
Sovereign consent at enterprise scale
Sovereignty only matters when it is in the DNA of your marketing infrastructure. Consent Studio is the Full Consent Stack with sovereignty built in, not bolted on. Custom-branded, expertly implemented, owned and operated under European law.
- 100% European-owned, no US parent and no US subprocessors
- Dedicated infrastructure with custom regional locations
- Named technical lead, RFI support, signed SLA options
Who runs consent on Consent Studio
Five kinds of organisation, each with a different reason for caring where their data lives and who can compel it.
Municipalities
Councils run dozens of sites: libraries, parks, citizen portals. One banner across all of them, one consent record behind it, and training for both council staff and the agencies who maintain the sites.
- Many domains, one account
- Agency training
Government and semi-government
Every consent logged and defensible under review. Launcher gives you sovereign tag management rather than sovereign consent alone, which is where most stacks still leak.
- 1M+ events monthly
- RFI questionnaires answered
Corporations
Web CMP carries your brand across every market, Launcher closes the tag-management gap, and Monitoring catches drift before an authority does. One platform for global marketing compliance.
- Every market, one brand
- Drift detection
Political parties, NGOs and charities
Sovereign European consent for organisations whose data is politically sensitive and whose budget is not enterprise. Article 9 categories are the norm here, not the exception.
- Special category data
- Budget-aware
Education
Schools, universities and research institutions, at pricing built for educational budgets and with the data-residency answers a research ethics board will ask for.
- Education pricing
- Residency answers
The expensive part is the part nobody can see
A consent stack fails quietly. Tags fire that nobody approved, measurement stops without ever throwing an error, and the record you need at review is the one that was never written. None of it raises an alarm, which is why it runs for months before anyone counts what it cost.
- Tags nobody approved
- Measurement that stopped quietly
- Consent you cannot produce
- An accept rate nobody optimised
The Full Consent Stack, For Enterprise
Three products, one consent record. Every plan carries all three; Enterprise changes what sits underneath them.
- Web CMPBespoke banner design, custom cookie prefixes and consent retention set to your own schedule.
- LauncherSovereign tag management with real-time APIs, self-hosted or on infrastructure dedicated to you.
- MonitoringContinuous scanning with advanced analytics, and an agreement behind the response time.
What Enterprise adds
Most CMPs handle consent capture and leak through the tag-management layer. These three are what close that gap.
Sovereign martech, end to end
Consent and tag management both move off US cloud. Launcher is European-owned and EU-hosted, or self-hosted, so nothing in the chain answers to a foreign disclosure regime.
Expert implementation
A named technical lead, custom integration help, dedicated onboarding and security-questionnaire responses. You are not left alone with a portal and a documentation site.
A branded consent experience
Not white-label, bespoke. The consent moment is the first thing many visitors see of your brand, and it should look like it belongs to you rather than interrupting you.
What the Enterprise agreement carries
Everything in Professional, plus what a standard plan cannot sign for. This is the list a security review asks for, gathered in one place instead of spread across a pricing table.
Infrastructure and residency
- Dedicated infrastructure
- Custom regional data locations
Contract and commercials
- A custom data processing agreement
- Your own purchase terms
- Shared liability
- Service level agreement options
- One consolidated agreement across every domain
- Negotiated pricing at high volume
Governance and audit
- Single sign-on
- Roles and permissions for your own teams
- Audit trails on every consent decision
- RFI, RFP and security questionnaire support
- Audit and DPIA support
APIs and integration
- Consent Log API
- Monitoring API
- Real-time APIs
- Custom integrations and bespoke work
Brand and configuration
- Custom themes
- Custom cookie prefixes
- Advanced analytics
Your team
- A named success manager
- Implementation guidance and training
Sovereign Infrastructure is our Normal
Storing data in Europe is not sovereignty. A provider owned elsewhere can hold your records here and still be compelled to hand them over, because the order follows the company and not the disk. Ours is European-owned end to end, and Europe is what you get without asking.

