Introduction
The European CMP Association (ECMPA) is a Brussels-based non-profit association that gives the European CMP industry a unified, collective voice on consent infrastructure and data protection policy. It represents consent management platform providers across Europe and serves as the consent management sector’s voice with EU institutions.
A consent management platform is a tool that manages user consent, often through a cookie banner, and maintains consent logs for GDPR and other data protection laws across websites, apps, and connected devices. ECMPA focuses on Europe’s consent infrastructure as a whole: the technical, legal, and operational systems through which users interact with privacy preferences online.
Organizationally, ECMPA is independent, open to CMP providers and related privacy tech actors, and structured to engage directly with EU institutions and regulators. It is not a regulator itself, but an industry association that contributes operational expertise, real-world technical experience, and position papers into ongoing discussions around digital policy. The association emphasizes the importance of industry representation in regulatory discussions, ensuring that the people who build and run consent systems have a seat at the table.
Why the European CMP Association Was Created
ECMPA emerged in direct response to the European Union’s Digital Omnibus proposal-widely described as the most significant rewrite of EU consent rules since the GDPR started being enforced in 2018. The Digital Omnibus was published in November 2026 and introduced sweeping changes to how consent, cookies, tracking, and browser-level consent signals are regulated.
Before this, CMP providers-companies collectively serving hundreds of thousands of organizations and millions of users-lacked a single, coordinated association to represent their operational experience in Brussels. The European CMP Association was established on March 20, 2026, precisely as Articles 88a and 88b of the Digital Omnibus became central topics in data protection circles.
Several concerns drove ECMPA’s creation. Consent fatigue occurs when users tire of repetitive consent banners, leading to disengagement. At the same time, proposals for browser-level consent signals threatened to centralize Europe’s consent infrastructure in a few large, often non-European platforms. ECMPA also aims to bridge the gap between regulatory theory-legal texts drafted in committee rooms-and actual technical reality: how CMPs and cookie banners work at scale for European publishers, advertisers, and e-commerce brands.
- No coding required
- Works with all Shopify themes
- Blocks tracking before consent
- Google Consent Mode v2 ready
- Trusted by 180k+ stores
- 2,900+ 5-star reviews
- Google CMP Partner
Founding Members and Governance
ECMPA’s credibility comes from its founding members, who already operate large-scale compliance infrastructures for European users. Four major European CMP providers co-founded the association: Axeptio (France), Didomi (France), iubenda (Italy), and Usercentrics (Germany). These European players operate across the EU, the UK, and, in many cases, globally, and together support hundreds of thousands of businesses and millions of users. Pandectes is also a proud member of ECMPA, actively participating in the association’s initiatives to advance interoperable, GDPR-compliant consent management solutions throughout Europe.
ECMPA held its first general assembly on June 2, 2026, in London, where members formalized governance rules and appointed Romain Bessuges-Meusy, CEO and co-founder of Axeptio, as the association’s first President. The governance structure follows an association-style model, with a President, steering oversight, and working groups dedicated to topics like interoperability, legal positions, and technical standards.
Membership is open to the wider CMP ecosystem, including other consent platforms, consent assistants (such as browser extensions or AI assistants that act on user preferences), and related service providers that contribute to European consent infrastructure. The association is designed to grow as further engagement from the privacy tech sector takes shape.

ECMPA’s Mission and Core Pillars
ECMPA’s overarching mission is to make Europe’s consent infrastructure interoperable, user-friendly, and compliant with GDPR-level data protection-without concentrating control in a handful of gatekeepers. The association aims to unify Europe’s digital privacy consent infrastructure so higher standards benefit users, businesses, and regulators alike. It also aims to simplify compliance while preserving user rights.
The CMP association ECMPA actively participates in EU legislative processes: responding to European Commission consultations, engaging members of the European Parliament, and liaising with national data protection authorities. Its priorities group around several core pillars.
GDPR-Compatible, Contextual Consent
Under the GDPR, consent must be specific, informed, freely given, and tied to distinct purposes-analytics, advertising, personalization, and so on. GDPR mandates contextual, purpose-specific consent for data processing, and ECMPA promotes GDPR-compatible contextual consent models to ensure user privacy is never diluted.
