What does valid cookie consent require in the EU? Active choice. Under Article 5(3) of the ePrivacy Directive, storing or reading anything on a user’s device requires consent, and that consent takes its meaning from the GDPR: freely given, specific, informed, unambiguous, and expressed through active behaviour. The Court of Justice settled the floor in Planet49 in 2019: a pre-ticked box is not consent, and neither is silence or inactivity. Regulators have since built on that floor, and France’s CNIL fined Google €150 million and Facebook €60 million for banners that made rejecting harder than accepting.
For a diligence audience the interesting part is not the banner. It is what the banner feeds. Consented data is the raw material of the entire performance-marketing stack: the retargeting pools, the lookalike seed audiences, the analytics that attribution and bidding optimise against. A target whose banner would not survive scrutiny has not merely a compliance gap on its website; it has a marketing engine whose fuel was acquired on terms it may not get to keep. That accumulated dependence is best understood as debt, and this piece is about who collects on it.
This is the last of the GP3 pillar’s manufactured-input analyses, and it completes a set: the reference price manufactures the offer, the review base manufactures the trust, interface patterns manufacture the choice, and a non-compliant consent flow manufactures the audience itself.
The Mechanism
Consent gets manufactured the same way the other signals do, through design rather than through any single deceptive sentence:
- Asymmetric banners. A saturated accept button beside a grey “manage preferences” link that opens a second screen of toggles. Accepting is one click; refusing is a project. This is the exact conduct behind the CNIL’s headline fines.
- Consent assumed from motion. Banners that treat scrolling, continued browsing, or dismissal as agreement. Only active behaviour qualifies, and none of those is it.
- Fire first, ask later. Tags that load and cookies that set before the banner is answered, making the banner a decoration over processing that already happened. This one matters for diligence because it is directly observable from outside.
- Consent recorded, not honoured. The banner works, the refusal is logged, and the tags fire anyway, because nobody wired the consent signal into the tag manager. An implementation gap with the same practical effect as having no banner.
- Purchased and imported audiences. Consent debt can also be acquired second-hand, through list purchases and data-broker segments whose original consent chain nobody can produce.
Each variant produces the same asset: audiences and analytics that are larger and richer than valid consent would have delivered. The performance marketing built on them is correspondingly cheaper, and the P&L books the difference as skill.
Where This Sits in EU Law: A Settled Floor and Two Collectors
The floor is settled. ePrivacy Article 5(3) requires consent for device storage and access; the GDPR defines what consent means; and Planet49 forecloses the pre-ticked and passive variants. What remains genuinely variable is enforcement practice per member state, since ePrivacy is enforced nationally, and that variation has a consequence acquirers underrate: national authorities like the CNIL can act on cookie violations directly under national law, without the GDPR’s one-stop-shop routing through a lead authority. The French fines against Google and Facebook came through exactly that faster lane.
The regulator is the slower of the two collectors. GDPR-side exposure runs to 4% of worldwide turnover at the ceiling, and consent-banner sweeps have become routine regulatory work. But the process is still investigation-shaped: correspondence, findings, appeals.
The ad platform is the faster one. Since March 2024, Google’s Consent Mode v2 has been mandatory for advertisers targeting the EEA: tags must pass valid consent signals, and without them Google stops populating remarketing audiences and degrades measurement for those users. Google has since begun enforcing against non-compliant accounts, with personalised advertising and remarketing switched off rather than fined. This is the same pattern mapped in the marketplace piece: the platform protects its own regulatory position by policing its customers, through business logic rather than legal process, on the platform’s timeline rather than a court’s. A target’s consent implementation is no longer only a legal question; it is an operational dependency of its advertising accounts.
The Fake GM3 Problem, and the Part That Is Genuinely Different
The familiar mechanics first. Richer audiences and fuller analytics make performance marketing measurably cheaper: retargeting converts warm traffic, lookalikes extend it, attribution steers budget. If that richness rests on invalid consent, the target’s CAC is subsidised by data it should not have, and GM3 reads as marketing efficiency in exactly the way this pillar has documented three times before. When the consent flow is corrected, and post-close it will be, whichever of counsel, a regulator, or an ad platform moves first, opt-in rates fall, the pools shrink, attribution blurs, and the CAC the model was built on steps upward. The industry has already run this experiment at scale: the privacy-driven signal losses of the past five years have repriced acquisition for the businesses that depended on them.
The genuinely different part is what happens to the asset itself. A suppressed churn rate normalises; a fake discount stops; but unlawfully collected data is not merely a practice to cease, it is an asset that may have to be deleted. Where consent was invalid, the remedy regulators reach for includes erasure of what was gathered under it: the retargeting pools, the analytics history, the seed audiences. An acquirer pricing the target’s first-party data as an asset should price the scenario where part of it is a deletion obligation instead. Sizing that is counsel’s work per market; noticing that the scenario exists requires only reading the banner.
Why This Slips Through Due Diligence
Privacy diligence reads documents: the privacy policy, the records of processing, the DPA register. Those are usually in order, because they are written by lawyers describing what should happen. The banner and the tag firing order are implementation, owned by a marketing team and a tag manager, and no workstream diffs the two. Marketing diligence, meanwhile, takes CAC and audience sizes as inputs and audits neither for legal provenance; the better the retargeting performance, the less anyone wants to ask why the pools are so full. The gap is the same one this series keeps finding: the metric is examined, the mechanism that produced it is not.
What Outside-In Analysis Can Detect Before the Data Room
This exposure is unusually observable, because the consent flow runs in every visitor’s browser:
- Whether rejecting is as easy as accepting: one action against one action, or one action against a settings expedition
- Whether any consent is assumed from scrolling, dismissal, or continued browsing
- Whether tags fire and cookies set before the banner is answered, and whether a recorded refusal actually stops them: both visible in a browser’s network log on a single visit
- Whether the cookies actually set match what the privacy policy and the banner claim: a divergence is an indication that implementation and documentation have separated
- Whether the target’s ads stack still shows remarketing activity in EEA markets alongside a consent flow that could not be feeding valid signals, a tension in which one of the two facts has to give
- Review and forum language from the target’s own customers about tracking and spam, which occasionally surfaces list-buying no document will admit to
None of this establishes unlawfulness, which is an assessment for counsel and authorities against the specific facts and the relevant member states’ practice. What it establishes is how much of the target’s marketing efficiency depends on consent architecture, and which way the correction would move the numbers.
The Pre-LOI Question Every PE Fund Should Ask
Audience size and CAC arrive in the deck as achievements. Both are downstream of a banner nobody in the deal has looked at. The question that connects them: if the target’s consent flow were rebuilt to the standard the Court set in 2019, what share of its audiences would it have been allowed to build, and what does acquisition cost look like for the audience it can actually keep?
A target whose marketing runs on validly consented data owns its engine, and the efficiency is real. A target whose engine runs on consent debt is showing the buyer performance borrowed from data it may be ordered to erase, with two collectors, one regulatory and one commercial, already at the door.
This analysis is part of Tronvik’s GP3 Waterfall methodology, focused on GM3 marketing-efficiency mapping. Nothing in this article constitutes legal advice. To initiate an outside-in consent-architecture screen on a specific acquisition target, contact info@tronvik.com.