Home / Blog / What your CMP contract should guarantee, and what it quietly doesn't

What your CMP contract should guarantee, and what it quietly doesn't

A consent management platform sells compliance, but its contract mostly guarantees delivery: the banner will load, the preference center will be available, uptime will hit a number. The legal risk stays with you. Before signing, know which guarantees are real, which are marketing, and which clauses actually matter when something goes wrong.

What the contract actually guarantees

Read a CMP master services agreement and you will find service levels about availability, support response times, and data processing terms. What you will not find is a guarantee that your site is compliant. The vendor delivers the tool; the configuration, the tracker inventory, and the category mapping are yours. If your banner collects consent and your tags ignore it, that is a configuration failure, not a vendor breach. No contract term changes that.

The clauses worth negotiating

The questions vendors dodge

Ask the vendor what happens when their script fails to load: does the site fail closed, blocking tracking, or fail open, tracking everyone? Ask how the banner behaves when their API is down. Ask who owns the default configuration the product ships with, and whether that default has ever drawn regulatory attention. The answers tell you more about your real exposure than any certification badge on the pricing page.

Compliance is a configuration, not a product

The uncomfortable truth is that two sites on the same CMP can have opposite compliance postures, because compliance lives in the setup: the categories, the blocking logic, the inventory. The contract buys you the machinery. The machinery only works if someone maintains it. Negotiate the contract well, but budget for the ongoing work of keeping the configuration honest. That is the part no vendor can sell you.

The renewal conversation

CMP contracts renew annually, and the renewal is when you have leverage. Come to it with data: how many consent-related incidents the past year produced, how the vendor's support responded, and whether any product change broke your configuration without warning. Vendors negotiate hardest on multi-year terms, so use the renewal to trade term length for the clauses that matter: change-notification windows, data export formats, and clearer indemnification around the vendor's own software failures.

Also use the renewal to reassess whether the product still fits. Consent needs change as the site changes: new markets bring new regulations, new vendors bring new categories, and a CMP that was right two years ago may be wrong now. The renewal conversation is the natural moment to ask whether the configuration still matches the site, whether the category model still matches the tracker inventory, and whether the vendor's roadmap covers the regulations coming next year. A contract renewal that only discusses price is a missed audit.

Documenting the configuration, not just the contract

Whatever the contract says, your real protection is the configuration record: the category definitions, the tracker inventory, the blocking-logic documentation, and the scan history. If a regulator ever asks questions, the contract shows you bought a tool; the configuration record shows you ran a program. Keep the two together. The contract gets filed with legal. The configuration record lives with the team that owns the site, updated every time the site changes, because a compliance story told from stale documentation falls apart on the first follow-up question.

Get a free consent audit of your website

Free consent audit