Agencies manage consent for multiple clients in Secure Privacy by adding every client site as its own licensed domain inside a single agency account, then controlling who touches what with three access roles: Account Owner, Account Admin, and Domain Admin, the last scoped only to the domains you assign it. Banner designs, legal templates, and privacy policies live at the account level and get applied per domain, so a client's site inherits a configuration you built once. What you do not get is a separate tenant per client: consent records and dashboards are per-domain, and licensing is per domain and subdomain, not per account.
Key Takeaways
- Licensing is per domain and per subdomain. Secure Privacy's support documentation states that each domain and subdomain independently placing cookies needs its own license, so a client with example.com, blog.example.com, and shop.example.com is three licenses, not one.
- The Free plan caps you at 10 domains. Every paid tier from Small ($15/month) upward carries no domain limit, which makes the real ceiling on an agency portfolio the seat count and the monthly consent volume, not the number of client sites.
- Seats are the tighter constraint than domains: Small includes 2 users, Business 3, and Advanced unlimited. An agency that wants to hand each client a login of their own will hit the seat wall long before the domain wall.
- Domain Admin is the role built for this arrangement. Secure Privacy's own user-management docs name external agencies and developers as its intended holders. It cannot see other domains on the account, cannot reach billing, and gets view-only access to templates configured outside its assigned domains.
- White-label is real but scoped: removing Secure Privacy branding, white-label banners, and custom CSS start on the Small plan. A branded dashboard on your own domain and branded reports are Partner Program benefits at the Certified and Elite tiers, not standard plan features.
- Google Consent Mode v2 is enabled per domain, not per account. Secure Privacy sits at Gold tier in Google's CMP Partner Program and appears in Google's own consent mode setup wizard, but the toggle lives in each domain's Installation tab, so every client site is its own enablement step.
- Secure Privacy v1 reached end-of-support in Q2 2026. Agencies still holding client sites on v1 get no further regulatory updates there; migration to v2 is free, guided, and carries domains, consent records, and banner customizations across.
Why managing consent for multiple clients is a different job
A single-site business needs one banner to be correct. An agency needs forty banners to stay correct while nobody is looking at thirty-nine of them.
That difference is what makes consent unusual as an agency service line. Most deliverables are finished when they ship. A cookie banner degrades: the client's marketing team adds a new pixel through Tag Manager, a plugin update introduces a tracker, a regional office spins up a subdomain. Each of those events silently breaks a configuration that was compliant on launch day, and the agency is the party that gets the phone call. The practical consequence is that you cannot run this service on memory and screenshots. You need a system where the current state of every client site is visible from one place, and where the evidence that consent was collected properly is retrievable per client, on demand, months later.
France's CNIL fined SHEIN's Irish subsidiary, INFINITE STYLES SERVICES CO. LIMITED, €150 million on September 1, 2025, and Google €325 million across two group entities in a decision published three days after that. The SHEIN decision turned on advertising cookies landing on visitors' devices, in CNIL's account, "even before they interacted with the information banner," and on clicking "Refuse all" failing to stop new cookies from being written. Neither failure requires bad intent. Both are the ordinary output of a tag that fires too early, which is precisely the class of defect an agency introduces or prevents. If you are still deciding whether the service line is worth building, the ROI case for adding cookie consent to an agency offering is a separate argument from the compliance one.
How the major CMPs structure agency accounts
Vendors converge on the same shape (one agency account, many client properties, scoped access) and diverge on billing and on what the client sees. Every row below follows the vendor's own documentation; third-party CMP rankings credit at least one of these platforms with per-client sub-accounts and a white-label dashboard that its own agency documentation never mentions.
