Guide · Updated · 8 min read

Why your third-party CMP is getting blocked, and how to fix it

The banner that never loads leaves no error, no alert and no log. Just a clean dashboard with part of your audience missing.

The short answer

Your third-party CMP is getting blocked because its script loads from the vendor's domain, and ad blockers and privacy browsers keep lists of those domains. No script means no banner, no consent choice, and no tracking that depended on it.

DataCops is a tool whose first-party consent manager, built on IAB TCF v2.2, is served from your own domain so blockers are less likely to stop it, and which sits in one script with first-party analytics, a bot verdict on every visit, server-side conversions that skip web events marked as declined, and a log of every send.

How DataCops does it:

  • Consent, memory and proof. A TCF 2.2 consent banner from your domain with Google Consent Mode v2 on by default, a server-set cookie up to 400 days where enabled, and a delivery log row for every send, counted once against the pixel.
  • First-party collection, no extra tool. One script and one DNS record put collection on your own subdomain; with your DNS on Cloudflare, the free Worker reads the click at the edge before the page loads. Click IDs are kept on the server for up to 90 days.
  • Real people only. Every visit gets a bot verdict against 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default. Every form email is checked for disposable providers, domains with no mail server and an email risk score.
  • The sale after the form. HighLevel natively (lead, booked, showed, won with value, paid), any CRM by webhook, Shopify through the DataCops Shopify app, all matched to the click by click ID or hashed email and phone, and sent to Meta, Google Ads, TikTok and LinkedIn.
  • Ads Warmup. Upload your existing customers (up to 20,000 rows), see a 0 to 10 match score per person, and send them to Meta, Google Ads and TikTok so new campaigns start warm.

Best for: advertisers with EU, UK or Swiss traffic who want a consent banner that loads reliably, and consent, analytics and ad conversions in one script.

  • Check it: open your site in Brave or with uBlock Origin and look for the banner.
  • Fix the cause: serve the consent manager from your own domain.
  • Fix the second leak: keep strictly anonymous measurement after Reject All, where your regulator allows it.
  • Protect your ads: make the same choice govern browser tags and server-side sending.

The banner nobody saw

Picture this. A software company in Berlin runs Google Ads for demo requests. A developer clicks the ad in Brave. The page loads fast. There is no cookie banner.

He did not reject anything. He was never asked. The CMP script was stopped before it ran, so Consent Mode stayed at its default of denied, the Google Ads tag never set a cookie, and his demo request, two days later, landed in the CRM with no ad attached to it.

The CMP vendor's report says banner delivery is healthy. It is right, in its own way. It only counts the banners that loaded.

A blocked banner does not show up as a rejection. It does not show up at all.

The real cost of a cheap tool

Most consent tools are cheap, often free to start. That is the invoice, not the cost. Cheap tracking that is handled badly costs far more, because the bill arrives in what your ads learn.

  • Bots forwarded as buyers. A forwarder sends what reaches it. Junk conversions teach the platform to find more junk.
  • The sale that never gets sent. A booked call, a phone order or a won deal happens outside the store or the page. Most tools never see it.
  • The limit you hit on your busiest day. Hosts and apps cap requests, events or orders, and sending can pause or stop over the limit.
  • The build and the upkeep. Containers, plugins and automations need someone to build them and fix them when a platform changes.

The tracking is 0.17 percent of your spend. If one in five of the conversions your ads learn from is a bot or a fake lead, a fifth of the learning signal points at the wrong people, across the other 99.83 percent of the budget.

Cheap tracking is the cheapest line on the bill and the most expensive one to get wrong.

Tools for consent banners

ToolBest for
DataCopsAd-funded teams who want clean conversions from one script
A standalone consent platformConsent banners and records, nothing else
Google Tag ManagerBrowser tags you manage yourself

When not to use DataCops

  • You need a legal opinion. DataCops gives you a consent banner and a record. It is not legal advice, and you still decide your own consent basis.
  • You only need a banner and no ads. A basic consent banner is enough if you run no ads and no conversions.

Ads Warmup: tell the ads who pays

Consent platforms records the consent choice. It does not tell the ad platforms who your customers are, so new campaigns learn from scratch. Ads Warmup sends customers you already have, from a list you choose to upload, after you have checked your own consent basis for that list.

