Cookie banner and GDPR check

Most cookie banners are not broken because they are missing, but because they arrive too late. The banner sits neatly on screen while Google Analytics, the Meta pixel and three ad networks have long since fired. Legally that is the moment that counts: prior consent means before anything happens, not somewhere during.

Lees deze pagina in het Nederlands

Run free audit

How we measure

The check loads your page cold — no prior session, no stored preferences — and clicks nothing. It then records which requests went to known tracking domains and which cookies were set, all before anything was accepted.

That is deliberately the strictest and simultaneously the fairest measurement, because it is exactly the scenario Article 5(3) of the ePrivacy Directive governs, with the GDPR setting the bar for what counts as valid consent. A banner that behaves properly after acceptance does not undo the problem that already occurred.

What gets found

The privacy category reports four things:

  • Trackers loaded before consent, with the domain and the captured request attached
  • Non-essential cookies already set on a first visit
  • Cookies with unsafe attributes — no Secure, no HttpOnly, or an overly permissive SameSite
  • A missing consent mechanism while tracking is present, and a missing link to your privacy policy

Functional cookies are fine

Not every cookie requires consent. A session cookie remembering your basket, a cookie storing a language choice, a token keeping someone logged in — those are strictly necessary for a service the visitor asked for themselves, and they are allowed without a banner.

The distinction lies in the purpose, not the party. Analytics is the well-known grey area: genuinely anonymised statistics you host yourself are treated more leniently in practice than an analytics service forwarding data to a third party. The audit draws that distinction where it can and flags it where the judgement is yours.

Why this is more than a fine risk

Enforcement on cookie banners has visibly tightened across Europe, and regulators have issued substantial fines for precisely this pattern. But the practical argument arrives sooner: if your trackers fire before consent, your consent records are worth nothing. Faced with a complaint, you cannot demonstrate that you do what you say you do.

And there is a technical flip side. Trackers firing immediately on load also cost you speed — they compete with your own content for bandwidth and for the main thread. Deferring them properly until after consent is often an immediate, measurable improvement to your Core Web Vitals.

Frequently asked questions

Is this legal advice?
No. The check measures factual behaviour: which requests and cookies exist, and when. Whether that is permitted in your specific situation is a question for a privacy lawyer.
My cookie banner comes from an external service. Can anything still go wrong?
Certainly. A consent management platform only blocks the scripts correctly wired into it. A pixel someone later pasted straight into the template simply goes around it. That is exactly what this measurement exposes.
Is the banner itself assessed?
We establish whether a consent mechanism is present and whether tracking happens before that consent. Whether the buttons are equally weighted — refusing as easy as accepting — is a judgement a human has to make.

Curious what is on your own site? Paste a URL and you have a report within a minute.

Run free audit