The banner can look perfect while the tags fire the moment the page loads - before anyone clicks "accept". In the EU that's a real liability. We watch the actual order of events and tell you what fired, and when.
We measure when each platform fires relative to the consent decision. Anything that sends data before "accept" is flagged - the single most common GDPR gap.
Are ad and analytics tags actually gated by consent state, or is the integration cosmetic? We check the signal, not just the banner.
If gcs says G100 (denied) but data still flows, consent is being ignored. We catch that contradiction.
Email or phone in URLs or event parameters is a ToS breach and a GDPR problem at once. We surface it.
This is not legal advice. We technically verify when tags fire, which consent signals are sent, and whether data is transmitted before the visitor’s choice.
Consent that's wired wrong doesn't just risk a fine - it quietly corrupts your data. Tags blocked when they shouldn't be lose conversions; tags firing when they shouldn't inflate them. Either way your reports and your bidding learn from the wrong numbers.
The free scan already flags consent timing on your homepage. The full audit walks the whole journey.