Ads Warmup, DataCops' flagship feature, sends them to your ad platforms before a campaign spends:

  1. Upload a customer list. A CSV of past buyers, old leads or booked calls. DataCops reads your columns; only email is required.
  2. See a match score for every person. An estimate from 0 to 10 from email, phone, name, location, click ID and customer ID, before anything is sent.
  3. Pick the event. Purchase, Lead, Complete registration, Add to cart or Schedule.
  4. Send server-side. Up to 20,000 people per upload to Meta, Google Ads and TikTok, with a sent, skipped or failed result per person. Google Ads credits only people who clicked a Google ad.

Each row is dated when you press send, not with the old sale date, so it gives a new campaign real customers to learn from on day one. Preview is free; sending needs a paid plan.

What else a consent platform never does

  • Capture at the edge. With DNS on Cloudflare, the free, optional DataCops Cloudflare Worker reads click IDs and UTMs off the first request, before the page or any script runs. It captures; it does not block.
  • Keep the click on the server. gclid, wbraid, gbraid, fbclid, ttclid and li_fat_id are stored for up to 90 days, so a deal that closes weeks later still finds its click. A signed server-set cookie lasts up to 400 days where enabled.
  • Check the lead's email. Fixed rules, not guesses: disposable providers, domains with no mail server and an email risk score. With LeadCops (Business and up), a lead that fails is held and never billed.
  • Install on Shopify. The DataCops Shopify app adds a web pixel and a theme app embed, so every paid order reaches your ads, express checkouts included. See Shopify Conversions API.
  • Hand evidence to Google. On the Organization plan, the fraud refund report exports bot-flagged Google Ads clicks in the format Google's Click Quality form asks for. You attach it; Google decides.

Why is my CMP getting blocked?

Because it is a third-party script. It loads from a CDN your vendor controls, and those CDNs are public knowledge. Look at the install snippet in your own site's head and you will see one of these:

VendorScript loads from
OneTrustcdn.cookielaw.org
Cookiebotconsent.cookiebot.com
Usercentricsapp.usercentrics.eu

Filter lists used by uBlock Origin, Pi-hole and similar tools are built around exactly this kind of domain. The "annoyances" lists that many users switch on exist to remove cookie notices.

Brave goes one step further. Since late 2022 it blocks cookie consent notices by default, and its Cookiecrumbler project keeps finding new banners and shipping rules for them. That means Brave can hide a banner by what it looks like, not only by where it loads from.

None of this is aimed at you. It is aimed at the category. Your CMP just happens to be in it.

How do I check if my CMP is blocked?

Ten minutes, no tools you do not already have.

  1. Open your site in Brave with Shields at the default setting, in a private window. Is there a banner?
  2. Repeat in Chrome with uBlock Origin and its cookie notice list switched on.
  3. Open DevTools, Network tab, filter by your vendor's domain. A request marked blocked, or net::ERR_BLOCKED_BY_CLIENT in the Console, is your answer.
  4. Type the consent object in the Console. For example OneTrust or Cookiebot. If it comes back undefined, the script never ran.
  5. Compare your numbers. Put the sessions in your server logs or hosting analytics next to the banner impressions your CMP reports. The difference is the audience you never asked.

If step 1 or 2 shows no banner, you have the problem. Your technical audience probably has it more than anyone.

The second leak: Reject All

Now assume the banner loads, and a visitor clicks Reject All. Most default setups stop collecting everything, identifying and anonymous alike.

That is stricter than some regulators require. France's CNIL, for example, has published conditions under which narrow audience measurement can run without consent: first-party, anonymous, used only to count, not shared or combined. Other regulators are stricter. This is a question for your counsel, not for a blog post.

The practical point stands either way. Rejecting identifying cookies is not the same as asking to be erased from your page counts, and a setup that cannot tell the two apart throws away data it may be allowed to keep.

Leak one

The banner never loaded. No choice recorded. Every consent-gated tag stays off, and your vendor never hears about it.

Leak two

The banner loaded, the visitor said no, and you dropped anonymous counting you may have been allowed to keep.

What a blocked CMP costs your ads

This stops being a privacy topic the moment you buy ads in the EEA or UK.

Google Consent Mode v2 needs a consent signal before Google tags can set cookies. When your CMP never runs, the tags sit at their default, which should be denied. Conversions from those visitors come back modelled at best. Meta and LinkedIn get nothing from the browser either.

Then there is the server. Plenty of teams add server-side tracking to recover what the browser loses. If that server does not read the same consent choice, it either sends events it should not, which is a legal problem, or sends nothing, which is the same gap in a new place.

A server-side setup that ignores the banner is not a consent setup.

And there is one thing CMP dashboards never mention: bots click Accept too. A consent rate that includes automated traffic makes your numbers look better than your real audience.