| CMP | Account model for client sites | How clients get access | Client-facing branding | Reseller or commission route | What pricing scales on |
|---|---|---|---|---|---|
| Secure Privacy | One account holding unlimited domains on paid plans; each client site is a licensed domain, not a separate tenant | Domain Admin role, scoped to assigned domains only; no visibility of other clients' domains | Remove branding, white-label banner, and custom CSS from the Small plan; branded dashboard on your own domain and branded reports at Certified and Elite partner tiers | Partner Program with three tiers: Referral at 15%, Certified at 25%, Elite at 30% recurring commission, plus a partner portal | Number of domains and subdomains licensed, monthly consent volume, and seat count |
| CookieYes | Agency Partner Program with a centralized agency dashboard covering all client websites | Managed through the agency dashboard; per-client access model not specified in program documentation | White-label not named as a program benefit; banners are customizable and multilingual | Resell purchased licenses at your own margin, with discounts documented as up to 50% | Volume-based license purchasing across client sites |
| Enzuzo | Each client property runs in its own isolated environment with separate consent settings, audit logs, and reporting | Per-client environments plus a centralized dashboard for the agency; access mechanics not detailed publicly | White-label options for delivering consent experiences under agency branding | Partner and reseller program with a dedicated signup path | Unique visitors, with unlimited domains or client accounts inside one plan |
| CookieHub | Reseller account holding a list of Client Accounts, each client its own account under the reseller's portal | Clients invited as users to their own account, seeing their own data and settings | White-label or custom-domain dashboard is not named on the reseller page | Reseller program paying 30%, taken either as commission when the client pays or as a discount when the agency invoices | Subscription level per client account, with domains uncapped and free plans available for small sites |
| CookieScript | One account holding multiple clients and banners; not sub-accounts, per its own agency documentation | Banner sharing by client email, granting full or read-only access to that banner only | White-label dashboard on a custom domain is not documented | Agency buys a multi-domain plan and invoices clients directly; CookieScript does not control the invoicing | Standard published per-domain pricing, with no separate reseller rate card documented |
Two terms in that table get used loosely across the market and are worth pinning down.
Multi-tenant properly means each client's data sits in a logically separate environment with its own records and reporting boundary. Domain-scoped access, which is what Secure Privacy provides, means all client sites live in one account and the boundary is enforced by permissions rather than by separate tenants. CookieHub's reseller program is the clearest example of the other model in this table: its own page describes a list of Client Accounts under the reseller's portal, with clients invited as users into their own account rather than into a shared one. For most agency work the practical difference is narrow, because a Domain Admin still cannot see another client's domain. It becomes real when a client's procurement team asks where its consent records are stored relative to other customers of yours, or when you want to sell the client book and hand over one client's account cleanly.
Decide which of those two models your client contracts actually require before you compare price tables; Secure Privacy's plan and domain pricing is the fastest way to test the domain-scoped model against a real client list.
How one Secure Privacy account holds multiple client domains
Domains are the unit of everything
Every client site you take on becomes an entry under the Domains tab, which gives an overview of all domains attached to the account. That tab is the closest thing to the portfolio view an agency wants: one screen listing what you are responsible for.
The billing consequence deserves attention before you price a retainer. Secure Privacy's domain licensing model licenses per domain and per subdomain, on the reasoning that both can independently write cookies to a device regardless of shared roots. Subpages like /about fall under the parent license; shop.example.com does not. Language paths such as /fr normally sit under the parent too, unless you give that version its own blocking rules or banner text, at which point it needs its own license. An agency that quotes a flat per-client fee without auditing subdomains first will absorb that difference itself. The Free plan's 10-domain ceiling is generous enough to test the model on real client sites before you commit to a paid tier.
Roles decide what your client sees
Secure Privacy's user management model has three levels, and the distinctions map neatly onto agency reality. Account Owner holds everything including billing. Account Admin reaches all features and all domain configurations but cannot touch billing or core account details, which is the right level for your own delivery lead. Domain Admin is confined to the domains you assign, cannot open billing or account settings, cannot see the rest of the portfolio, and gets read-only visibility of designs, templates, and policies that were configured outside the Domains tab.
That last restriction is the one worth explaining to clients in advance. A client with Domain Admin access can inspect and manage their own site but cannot edit the shared template their banner inherits, which is usually exactly what you want. It prevents a client's in-house marketer from changing a legal template that eleven other sites depend on. It also means genuine self-service is partial: template changes route back through you. Whether that is a feature or a support burden depends on how you have priced the retainer.
Seats, not roles, are where this gets expensive. With 2 users on Small, 3 on Business, and unlimited on Advanced, the plan that supports giving every client their own scoped login is Advanced at $249/month. Below that, client access is something you ration.
Templates and designs are built once
Templates sit in their own top-level tab, outside the Domains tab, and bundle the decisions that repeat across a portfolio: banner configuration and appearance, consent framework (standard or IAB TCF), geographic scope down to individual US states and Canadian provinces, retention period, opt-in versus opt-out model, language settings, and the associated preference center, privacy policy, and data request form.
Because those objects live at account level, the work of deciding how a compliant banner should behave in the EU versus California is work you do once and then apply as you onboard. Secure Privacy's documentation describes applying templates and designs per domain; it does not document pushing a template change to a set of domains in a single action, so treat portfolio-wide changes as a sequence of per-domain applications when you scope the effort. Business and Advanced carry 55+ legal templates against 5 on Small, which is the line an agency crosses as soon as its client book spans more than a couple of jurisdictions. The broader question of how organizations keep consent consistent across many web properties applies just as directly to an agency's portfolio as to a single company's.
