Choosing a KVKK & GDPR-Compliant Consent Management Platform for Corporate Websites and Holding Groups
How holding companies, banks, insurers, energy and manufacturing groups should select a cookie consent management platform for multi-brand, multi-country website portfolios: multi-domain management, audit reports, Türkiye data residency, agency access and procurement criteria.
In short
Choosing a CMP for a corporate portfolio differs from choosing one for a single site: dozens of brand, subsidiary and country domains must be managed from one dashboard; legal, marketing and IT need separate permissions; every consent must convert into an audit report; data must be hostable in Türkiye; and procurement needs a DPA, security questionnaire and SLA. Cookietrace covers up to 100 domains on Premium ($79/mo) and offers an Enterprise contract with Türkiye data residency.
- Cookietrace Privacy Engineering Team — Published 2026-09-12 · 9 min read
Why consent management is different at corporate scale
A holding group's web presence is a portfolio of 10 to 100 domains: the corporate site, subsidiaries, brand microsites, careers and investor relations pages, country editions and campaign domains. Some are run by agencies and sit on different CMSs. At this scale consent is a governance problem, not a banner problem.
- Portfolio visibility: per-site reporting during an authority review requires central knowledge of every domain
- Allocation of responsibility: each domain must be attached to the correct legal entity
- Agency and vendor risk: one pixel added by an agency exposes the whole group
- Audit expectations: internal audit and independent auditors want consent proof in report format
- Procurement: a group contract, DPA, security questionnaire and SLA instead of single-site licences
Eight criteria for evaluating a corporate CMP
Multi-domain management, role-based access, audit reporting, data residency, separate EU rule sets, Consent Mode v2 and TCF, extensibility to new obligations, and local support with an SLA.
- All domains in one dashboard with a central banner template and per-domain exceptions
- Role-based access for legal, marketing, IT and agencies
- Consent rates and integrity-proofed records exportable for audits
- Türkiye data residency aligned with KVKK Article 9
- GDPR/ePrivacy rule sets, TCF v2.2 and local languages for EU subsidiary sites
- Consent Mode v2, TCF v2.2 and group-wide GTM compatibility
- Room to extend to EU AI Act Article 50 transparency duties from 2 August 2026
- Turkish-language support, DPA, security questionnaire answers and an SLA
Additional sector expectations
Banking and insurance need strict classification on payment and customer portals plus data residency. Energy and manufacturing groups need multi-country subsidiary structures and minimal cookies on investor relations pages. Retail brands need per-brand banner design and fast onboarding of campaign domains. Health and education need restricted analytics because of sensitive data.
Ten questions to ask the vendor
Use the list in the RFP so answers can be compared side by side.
- How many domains are included in one contract, and are subdomains counted separately?
- Where are consent records hosted; is there a Türkiye option?
- Are role-based access and agency accounts supported?
- In what format is the consent-proof report exported?
- Are Consent Mode v2 and TCF v2.2 included in the plan?
- How fast can a new subsidiary site go live?
- Is cookie scanning automatic and recurring?
- Are policy texts updated automatically?
- Are a DPA, security questionnaire and SLA provided?
- When and through which channel is Turkish-language support available?
What Cookietrace offers corporate groups
Cookietrace manages KVKK, GDPR, ePrivacy, CCPA and LGPD from one dashboard, supports IAB TCF v2.2 and Google Consent Mode v2, and scans every domain to build the cookie inventory. Premium covers up to 100 domains on one licence at $79/mo; Enterprise covers a custom domain count, Türkiye data residency, a DPA and an SLA. Consent records are retained with timestamps and integrity proof for at least three years, and the AI Disclosure Module for EU AI Act Article 50 runs on the same platform. Global alternatives include OneTrust, Cookiebot, Usercentrics and Didomi.
A four-week corporate rollout plan
Sequence the rollout so legal sign-off happens before portfolio-wide deployment.
- Week 1: domain inventory, legal-entity mapping and an automatic scan of all sites
- Week 2: corporate banner template, category classification and legal sign-off
- Week 3: pilot subsidiary go-live, GTM and Consent Mode v2 wiring, agency permissions
- Week 4: full portfolio rollout, first audit report and presentation to internal audit
Frequently asked questions
Choosing a CMP for a corporate portfolio differs from choosing one for a single site: dozens of brand, subsidiary and country domains must be managed from one dashboard; legal, marketing and IT need separate permissions; every consent must convert into an audit report; data must be hostable in Türkiye; and procurement needs a DPA, security questionnaire and SLA. Cookietrace covers up to 100 domains on Premium ($79/mo) and offers an Enterprise contract with Türkiye data residency.
Who is the data controller in a holding structure?
Each domain is attached to the relevant legal entity, and banners and policy texts are published in that entity's name. In Cookietrace domains can be grouped by legal entity and reported per group.
We have more than 50 websites; can they run on one licence?
Yes. The Premium plan covers up to 100 domains on a single licence; larger portfolios move to an Enterprise contract.
Can agencies access sites without seeing the whole portfolio?
Yes. With role-based access, agency accounts only see and edit the domains they are authorised for.
Can consent records be kept in Türkiye?
Yes. Data hosting is available in the EU by default or in Türkiye, and the location is set out in writing in an Enterprise contract.
Can EU subsidiary banners be managed from the same dashboard?
Yes. Geo-targeting applies KVKK rules to Turkish visitors and GDPR/ePrivacy rules plus the local language to EU visitors; TCF v2.2 is supported.
Do you provide a DPA, security questionnaire and SLA?
Yes, all three are provided under the Enterprise contract.
Sources
Official sources cited in this guide.
Who should read it
Website owners, marketing teams and developers responsible for cookie consent, analytics tagging and privacy documentation.
Cookietrace
Written and reviewed by the Cookietrace Privacy Engineering Team. (9 min — enterprise)