The Location Settings section enables you to set the behavior and default consent toggle values in your consent manager for a specific country or state to be compliant with a specific privacy regulation set by any country or state. Configuration set for granular locations will override the configuration for high-level locations.
Adding New Location Settings
To add a new location setting, follow these steps:
Open Location Settings
-
On the Configure Consent Manager page, scroll to the Location Settings section and click Add New Location Setting.
Configure the Experience Tab
-
In the Experience tab, select a Location: Region, Country, and States/Provinces from the dropdown lists.
Disclaimer: IP Address Geolocation is inherently less accurate at the state/province level than at the country level.
-
Select a Design from the dropdown list. A preview is displayed once a selection is made. To create a new design, click Add Custom and follow the steps in the design configuration here.
-
Enable the Set Consent Language checkbox and select a language from the dropdown list to ensure visitors from the specified location always see the consent manager in that language. The language must be added in Language settings before it can be selected here.
NOTE: If a language assigned to a location in the Set Consent Language setting is later removed, a warning is displayed indicating that the language will also be removed from the associated consent design.
-
Click Next to proceed to the General Settings tab.
Configure Default Consent
-
In the General Settings tab, select a Consent Model from the dropdown to define how consent is collected from visitors in the specified location. The consent model determines the overall consent behavior applied to this location setting.
-
Set the 2 Step Opt-In dropdown to Enable to require visitors to re-confirm their opt-in selection after updating their preferences.
-
Use the Default Consent field to set the default toggle state for each category when the consent manager first opens for a visitor. By default, the toggle states are set to No (Opt-out), which automatically opts users out in all categories. You can change the settings to Yes (Opt-in) or Deselected.
When the Deselected option is selected for the categories, there will be no toggle options pre-selected in the Overlay Panel, except for Required Category as it has a fixed "ACTIVE" toggle, meaning it always opts in.
-
Select Execute "Auto-block" to signal that this CCM instance should honor the TrustArc auto-block deployment for the specified region, country, or state. Before enabling this setting, ensure you have completed all steps in the TrustArc Auto-block Deployment Guide.
When Auto-block is enabled, the Default Consent settings control which category trackers fire by default. Setting a category to Yes opts it in by default under Auto-block behavior, including Functional Category trackers, until the visitor opts out.
Configure Browser Tracking Preferences
-
Select Recognize "Do Not Track" (DNT) to automatically opt visitors out of the configured cookie categories when a DNT browser signal is detected. Use the Opt-Out toggles to specify which categories are honored when a DNT signal is present.
NOTE: This setting requires either Auto-block to be enabled or CCM to be integrated with your site’s Tag Management System. See Settings for configuration details.
-
Select Recognize "Global Privacy Control" (GPC) to automatically opt visitors out of cookie categories based on their GPC browser preference. Use the Opt-Out toggles to specify which categories are honored when a GPC signal is present.
NOTE: This setting requires either Auto-block to be enabled or CCM to be integrated with your site’s Tag Management System. See Settings for configuration details. When both DNT and GPC are enabled, GPC takes precedence and is honored first.
Under Global Privacy Control Mechanism, select how the system should handle a website visitor’s existing or previous consent when a GPC signal is detected:
-
Apply & Ignore Previous Consents - When this GPC Consent option and the GPC browser signal are enabled, the system will execute the GPC flow when there is no existing consent.
- When users visit without consent, GPC consent will be applied.
-
When users visit with consent, the GPC will be ignored.
-
Apply & Override Previous Consents - When this GPC Consent option and the GPC browser signal are enabled, the system will execute the GPC flow when GPC has not been honored yet.
- When users visit without consent, GPC consent will be applied.
-
When users visit with consent, the system will check if GPC has been honored previously. If not, GPC consent will be applied.
Additionally, when DNT or GPC opt-out signals are detected, CCM Pro automatically logs these events for GDPR reporting purposes. No additional configuration is required.
Configure IRM Integration (Optional)
A separate Individual Rights Manager (IRM) license is required to enable this integration within CCM Pro.
-
If your organization uses IRM, select the IRM Integration tab to configure this setting. This allows you to embed IRM forms directly within the consent experience. When enabled, CCM Pro detects Do Not Sell or Share requests submitted through IRM forms and automatically updates the visitor’s consent state using the Auto Opt-out feature.
NOTE: IRM Integration is disabled by default.
-
Click the Add button to add the location settings.
NOTE: An error message is displayed when a user:
- adds an entry with the exact same values
- adds the same location with different experiences
- adds the same location with the same experiences but different default consent