For years, mobile apps got away with treating consent as an afterthought: a checkbox screen bolted on to satisfy the legal side, built once and never touched again. That approach is running out of room. Enforcement has caught up, Google has made consent signals a condition of full access to its ad stack, and the way an app handles consent has quietly become an onboarding and conversion question as much as a legal one.
To take care of this layer of the funnel, the Scalebay team partners closely with Axeptio, the consent management platform (CMP) we deploy across client accounts to handle mobile consent without it becoming its own onboarding project.
This article covers why the problem is more urgent than most teams realise, how Axeptio actually removes the stress, and where it fits into the rest of the funnel.
Why mobile consent stopped being a "later" problem
GDPR has covered mobile apps since 2018, but enforcement only caught up recently. In September 2024, France's CNIL (the French data protection authority) published a 95-page set of recommendations dedicated to mobile applications, and since spring 2025 it has been running compliance inspections on apps. It has already fined Voodoo €3 million for using browsing data without consent. Reputational hits are part of it too: noyb filed a complaint against BeReal in 2024 over a manipulative consent flow.
At the same time, the major ad platforms have started making consent a business dependency rather than a legal nicety. Google is furthest along: since March 2024, Google Consent Mode v2 has been required to make full use of Google Ads and GA4, for apps as well as websites, and without those signals set explicitly, an app risks losing attribution data and the ability to build consistent web-and-app audiences. It is not just Google, either. Meta supports an analogous modelled-conversions flow through the Pixel and Conversions API, and TikTok's Events API does something similar, though neither is a hard requirement yet the way Google's is. In every case the logic is the same: the platform models conversions from non-consenting users based on the behaviour of consenting ones, turning a hard data loss into a partial one, and the size and quality of your consenting base is what determines how good that modelling is.
In other words: your consent rate is now, indirectly, a media-buying metric, on more than one channel.
The part most teams get wrong: ATT, OS permissions and a CMP are not the same thing
A first app session now routinely stacks three different requests: the CMP, Apple's App Tracking Transparency (ATT) prompt, and OS-level permissions (notifications, camera, mic, sensors, geolocation, local networks, contacts). Most teams treat them as interchangeable. They are not.
ATT tells a user the app wants to track them across other apps and websites, in a format and timing Apple controls. It isn't GDPR consent. OS permissions grant technical access to a device capability, also not GDPR consent. A CMP is the only one of the three that presents purposes, records a granular choice, stores proof, and transmits the signal to partners. That is also, not coincidentally, why it converts better.
The numbers back this up: ATT opt-in rates plateau around 50% according to AppsFlyer, while CMPs frequently reach 65 to 83%. As Axeptio's Jérôme Perani put it, that gap makes consent "a critical onboarding and conversion lever", not just a compliance one, a point he has written about in more detail on Axeptio's blog.
Axeptio's own recommendation, and one we apply as standard practice across client accounts, is to sequence the CMP before the ATT prompt, so a user understands the purpose before Apple's fixed-format dialog interrupts them.
And with Germany's competition authority now pointing in that direction, the ATT screen may soon sit inside the CMP itself, sparing users one more prompt in an already crowded first session.
Enter the consent flow builder: how Axeptio actually removes the stress
Axeptio removes the friction from this process by treating the consent banner not as a legal hurdle, but as an onboarding, marketing and conversion lever.
- Geo-adaptive journeys. Axeptio's platform lets brands create smooth, geo-adaptive consent flows baked into the onboarding experience from day one, navigating the technical and legal standards that differ from one country to the next.
- The CMP as a media channel. Axeptio turns the consent screen into a space for brand expression. Brands can integrate native video directly into the banner to support product launches, seasonal campaigns or new services early in the user journey.
- Conditional SDK initialisation. On the technical side, Axeptio provides the framework needed to keep SDKs and trackers completely disabled until explicit consent is given for their respective purposes, which is essential for compliance.
Consent on mobile is a real engineering problem, and that is exactly the argument for not building it in-house. A consent screen ships in a sprint. What costs is everything that happens afterwards: Google revises its signal specification, the IAB publishes a new TCF version, a new state law lands, a tracker changes its behaviour, a regulator asks to see proof of a choice made eighteen months ago. All of this requires expertise, and that is where the Axeptio and Scalebay partnership really makes sense.
What Axeptio's mobile SDK does is take that recurring work off the app team:
- Consent signals, kept in spec. The four Consent Mode v2 signals are propagated to Google's APIs automatically, and the TCF string is generated to the current IAB Europe version, with IAB Canada supported alongside it.
- Runtime constraints handled. The SDK is under 2 MB, so the consent step costs no meaningful load time. It works offline and syncs when connectivity returns, which matters wherever a first session happens on a weak connection.
- Jurisdiction logic as configuration, not code. Deployment is geotargeted and available in 25 languages. Around 71% of countries now have a data-protection text comparable to GDPR, resolving in practice into five regulatory zones, from strict EU opt-in to US opt-out states.
- Built-in analytics and A/B testing. Consent metrics are available by operating system, in the dashboard and through the API, so a drop in opt-in surfaces immediately.
Axeptio holds Gold status in Google's CMP Partner Program, is compliant with the IAB standard and is ISO 27001 (v2022) certified. The solution runs on more than 200,000 websites today and has collected over 20 billion consent proofs.
Proof of work: TUI France and FIBA
Two live examples worth a look, both public on Axeptio's blog.
TUI France rebuilt its cookie banner as a branded, hospitality-toned welcome moment rather than a legal checkbox, and over 12 months recorded a 71% interaction rate, a 78% consent rate and a 55% opt-in rate. More interesting for a UA audience: TUI used the CMP's native video support to promote its new mobile app launch directly inside the banner, turning a first-party surface that sits earlier in the funnel than any paid channel into a media placement that reused creative already made for other campaigns.
FIBA, the international basketball federation with a claimed audience of 3+ billion fans across 212 national federations, migrated to Axeptio and deployed Consent Mode v2 across its media sites, institutional platforms and mobile apps in under a month, reaching a 90% consent rate on monetised properties and materially improving GA4 data reliability.
Where this fits into the rest of the funnel
Consent is now one more screen competing for a user's attention in the first session, alongside onboarding, activation and eventually the paywall, which is exactly why we treat it as part of the same funnel rather than a separate legal workstream bolted on by an engineering team. Get it wrong and you don't just risk a fine; you lose the attribution data that tells you whether your user acquisition spend is working, and you add friction to an onboarding sequence that a paywall further down the funnel is depending on to convert.
If you are implementing a CMP yourself and want the SDK-level detail (Adjust and AppsFlyer integration, GDPR and ePrivacy requirements article by article, common implementation mistakes), we have written a deeper technical walkthrough on the Scalebay blog. This article is the "why it's a growth problem" companion to that one.
And if you want to see how we use consent data specifically to sharpen paid UA decisions, that is the subject of a companion piece we wrote for Axeptio's blog. If you would rather have Scalebay's team look at your own onboarding-to-consent-to-paywall sequence directly, get in touch.




.png)

.png)
