Privacy

The Consent Gap on Your International Domains: Why the .mx Site Fails Where the .com Passes

By Rawsoft Team | August 2026 | 6 min read

The pattern that keeps showing up

Scanning this week surfaced it again, and it is always the same shape. The flagship .com has a consent management platform, fires Consent Mode correctly, and passes review. Then you load the regional site, the .mx or the .de or the .co.uk, and there is nothing. No banner. No Consent Mode signals. No way to reopen consent preferences, because there was never a consent to reopen.

Same brand, same logo, often the same campaigns pointing at it. Completely different consent posture.

Nobody chose this. It happens structurally. Regional sites get launched by a different team, on a different builder, on a different timeline. The .com went through the consent project two years ago; the regional site went live eight months ago through a local agency and never inherited any of it. There is no GTM parity, sometimes no GTM at all, and the tag stack is whatever the builder's marketing plugin injected. Then the compliance review happens, and it happens on the domain everyone thinks of as "the site." The regional domains are not in scope because they are not in anyone's head.

The result is a consent program whose coverage is defined by org chart, not by where your visitors actually are. And the domain most likely to serve EU or LATAM visitors with consent requirements is exactly the one that never got the treatment.

What Consent Mode has required since March 2024

This stopped being a best-practice conversation in March 2024. Since then, Google has required consent signals for ads features serving users in the EEA and UK: alongside ad_storage, Consent Mode v2 added ad_user_data and ad_personalization, and without those signals audience building and remarketing for those users degrade or stop.

Read that against the pattern above. Your .com sends the signals. Your regional domain, the one actually collecting the EU traffic, sends nothing. The campaigns pointing at that domain are the ones quietly losing audience data, and the loss does not show up as an error anywhere. It shows up as regional remarketing lists that never seem to grow, which someone will eventually blame on the creative.

And the compliance exposure is not smaller on the regional site just because the site is smaller. A missing banner is a missing banner. Whether the banner that does exist actually gates anything is a separate question, the one we walked through in Is Your Consent Banner Actually Blocking Anything?, but the regional domain usually fails before that question can even be asked.

The 10-minute inventory

You cannot fix domains you have not listed, and most teams have never produced the list. GA4 will produce it for you.

  1. Pull the hostname report. In GA4, add the Hostname dimension to any traffic report, or run an Exploration with Hostname as the row. This lists every domain that sends data to your measurement ID. It routinely contains domains the analytics team forgot existed, plus a few nobody can explain.
  2. Turn it into a domain list. Add the domains you know about that are NOT in the report, which is its own finding: a regional site absent from the hostname report either has its own measurement ID or no measurement at all. Either way you want to know.
  3. Scan each domain like a visitor. Fresh private window, ideally through a VPN endpoint in the region the site serves. Three checks per domain: does a consent banner appear before tags fire, do the Google requests carry consent state (look for the gcs and gcd parameters on the collect calls), and is there a control in the footer to reopen consent preferences after the banner is dismissed.

Ten minutes gets you through a handful of domains, and a handful is usually enough to find the gap. This is the same lesson consent keeps teaching: it does not travel across domain boundaries on its own, which is exactly what breaks hosted checkouts too, as covered in Your Checkout Is on a Different Domain. A consent program is only as wide as the domains it was actually installed on.

The three findings we see most

Fix order, and who owns what

The order matters because the later steps depend on the earlier ones, and the ownership matters because "everyone's job" is how the gap formed in the first place.

  1. Inventory first. The hostname pull and the per-domain scan above. Owner: whoever runs analytics. One afternoon.
  2. CMP on every domain that needs one. Regional builders vary in what they allow, so this is per-domain work. Owner: each site's web team, with the consent platform's config coming from whoever owns privacy centrally so the domains behave consistently.
  3. Consent Mode parity. Wire the signals the same way on every domain, ideally by bringing regional sites into the same GTM structure instead of hand-installing per builder. Owner: the tag management team.
  4. The reopen control. A footer link on every domain that reopens preferences. Small, visible, and the first thing an outside reviewer clicks. Owner: web team, same release as the CMP.
  5. Decide the measurement ID architecture on purpose. Shared property or per-region properties, either is defensible; undocumented drift is not. Owner: analytics lead, written down.
  6. Rescan on a cadence. The next regional site will launch the same way this one did, outside the stack. A domain scan that runs on a schedule is the only thing that catches it before a review does. Owner: whoever owns monitoring.

Coverage is the whole game

The .com passing review tells you the consent project worked where it was pointed. It tells you nothing about where it was never pointed. Regional domains launch outside the main tag stack, and nobody ever scans them, so the gap sits there until a regulator, a platform, or a curious customer finds it first.

The inventory takes ten minutes. Run it before someone else does.

Want the scan done for you? Run a free WPI scan across every domain in your portfolio, not just the one on the business card. Or book a Privacy Audit and we'll map the whole estate.

About Rawsoft

Rawsoft is an Atlanta-based digital data agency specializing in analytics implementation, privacy compliance, and media tracking for enterprise brands.

More from the blog

Privacy
Your Checkout Is on a Different Domain. Your Consent Record Did Not Follow It.

A consent cookie can't cross a domain boundary, so a hosted checkout starts from nothing. Why "not our domain" gets the responsibility test backwards.

August 2026 Read →
Privacy
Every US Privacy Enforcement Action So Far Comes Down to One Broken Link

Enforcement keeps landing on the opt-out: broken links, ignored GPC signals, and consent UIs that make declining harder than accepting.

July 2026 Read →