" β
β jurisdiction β VARCHAR(16) β "EU_GDPR" β
β accepted_purposesβ BIGINT β 64-bit Bitmask β
β tc_string β VARCHAR(256) β IAB TCF Encoded Base64β
β sha256_hash β CHAR(64) β Cryptographic Hash β
β prev_hash β CHAR(64) β Blockchain/Merkle Linkβ
β created_at β TIMESTAMP β Legal Audit Time β
ββββββββββββββββββββ΄βββββββββββββββ΄βββββββββββββββββββββββ
The API Design
1. Edge Policy Evaluation APIβ
GET /api/v1/consent/evaluate?domain=shop.example.com
CF-IPCountry: DE // Injected by Cloudflare / Edge CDN
Response (200 OK):
{
"jurisdiction": "EU_GDPR",
"consent_model": "STRICT_OPT_IN",
"banner_required": true,
"default_purposes": {
"necessary": true,
"analytics": false,
"marketing": false
},
"tcf_vendor_list_version": 142
}
2. Submit Consent Choiceβ
POST /api/v1/consent/submit
Content-Type: application/json
{
"user_token": "u_9481a829104",
"domain": "shop.example.com",
"accepted_purposes": ["necessary", "analytics"],
"rejected_purposes": ["marketing"],
"policy_version": 4,
"client_timestamp": 1727020800000
}
Response (201 Created):
{
"receipt_id": "rcpt_7a81094b",
"tc_string": "CP9481A09481AAACABENA...",
"audit_hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
"cookie_directive": "Set-Cookie: euconsent-v2=CP948...; Domain=.example.com; Max-Age=31536000; Secure; SameSite=Lax"
}
3. High-Level Design
Walkthrough of Core Flows
1. The Edge Evaluation Flow (Sub-10ms)β
- User visits
https://shop.example.com. - The request hits the Edge CDN (Cloudflare Workers / Fastly Varnish).
- The Edge Worker inspects the request headers:
- Evaluates the incoming 1st-party cookie
euconsent-v2. If valid, user preferences are already known page loads with no banner! - If cookie is missing, inspects the Edge Geo-IP header (
CF-IPCountry/X-Country-Code).
- Evaluates the incoming 1st-party cookie
- The Edge Worker matches the country against an in-memory Regional Policy Map stored in Edge KV (e.g. Cloudflare Workers KV):
- User in Germany (
DE) MatchEU_GDPRReturns config requiring strict opt-in banner. - User in California (
US-CA) MatchUS_CCPAReturns config with "Do Not Sell My Info" footer link.
- User in Germany (
- Injects the lightweight CMP Client Loader Script () directly into the HTML
<head>.
2. The Client-Side Script Blocking Flowβ
- Third-party tracking scripts on the page are marked with custom MIME types:
<script type="text/plain" data-consent-category="marketing" src="https://connect.facebook.net/en_US/fbevents.js"></script>
- The browser treats
type="text/plain"as raw text and does not execute it. - When the user clicks "Accept All" on the banner, the CMP SDK:
- Changes the script
typetotext/javascript, dynamically executing the tag. - Sets the
euconsent-v2cookie locally. - Dispatches an asynchronous Beacon
POST /api/v1/consent/submitto the backend.
- Changes the script
3. The Immutable Audit Trail Ingestionβ
- The consent submission hits the Consent Ingestion Gateway.
- Encodes the choice into an IAB TCF v2.2 Base64 TC String.
- Computes a SHA-256 Merkle Hash over the payload and writes the receipt to Apache Kafka.
- Stream workers append the receipt into an Append-Only Analytical Ledger (ClickHouse / Amazon QLDB).
4. Potential Deep Dives & Bottlenecks
Deep Dive 1: Geo-IP Regulatory Policy Engine at the CDN Edge
How do we evaluate privacy regulations without hitting origin database servers?
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β CDN EDGE GEO-IP EVALUATION β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β
β User Request βββΊ Cloudflare / Fastly CDN Edge Worker β
β β β
β βββΊ Reads `CF-IPCountry`: "FR" β
β β β
β βΌ β
β Edge Memory Key-Value β
β βββββββββββββββββββββββββββββββ β
β β "FR": GDPR Strict Opt-In β β
β β "US-CA": CCPA Opt-Out Only β β
β β "BR": LGPD Opt-In β β
β β "GLOBAL": Default Notice β β
β βββββββββββββββββββββββββββββββ β
β β β
β Latency: < 2ms! βββββββ β
β β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
- Edge KV Sync: The regulatory matrix (a few kilobytes of JSON mapping 240 countries and US state regions to policies) is replicated globally across all 300+ CDN edge datacenters. Zero origin database queries occur on page load!
Deep Dive 2: The IAB TCF v2.2 Compact Bitfield Encoding
How do ad tech networks (Google AdSense, Prebid, Criteo) read user consent in milliseconds without database queries?
