small logo tdpg retina - The Data Privacy Group
restaurant group cs header - The Data Privacy Group
Published On: 4 March 26

Cookie Compliance Resolved, Consumer Trust Secured

How a Multi-Site Restaurant Group Achieved Full Digital Privacy Compliance Across Three Domains — and Built a Foundation for Ongoing Governance

restaurant group cs 02 - The Data Privacy Group
0
Cookies Dropping Without Consent — Resolved
0
Domains Brought Into Compliance
0
Weeks End-to-End Delivery Timeline
0/5
Client Satisfaction Rating

Client Overview

The client is a fast-casual restaurant group operating across multiple US states, with a strong digital presence built around online ordering, catering services, and brand marketing. Their estate spans a primary marketing domain alongside dedicated subdomains for online orders and catering — each collecting customer data through cookies, tracking tools, and third-party integrations.

In the restaurant and hospitality sector, digital channels are not optional; they are the primary engine for customer acquisition, loyalty, and revenue. For a brand of this scale, the collection of customer behavioural data is commercially essential — but only when done lawfully. Operating in California, the organisation falls squarely within the scope of the California Consumer Privacy Act (CCPA) and its successor regulation, the California Privacy Rights Act (CPRA). The Texas Data Privacy and Security Act (TDPSA) added further obligations for employee and external data subjects in that state. Non-compliance in this environment carries meaningful financial, legal, and reputational consequences for a consumer-facing brand.

restaurant group cs 03 - The Data Privacy Group

The Challenge

When DPG first conducted a review of the client’s primary domain, the findings were material. A pre-engagement audit identified 52 cookies dropping on the site without prior user consent — a direct breach of CCPA/CPRA requirements. The OneTrust script in use was over a year out of date. Thirty-five cookies carried no category classification, meaning the platform could not apply correct consent logic to them. Geolocation rules, which determine which regulatory regime applies to a given user’s session, were entirely absent. The consent banner itself had multiple configuration errors, and cookies were actively dropping under incorrect consent categories.

The situation was not limited to the main marketing domain. Two critical subdomains — serving online ordering and catering customers — had no compliant cookie management in place at all. Each domain required independent assessment, configuration, and implementation.

In parallel, the organisation’s OneTrust Privacy Rights Automation (PRA) module — responsible for managing consumer and employee data subject requests under CCPA, CPRA, and TDPSA — was in poor shape. Of 147 requests logged in the system, the majority had been rejected incorrectly or allowed to pass their legal response deadlines. The root cause was an incomplete and stale configuration: workflows were broken, webforms were misrouted, response templates were inconsistent, and geolocation logic was excluding valid California and Texas requestors due to a configuration error.

The consequences of inaction were concrete. Under CPRA, the California Privacy Protection Agency can impose fines of up to $7,500 per intentional violation — and 52 cookies dropping without consent represents 52 potential violations per user session, at scale. Beyond regulatory exposure, failure to respond to data subject requests within statutory deadlines is itself a separate and actionable breach. For a consumer restaurant brand, the reputational cost of a privacy enforcement action or a data subject complaint reaching regulatory attention could far exceed any direct financial penalty.

Objectives of the Engagement

The engagement had three clear objectives, ranked in order of regulatory urgency:

  • Bring the primary domain and both subdomains into full CCPA/CPRA cookie compliance, ensuring no cookies drop without valid prior consent and that geolocation-based regulatory logic functions correctly across all three domains.
  • Rebuild and properly configure the OneTrust Privacy Rights Automation module to correctly intake, route, and resolve data subject requests from California and Texas individuals — both external consumers and internal employees — within statutory deadlines.

  • Establish ongoing governance through a managed service, ensuring that compliance is maintained as the cookie landscape evolves and regulations change, without requiring continuous internal resource commitment.

restaurant group cs 04 - The Data Privacy Group

Our Approach

DPG structured the engagement across two parallel workstreams — cookie compliance and privacy rights automation — each running on a sprint-based delivery model. The use of two-week sprints allowed the client to review, provide feedback, and approve outputs at each stage, preventing the accumulation of rework and ensuring the solution was built to their actual operational requirements rather than a generic template.

