The Velo journal

White label cookie consent for agencies: what actually matters

Guides·21 July 2026·The Velo team

White labelling cookie consent means your agency's brand on the banner and one dashboard for the whole roster, while somebody else's platform runs underneath. Every agency plan sells that, so the branding is not the decision. What separates them is governance: who is named on each client's consent record, whether the logs leave with the client, and whether the banner keeps their measurement alive.

What white labelling actually covers

Three layers, in rising order of effort. The banner itself, which takes your client's colours, logo and wording. The admin side, meaning the dashboard and the notification emails your client sees. And the domain the consent script loads from, usually a CNAME you point at the platform so nothing on the page carries a vendor name.

Everything in that list is presentation. None of it moves a legal duty, and the branding invites people to assume otherwise.

YOUR BRAND COVERS Banner design and copy Admin dashboard Notification emails The script domain STAYS WITH THE CLIENT Controller on the record The consent log history The privacy notice Regional duty Relabelling moves the logo. It never moves the accountability, and your client is still the one answering for it.
presentation, yours to changelegal position, theirs to keep
What white labelling actually moves. Everything on the left is presentation and every agency plan sells it. Everything on the right stays with your client whatever logo sits on the dialogue.

Your client is the data controller. They decide what is collected on their site and why, they answer to the regulator, and their name belongs on the consent record and in the privacy notice. You are acting on their instruction and the platform is acting on yours. Say that in writing at the start, because an agency that lets the logo imply ownership of the decision has taken on a liability nobody priced.

The consent log is the client's asset, not yours

Consent records are the evidence half of the job: who agreed to what, when, and under which version of the banner. Nobody asks about them in the demo, and then a client gives notice.

At that point they need their history. If the platform exports at account level rather than per client domain, your choice is between handing over a file containing your whole roster and handing over nothing. Both answers are bad, and you will be making that call under time pressure. Ask for a single domain export before you sign, in a format somebody else can open, and check the retention window while you are there.

The contract chain deserves the same attention. If the client buys from you, their processing agreement runs to you, and the platform sits behind you as a sub processor. That is a normal arrangement, but it means you need the sub processor list and you inherit the duty to tell clients when it changes.

One roster, several legal geographies

A client list is rarely one jurisdiction. In the EU and UK the model is prior opt in, so non essential tags wait for a positive choice. Across most US states with a comprehensive privacy law the model is an opt out, including the Global Privacy Control signal arriving from the browser before your banner has drawn anything.

So a single configuration copied across the roster is wrong for somebody. The regional rules have to live on the client domain rather than on your account, and the answer to whether a given client needs a banner at all genuinely differs between two clients you onboard in the same week.

The banner is the easy half. The tag stack is the tax.

Push a change once and it rolls out everywhere is true of the dialogue, and only of the dialogue. Behind each banner sits a different container, a different set of tags and sometimes a different server side setup, assembled by different people over several years. The consent signal has to reach those tags on every site, and no shared dashboard does that for you.

This is where the per client hours actually go, and it is worth quoting honestly. Budget the first client as a build and the rest as a template: our own agency partner work gets much faster after the first rollout, never instant. If you are pricing it, the reference point is what it takes to wire a banner through Google Tag Manager once, properly, with the verification step included.

What you are actually selling

Compliance is table stakes and your client assumes it. The deliverable they renew for is proof their measurement survived the banner, and that is the part every white label roundup leaves out.

Across Amplio Data client implementations we typically see around 34% of sessions hidden once consent is enforced, and 20 to 40% of the lost conversions recoverable when Consent Mode v2 and server side tagging are wired properly. Figures are measured ranges across Amplio Data client implementations, not a guarantee. Recovery depends on your traffic mix, regions and how your tags are configured. Put that number next to each client's name every month and consent stops being a line item they query. If you want the mechanism rather than the headline, we wrote up what happens to GA4 data when users reject cookies.

What to check before you put your name on it

  1. Confirm who is named on the consent record

    It should be your client, on every domain you run. Say it plainly in your own contract too, so the branding never gets read as a transfer of responsibility. A five minute conversation now, a very expensive one later.

  2. Ask for a per client export of the consent log

    Request an export for a single domain, in a format a lawyer or a successor agency can open. If the platform can only export at account level, you have a roster shaped problem the first time anyone leaves.

  3. Check that regional rules are set per domain

    A roster spread across the EU, the UK and the US does not share one banner configuration. The rules have to sit on the client domain, not on your account, or the first US client quietly inherits an opt in flow built for Europe.

  4. Match the pricing model to the shape of your roster

    Per visitor pricing suits a few large sites and punishes a long tail of small ones. Per domain pricing does the opposite. Only one of them fits what you actually run, so price your own retainer after you know which.

  5. Verify the consent signal reaches each client's tags

    Load each site with everything denied and watch what the tags receive. A branded dialogue that looks right while the advertising tags fire regardless is the most common failure we find, and it is invisible from the dashboard you are reselling.

  6. Decide what your monthly deliverable is

    Consent is thin as a line item on its own. Attached to a report showing what each client recovered, it becomes the reason the retainer renews. Pick that number before the first rollout and measure it from day one.

The short version

Branding is the cheapest thing on the list and the only one every vendor advertises. Judge an agency plan on where the consent record lives, whether one client's log can leave on its own, whether regional rules are set per domain, and whether anyone is checking that the signal reaches the tags.

Velo runs consent for a roster from one dashboard, with per client domains, roles and reporting, shipped under your brand with Amplio Data running the engine underneath, and a revenue share that does not climb with your clients' traffic. The details of that live on the agencies page.

Common questions

What should agencies look for in a white label cookie consent banner?

Past the branding, three things decide it. Ask who is named as controller on each consent record, because that stays your client and no amount of relabelling changes it. Ask whether the consent log exports per client domain rather than per account, which is what you will need the day a client leaves. And ask how the consent signal reaches each client's existing tags, because that is the work a shared dashboard cannot do for you.

Does white labelling a cookie banner make your agency the data controller?

Normally no. Your client decides what is collected on their site and why, so they remain the controller and their name belongs on the consent record and in the privacy notice. You are acting on their instruction, and the platform underneath you is acting on yours. Putting your logo on the dialogue changes the presentation, not the accountability, and it is worth saying so in writing before anyone assumes otherwise.

What happens to a client's consent records when they leave your agency?

They should leave with the client, which is only possible if the platform can export the log for one domain on its own. Where export runs at account level, your options are handing over a file that contains your entire roster or handing over nothing, and neither is acceptable. Check the export format and the retention window before you sign, not on the week somebody gives notice.

Can you resell cookie consent as an agency service?

Yes, and it works best inside a measurement retainer rather than as a licence you mark up. The banner alone is a commodity your client can buy in ten minutes. What they cannot buy is somebody confirming the consent signal reaches their tags and reporting each month on what the setup recovered.

Back to the journal

Stay compliant.
Recover the signal.

Add Velo once and get the banner, the regions, the audit log
and Consent Mode v2 working together, live in minutes.