ECMPA’s position is that browser-level or device-level privacy signals (like generic “do not track” style settings) cannot fully replace purpose-specific consent collected through a CMP on each website. The association warns against treating any single technical signal as a “magic consent” that would override detailed user choice at the site or app level.
The goal is to reduce consent fatigue not by weakening standards, but by designing smarter, interoperable systems so users don’t face repetitive cookie banners without understanding them. CMPs remain central tools for businesses, ensuring that consent logs are auditable and aligned with GDPR-even if the Digital Omnibus introduces new layers or signals.
Tech-Neutral Interoperability
Interoperable consent infrastructure means user preferences can move between browsers, wallets, CMPs, and services in a standardized, technology-neutral way. Interoperability lets user preferences move between services without friction and is crucial for a competitive digital ecosystem across Europe.
The ECMPA advocates for tech-neutral interoperability standards created or endorsed by recognized standardization bodies such as ETSI and CEN-CENELEC, rather than proprietary systems controlled by a few large vendors. Tech-neutrality means the law should not favor a specific technical solution-like browser signals only-but allow different compliant implementations to coexist and communicate.
ECMPA advocates interoperability to combat consent fatigue and aims to reduce it through both interoperability and standardization. The association envisions layered consent architectures in which CMPs orchestrate consent while integrating with browser APIs, wallets, or future standards, as long as they respect GDPR requirements.
European Digital Sovereignty
In practical terms, European digital sovereignty means Europe retaining meaningful control over how its citizens’ data is processed and who controls the underlying consent infrastructure. The association supports European digital sovereignty in consent technology, warning that if Article 88b or similar rules grant dominant browser vendors unilateral power over consent, much of Europe’s consent infrastructure could be centralized outside of European control.
ECMPA seeks to prevent single entities from dominating consent architecture. Instead, it aims to keep a diverse, competitive ecosystem of European CMP providers and privacy tech companies, supporting European publishers, e-commerce brands, and app developers across the continent. Preserving sovereignty supports innovation and competition in the European digital ecosystem, ensuring that businesses can choose among multiple CMP solutions instead of being locked into one browser-driven consent model.
The association sees itself as part of a broader European effort to combine high data protection standards with a vibrant, independent digital economy-a common framework where technology providers and regulators work together, not in opposition.
The Digital Omnibus: Why This EU Proposal Matters
The Digital Omnibus is the European Commission’s legislative package intended to modernize digital rules, including consent, advertising, and user choice online. For consent management, the Digital Omnibus proposals are widely seen as the biggest overhaul of EU consent rules since the GDPR-the proposal is the most significant rewrite since GDPR enforcement began in 2018.
The Digital Omnibus proposal directly addresses consent fatigue in Europe-the problem of users being overwhelmed and annoyed by constant consent prompts. Consent fatigue impacts user experience and compliance efforts alike, and the proposal tries to streamline UX while preserving data protection. The Digital Omnibus is a key focus of ECMPA’s regulatory advocacy.
The package includes specific provisions-Articles 88a and 88b-discussing browser- or device-level privacy settings, delegation of consent collection, and the future shape of Europe’s consent infrastructure. ECMPA has responded with detailed position papers and consultation responses, arguing for interoperable, layered consent that doesn’t undermine site-level control or the specificity that the European framework requires under GDPR.
Article 88b and the Battle Over Consent Fatigue
Article 88b is a focal point in the ongoing discussions because it explores delegating consent decisions from websites to browser vendors or similar gatekeepers. Under some interpretations, Article 88b could allow browser-level consent choices to override or replace website-level consent flows, potentially sidelining CMPs and consent banners on individual sites. Article 88b may conflict with GDPR’s specificity requirement, which demands that consent be tied to defined purposes and informed by context.
ECMPA’s primary objections center on three risks: concentration of control in a few global platforms (a single browser vendor could dictate consent for millions of users), unclear allocation of GDPR responsibilities and data accountability, and reduced transparency for users about where and how their consent is applied.
The association acknowledges consent fatigue as a genuine problem, but argues that solutions should be interoperable and privacy-protective-not simply centralizing power into a single layer like the browser. In a significant development, the Council’s revised compromise text of June 18, 2026 removed Article 88b entirely, though the matter remains unresolved as negotiations with the European Parliament continue.
