Skip to content

Compliance overview

The Command center (app.monita.ai/compliance) is the screen a privacy lead keeps open: where your traffic originates, how much of it carries a consent signal, and how every property in the portfolio stands — computed from what your tags actually did, not from a questionnaire.

A US map shows event volume by state, geolocated at the edge when each event is collected — country, state and city only, no IP address stored. Three things are overlaid:

  • Event volume — state shading scales with traffic.
  • Consent-negative activity — a red marker on any state where third-party tags fired while the consent signal was negative.
  • State privacy statutes — outlined states (California, Washington, Nevada, Colorado, Connecticut, Virginia, Texas, Utah) have the privacy or wiretap laws the regulations view tracks, so “why is Washington highlighted?” answers itself on hover.

Pick a window from 24 hours to 30 days; the whole page follows it.

The Consent by vendor table shows what each vendor’s fires carried in the consent signal your CMP hookup reports — filterable to GDPR/UK or US traffic. Each vendor’s events split into:

Column Meaning
Consented Fired with an affirmative consent signal
Fired without consent Fired while the signal was negative — flagged as a breach
Indeterminate The consent payload doesn’t enumerate this vendor (e.g. a raw TCF string)
No consent data The tag fired with no consent signal attached at all

Counts are sampled from recent events, so read them as proportions rather than exact totals. To grade consent at all, your CMP must be wired into the page hook — see Consent settings.

A vendor’s row respects its consent expectation: a vendor set to consent mode (fires anonymized without consent by design, like Google Advanced Consent Mode) shows a consent mode badge instead of a breach flag, and a vendor your organization marked exempt shows a grey exempt badge. The counts stay visible either way.

The Property portfolio table gives every property a standing — Good, Review or Critical — from its open compliance issues, whether any blocked vendor is still firing, whether a CMP was detected, and when it was last audited. Critical properties sort to the top; the “Properties needing action” KPI counts them.

A property with no detected CMP shows amber not detected — unless it’s marked as having no on-page CMP by design (an in-product surface, say), in which case the column shows a neutral n/a.

The Regulations view tracks your exposure to US privacy statutes — CIPA, CCPA/CPRA, Washington My Health My Data, Nevada SB 370, VPPA, the state comprehensive acts (Colorado, Connecticut, Virginia, Texas and successors) and FTC Act §5 — by evaluating observed tag behaviour against each statute’s checks: session replay active, PII reaching ad vendors, unconsented traffic from covered states, video events flowing to ad pixels, and so on.

Each statute gets a posture:

  • Action needed — at least one critical signal, with the evidence attached.
  • Review — warning-level signals worth a look.
  • No signals — nothing observed in the window trips the statute’s checks.

Statutes that don’t apply to your business can be ignored per organization; any open issue they raised auto-resolves.

Every compliance page carries Export report, which produces the evidence auditors ask for:

  • Evidence pack (PDF) — a print-ready summary of posture, vendors and findings.
  • Vendor register (CSV) — every observed vendor with its policy verdict, from Vendor lists.
  • PII findings (CSV) — detections from the PII viewer.
  • Full data (JSON) — everything, machine-readable.

Exports are authenticated downloads — the report is organization data, never a bare link.