Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Ensighten, now part of Cheq, is an enterprise tag management and website privacy platform that controls which marketing and analytics tags run on a site. It enforces consent in the browser by blocking unapproved or unconsented tags before they can collect data, and it provides audit trails to demonstrate compliance. Because it governs tracking technologies and stores consent signals, it plays a central role in privacy compliance.
Ensighten, now part of Cheq and branded as Cheq Control and Compliance, is an enterprise tag management and website privacy platform. It lets organisations deploy, organise and govern the marketing and analytics tags that run on their websites through a single container. Beyond classic tag management, it focuses on consent enforcement by scanning the page and blocking unapproved or unconsented tags in the browser before they can collect any data. It supports both client side and server side deployment and produces audit trails that help demonstrate compliance. Because it sits in front of every other tracking tool, it has a powerful influence over how personal data is collected across the whole site.
Ensighten itself stores the signals needed to record how a visitor has opted in or out of tracking technologies, typically in a first party cookie or in browser storage. The platform can be configured so that no non essential data is stored until a visitor has given consent. The far larger data footprint comes from the third party tags that Ensighten loads, since each analytics or advertising tag may set its own cookies and collect its own personal data. This makes the tag inventory the key artefact for compliance, because the cookies a visitor actually receives depend on which tags are allowed to fire. Operators should map every managed tag and the storage it creates so the cookie policy reflects reality.
Under the GDPR and the ePrivacy Directive, reading or writing non essential identifiers requires consent, and Ensighten is the control point that can make this lawful in practice. The strictly necessary function of enforcing consent and keeping an audit record can often rely on legitimate interest, but the marketing and analytics tags it releases almost always require consent. National rules such as the German TTDSG and French CNIL guidance reinforce that consent must be obtained before non essential tags fire. The website operator is the data controller responsible for the overall configuration, while Cheq acts as a processor for the platform. Correct configuration turns Ensighten from a compliance risk into a compliance safeguard.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Ensighten can act as the enforcement layer for a consent management platform, ensuring that the choices a visitor makes are actually applied in the browser. Each managed tag should be mapped to a purpose category so that it only fires when the visitor has consented to that category. Because the platform blocks tags at the source rather than relying on each vendor to behave, it provides a strong technical guarantee that unconsented tracking does not occur. Operators should verify that withdrawing consent immediately stops the relevant tags and that the consent record is updated. Regular testing across browsers and pages confirms that enforcement works and that the audit trail matches the visible behaviour.
Ensighten is provided by Cheq, a vendor headquartered in the United States, so personal data may be processed in the United States and other third countries. Transfers outside the EEA should be governed by EU Standard Contractual Clauses and, where the recipient is certified, by the EU US Data Privacy Framework, supported by a transfer impact assessment. Operators should also consider where the container script and any server side endpoints are hosted, and whether EU or EEA processing options are available. Each third party tag that Ensighten loads can introduce its own onward transfers, so the transfer analysis must cover the whole tag stack. These mechanisms should be recorded in the record of processing activities.
Start by building a complete inventory of the tags that Ensighten manages and the cookies each one sets, then map every tag to a consent purpose. Sign a data processing agreement with Cheq, confirm controller and processor roles, and document the transfer mechanisms for processing in the United States. Configure consent enforcement so that no non essential tag fires before opt in, and test that withdrawing consent stops the tags and updates the record. Update the privacy notice and cookie policy to reflect the managed tags and the audit logging, and keep them in sync as tags change. Finally, complete a Data Protection Impact Assessment given the platform broad influence over site wide tracking, and review the configuration whenever new tags are added.
Websites using Ensighten must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is recommended because Ensighten governs the tracking technologies that load on a website and therefore influences large scale processing across many tools. The assessment should map every tag that Ensighten controls, the consent signals it stores, the categories of personal data those tags collect, and the safeguards for transfers to the United States. It should also confirm that the consent enforcement actually prevents unconsented tags from firing and that audit logs do not themselves create excessive records of individual behaviour.
Sample consent text
We use Ensighten to manage the tags on our website and to enforce your privacy choices. With your consent we allow marketing and analytics tags to run, and we record your consent decision so we can honour it. You can change or withdraw your consent at any time in our cookie settings.
Third-party domains contacted
ensighten.comnexus.ensighten.comcheq.aiCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Ensighten consent signal | first party cookie | up to 1 year | Records the visitor consent decision so that the platform can enforce which tags are allowed to fire and demonstrate compliance. |
| Ensighten browser storage | localStorage | persistent until cleared | Stores consent state and tag configuration in browser storage so the enforcement layer can apply the visitor choices across pages. |
Ensighten collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Ensighten stores the signals that record how a visitor opted in or out of tracking, usually in a first party cookie or browser storage, and it can be configured to store nothing until consent is given. The much larger footprint comes from the third party tags it loads, since each managed tag may set its own cookies. The exact cookies a visitor receives depend on which tags are allowed to fire.
The marketing and analytics tags that Ensighten releases require consent before they fire under the ePrivacy rules and the GDPR. The strictly necessary consent enforcement and audit functions can often rely on legitimate interest. In practice Ensighten is the tool that makes consent enforceable for all the other tags.
Consent under GDPR Article 6(1)(a) is the basis for the non essential marketing and analytics tags that Ensighten controls. Legitimate interest under Article 6(1)(f) may support the strictly necessary consent enforcement and audit logging, with a documented balancing test. The lawful basis should be assessed tag by tag.
Ensighten is provided by Cheq, a vendor headquartered in the United States, so personal data may be processed in the United States and other third countries. Such transfers should rely on EU Standard Contractual Clauses and, where the recipient is certified, the EU US Data Privacy Framework, supported by a transfer impact assessment. The managed third party tags may also create their own onward transfers.
A Data Protection Impact Assessment is recommended because Ensighten governs site wide tracking and influences large scale processing across many tools. The assessment should map the managed tags, the consent signals stored, the data those tags collect and the transfer safeguards. It should confirm that enforcement actually blocks unconsented tags.
Build a full inventory of the managed tags and map each one to a consent purpose, then sign a data processing agreement with Cheq. Configure consent enforcement so no non essential tag fires before opt in, and test that withdrawing consent stops the tags and updates the record. Keep your privacy notice and cookie policy in sync with the managed tags.
Other enterprise tag management and consent enforcement options include Tealium iQ, Google Tag Manager with a consent mode, Commanders Act and dedicated consent platforms such as OneTrust or Cookiebot. The most privacy protective setups block tags at the source and offer EU data residency. The right choice depends on the size of your tag stack and your data residency needs.
List the Ensighten consent cookie and any browser storage it uses, then describe each managed tag and the cookies it sets, grouped by purpose. Explain that tags are blocked until the visitor consents and that consent decisions are recorded. Review and update the policy whenever a managed tag is added, changed or removed.