# Usercentrics

> Blocks every script on a website that requires consent, shows visitors a dialogue in which they choose, and files each decision with its timestamp and version in a log that can be downloaded.

- Vendor: Usercentrics GmbH, Munich, Germany
- Canonical URL: https://www.convios.com/en/toolbox/usercentrics
- Language version: https://www.convios.com/de/werkzeugkasten/usercentrics
- Area: Governance & security · Cluster: consent management
- Role: Off-the-shelf product · Origin: Established, AI retrofitted
- As of: 2026-09-02 · Reviewed: 2026-09-02 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Prevents falling behind: A consent platform wins no customers. Its absence costs some. Anyone wanting to serve personalised ads through Google's advertising products to users in the European Economic Area and the United Kingdom has needed a Google-certified platform connected to the Transparency and Consent Framework since 16 January 2024; without one, only non-personalised delivery remains. Alongside that sit section 25 of the German TDDDG for access to end devices and Article 7(1) GDPR for the record of consent. The benefit therefore stays one-sided. It prevents falling behind and creates no lead, because competitors buy the same banner from the same vendor. What separates Usercentrics from the rest is the place of jurisdiction. The company sits in Munich, the data processing agreement follows German law, and the servers are in EU member states according to the vendor. For a tool whose only purpose is proof towards a European supervisory authority, that weighs more than any feature list.

## Suitability by company size

- Solo: suitable — Getting started is cheap and the price is public. Below 1,000 sessions a month on one domain the platform costs nothing; above that the Essential plan starts at 7 euros a month for 1,500 sessions and a single legal regime. Anyone running a site with a contact form and one analytics tool is covered. The limit sits at the session count, because the pricing page states that the plan rises by itself under the terms once the number is exceeded.
- Mid-market: suitable — Here the number of domains decides. The Pro plan covers three domains and 15,000 sessions for 30 euros a month, Business ten domains and 50,000 sessions for 50 euros, each excluding VAT. A company with a main site, a careers site and two landing pages therefore sits in the middle of the price list. Two things are missing entirely up to this point: sign-in through the company's own directory service, and a second factor for access to the administration account. The comparison table of 2 September 2026 places both in the Corporate plan only, which is notable for an account holding the records of every consent the company has collected.
- Enterprise: suitable — The procurement checklist is largely served. A data processing agreement as an open document with standard contractual clauses and a named sub-processor list, storage in EU member states, plus ISO 27001:2022, ISO 27701:2019, SOC 2 Type 2 and TISAX level 3. The price for it appears nowhere. The Corporate plan starts at one million sessions a month and carries, instead of an amount, the instruction to approach sales. The same tier holds the approval chain before going live, bulk editing across configurations, the second factor and sign-in through the company's own directory service. Those are exactly the points without which a corporate group may not run such a platform at all, and every one of them hangs on the negotiated price.

## Vendor staying power

Established: Registered in the commercial register (Handelsregister) of the Munich local court (Amtsgericht) since 30 May 2018, and therefore eight years in market. In August 2021 Cybot ApS, the parent of Cookiebot, joined as a voting shareholder; in September 2021 the share capital rose from 65,408 to 152,112 euros. January 2026 brought an acquisition in New York. The contract documents are maintained: the data processing agreement carries version 3.1 of February 2026, and the attestations in the trust centre were renewed on 6 August 2026.

