CMP Comparison

Does Osano Make You CCPA Compliant? An Audit View

Osano is a consent management platform, not a network-layer auditor. Here’s what it does well, and what it structurally can’t see.

What Osano does well

Osano built its reputation on a straightforward, transparent free tier for cookie consent banners, which made it a common first CMP for small and mid-market companies before they need enterprise features. It has since expanded into a broader "Data Privacy Platform" covering consent management, data mapping, and vendor risk assessment, aimed at teams that want privacy tooling without a large enterprise procurement process.

What Osano structurally can’t see

A CMP manages consent intent — the rules it’s configured with. It doesn’t verify what actually fires on the wire. These gaps aren’t unique to Osano; they’re structural to client-side consent management as a category.

Shadow pixels bypass the configured rule set

Osano's banner and blocking rules are built from the vendor list configured at setup. A pixel that starts sharing data with new third-party networks after that configuration isn't automatically added to the rule set, regardless of which CMP is managing consent.

Pixel piggybacking loads scripts the CMP never sees

A script Osano has categorized as approved can itself load additional third-party scripts, commonly through embeds like chat widgets or forms. Those nested trackers were never registered in Osano's configuration, so they were never categorized or blocked.

Server-side tracking is invisible to client-side consent tools

Osano operates in the browser. It cannot see traffic that a server-side tag manager or analytics pipeline sends directly, outside the page the CMP is running on. The dashboard can show a clean consent record while server-side data flows continue.

No independent verification that GPC opt-outs actually stop network traffic

Osano can be configured to recognize the Global Privacy Control signal, but recognizing the signal and actually halting every downstream request are different things. Verifying that outcome requires inspecting real network traffic after the signal is sent, something outside what a consent-management dashboard reports on itself.

Frequently asked questions

Does Osano make my site CCPA compliant on its own?

Osano helps you configure and publish the consent mechanisms CCPA/CPRA requires, including opt-out links and cookie categorization. It does not independently verify that every tracker on your site actually stops firing after a consumer opts out — that requires network-layer inspection, which is a different function than consent management.

Can Osano detect shadow pixels or piggybacked tags?

Osano scans and categorizes the vendors it's told about at setup and during periodic re-scans. Shadow pixels added after the initial install, and tags piggybacked inside another approved script, aren't part of that configured rule set until a fresh scan or an independent network-level audit catches them.

Does Osano catch server-side tracking?

No consent management platform that operates client-side, including Osano, can see traffic sent directly from your servers or a server-side tag manager. That traffic bypasses the browser entirely, so it falls outside what any CMP dashboard reports.

Should I replace Osano with an audit tool like Privisy?

No — they solve different problems. Osano manages consent collection, banner configuration, and vendor risk documentation. Privisy is an independent audit layer that verifies what's actually happening at the network level, including whether Osano's own blocking rules are taking effect in practice. Most teams run both.

Verify your Osano setup with an independent audit

Run a free, instant network-layer scan to see exactly what fires on your site, before or after consent.

Run a Free Scan