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β IAB TCF V2.2 TC STRING BITFIELD LAYOUT β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β
β [6 bits] Version = 2 β
β [36 bits] Created Timestamp (Epoch Deci-seconds) β
β [36 bits] Last Updated Timestamp β
β [12 bits] CMP ID = 142 β
β [12 bits] CMP Version = 4 β
β [2 bits] Consent Screen ID β
β [24 bits] Special Purposes Bitmask β
β [N bits] Vendor Consent Bit Range (1000+ Ad Tech IDs)β
β β
β Result: Compact Base64 String: β
β "CP9481A09481AAACABENAYCgAAAAAEAAA..." β
β β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
- By packing hundreds of vendor consents and 10 legal processing purposes into a compact binary bitfield encoded as Base64, the entire consent state is passed directly inside HTTP Cookie headers and OpenRTB bid requests, requiring zero network lookups by downstream advertising platforms.
Deep Dive 3: Tamper-Evident Cryptographic Audit Receipts
When a privacy regulator (e.g. the French CNIL or Irish DPC) issues a formal inquiry demanding proof that a specific user consented to tracking on March 12:
Audit Block Structure:
Receipt N:
Payload: { User: U1, Domain: D1, Choices: [Analytics, Marketing], Time: T }
SHA-256 Hash = Hash(Payload + Prev_Hash) βββ
β Linked Hash Chain
Receipt N+1: βΌ
Payload: { User: U2, Domain: D2, ... }
SHA-256 Hash = Hash(Payload + Hash_N)
- Cryptographic Immutability: Each consent receipt incorporates the cryptographic hash of the preceding receipt, forming a Merkle DAG / Hash Chain.
- If a malicious insider modifies a database record in an attempt to retroactively forge consent, the hash chain breaks, immediately proving data tampering during legal discovery.
Deep Dive 4: Script Blocking Techniques (Network Interception vs DOM Rewriting)
How does a CMP prevent tracking scripts that are hardcoded into customer HTML from firing?
- MutationObserver (DOM Interception):
- The CMP loader script registers a
MutationObserveron the HTML document root before any other script runs. - When the browser's HTML parser attempts to append a
<script>tag matching known tracker domains (e.g.,google-analytics.com/analytics.js), the observer intercepts the node and changes itstypetotext/plain, preventing execution.
- The CMP loader script registers a
- Network Proxy / Service Worker:
- On progressive web apps, a Service Worker intercepts all outgoing HTTP requests; if an analytics request is made without a valid
euconsenttoken, the Service Worker aborts the fetch.
- On progressive web apps, a Service Worker intercepts all outgoing HTTP requests; if an analytics request is made without a valid
5. Architectural Trade-Off Matrix
| Design Alternative | Option A | Option B | Selected Choice & Rationale |
|---|---|---|---|
| Policy Evaluation | Origin Database Query | CDN Edge Worker (KV Cache) | CDN Edge Worker: Slashes evaluation latency from 150ms to ; protects Core Web Vitals (LCP). |
| Script Blocking | Manual Customer Code Integration | Automatic DOM MutationObserver | Automatic MutationObserver: Prevents tracking leaks caused by developer human error or third-party tag managers. |
| Consent Storage | Client-Only LocalStorage / Cookie | Dual-Store (1st-Party Cookie + Cloud Audit Log) | Dual-Store: Cookies provide instant zero-network reads for client scripts; cloud ledger provides non-repudiation during regulatory audits. |
| Audit Storage Engine | Standard Relational SQL (Postgres) | Append-Only Columnar TSDB (ClickHouse) | ClickHouse: 10x higher write ingestion throughput; columnar compression slashes 5-year audit storage costs by 80%. |
6. What is Expected at Each Level?
Mid-Level (L4 / IC4)
- Understands GDPR opt-in vs CCPA opt-out differences.
- Designs basic schemas for consent records and cookie categories (Necessary, Analytics, Marketing).
- Explains how cookies and LocalStorage store user choices in the browser.
Senior (L5 / IC5)
- Designs Edge CDN policy evaluation using Geo-IP headers to achieve sub-10ms response times.
- Explains third-party script interception mechanics (DOM
MutationObserverand MIME type manipulation). - Details the IAB TCF v2.2 binary bitfield encoding and why ad tech ecosystems rely on it.
- Implements asynchronous audit logging using Kafka and append-only datastores.
Staff+ (L6 / Principal)
- Evaluates cryptographic tamper-evidence (Merkle DAGs / SHA-256 hash chaining) for legal non-repudiation during regulatory investigations.
- Formulates cross-domain and cross-device consent synchronization architectures using first-party identity stitching.
- Designs fail-safe mechanisms ensuring that system degradation defaults to legal compliance (strict blocking in GDPR territories).
- Analyzes privacy-preserving analytics alternatives (e.g., Differential Privacy, Google Consent Mode V2 pings).