- Legal entity, registered office and representation: Usercentrics GmbH, Sendlinger Strasse 7, 80331 Munich, HRB 241272 at the Munich local court (Amtsgericht), VAT identification number DE318857096, represented by Donna Dror and Ea Luise Andersen (source: https://usercentrics.com/legal-notice/, as of 2026-09-02)
- Registration and shareholding position in the register: registered on 30 May 2018; share capital raised from 25,000 euros at founding to 164,960 euros most recently in December 2022; Cybot ApS a voting shareholder since August 2021, with Usercentrics A/S listed as parent (source: https://www.northdata.de/Usercentrics+GmbH,+M%C3%BCnchen/HRB+241272, as of 2026-09-02)
- Most recent acquisition: MCP Manager of New York, announced on 14 January 2026; no purchase price was disclosed (source: https://usercentrics.com/press/usercentrics-acquires-mcp-manager/, as of 2026-01-14)
- Renewal of attestations: SOC 2 Type II and HIPAA re-attested on 6 August 2026, ISO 27701:2019 since 27 October 2025, NIST CSF 2.0 since 10 February 2026; the vendor releases the reports only after a request form (source: https://trust.usercentrics.com/, as of 2026-08-06)
- Maintenance state of the legal documents: data processing agreement in version 3.1 of February 2026, 24 pages, with technical and organisational measures, the sub-processor list and the service description as annexes; the terms and conditions have applied since 21 August 2025 according to the site index, with earlier versions still retrievable (source: https://usercentrics.com/data-processing-agreement/, as of 2026-09-02)
- Documented court proceedings: On 1 December 2021 the Wiesbaden administrative court prohibited a university from embedding Cookiebot, because IP addresses were transmitted to Akamai servers in the United States (case 6 L 738/21.WI). The Hessian higher administrative court set the order aside on 17 January 2022, resting on the absence of urgency (case 10 B 2486/21). Cookiebot has belonged to the group since September 2021. (source: https://www.heise.de/news/Daten-in-die-USA-Hochschule-RheinMain-darf-Cookiebot-vorlaeufig-weiter-nutzen-6345246.html, as of 2022-01-17)

## Cost of leaving

Moderate: The data comes out. The consent log can be downloaded, and the switch itself is an exchange of the script in the page head. Two things the export does not carry. The first is the configuration: which of the more than 2,200 service descriptions were active, in which category, on which legal basis, under which version of the banner. A list of decisions without the text that was on screen when the decision was made carries little weight as a record under Article 7(1) GDPR. The second is whether the consents themselves carry over. Whether a consent given under the old banner still holds under the new one depends on purposes, service list and text staying unchanged. Where they differ, the question has to be put again, and the opt-in rate starts from scratch. Anyone anchoring their reach measurement to that rate loses comparability across the switch.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | public PDF, version 3.1 dated February 2026 — The agreement sits in the legal document library without any login and runs to 24 pages, with the technical and organisational measures as Annex 1, the sub-processor list as Annex 2 and the service description as Annex 3. Clause 7.1 of the terms and conditions provides for it as a separate document and gives it precedence in case of conflict. The published copy carries no signature; anyone needing a signed version for their files obtains it from the vendor. For Cookiebot the same vendor maintains a second, separate agreement. | evidenced | 2026-09-02 |
| Storage location | EU member states, mainly Germany and Belgium — Annex 2 of the data processing agreement lists Google Cloud EMEA Ltd. for the consent platform with the place of processing in the European Union. The trust centre is more precise and names statically hosted resources, application programming interfaces and databases in EU member states, mainly in Germany and Belgium. The storage location depends on no plan and costs nothing extra. For the server-side tracking add-on this does not hold in the same form; see the third-country point. | evidenced | 2026-09-02 |
| Subprocessors | two public lists with different contents — Annex 2 of the data processing agreement lists four processors with company, address, place of processing and purpose: Google Cloud EMEA Ltd. of Dublin for operations, Bunny Way d.o.o. of Medvode for delivery, Hetzner Online GmbH of Gunzenhausen for operations, and Cloudflare, Inc. of San Francisco for delivery in server-side tracking. On the same day the trust centre carries a different list of six entries, namely Google Cloud Platform, Microsoft Azure, MongoDB Atlas, Salesforce, Zendesk and Vanta, without country and without place of processing. Neither list contains the other. Under clause 6.1.1 the annex is the binding one, and the thirty-day objection period runs against changes to it alone. This divergence belongs on the table in contract negotiation. | partially evidenced | 2026-09-02 |
| Third-country transfer | transfer only with the server-side tracking add-on, basis assigned per recipient only in part — For Google Cloud EMEA Ltd. Annex 2 names the standard contractual clauses between Usercentrics and Google explicitly, points to a retrievable address and grounds this in the European Court of Justice judgment of 16 July 2020 in case C-311/18. For Cloudflare, Inc. of San Francisco the same annex gives the word global as the place of processing and names no basis of its own. That entry concerns the server-side tracking add-on alone; by the same list the consent platform stays inside the Union. Anyone booking the add-on settles this point before signing. | partially evidenced | 2026-09-02 |
| Training on customer data | no statement on model training, analysis of anonymised data permitted by contract — Clause 6.4 of the terms and conditions grants the vendor the right to create analyses from aggregated and anonymised customer data and to use them for product improvement, for the development of new products, for industry analysis and for anonymous benchmarking. No right to object appears at that point. On training models with customer content, the terms and conditions and the data processing agreement are silent in both directions. What is rated here is that silence, not a documented training practice. | partially evidenced | 2026-09-02 |
| Retention and deletion | 30 days after the contract ends, backups up to 6 months, consent log 12 months — Clause 11.1 of the data processing agreement obliges the vendor to hand over or delete within thirty days of the contract ending, at the controller's choice, and to submit a deletion protocol on request. Backups carry their own limit of no more than six months. Inside the product a third figure applies: the pricing page states that the consent log is accessible and downloadable for twelve months. Anyone who has to keep the record beyond that period exports regularly and files it themselves. | evidenced | 2026-09-02 |
| Certifications | ISO 27001:2022, ISO 27701:2019, SOC 2 Type 2, TISAX level 3, HIPAA — The trust centre names the standard and its version and states the scope as Usercentrics GmbH together with Usercentrics A/S, Usercentrics s.r.o., Usercentrics Inc. and Usercentrics Unipessoal. The renewal for SOC 2 Type II and HIPAA carries 6 August 2026, the ISO 27701:2019 certification 27 October 2025, and the TISAX result the year 2025. The certificates and audit reports themselves sit behind a request form and become visible only once the vendor grants access. ISO 27001 is additionally named openly on the pricing page. | evidenced | 2026-09-02 |
| EU AI Act, Article 50 | no statement on its own classification; no AI system faces visitors in the banner — The vendor maintains its own pages on the regulation on artificial intelligence and lists roles for AI engineering and AI governance in the trust centre. On its own obligations it says nothing there, neither about a classification nor about its role as provider or deployer. For the consent platform this has no consequence. No labelling duty under Article 50 of Regulation 2024/1689 arises here, because that provision targets systems that interact with people or generate content, and the machine translation of a self-written banner text falls outside it. Anyone booking the AI agent governance component acquired in January 2026 from the same account carries the classification of that deployment themselves. | partially evidenced | 2026-09-02 |
| Audit logging | consent log in all six plans, downloadable, twelve months — The comparison table on the pricing page places proof of consent in all six tiers, including free access. The log is held centrally, remains accessible for twelve months and can be downloaded as the history of individual users. Clause 10 of the data processing agreement adds the controller's rights to information and inspection, including on-site audits. Securing the administration account is a separate matter: by the same table, the second factor and sign-in through the company's own directory service appear in the Corporate plan alone. | evidenced | 2026-09-02 |

