Is It Out of Scope? — Web development
Is adding GDPR / cookie consent tooling out of scope for a web development project?
Usually yes, beyond a basic banner script. A full consent-management platform with script-blocking logic is a distinct technical build.
A simple cookie banner script is a small addition. A real consent-management platform — conditional script-loading by category, region detection, a persisted preference store — is a meaningfully larger technical integration than the banner it sounds like.
Is it out of scope?
Usually yes, beyond a basic banner. Integrating a full consent-management platform with category-based script blocking is its own technical build, not covered by a general "add a cookie notice" scope.
Clause typically implicated
Clause typically implicated
Data protection clause→ — Defines the technical scope of privacy/consent compliance work covered; full consent-management platform integration typically exceeds a basic notice and needs its own scope.
Example contract wording
Example contract wording (illustrative, not legal advice)
A basic cookie banner is straightforward, but a full consent-management platform with category-level script blocking is a larger integration — I'd scope and quote that separately.
How MarginFlow flags it
MarginFlow flags full consent-management-platform integration requests outside_scope on development contracts, distinguishing them from a basic cookie notice add.