At Consent Studio, we enable businesses to process and store consent in their own region, without PII ever crossing any sea.
Where most consent stacks still leak
This is the argument procurement forwards to legal, so it is worth stating precisely rather than as a slogan.
The CLOUD Act reaches the company, not the disk
US authorities can compel data from US-owned providers regardless of where that data is physically stored. A US company hosting in Frankfurt is still a US company under a US order, which is why "EU hosting" on its own answers nothing. The question is who owns the provider.
Schrems II removed the paperwork answer
The CJEU invalidated Privacy Shield in 2020 and held that Standard Contractual Clauses cannot rescue a transfer where the destination allows access of that kind. The adequacy decision that replaced it in 2023 is under appeal at the Court of Justice. For a US-owned CMP or tag manager, that leaves an EU organisation relying on an arrangement whose two predecessors were both struck down, under GDPR Articles 44 to 49.
The leak is usually the tag manager
Most attention goes to the CMP, and most exposure sits one layer down. An EU-hosted banner in front of Google Tag Manager still loads GTM from US infrastructure before a visitor has chosen anything. Launcher replaces it with an EU-hosted tag manager, which is the part of this that is actually hard to buy elsewhere.
What Customers Say
Van Vulpen: the groundwork for solid online privacy compliance
As a large contractor, it is incredibly important for us to meet the expectations of our clients. Handling the privacy of all our stakeholders with care is part of that. The consent banner on our website plays a crucial role as the first impression of this.
Nathan den Breejen, Van Vulpen 

AdRock Marketing GmbH: seamless cookie consent setup
In our opinion, Consent Studio is the best cookie consent solution on the market. For agencies like us it's perfect, especially because of the fair pricing and easy setup. We've had significantly better experiences with Consent Studio than with other well-known alternatives.
Dennis Berse, AdRock Marketing 

Movisie: Dutch social knowledge institute chooses Consent Studio
Consent Studio is a very affordable alternative to the large, well-known providers. The contact is very pleasant. Requested adjustments are done quickly, and the overall implementation was very straightforward.
Wendy H., Movisie Fiterman Pharma: compliance across 15+ websites
We've implemented Consent Studio across over 15 websites, and it has made managing cookie consent so much easier. The multilingual support is a huge plus since we operate in different regions. The pricing is straightforward and cost-effective.
Valentin Acatrinei, Fiterman Pharma 
SB Supply: compliance across multiple storefronts
Our online shops operate in many European countries and it is important to us that we both comply to local regulations, but also that we offer the banner in all visitors' native languages.
Sander Berendsen, SB Supply 
Procurement questions
The ones that come up in every security review. If yours is not here, ask us directly.
We already run another CMP. What does migrating look like?
Your existing consent records come across rather than being discarded, and your tag configuration is rebuilt in Launcher before anything is switched over. The two run in parallel until you are satisfied, so there is no day on which consent is not being collected. Most of the work is ours, and the named technical lead who scopes it is the one who runs it.
Can I use the Consent Studio CMP with Launcher?
Yes, and it is what the stack is built for. Web CMP collects the consent and Launcher reads that same record before it fires anything, so there is no integration to configure and no second banner. That is the whole point of buying them together: with a CMP in front of a foreign tag manager, the tag manager loads before the visitor has chosen, and the consent you collected never reaches the thing it was meant to govern.
Can our own teams have separate roles and permissions?
Yes. Enterprise accounts carry roles and permissions, so the agency maintaining a site does not need the access your privacy officer has. If you run several brands or domains, they sit under one account with one consolidated agreement behind them.
Where do we find your DPA and your subprocessor list?
Both are linked in the footer of every page, and neither needs an account to read. If your legal team would rather work from your own template than ours, that is part of what an Enterprise agreement negotiates.
Does Consent Studio fall under the US CLOUD Act?
No. Consent Studio is owned and operated by Vallonic B.V., a Dutch company, with no US parent, no US shareholders and no US subprocessors. The CLOUD Act reaches US-owned companies; there is no entity in our ownership chain for it to reach.
How do you handle Schrems II?
By ownership rather than by contract. We do not rely on Standard Contractual Clauses to defend a transfer, because there is no transfer to defend: data stays inside the EU by default, on infrastructure operated by a European company under European law. That is a structural answer rather than a paperwork one.
What SLA options are available?
Custom service level agreements covering uptime, response time and incident handling, signed per contract. The specifics are set with you rather than picked from a tier, because a public body and a high-volume retailer need different things from the same word.
Can we self-host the consent layer?
Yes. Self-hosted deployment on your own infrastructure is available on Enterprise, as are dedicated infrastructure and custom regional locations if you would rather we ran it somewhere specific.
How is data residency enforced?
EU-only by default, with custom regional locations on request. Residency is a deployment decision here rather than a setting, so it is answered in the contract and reflected in where the infrastructure actually is.
Do you support custom modifications?
Yes. Custom modifications and bespoke solutions are part of the Enterprise agreement, including banner designs built to your brand rather than themed from a template.
What does implementation look like?
A dedicated customer success manager and a named technical lead. Kick-off workshop, staged rollout, integration support, and training for both your internal teams and any external agencies maintaining your sites.
Every consent: earned, honoured, proven.
Tell us what you are running and what you have to answer for. We will tell you honestly whether we are the right fit.
Prefer to see it first?
A walkthrough on your own domains, with the questions your security team will ask answered live rather than in a follow-up email.