Google Consent Mode v2, one client site at a time
If your agency also buys media, this is the part of consent management with a consequence the client notices inside a reporting cycle. Google requires advertisers to collect consent from end users in the EEA and pass two signals alongside the storage ones: ad_user_data, covering the sending of user data to Google for advertising, and ad_personalization, covering personalized advertising. Google's own guidance names the failure mode directly: if you stop Google tags loading until a visitor interacts with the banner, Google cannot verify the consent choice, and this may lead to loss in data. A client whose remarketing audiences quietly stop filling will not diagnose that themselves; they will ask the agency that installed the banner.
Clients monetizing with AdSense, Ad Manager, or AdMob carry a second requirement. Google obliges publishers serving personalized ads to users in the EEA and UK to use a CMP certified by Google that integrates the IAB Transparency and Consent Framework. That turns CMP choice into an ad-revenue dependency rather than a legal preference.
Secure Privacy is listed at Gold tier in Google's CMP Partner Program, the top of a three-tier Gold, Silver, and Bronze structure that Google assigns on criteria including customer support and ease of technical integration. It is also one of the platforms in Google's own consent mode setup wizard, which matters operationally: per Secure Privacy's setup guide for the Google tag route, you open the Google tag admin settings, choose Set Up Consent Mode, pick Secure Privacy from the fully integrated platform list, and skip writing and maintaining gtag('consent', 'update', ...) calls yourself. On a portfolio of client sites, hand-maintained gtag snippets are the thing that rots first, because whoever wrote them has usually moved on.
The Google Consent Mode integration maps consent categories to all seven signal types, ad_storage, analytics_storage, functionality_storage, personalization_storage, security_storage, ad_user_data, and ad_personalization, and takes per-region defaults by ISO 3166-2 code, so DE and US-CA can start from different states on the same client site. The mode choice is worth making deliberately per client rather than once for the book: Advanced mode lets tags fire with limited cookieless data before a choice and gives modeled coverage across all users, while Basic keeps tags paused until consent and reports only consenting users. An ecommerce client tracking conversions and a public-sector client with a conservative legal team will not want the same answer.
For clients who need the framework, Secure Privacy is an IAB Europe-registered CMP for TCF 2.2 and supports the v2.3 disclosed-vendors requirement through a dashboard toggle rather than a code change. Both consent mode and TCF are switched on in the individual domain's settings, so a newly onboarded client site is not covered by anything you configured on the last one.
Branding, and the honest limits of white-label
Removing Secure Privacy's branding from the banner, applying custom CSS, and running white-label banners are all included from the Small plan onward, so the consent experience on a client's site can look like the client's site rather than a vendor's. The visitor preference center supports custom branding as well, and 70+ pre-translated languages mean a multi-region client does not need a separate build per market.
What sits behind the login is different. A dashboard carrying your agency's brand on your own domain, and reports issued under your name, appear as Partner Program benefits at the Certified and Elite tiers rather than as line items on the standard plan table. If white-label is the reason you are choosing a CMP at all, that distinction is the one to raise on a sales call, and the general case for white-label consent management covers the positioning side of the decision.
The Partner Program is also the commercial answer to the question of how the service line pays for itself. Three tiers carry 15%, 25%, and 30% recurring commission respectively, with monthly payouts and no cap, and a separate Solution Provider track for agencies that would rather own the whole client relationship (sales, support, invoicing, and account management) against product discounts. Which of those two shapes fits depends on whether you want compliance to be a margin on a resold license or a billable service with the license as cost of goods.
Evidence, per client, when someone asks for it
Consent logging is automatic and the record set is exportable from the dashboard, accepted and declined alike. The consent dashboard shows visitor consent records for a selected domain (accepted, declined, and partial, broken out by category, with location and device detail) and exports the full dataset to CSV for a chosen domain and date range.
Reporting is scoped to a domain. Cross-domain aggregation, meaning one figure for consent rates across your whole client book, is not a documented feature of the Cookie & Consent Solution; cross-entity comparison appears in Secure Privacy's separate Governance Solution. In practice an agency producing monthly client reports exports per domain, which is the natural unit for a client-facing report anyway, and builds any portfolio roll-up outside the tool. If reporting is the core of your retainer, the mechanics of client reporting under privacy constraints are worth working through before you promise a format.