For businesses, this debate means fewer but more meaningful consent prompts in the future, the potential use of persistent preferences, and the continued role of CMPs in logging and demonstrating lawful bases for data processing.

How ECMPA Engages With EU Institutions and Standards Bodies
ECMPA acts as the operational voice of the CMP industry in Brussels, offering regulators and lawmakers concrete evidence of how consent infrastructure works at scale. The association engages with EU institutions and data protection authorities to ensure that policy is informed by practical, on-the-ground experience.
The ECMPA submitted a joint response to the Digital Omnibus consultation in March 2026, and participates in follow-up discussions with Commission services. The association engages EU institutions on GDPR compliance and dialogues with members of the European Parliament, Council representatives, and national data protection authorities to refine legislative language and enforcement expectations.
ECMPA also helps shape technical standards for consent management by collaborating with standardization bodies like ETSI and CEN-CENELEC. These efforts support harmonized technical standards for consent signals, logs, and interoperability between browsers, CMPs, and other components of the European digital ecosystem.
One concrete ambition: the ECMPA aims to create a formal Code of Conduct under Article 40 of the GDPR, which would set industry-wide best practices for CMPs-potentially easing compliance for businesses adopting certified solutions. This collective platform would serve as a reference point for data protection authorities across Europe.
- No coding required
- Works with all Shopify themes
- Blocks tracking before consent
- Google Consent Mode v2 ready
- Trusted by 180k+ stores
- 2,900+ 5-star reviews
- Google CMP Partner
What ECMPA Means for Businesses, Publishers, and Shopify Merchants
What does the European CMP Association’s work mean in practice? If your company relies on a CMP to handle EU user consent-whether you run an online store, a media site, a SaaS platform, or an app-ECMPA’s advocacy directly affects your compliance landscape.
ECMPA’s work aims to keep consent rules predictable, standardized, and technically realistic, reducing the risk of sudden changes that would force costly, repeated implementation overhauls. For European publishers and SMEs, ECMPA’s stance on Article 88b helps protect their ability to implement purpose-specific consent flows tailored to their business models and monetization strategies.
Shopify store owners specifically should note: merchants using CMP tools-such as Pandectes’ Google-certified CMP and cookie banner solution-depend on clear, interoperable consent infrastructure to remain compliant with GDPR, ePrivacy, and related laws. Regardless of how the final Digital Omnibus text looks, businesses should expect to continue using CMPs for contextual, auditable consent, but potentially with new integrations for browser- or wallet-level preferences as standards mature.
Pandectes and Europe’s Consent Infrastructure
Pandectes sits squarely within Europe’s evolving consent infrastructure. As a GDPR compliance app for Shopify, Pandectes provides cookie banners, consent tracking, and Google-certified CMP features for merchants selling to EU customers.
Pandectes closely follows ECMPA’s work and the Digital Omnibus debates, because these developments influence how consent must be collected and demonstrated for EU, UK, and EEA visitors. With support for GDPR, CCPA, LGPD, and other global data protection frameworks already in place, adapting to a more interoperable European consent infrastructure through new standards or browser APIs is part of its long-term development roadmap.
Shopify merchants using Pandectes GDPR Compliance app can expect practical guidance and product updates when new consent rules or technical standards take effect, minimizing manual reconfiguration of their consent banners and consent logs. By using a dedicated consent management platform integrated with their Shopify store, merchants retain control and visibility over consent decisions, even as ECMPA and EU legislators refine the market architecture.
Conclusion
The Digital Omnibus is still moving through the European Union’s legislative process-Commission proposal, Parliament and Council negotiations, trilogues, and eventual implementation timelines. Much can still change, and both companies and their CMP providers must track these shifts.
ECMPA will likely continue publishing joint position papers, participating in industry roundtables, and working through its internal groups on interoperability, browser signals, and consent logs. One concrete goal is developing a shared technical framework for interoperable online consent across Europe, with ongoing discussions around APIs.
Businesses should anticipate multi-year transition periods once final rules are adopted, giving CMPs, browsers, and merchants time to adapt infrastructure, UX, and documentation. The long-term direction points toward fewer, higher-quality consent interactions and a more unified consent infrastructure. ECMPA’s role is to help ensure that solutions remain GDPR-compatible, business-friendly, and free from the control of any single entity-protecting user rights and industry innovation in equal measure.


