OneTrust

OneTrust

Consent management and privacy compliance platform. The OneTrust script serves the cookie consent banner, records consent decisions, and conditionally blocks or allows other scripts based on user preferences. Also powers cookie audits, privacy preference centers, and data subject access request workflows.

Overview

OneTrust is a leading consent management platform (CMP) and privacy compliance suite used by enterprises to manage GDPR, CCPA, and global privacy regulation compliance. Its script serves the cookie consent banner, records granular consent decisions, conditionally blocks or activates third-party scripts based on category, and powers privacy preference centers, cookie audits, and data subject request (DSR) workflows. OneTrust is the consent infrastructure itself — not a third-party tracker.

What This Script Does

Consent Banner and Preference Center

  • Loads and renders the cookie consent banner or modal on first visit, configured by the site operator
  • Presents granular category controls: Strictly Necessary, Performance/Analytics, Functional, Targeting/Advertising
  • Fires the preference center when users click "Manage Preferences" or equivalent triggers
  • Stores user consent selections and preference timestamps

Script Blocking and Activation (Tag Manager Integration)

  • OneTrust integrates with Google Tag Manager, Adobe Launch, and standalone tag deployments to conditionally fire or block scripts based on consent state
  • Uses <script type="text/plain" class="optanon-category-C0002"> pattern to hold scripts until consent is granted for the relevant category
  • Dispatches custom JavaScript events (OneTrustGroupsUpdated, OTConsentApplied) so other scripts can react to consent changes in real time

Cookies Set

  • OptanonConsent — the primary consent record cookie; stores consented/rejected category codes, timestamp, and version string; first-party, 1 year
  • OptanonAlertBoxClosed — records that the banner has been dismissed; first-party, 1 year
  • OTGPPConsent — encodes consent in IAB Global Privacy Platform (GPP) string format for downstream systems
  • eupubconsent-v2 — IAB TCF v2.x consent string written to the TC String cookie for ad tech vendors
  • _oneTrustCDNDomainCheck — CDN availability probe, session

Script Files and CDN

  • Primary loader: https://cdn.cookielaw.org/scripttemplates/otSDKStub.js (or cdn.cookielaw.org variants)
  • Domain script: https://cdn.cookielaw.org/consent/<UUID>/OtAutoBlock.js
  • IAB TCF stub: loaded inline to ensure the __tcfapi function is available before any ad scripts fire
  • All assets served from OneTrust's Cloudflare-backed CDN (cdn.cookielaw.org)

Additional Features

  • Cookie scanning and auto-categorization (crawls the site to discover and classify cookies)
  • Data Subject Access Request (DSAR) portal for handling Article 15–22 GDPR rights requests
  • Vendor management and IAB TCF Vendor List integration
  • Consent audit log storage for regulatory record-keeping (Article 7(1) GDPR requirement)

Consent & Compliance

Consent category: Essential / Functional

OneTrust is the consent management infrastructure and is strictly necessary under GDPR. Article 7(1) requires that the controller be able to demonstrate that the data subject has consented — OneTrust fulfills this obligation by recording and storing consent decisions. The OptanonConsent cookie is the mechanism for honoring user privacy choices across sessions. Blocking it would make it impossible for users to exercise rights under GDPR Article 7(3) (withdrawal of consent) and CCPA's opt-out mechanisms. The IAB TCF stub must load before any advertising scripts to prevent unlawful processing.

Should You Block This Without Consent?

No. OneTrust is the consent management tool itself. It must always load first, unconditionally — blocking it would prevent the consent banner from appearing and remove the mechanism by which users exercise their privacy rights. It is strictly necessary infrastructure.

Is OneTrust GDPR compliant?

OneTrust typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So OneTrust can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads OneTrust, not on OneTrust itself.

Visit website

Consent Categories

Also Known As

onetrust CMPonetrust GDPRonetrust cookie bannerconsent management platformonetrust preference centeronetrust blocking

Industries

Programming and Developer SoftwareComputers Electronics and Technology

Tracked Domains (3)

OneTrust's trackers are common, seen on about 8% of the sites ConsentStack has scanned. Scan your own site to see which of these are firing before consent.

cookielaw.orgFunctional

cookielaw.org is a functional domain operated by OneTrust, used to run site features like chat, video, embeds, and preferences. Seen on about 8% of scanned sites.

onetrust.comFunctional

onetrust.com is a functional domain operated by OneTrust, used to run site features like chat, video, embeds, and preferences. Seen on about 7% of scanned sites.

cookiepro.comConsent

cookiepro.com is a consent domain operated by OneTrust, used to manage cookie consent and preferences. Seen on under 1% of scanned sites.

Cookies OneTrust Sets (2)

OptanonConsentEssential

OneTrust consent record storing the visitor's purpose-by-purpose decisions.

OptanonAlertBoxClosedEssential

OneTrust alert-box dismissal flag.

Frequently Asked Questions

Related Vendors

comScore
comScore
Audience measurement company providing digital and cross-media audience analytics. comScore scripts fire on publisher pages to measure audience size, demographics, and content consumption. Data is used by publishers to demonstrate reach to advertisers and by agencies for media planning.
Sovrn Holdings
Sovrn Holdings
Programmatic advertising platform and SSP for independent publishers. Sovrn Holdings scripts serve display ad units and participate in header bidding auctions. Also operates the Sovrn Commerce affiliate link monetization product.
Cloudflare
Cloudflare
CDN and network security infrastructure provider used to accelerate and protect websites. Scripts include the Cloudflare Turnstile CAPTCHA widget, Web Analytics (cookieless analytics), and Bot Management signals. Core CDN functionality operates at the network level, but challenge and analytics scripts do execute in the browser.
OpenJS Foundation
OpenJS Foundation
Open-source JavaScript module hosting CDN provided by the OpenJS Foundation. The jsDelivr and similar CDNs serve JavaScript packages globally. No behavioral tracking or advertising cookies are set by the CDN itself.
Google Fonts
Google Fonts
Google Fonts is a free font hosting service that serves hundreds of typeface families via a global CDN. Stylesheets and font files load from fonts.googleapis.com and fonts.gstatic.com to deliver web fonts to visitors. No advertising or tracking functionality is included.
unpkg
unpkg
Open-source JavaScript package registry served via CDN. The unpkg CDN delivers npm package files globally. No behavioral tracking or advertising cookies are set; access logs record standard request metadata.

Manage consent for OneTrust

ConsentStack automatically detects and manages OneTrust trackers so your site stays compliant with global privacy regulations.