Monitoring closes the loop. Automated monthly scanning is included from the Small plan and covers plugins, cookies, TLS, SSL, and data locations, with the system updating itself as it detects changes. Scanning behind login pages is Advanced-only. For an agency, monthly scanning across the portfolio is what converts consent from a launch-day deliverable into something you can honestly describe as managed. A client's newly added pixel surfaces in a scan rather than in an enforcement letter. Bulk privacy scanning across many sites is the pattern this supports.
Who is actually liable
The website operator, your client, is the controller for cookies on its own site, and the obligation to demonstrate lawful consent sits with the controller. Under GDPR Article 4(7), the controller is the party determining the purposes and means of processing; a processor acts on the controller's documented instructions under Article 28(3)(a).
The line to watch is Article 28(10), which provides that a processor determining purposes and means itself is then "considered to be a controller in respect of that processing." An agency that selects which analytics and advertising tags a client's site runs, decides how they are categorized, and sets the consent defaults is making decisions that look less like following instructions and more like determining means. That is not a reason to refuse the work; it is a reason to document the decisions in a data processing agreement, name the client as controller in writing, and keep a record of what you configured and when. Article 28(1) requires controllers to use processors offering sufficient guarantees of appropriate technical and organizational measures, which is the clause your client's legal counsel will point at when asking why you chose the CMP you chose.
Onboarding a client site without a developer
- Audit the domain list first (root domain plus every subdomain that writes cookies) and price the license count from that, not from the client's site count.
- Run a scan before configuring anything, so you have a baseline record of what was firing on the site when you inherited it.
- Build or select the account-level template that matches the client's jurisdictions, then apply it to the domain.
- Apply a design, adjust colors and copy to the client's brand, and set default consent states per region.
- Deploy the script through the client's own stack. The Installation tab takes a platform selection and returns tailored instructions, with documented paths for WordPress, Shopify, Squarespace, HubSpot, Weebly, Joomla, Magento, Drupal, Google Tag Manager, and Adobe Tag Manager. Where a client's developer controls releases, the dashboard will email the script to them rather than making you relay it.
- Enable automatic blocking so nothing loads before consent, then test acceptance and refusal separately. The SHEIN decision turned partly on refusal not being honored.
- Turn on Google Consent Mode v2 in that domain's Installation tab, and IAB TCF in its domain settings if the client sells programmatic inventory. Neither carries over from the last site you onboarded.
- Add the client as Domain Admin scoped to their domain only, if your seat count allows it.
- Set the export cadence for their monthly consent report and confirm the internal email address that receives DSAR submissions.
Repeating nine steps by hand across a growing client book is the point at which agencies start asking about automation. Secure Privacy publishes a REST API at https://api-prod.secureprivacy.ai, authenticated with a bearer API key generated under Account then API Integrations, and its documentation describes interacting with domains, mobile apps, and policies programmatically, under published rate limits. What that documentation does not lay out is a provisioning recipe for standing up a new client domain end to end, so read the endpoint reference before you scope an onboarding integration, and treat the API as the thing that could remove the repetitive steps rather than as a shipped bulk-onboarding feature.
If any of your client sites are still on Secure Privacy v1, that queue jumps ahead of the rest. v1 reached end-of-support in Q2 2026. Existing banners keep working, but new regulatory features, including ongoing Google Consent Mode v2 and IAB TCF v2.3 work, land only on v2. Migration is free and included with the existing plan, carries domains, consent records, and banner customizations across, and typically completes inside a working week per account.
Common issues and fixes
Most of what goes wrong in a client portfolio is one of seven things, and none of them are mysterious once you know where to look.
| Symptom | Why it happens | What to do |
|---|---|---|
| A client's banner no longer blocks everything the site loads | Marketing added a tag through Tag Manager after you configured the banner, so the new cookie sits in no consent category you defined | Treat the monthly scan as the trigger: recategorize the new cookie, then re-test acceptance and refusal separately |
| A live client page has no banner at all | A new subdomain went up, and licensing is per domain and per subdomain, so it is not covered by the parent license | Add the subdomain as its own licensed domain, then check the client's DNS records or sitemap for the ones you have not found yet |
| The client wants one consent-rate number for all their sites | Dashboard reporting and CSV export are scoped to a single domain and date range | Export per domain and assemble the roll-up outside the tool, and agree the report format with the client before you commit to it |
| A client's in-house marketer cannot edit their own banner's legal template | Domain Admin gets read-only access to designs, templates, and policies configured outside the Domains tab | Nothing is broken. Route template changes through your team and price that handoff into the retainer instead of promising full self-service |
| You run out of client logins | Small includes 2 users and Business 3, so seats run out well before domains do | Ration Domain Admin access to the clients who genuinely log in, or move to Advanced for unlimited users |
| A client's Google Ads audiences and conversion data thin out after the banner goes live | Google tags are held back until the visitor interacts with the banner, so Google cannot verify the consent choice and data is lost | Enable Google Consent Mode v2 in that domain's Installation tab, then decide Advanced or Basic mode with the client rather than defaulting |
| An older client site stops receiving new regulatory features | That site is still on Secure Privacy v1, which reached end-of-support in Q2 2026 | Request the free guided v2 migration, which carries domains, consent records, and banner customizations across |
Every row in that table is a monitoring problem before it becomes a compliance problem. The Cookie & Consent Solution is what closes that gap across a portfolio: trackers blocked until a visitor consents, consent logged and exportable per client site, and a monthly scan that tells you what changed on a client's site before the client tells you.
