Is It Out of Scope? — Web design
Is adding GDPR / cookie consent tooling out of scope for a web design project?
Usually yes, beyond a basic consent banner. Full cookie-category management and legal-compliance configuration go beyond design scope.
A basic cookie notice banner is often included as a standard footer element. The request that goes beyond that is category-level consent management — granular opt-ins, a preference center, region-based rule logic — which is a real compliance build.
Is it out of scope?
Usually yes, past a basic banner. Full consent-category tooling with a preference center and conditional script-blocking is compliance configuration work, not a design deliverable.
Clause typically implicated
Clause typically implicated
Data protection clause→ — Defines each party's responsibility for privacy and consent compliance; full consent-management tooling is typically the client's own compliance decision to configure, not a standard design deliverable.
Example contract wording
Example contract wording (illustrative, not legal advice)
The build includes a basic cookie notice, but a full consent-management setup with category opt-ins is a compliance configuration piece I'd scope separately, ideally with input from whoever advises you on privacy compliance.
How MarginFlow flags it
MarginFlow flags full consent-management-platform requests outside_scope on design contracts, while treating a basic cookie notice banner as standard.