Skip to content

Free Consent Scan

Your website is probably tracking visitors before they consent

Most are. We will check yours and send you the evidence. Free, no call required.

A consent banner is not consent management. On most sites, analytics, advertising pixels and embedded content start collecting data the moment the page loads, before anyone clicks anything. The banner appears, the visitor clicks accept or decline, and it makes very little difference to what already happened. Teams usually find out from a regulator, a client security review, or their own lawyer.

Enter your URL

Free, no call required, three working days.

We use your email to send the report and nothing else. No list, no sequence.

We run a limited number of scans each week. If we are at capacity, we will tell you when yours is scheduled.

check

What we check

  • Which tags, pixels and scripts fire before consent is given
  • What happens when a visitor declines, and whether anything ignores it
  • Whether cookies are set before any choice is made
  • Whether Google Consent Mode v2 is present and correctly initialised
  • Whether your CMP blocks what it claims to block
  • Third party embeds loading on their own (video, maps, chat, ad tech)

Each case is tested in a clean session: page load, decline, and accept, tested separately so results cannot contaminate each other.

evidence

Sample finding

sample finding · descriptor only

Global manufacturer, EU division. Google Analytics, Meta Pixel and two advertising tags fired on page load, before the consent banner rendered. Declining consent stopped none of them. Consent Mode was present but never initialised, so every hit was recorded as fully consented regardless of the visitor’s choice.

report

What you receive

A PDF report containing:

  • A plain summary of whether the site is leaking data before consent
  • The list of tags and pixels involved, named
  • Network evidence and screenshots showing exactly what fired and when
  • Cookies present at each stage
  • Findings ordered by severity, with what to fix first
  • An estimate of effort for each fix

Written for whoever has to act on it. Legal can read it. So can a developer. Delivery: 3 working days.

consent-scan-report.pdf
3 working days
tags before consent
cookies set pre-choice
consent mode init
on decline: blocked
network evidence · screenshots · severity ordered
evidence
scope

What this is not

  • Not an automated scanner report. A person runs and reviews every scan.
  • Not a sales call in disguise. The report arrives by email. If you want to talk afterwards, that is your move.
  • Not legal advice. We report what your site technically does. Your counsel decides what it means for you.
fit

Who this is for

Companies with visitors in GDPR jurisdictions (EU, UK, Switzerland) and US states with privacy legislation: California, Virginia, Colorado, Connecticut, Texas, Utah, Oregon, and the growing list of others. If you run Google Analytics, advertising pixels or embedded third party content, the scan applies to you.

Sites without any analytics or advertising tags will produce a very short report, and we will tell you that instead of inventing findings.

After the report

If the report shows problems and you want them fixed, the next step is a tracking audit for full depth, or a scoped Consent Mode v2 Implementation. Both are quoted with a fixed price.

If the report is clean, you have documentation showing that, which is useful the next time someone asks.

See how we handle compliance work