The cookie compliance workstream followed a four-phase sequence. Sprint 0 focused on discovery and planning: documenting the technical landscape across all three domains, confirming stakeholder responsibilities, identifying dependencies, and establishing a dedicated project governance structure. Sprint 1 addressed solution architecture — designing the geolocation ruleset, the consent banner configuration, and the preference centre layout, with input from the client’s design team to ensure brand consistency. Sprint 2 executed the OneTrust implementation: full rescans of all three domains, cookie recategorisation, banner and preference centre configuration, and the linking of geolocation rules to the appropriate regulatory templates. Sprint 3 covered script implementation and blocking method deployment, including guidance on Google Tag Manager integration, Google Consent Mode configuration, and JavaScript rewrite support where required. Sprint 4 completed final compliance audits across all three domains and delivered handover documentation.

The Privacy Rights Automation workstream ran concurrently. DPG began with a full review of the existing OneTrust PRA environment, documenting the state of all webforms, workflows, response templates, and data. This informed a cleanse phase, in which stale and incorrectly configured artefacts were assessed and updated. DPG then rebuilt the module: a unified webform capable of routing both consumer and employee requests from California and Texas, jurisdiction-specific workflows for each right and individual type under CCPA/CPRA and TDPSA, automated routing rules, and standardised response templates. Solution sign-off was iterative, with the client conducting two full reviews before final acceptance.

Throughout both workstreams, a dedicated project manager maintained fortnightly sprint reviews with the client, a live project tracker visible to both teams, and a dedicated support email for real-time escalation. Risk and issue tracking was maintained in a RAID log updated at each sprint, ensuring that dependencies — including a third-party subdomain provider whose implementation timeline required active management — were surfaced and addressed promptly.

Technology and Tools Used

The engagement was built on the OneTrust platform, across two of its primary modules.

OneTrust Cookie Compliance was used to perform domain scanning, cookie categorisation, consent banner configuration, geolocation rule management, and script generation. DPG’s status as the first OneTrust Certified Deployment Partner, with 90% of implementation staff holding OneTrust Fellow certification, meant that the platform was configured to its current best-practice standard rather than to legacy defaults. This distinction mattered: the client’s pre-engagement configuration had been built on an outdated script.

OneTrust Privacy Rights Automation was used to manage the end-to-end data subject request lifecycle. The module was configured to support both CCPA/CPRA and TDPSA obligations simultaneously, with automated routing logic that correctly identifies and processes requests by jurisdiction and individual type. The webform was implemented directly on the client’s website and intranet.

Google Tag Manager was used to deploy consent scripts across the ordering subdomain, and Google Consent Mode was configured to ensure that advertising and analytics tracking downstream of the consent layer behaved correctly — protecting the client’s marketing data flows while maintaining compliance.

What We Delivered

Across both workstreams, DPG delivered the following:

Cookie Compliance:

  • Full compliance audit and cookie scan across three domains
  • Recategorisation of 35 previously uncategorised cookies and correction of incorrectly categorised cookies across all domains
  • Configured and branded consent banners and preference centres for each domain
  • Geolocation rule configuration covering CCPA, CPRA, and other applicable regulations, linked to the appropriate consent templates
  • Updated and republished OneTrust scripts; Google Tag Manager container updates and Google Consent Mode configuration
  • JavaScript rewrite guidance where blocking methods required it
  • Final compliance audit reports confirming compliant status across all three domains
  • Handover documentation covering configuration, maintenance procedures, and future change guidance

Privacy Rights Automation:

