Is It Out of Scope? — Web design

Is adding GDPR / cookie consent tooling out of scope for a web design project?

Usually yes, beyond a basic consent banner. Full cookie-category management and legal-compliance configuration go beyond design scope.

A basic cookie notice banner is often included as a standard footer element. The request that goes beyond that is category-level consent management — granular opt-ins, a preference center, region-based rule logic — which is a real compliance build.

Is it out of scope?

Usually yes, past a basic banner. Full consent-category tooling with a preference center and conditional script-blocking is compliance configuration work, not a design deliverable.

Clause typically implicated

Clause typically implicated

Data protection clause→ — Defines each party's responsibility for privacy and consent compliance; full consent-management tooling is typically the client's own compliance decision to configure, not a standard design deliverable.

Example contract wording

Example contract wording (illustrative, not legal advice)

The build includes a basic cookie notice, but a full consent-management setup with category opt-ins is a compliance configuration piece I'd scope separately, ideally with input from whoever advises you on privacy compliance.

How MarginFlow flags it

MarginFlow flags full consent-management-platform requests outside_scope on design contracts, while treating a basic cookie notice banner as standard.

Catch scope creep the moment it lands in your inbox

14-day free trial · No credit card required