GDPR (EU & UK)
GDPR-ready consent, preferences, DSAR handling and record-keeping — for every property, every policy version, every audit.
The General Data Protection Regulation (and its UK equivalent) is now seven years old — but the enforcement bar keeps rising, and every year the number of adjacent frameworks that reference it grows. Gravito is the platform Nordic teams use to stay on the right side of that bar without turning compliance into an engineering programme.
What the platform gives you.
Every purpose in the CMP is tied to its legal basis — consent, contract, legitimate interest — and every event stored with which basis was invoked.
Deletion requests trigger real-time propagation to every downstream system, with an audit line to prove completion.
Portability requests generate machine-readable exports in seconds, in the format the requesting authority expects.
Purpose limitation and data minimisation enforced at ingest — the platform refuses to store what a legal basis doesn't cover.
What we hear from teams like yours
- Records of consent are stored but not queryable
- Withdrawal of consent doesn't reliably propagate downstream
- Every new market variant means a new banner and a new legal review
- Data-subject rights requests pile up faster than the team can process them
Freely given, specific, informed, unambiguous — and revocable.
GDPR sets seven conditions for valid consent — freely given, specific, informed, unambiguous, opt-in, granular, and easy to revoke. Gravito CMP ships with templates that pass every one of these by default, and refuses to configure banners that would fail them.
- ◆ Per-purpose granular consent — no bundling
- ◆ Opt-in only, no pre-ticked boxes, no dark patterns
- ◆ Revocation as easy as consent — same UI, same click count
The record-keeping regulators actually want.
GDPR Article 30 requires records of processing activities that most CMPs technically produce but no one can actually query. Gravito's audit trail is queryable — by data subject, by processing activity, by policy version, by date range — and export-ready in the format your DPA prefers.
- ◆ Records of processing activities as queryable data, not screenshots
- ◆ Every consent tied to the policy version live at the moment
- ◆ Export formats matched to EU and UK data protection authorities
Access, deletion, portability — as a workflow that closes on its own.
Data-subject rights requests flow through a workflow with automated verification, SLA tracking, downstream propagation and an audit trail. Your DPO sees the queue close on its own — with alerts only when a request is at risk.
- ◆ Automated identity verification before data is released
- ◆ Real-time propagation to every downstream system
- ◆ SLA alerts when a request approaches the statutory deadline
From setup to signal, in three steps.
- Step 1Configure your CMP
Choose the regime (GDPR, UK GDPR or both), pick your purposes and vendor list, and customise the banner to match your brand.
- Step 2Implement in your stack
Drop the script or SDK in your web, mobile and CTV surfaces. Compatible with Google Tag Manager, WordPress and every major analytics and ad stack.
- Step 3Collect and prove consent
Every consent event is stored immutably with the policy version that was live. Every DSAR flows through the workflow. Your audit trail builds itself.
What customers see
GDPR without the special-case engineering
Every European market has its regulator quirks. Gravito’s platform absorbs them so your engineering team doesn’t have to — and your compliance team sees a queue that closes on its own.
Where to start
Native consent for iOS, Android and CTV — one policy source across every surface, every store review passed on the first submission.
This is how to do cookie consent properly — a modular, enterprise-grade CMP with built-in identity resolution.
A self-service hub where your customers manage consent, preferences and data-subject rights — and your DPO watches the queue disappear.
Let's map it to your traffic
Bring a URL. We'll show you what changes.