CMP Comparison

Does Didomi Make You CCPA Compliant? An Audit View

Didomi is a consent management platform, not a network-layer auditor. Here’s what it does well, and what it structurally can’t see.

What Didomi does well

Didomi is an enterprise-grade consent and preference management platform with particularly strong adoption among publishers and media companies managing high-traffic properties across multiple regions and regulations. It gives privacy teams a centralized SDK-based configuration for consent rules, preference centers, and cross-property enforcement.

What Didomi structurally can’t see

A CMP manages consent intent — the rules it’s configured with. It doesn’t verify what actually fires on the wire. These gaps aren’t unique to Didomi; they’re structural to client-side consent management as a category.

Shadow pixels bypass the configured rule set

Didomi's SDK enforces the vendor list configured at setup. A pixel that starts sharing data with additional third-party networks after that configuration isn't automatically added to the enforcement rules, regardless of which CMP is in place.

Pixel piggybacking loads scripts the CMP never sees

A vendor Didomi has categorized and approved can load additional third-party scripts of its own, commonly through ad-tech or content embeds. Those nested trackers were never registered as a distinct vendor in the platform, so they were never categorized or blocked.

Server-side tracking is invisible to client-side consent tools

Didomi's SDK operates in the browser. It cannot see traffic that a server-side tag manager or analytics pipeline sends directly, outside the page the CMP is running on. Cross-property reporting can look clean while server-side data flows continue.

No independent verification that GPC opt-outs actually stop network traffic

Didomi can be configured to recognize the Global Privacy Control signal, but recognizing the signal and actually halting every downstream request are different things. Verifying that outcome requires inspecting real network traffic after the signal is sent, something outside what a consent-management SDK reports on itself.

Frequently asked questions

Does Didomi make my site CCPA compliant on its own?

Didomi helps you configure and enforce the consent mechanisms CCPA/CPRA requires across your properties. It does not independently verify that every tracker on your site actually stops firing after a consumer opts out — that requires network-layer inspection, which is a different function than SDK-based consent enforcement.

Can Didomi detect shadow pixels or piggybacked tags?

Didomi scans and categorizes the vendors it's configured to track at setup and during periodic re-scans. Shadow pixels added after the initial install, and tags piggybacked inside another approved vendor, aren't part of that configured rule set until a fresh scan or an independent network-level audit catches them.

Does Didomi catch server-side tracking?

No consent management platform that operates client-side, including Didomi, can see traffic sent directly from your servers or a server-side tag manager. That traffic bypasses the browser entirely, so it falls outside what any CMP dashboard reports.

Should I replace Didomi with an audit tool like Privisy?

No — they solve different problems. Didomi manages consent configuration and enforcement across your properties. Privisy is an independent audit layer that verifies what's actually happening at the network level, including whether Didomi's own blocking rules are taking effect in practice. Most teams run both.

Verify your Didomi setup with an independent audit

Run a free, instant network-layer scan to see exactly what fires on your site, before or after consent.

Run a Free Scan