## Cost

- Entry: Free below 1,000 sessions a month on one domain. Above that, 7 euros a month for 1,500 sessions, 15 euros for 3,000, 30 euros for 15,000 across three domains and 50 euros for 50,000 across ten domains, each excluding VAT. From one million sessions a month the Corporate plan applies, for which the pricing page names no amount. (as of 2026-09-02)
- Where it gets expensive: Sessions. The session is the unit counted, and a returning visitor produces several a month. The pricing page states that the plan rises by itself under the terms once the limit is exceeded, so a campaign with four weeks of raised traffic lifts the running cost. The second threshold is the jump to Corporate, because that is where sign-in through the company's own directory service, the second factor, the approval chain before going live and bulk editing sit. No amount can be named for it, because the vendor publishes none for that tier.

## Three routes compared

### OneTrust, one module inside the privacy programme

OneTrust of Atlanta is the established counterpart, and Usercentrics sets itself against it on a dedicated comparison page. Corporates stay with it because consent is one module among many there. The record of processing activities, handling of data subject requests, vendor risk assessment and the whistleblowing channel sit in the same interface and under the same contract. Anyone whose legal department already works there buys no second vendor relationship with the banner and runs no second audit. The price is lock-in, because switching consent alone means breaking a piece out of a running programme.

### Ketch, consent steered by agents

No distinct class of AI-native consent management has formed yet. The furthest along is Ketch of San Francisco, founded in 2020, where by the company's own account agents inventory the connected systems, classify personal data down to individual fields, and read terms out of vendor contracts where questionnaires would otherwise be sent. The price gap is clear. Ketch charges 150 US dollars a month for up to 30,000 unique users and from 499 US dollars for up to 100,000, while Usercentrics covers 50,000 sessions for 50 euros. The units counted differ, so the amounts are not comparable one to one, though the order of magnitude is. What has to be given up is the German place of jurisdiction, the contract under German law and the attestations a European procurement department asks for.