  • Full review and cleanse of the existing OneTrust PRA environment, including 147 historic requests, stale workflows, and outdated webforms
  • Rebuilt PRA module: single unified webform for consumer and employee request intake
  • Jurisdiction-specific workflows for each right type under CCPA/CPRA and TDPSA, including automated task assignment, deadline tracking, and guidance text for process actors
  • Automated routing logic to correctly direct requests by jurisdiction, with resolution of the misconfiguration that had been incorrectly rejecting valid California and Texas requestors
  • Standardised response templates aligned to each jurisdiction, right type, and request outcome
  • OneTrust platform configuration: branding, SSO, organisational structure, user roles and groups, and SMTP email setup
  • Ongoing managed service: monthly compliance monitoring, regulatory update reviews, monthly reporting, and ad hoc support
restaurant group cs 05 - The Data Privacy Group

Value Delivered

The most immediate value was the elimination of a material and documented compliance risk. Prior to engagement, 52 cookies were dropping on the primary domain without any form of user consent — a state that was directly auditable and enforceable under CPRA. That risk was fully resolved. All three domains passed their final compliance audits, and the geolocation and consent logic now correctly applies the appropriate regulatory framework to each user session.

The Privacy Rights Automation rebuild delivered a qualitatively different capability. Before the engagement, the client’s PRA environment was processing requests incorrectly: valid requestors from California and Texas were being rejected due to a routing misconfiguration, and requests that did enter the system were routinely missing their legal response deadlines. The rebuilt module now correctly identifies, routes, and tracks requests from both jurisdictions, with automated workflows that assign tasks, apply deadlines, and generate compliant responses. This reduces the operational burden on internal teams and materially reduces the risk of enforcement action arising from missed response obligations.

The ongoing managed service extends this value beyond the initial implementation. Cookie compliance is not a static state: new cookies are introduced by third-party tools, regulations change, and OneTrust scripts require periodic republishing. The managed service ensures that compliance is maintained continuously, with monthly audits, regulatory monitoring, and script updates — without requiring the client to maintain specialist OneTrust expertise in-house.

Client satisfaction following the engagement was rated 5 out of 5. Across all assessed dimensions — delivery quality, timeliness, communication, expertise, and business impact — the engagement was rated Excellent. The client specifically identified the delivery lead’s depth of technical and regulatory knowledge as the standout value driver. Overall experience was rated Very Good, and the client indicated they would be likely to recommend DPG to peers.

“Finn brought great knowledge and expertise.”

VP Information Technology, Restaurant Group

Why This Matters

The restaurant and hospitality sector has historically been slower than financial services or healthcare to address digital privacy compliance — but regulatory exposure is no less real. Consumer brands in this space collect significant volumes of behavioural data through their digital channels: browsing, ordering, loyalty, and marketing touchpoints all generate data flows that are subject to state privacy law. For operators with locations or customers in California, CCPA and CPRA apply. The TDPSA extends similar obligations to Texas. State privacy legislation continues to expand across the US.

The engagement illustrates a pattern that is common across the sector: an organisation that had invested in compliance tooling but lacked the specialist expertise to configure and maintain it correctly. OneTrust is a capable platform, but its value is entirely dependent on the quality of its implementation. A misconfigured consent banner, an absent geolocation rule, or a broken workflow does not reduce regulatory risk — it creates a documented record of non-compliance that is directly accessible to regulators and, in some cases, to consumers.

Proactive engagement with a specialist partner, before an enforcement action or consumer complaint, is consistently the more cost-effective path. The cost of remediation is a fraction of the cost of a regulatory investigation, and the reputational protection that comes from demonstrable compliance cannot easily be recovered once it is lost.

Is Your Digital Estate Compliant?

If your organisation operates consumer-facing digital properties and has not recently validated the state of your cookie compliance, privacy rights automation, or OneTrust configuration, the risk is likely greater than it appears. Compliant-looking consent banners frequently mask material configuration errors that create genuine regulatory exposure.

The Data Privacy Group works with organisations across all sectors to audit, implement, and maintain privacy compliance programmes that are defensible, operationally efficient, and built to last. As the first OneTrust Certified Deployment Partner and the only certified partner for OneTrust data discovery, DPG brings a depth of platform expertise that no generalist consultancy can replicate.

Contact DPG today to schedule a no-obligation compliance review of your digital estate.

Share this article

Go to Top