From CCPA to GDPR: Managing Global Cookie Compliance with OneTrust
Run GDPR opt-in and CCPA opt-out on one OneTrust stack with geolocation rules, templates, GPC, Consent Mode, and a shared cookie inventory.
- Stack: Scan and categorise once (article 6), then branch UX and blocking by geo rule.
- GDPR / UK: Prior consent for non-essential cookies, Reject equal to Accept, Auto-Blocking or equivalent gating, consent logging.
- California / US state: Sale/share opt-out patterns, “Do Not Sell or Share” style links, GPC where required; not a copy of the EEA banner.
- India: Prepare DPDP notice and consent quality now; Rules timelines still matter (article 4).
- Default rule: Always define what happens when IP geolocation is unknown.
This is article 10, the closing piece of the Cookie Compliance series. Articles 1 to 9 covered the map, OneTrust setup, GDPR, DPDP, banners, audits, CMP vs manual, Consent Mode v2, and consent records. This article ties those parts into one multi-region operating model.
Why “one global banner” breaks
ePrivacy/GDPR practice for the EEA and UK expects prior consent before non-essential storage/access, with informed and freely given choice (EDPB Cookie Banner Taskforce themes; see article 3). California’s CCPA/CPRA framework emphasises notice and the right to opt out of sale or sharing of personal information, including for cross-context behavioural advertising, with Global Privacy Control recognition obligations under CPRA regulations. Those are different UX contracts. A single Accept-only EEA banner shown in California, or a California-only footer link shown to French users with ads already firing, creates the wrong legal shape in both places.
OneTrust’s geo model (how the product expects you to work)
OneTrust Cookie Consent uses reverse IP lookup (via Cloudflare, per OneTrust docs) to estimate visitor location roughly at city level. That location is used to select a geolocation rule; OneTrust states it is not stored for that lookup purpose beyond selecting the rule.
You configure:
- Templates for banner, Preference Center, and cookie list (OneTrust ships preconfigured templates for frameworks such as GDPR, UK GDPR, US National, US Multi-State, Colorado CPA, and others).
- Geolocation rule groups that hold multiple rules plus a default rule for when nothing else matches or IP is unknown.
- Assignment of a rule group to each domain, then script publish.
Consent model, template, Auto-Blocking, Capture Records of Consent, and Google Consent Mode mappings can differ per rule. That is the lever for CCPA vs GDPR on one stack.
Region playbooks (starting points, not legal opinions)
EEA (GDPR + ePrivacy national rules)
- Template: GDPR (or counsel-approved equivalent).
- Consent model: opt-in for non-essential categories.
- Equal Reject; no pre-ticked optional boxes (article 5).
- Block optional tags until grant (Auto-Blocking and/or GTM).
- Enable consent record capture (article 9).
- Consent Mode defaults denied for the four v2 ad/analytics signals until grant (article 8).
United Kingdom (UK GDPR + PECR)
- Use the UK GDPR template path OneTrust documents separately from EU GDPR where your tenant offers it.
- OneTrust’s UK GDPR CMP guidance emphasises Reject All, equal choice, user identifier display, UK geolocation, consent logs, and Auto-Blocking for non-essential technologies.
- Do not assume EU and UK rules stay identical forever; keep separate rules so copy and toggles can diverge.
California and broader US state privacy
- Prefer US National or US Multi-State / state-specific templates OneTrust provides (for example Colorado CPA) after counsel picks the coverage model.
- Surface sale/share opt-out and sensitive-data limits your counsel requires; wire “Do Not Sell or Share” style entry points that actually change tags.
- Honour Global Privacy Control as an opt-out signal where CPRA regulations require it; test that GPC changes the same backend flags as a click.
- Opt-out is not prior consent. Do not paste an EEA Accept/Reject modal onto California traffic just because it is convenient.
India (DPDP)
- Track Rule notice and consent timelines from article 4.
- Prepare itemised notice language and consent withdrawal that match DPDP quality, even if your geo rule is still evolving.
- Avoid treating “India” as “same as GDPR banner” without counsel; the statute and Rules are their own text.
Default / unknown geolocation
OneTrust requires a default rule in each group for unmatched or unknown IP cases. Decide with counsel whether unknown defaults to the strictest opt-in model, a notice-only model, or another approach. Document the choice. Republish after you change which rule is default.
Operating model on one domain
- Single inventory of cookies and tags (article 6), shared across regions.
- Shared category taxonomy so Performance/Targeting mean the same thing in every rule, even when UX differs.
- Rule matrix: region, template, consent model, blocking, Consent Mode map, record capture, owner.
- Publish discipline: Testing CDN first, then Production; never edit live rules without a rollback note.
- QA matrix: VPN or geo test accounts for EEA, UK, California, India, and “unknown”; Accept, Reject, GPC where relevant, Preference reopen.
- Change control: marketing pixel additions trigger rescan + rule impact review, not only a GTM publish.
What stays global vs what stays local
| Usually global | Usually per region |
|---|---|
| Cookie inventory and vendor list | Banner copy and legal links |
| Category definitions | Consent model (opt-in vs opt-out) |
| GTM container structure | Which categories are blocked pre-choice |
| Preference Center information architecture | Consent Mode default grant/deny |
| Rescan cadence | Record capture on/off |
Governance that survives the first year
- Name a privacy owner and a marketing ops owner; escalate counsel for new states or countries.
- Keep a living rule matrix in the same place as the inventory sheet.
- Revisit US multi-state templates when new state laws launch; OneTrust’s template catalogue already treats US Multi-State as a moving target.
- Do not let brand teams fork a second CMP “just for APAC” unless geo rules truly cannot express the need.
Series wrap: the ten-step stack
- Know the legal map (article 1).
- Install OneTrust in order (article 2) or choose manual carefully (article 7).
- Meet GDPR/ePrivacy and DPDP duties (3, 4).
- Design banners that are usable and lawful (5).
- Audit before you trust categorisation (6).
- Wire Consent Mode v2 for Google tags (8).
- Capture consent records (9).
- Run geo rules so CCPA-style and GDPR-style traffic each get the right model (this article).
None of these steps replaces counsel. Together they are the operational spine most teams skip until a questionnaire or a regulator letter arrives.
FAQ
Can one OneTrust domain script serve GDPR and CCPA?
Yes. That is what geolocation rule groups are for: one script, multiple rules, different templates and consent models by location.
Should unknown IP get the GDPR banner?
Many risk-averse teams default unknown to the stricter opt-in experience. Others choose differently. Make an explicit counsel call and write it on the rule matrix.
Is this series legal advice?
No. See the disclaimer below. Use the posts as an implementation checklist beside your own counsel and current OneTrust / Google documentation.
Sources and further reading
- OneTrust: Configuring Geolocation Rules; Getting Started with Cookie Consent; Adding, Editing, and Managing Cookie Consent Templates; Configuring the OneTrust CMP for UK GDPR (MyOneTrust).
- EDPB Cookie Banner Taskforce report (17 January 2023) for EEA banner expectations.
- Google Consent Mode and OneTrust integration docs cited in article 8.
- Series index: articles 1, 2, 3, 4, 5, 6, 7, 8, 9.
Series complete
This article closes the Cookie Compliance series on imraan.in. Revisit the stack when tags, regions, or laws change, and keep counsel in the loop before you flip production CDN switches.
Disclaimer
This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, privacy policies, or other privacy and data-protection controls. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.
Last updated on 11 September 2026
