| Identity Sync | Carries consent and opt-out state across browsers, devices, sessions, and systems through configuration. | Customers migrating from OneTrust report identity sync required significant engineering time to get working at all. The Disney settlement (CA AG, $2.75M, February 2026) found opt-out choices weren't propagating across devices and services, so a single consumer could be asked to opt out up to ten separate times. Full breakdown → |
|---|
| Consent & rights enforcement | Permission Vault stores consent, preference, identity, and policy signals for real-time enforcement across systems. | Enforcement runs largely through browser-side tag blocking; downstream systems need separate, custom work to stay in sync. |
|---|
| Downstream (Type 2) orchestration | Server-to-server API calls reach into Facebook Ads, Google Ads, The Trade Desk, and other systems using each platform's own identifier, so an opt-out stops processing there, not just future collection in the browser. | Consent orchestration is client-side tag blocking; no documented server-to-server calls to downstream systems for consent enforcement. |
|---|
| GTM tag enforcement | Tags are fetched from the container, classified in Ketch's UI, and the consent dependency is written back into GTM automatically. | GTM consent triggers still have to be built manually inside GTM after tags are classified. |
|---|
| DSR operations | Automates fulfillment from intake to execution and connects requests to data maps and workflow evidence. | DSR handling depends more on manual review from the privacy team as request volume and complexity grow. |
|---|
| Proof on demand | The audit log is queryable by any identifier and returns consent state, interaction method, jurisdiction, and downstream API call status, per system. | Customers report needing to file support tickets to access their own consent data for reporting. As CalPrivacy's Head of Enforcement put it in the Todd Snyder settlement: "Using a consent management platform doesn't get you off the hook for compliance." |
|---|
| Demand letter defense | Configurable delay between notice and data collection, an individual-level (not browser-level) audit trail, and the ability to ingest and process the same HAR files plaintiffs' firms use to build CIPA/VPPA claims. | Most CMPs log consent at the browser or session level and can't process HAR files directly, leaving teams unable to verify or refute a claim themselves. |
|---|
| Opt-out enforcement | A Do Not Sell request closes in one action and reaches downstream systems automatically. | The Sling/Dish settlement (CA AG, $530,000, October 2025) found consumers had to navigate separate cookie-preference toggles as part of completing an opt-out (the multi-step pattern regulators keep finding). Full breakdown → |
|---|
| Sensitive data sharing | Consent-aware orchestration stops sensitive data (health, location, financial) from reaching ad platforms without valid authorization. | The Healthline settlement (CA AG, $1.55M, July 2025) found sensitive health data was shared with advertising networks without valid consent, despite a privacy policy describing compliant practices. Full breakdown → |
|---|
| Ketch Agent Network | One orchestrator agent runs a network of purpose-built sub-agents for discovery, risk, consent configuration, DPIA, and reporting. | AI claims are still measured against workflow depth and cross-system enforcement. |
|---|