FAQ
Can one Secure Privacy account manage cookie consent for multiple client websites?
Yes: every paid Secure Privacy plan from Small upward carries no limit on the number of domains you can add to a single account, and the Domains tab lists them all in one view. The Free plan caps out at 10 domains, and licensing is charged per domain and per subdomain rather than per account, so the cost of a portfolio scales with the number of cookie-setting hostnames rather than with the number of clients.
Does Secure Privacy give each client a separate sub-account?
No: Secure Privacy uses domain-scoped permissions inside one account rather than a separate tenant per client. A user assigned the Domain Admin role can only view and manage the domains explicitly assigned to them and cannot see other domains, billing, or account settings, which achieves client separation at the access layer without creating independent accounts.
Can an agency remove Secure Privacy branding from a client's cookie banner?
Yes: removing branding, white-label banners, and custom CSS are included from the $15/month Small plan onward. A dashboard carrying the agency's own branding and domain, along with branded reports, is a Partner Program benefit at the Certified and Elite tiers rather than a standard plan feature.
How much commission can an agency earn reselling Secure Privacy?
Secure Privacy's Partner Program pays 15% recurring commission at the Referral tier, 25% at Certified, and 30% at Elite, with monthly payouts and no stated cap. Agencies preferring to own the client relationship outright can instead take the Solution Provider track, which trades commission for product discounts and puts sales, support, invoicing, and account management in the agency's hands.
Can I see consent rates across all my client sites in one report?
No: the consent dashboard and CSV export are scoped to a selected domain and date range, so portfolio-wide consent figures need assembling outside the tool. Cross-entity comparison of privacy program metrics is a feature of Secure Privacy's separate Governance Solution rather than the Cookie & Consent Solution.
Is the agency or the client legally responsible for cookie consent?
The client is the controller for cookies on its own website and carries the primary obligation to demonstrate valid consent. An agency that decides which trackers run, how they are categorized, and what the consent defaults are can nonetheless be treated as a controller for those decisions under GDPR Article 28(10), which is why the allocation of responsibility belongs in the written agreement rather than in an assumption.
Does Secure Privacy support Google Consent Mode v2 on client sites?
Yes. Secure Privacy is listed at Gold tier in Google's CMP Partner Program and appears as an integrated platform in Google's own consent mode setup wizard, so a client's Google tag can be connected without hand-written gtag consent calls. It maps consent categories to all seven Consent Mode v2 signal types and accepts per-region defaults by ISO 3166-2 code. Enablement is per domain, in each domain's Installation tab, rather than a single account-wide switch.
Can an agency add client domains to Secure Privacy through an API?
Secure Privacy publishes a REST API at https://api-prod.secureprivacy.ai, authenticated with a bearer API key issued under Account then API Integrations, and its documentation covers programmatic interaction with domains, mobile apps, and policies under published rate limits. It does not document an end-to-end provisioning workflow for onboarding a new client domain, so check the endpoint reference against your intended sequence before building against it.
How many client logins does an agency plan include?
Seat counts are 1 user on Free, 2 on Small, 3 on Business, and unlimited on Advanced at $249/month. Giving every client their own scoped Domain Admin login therefore requires the Advanced plan in practice, since the lower tiers exhaust their seats on the agency's own team.
Getting a client portfolio onto a system you can defend
The version of this that fails is the one where forty banners were correct on launch day and nobody has checked since. The version that works is boring: one account listing every client domain, scoped logins so a client can see their own site and only their own site, a template you wrote once, a scan every month, and an export you can hand to a regulator or a procurement team without preparing anything first. Start with an audit of your client domains and subdomains against Secure Privacy's plan tiers and seat limits, and if you intend to resell rather than rebill, price the partner commission tiers into the retainer before your first client conversation.




