Let’s run the numbers before we get to the sudden, but inevitable, plot twist:
- In 2025, U.S. shoppers spent $44.2 billion online across the five-day Cyber 5 stretch — Thanksgiving and Black Friday through Cyber Monday — driven by nearly 135 million people shopping online in that same window.
- The year before, UK shoppers spent £1.12 billion online on Black Friday alone, the country's biggest online shopping day since 2021. And Cyber Monday captured 42% of Black Friday-weekend order volume compared to 30% for Black Friday itself.
This all bodes well for BFCM 2026, but here’s that twist: those record-breaking shopping volumes also increased the amount of data collected without valid user consent.
Companies can suffer badly for this gap. In 2025, Google and Shein were fined a combined €475 million for privacy violations that included placing advertising cookies without valid user consent.
Regulators don't reserve enforcement for companies of that size, either. In 2025 alone, CNIL issued 67 simplified confidential sanctions against micro-enterprises, SMEs, and liberal professions, alongside its headline enforcement actions against Google and Shein.
One driving force is the four letters that retailers are getting increasingly familiar with: General Data Protection Regulation (GDPR), whose influence now extends well beyond Europe as privacy laws around the world adopt many of its underlying principles.
GDPR can apply even when a company is headquartered outside the EU if it offers goods or services to people there or monitors their behavior.
That's the reach that makes "we're not a European company" beside the point, and it's the same logic Brazil's LGPD, Canada's PIPEDA, and a growing list of other frameworks have since adopted.
‘Ask first’ stopped being a European thing a while ago
Every click, cart, and checkout during BFCM arrives at light-speed. This unrelenting pace is exactly why many (mostly U.S.) companies’ philosophy of “just track everything” — every shopper's browsing and purchase data, no questions asked — seems almost reasonable, even responsible.
But that's exactly what makes it dangerous.
Why most sites still get this wrong
Everybody knows about GDPR. But knowing the rules and following them are two different things. A 2025 study examining thousands of leading websites across 31 countries found only 15% met its minimum standard for a compliant cookie banner.







The U.S. is busy building its own patchwork of GDPR-style rules, too. Nearly 20 states now have comprehensive consumer privacy laws on the books. With no federal law tying them together, that's nearly 20 separate rulebooks a U.S. retailer can trip over.
If you have sloppy consent shortcuts in place during BFCM, you're running them at the exact moment you're collecting the most data all year... which means whatever exposure exists gets scaled up accordingly.
Consent pays for itself







But here’s another plot twist: the same behavior that keeps you off a regulator's radar is the one that earns you a customer's loyalty.
Altering processes and systems to accommodate GDPR (and GDPR-like) rules sounds like a pain. But flip the picture around, and you’ll see consent works like an investment. If you ask for consent up front from customers — in the form of a clear ask — it earns you more data down the line.
Asking before taking also loosens purse strings. Forty-six percent of consumers say they'd willingly share more of their data if companies were clearer about what's being collected. And it doesn't stop at data — three in five consumers say they're more loyal to brands that clearly explain their privacy practices, with data governance now their top priority for companies to improve.
How Audiense Online keeps you consent-clean
Audiense Online, powered by Elevar, includes capabilities that automatically enforce consent at the point of collection, keep your measurement intact, and make compliance verifiable. Elevar isn't a consent management platform itself; it integrates with the CMP you already run and enforces whatever decision it passes along.
Most stores use the standard setup, which collects data but holds it back from destinations until consent is granted. Strict Consent Mode goes a step further for stores with more geographic or legal exposure: no tracking at all until a shopper opts in.
- A "no thanks" doesn't leave you flying blind: Cookieless tracking for Google Analytics and Google Ads keeps a privacy-safe pulse on performance, even from shoppers who opt out. You still get a read on what's working, just without the personal data attached to it.
- No data before consent, held as a system-level rule: In Strict Consent Mode, Elevar blocks all tracking, storage, and processing until a shopper explicitly opts in. That's not a setting someone can forget to toggle; it's enforced at the system level, so the rule holds whether or not anyone's watching.
- It plugs into what you're already running: Elevar works with the Shopify Privacy API, Audiense Online's own Consent API, or Google Consent Mode. That means no rip-and-replace; your existing setup becomes the enforcement layer instead of getting swapped out for something new, whether you're on a standard Shopify storefront or a headless build.
To be clear, no compliance tool can guarantee a specific legal outcome. That depends on how you configure it, what you collect elsewhere, and how regulators interpret a given case.
What it can do is enforce the rule consistently, not leave the outcome to chance. Every claim in this blog post holds at "supports" or "helps you comply," because that's the honest scope of what software does.
All upside, no downside, to proving consent
Picture this: three weeks after BFCM, a customer submits an erasure request — their right to be forgotten, under GDPR — asking you to delete everything you've collected on them.
This request used to trigger:
- A scramble through five different tools
- A Slack thread nobody wants to be tagged in
- With a 30-day clock ticking the whole time
But with Elevar, erasure isn't a scramble:
- The deletion runs automatically once the request comes in through Shopify (or another platform)
- No manual work across five different tools
- You can close out the request same-day instead of scrambling to make the 30-day deadline
That's the moment the twist resolves in your favor. Consent, handled right, compounds; more data, more trust, more of the relationship. When data is the whole game, that's the actual prize.
How to get there
BFCM 2026 will run on more data than any year before it, and the retailers who win it won't be the ones who collected the most — they'll be the ones who can demonstrate it was collected in accordance with your consent and privacy requirements.
That's what Elevar is built for: consent enforced at the system level, tracking that holds up when a shopper asks, and a stack you can defend without a scramble.
The brands that treat consent as infrastructure this BFCM are the ones customers trust with next year's data, too. Learn how Audiense Online, powered by Elevar, gets you there or schedule a demo.





















