Finance and accounting decision

Iubenda

A competent developer can build a narrow self-hosted CMP + policy generator and basic scanner, but reproducing iubenda's legal updates, certifications, enterprise features, and trust signals is impractical without a legal team and long-term investment.

Visit website
Subscription$5.99/month ✓ verified
Initial build80 hours
Monthly upkeep6 hours + $20
Evidence3/3 runs agree

Open-source builds that already do this

Every project below is open source and already does this job today. Fork one, self-host it, or take the parts you need — the build prompt further down assumes an empty file, and this is the shortcut past that. Licences differ; check the one on each card before you ship.

What a replacement has to do

  • Detect site trackers and cookies, show a consent banner, record user consents, generate and host privacy/cookie/terms documents, and run periodic site scans for new third-party services.

What it still won’t have

  • Lawyer-drafted automatic updates backed by an in-house legal team
  • Google-certified CMP / IAB validation and associated trust signals
  • Hourly site scans and advanced analytics available on higher tiers
  • Enterprise-grade features like mobile SDK, consent recovery, and white-labeling support
  • Dedicated support included on paid plans

What remains hard

  • Brand trustTrusted by 150,000+ customers
  • Brand trust15+ years at the forefront of digital compliance
Read the build prompt

First-year cost

Keep paying

Paying ischeaper in year one.

On cash alone, building overtakes the subscription at 5 seats.

Paid seatsseats

Money you would actually spend

Keep paying

Subscription price × seats × 12

Build it

AI build APIs + hosting

Time you would spend

What you would spend

What we assumed

The verdict above measures whether you could build it. This one is only about money.

Runnable build prompt

Not run yet
Build a minimal self-hosted privacy & consent service using: React frontend, Node.js + Express API, PostgreSQL, and a small crawler in Node. In scope: (1) a customizable cookie-consent banner that blocks scripts until consent and exposes a JS API; (2) REST endpoints to record consents and export a consent log; (3) a policy-generator that assembles selectable clause templates into a hosted policy page; (4) a basic crawler that scans a target site for third-party script domains and maps cookies; (5) admin UI to view consents, trigger scans, and edit policy text. Out of scope: lawyer review, formal certifications (IAB/Google), enterprise scaling, mobile SDK, and white-label portal. Include TLS, Docker deployment manifests, automated DB migrations, error handling, and unit/integration tests for API and banner behavior.
How we checked4 sources · 3/3 runs agreed · evidence score 67

How the score was reached

  • Partly verdict base52
  • An open-source build was found+5
  • 4 cited sources+3
  • Price verified on pricing page+3
  • 3/3 assessment runs agreed+4
  • Evidence score67

The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time — so the same evidence always produces the same number.

How scoring works →

Cited sources · 4

Every page the run actually retrieved.

Integrity checks

What held up, and what did not.

✓ Price read off the page✓ 3 independent runs, one answer✓ Citations limited to fetched pages! 2 moats quoted from the page