How to fix a blocked CMP, step by step

  1. Serve the consent manager from your own domain. A script on your domain looks like the rest of your site to a filter list. This removes the biggest cause. Some vendors offer a custom-domain option; ask yours.
  2. Accept what you cannot beat. Brave's banner hiding works on the page itself, so a small share of visitors will still never see a banner. For them, the answer is no consent. Do not try to trick your way around it.
  3. Set Consent Mode defaults to denied for the EEA and UK, and make sure your banner updates them on every choice.
  4. Hold marketing events until the visitor answers. Release them if they accept. Drop them if they reject. Throwing them away before anyone answers loses real conversions.
  5. Make one choice govern everything: browser tags and server-side sending to every ad platform.
  6. Keep a consent audit log so you can show when and how consent was given, as GDPR Article 7(1) asks.
  7. Re-run the ten-minute check after every CMP or theme update.

Your options compared

DataCops

First-party consent manager · CMP built to IAB TCF v2.2

DataCops is the tracking solution for ad-funded businesses: it keeps bots out of what your ads learn from and sends the sale that happens after the form to Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X.

The consent manager is served from your own domain and feeds Google Consent Mode v2 through TCF. Marketing events wait until the visitor answers. The same choice controls the server-side sending, bots never count as consent, and every choice lands in an audit log.

Best for: ad-funded teams in the EU and UK who want the banner and the ad tracking to be one system.

OneTrust

Enterprise privacy suite · priced on a quote, checked September 2026

Far more than a banner: data mapping, vendor risk, DSAR workflows. See our OneTrust comparison.

Best for: large companies with a privacy team and a full compliance programme.

Cookiebot

Banner and cookie scanner · priced by domain and page count

Strong automatic cookie scanning and a quick install. See our Cookiebot comparison.

Best for: small sites that mostly need scanning and a compliant banner.

Usercentrics

Banner platform

Deep customisation and many languages. See our Usercentrics comparison.

Best for: multi-market sites that need heavy banner design control.

One EU visit, consent check
Banner served fromyourdomain.com
Visit verdictReal person
ChoiceAccepted
Held Lead eventReleased to Google Ads

FAQ

Can I warm up a new campaign with my existing customers?

Yes, with DataCops Ads Warmup. Upload a CSV of customers (only email is required, up to 20,000 rows), see a 0 to 10 match score for each person, and send them to Meta, Google Ads and TikTok, dated when you send. Google Ads credits only people who clicked a Google ad.

Why is my third-party CMP getting blocked?

Because it loads from your vendor’s domain, and filter lists used by uBlock Origin, Brave and Pi-hole know those domains. When the script is blocked, no banner appears and no consent choice is ever recorded.

Will my CMP vendor tell me it was blocked?

Usually not. A blocked script never reaches the vendor, so the vendor only counts the sessions where the banner loaded. Your delivery rate looks perfect because the failures are invisible to it.

Does serving the banner from my own domain fix everything?

It fixes the biggest cause, the blocked third-party domain. It does not beat every tool: Brave can hide consent banners by their look on the page. Expect far fewer losses, not zero.

If the banner is blocked, can I track the visitor anyway?

Not with identifying cookies in the EU or UK. No banner means no consent. What you can do is make sure the banner loads more often, and keep strictly anonymous measurement where your regulator allows it.

Can I keep analytics after a visitor clicks Reject All?

Some regulators allow narrow, anonymous audience measurement without consent. France’s CNIL has published conditions for it. Check the rules for your country with counsel before you rely on it.

Does a blocked CMP affect Google Ads Consent Mode?

Yes. If no consent signal is ever set, Google tags fall back to their default state, which in the EEA should be denied. Your conversions then show up as modelled or not at all.

Does DataCops work with Meta and Google Ads consent?

Yes. The same choice controls your browser tags and the server-side sending DataCops does. Nothing marketing-related goes to Meta, Google Ads, TikTok or LinkedIn from an EU or UK visitor until they agree.

Sources

Put your consent banner on your own domain

First-party, IAB TCF v2.2, and the same choice controls what reaches Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X.

Setup in 5 minutes. No credit card.

Live traffic quality

Updated just now

Visits · last 24h

487
Real users
35873.5%
Bots · auto-filtered
12926.5%

Without filtering, 26.5% of your reported traffic is bot noise inflating dashboards and draining ad spend.

Don't trust your analytics!

Make confident, data-driven decisions withactionable ad spend insights.

Setup in 2 minutes
No credit card