Vendor management is privacy management
Most “consent failures” are actually vendor-graph failures: a pixel nobody owned, on a purpose nobody mapped.

Processors, independent controllers, and joint controllers all show up in a modern tag inventory. Laws care about the distinction. Your scanner might only see a script URL.
A consent manager should list vendors, purposes, and contracts in one graph. When marketing adds a tool, it should fail closed until legal maps it.
Discovery first
Run regular scans. Compare discovered trackers to approved vendors. The gap is your real risk register.
Educational overview only — not legal advice. Confirm requirements with counsel for your products and markets.