### Build the banner yourself, but not the certification

The dialogue itself is little work. A script that loads tools only after agreement, a cookie for the decision and a table for the log come together with Claude Code or Cursor from this catalogue in one to two days; Supabase for the log and Cloudflare Pages for delivery are enough as building blocks. Reckoned at a 1,200 euro day rate that is 1,200 to 2,400 euros once and under 50 euros of infrastructure a month (estimate). Three points make the self-build fail anyway. Since 16 January 2024 Google has required a Google-certified platform connected to the Transparency and Consent Framework for personalised ads to users in the European Economic Area and the United Kingdom, and a self-built banner does not get that certification. The vendor maintains more than 2,200 service descriptions with purpose and legal basis and keeps them current, while a self-build adds every new service by hand. And the record has to carry the version of the banner under which consent was given; self-built logs regularly omit exactly that versioning, and it only shows up once a supervisory authority asks.

Recommendation by size:

- Solo: Take it: below 1,000 sessions a month the platform costs nothing.
- Mid-market: Buy it, and pick the session tier with headroom, or the plan rises by itself.
- Enterprise: Negotiate Corporate, and reconcile the two divergent sub-processor lists into one.

## Context

- Implements method: ["Context: Moat or Wall?" Test](https://www.convios.com/en/methods/context-moat-or-wall-test) — The test separates what creates an edge from what prevents falling behind, and a bought consent platform reliably lands on the second side when the question is played through honestly.
- Implements method: [Regulatory Density Test](https://www.convios.com/en/methods/regulatory-density-test) — The density of evidence duties decides whether the log, the second factor and the approval chain are add-ons or the condition of purchase, and that is exactly what the jump into the negotiated tier hangs on here.
- Implements method: [Geo Experiment / Matched-Market Incrementality Test](https://www.convios.com/en/methods/geo-experiment-inkrementalitaet) — As soon as some visitors refuse consent, user-level attribution falls away, and the effect of advertising spend can only be measured through matched-market tests.
- Alternative: Plausible Analytics
- Displaces: The banner from a plugin that nobody has touched since the law last changed, The assurance in the privacy notice that only necessary cookies are set, without anyone having counted the scripts that load, The record of consent that nobody can produce when it matters, because it was never kept

## Evidence

- Legal entity, registered office, register number, VAT identification number and management — https://usercentrics.com/legal-notice/ (as of 2026-09-02)
- Data processing agreement version 3.1 of February 2026: sub-processors with place and purpose in Annex 2, standard contractual clauses for Google Cloud, a thirty-day objection period, deletion within thirty days and backups within six months — https://usercentrics.com/data-processing-agreement/ (as of 2026-09-02)
- Clause 6.4 on the analysis of anonymised and aggregated customer data, and clause 7.1 on the separate data processing agreement taking precedence in case of conflict — https://usercentrics.com/terms-and-conditions/ (as of 2026-09-02)
- Prices per plan, session limits, automatic plan upgrade once limits are exceeded, the twelve-month consent log in every tier, and the second factor and directory sign-in in the Corporate plan alone — https://usercentrics.com/pricing/ (as of 2026-09-02)
- Attestations with standard, version and scope, server locations in EU member states mainly in Germany and Belgium, and the second sub-processor list of six entries — https://trust.usercentrics.com/ (as of 2026-09-02)
- Acquisition of MCP Manager of New York, announced on 14 January 2026, with no purchase price stated — https://usercentrics.com/press/usercentrics-acquires-mcp-manager/ (as of 2026-01-14)
- Google's requirement of a certified consent platform connected to the Transparency and Consent Framework for personalised ads in the European Economic Area and the United Kingdom since 16 January 2024 — https://support.google.com/adsense/answer/13554116 (as of 2026-09-02)
- The Wiesbaden administrative court order of 1 December 2021 concerning Cookiebot and its reversal by the Hessian higher administrative court on 17 January 2022 for lack of urgency — https://www.heise.de/news/Daten-in-die-USA-Hochschule-RheinMain-darf-Cookiebot-vorlaeufig-weiter-nutzen-6345246.html (as of 2022-01-17)
- Commercial register data on registration date, development of share capital and shareholding position — https://www.northdata.de/Usercentrics+GmbH,+M%C3%BCnchen/HRB+241272 (as of 2026-09-02)
- Published plans and user volumes of the AI-native counterpart Ketch — https://www.ketch.com/pricing (as of 2026-09-02)
