Consent & GDPR

A cookie banner isn't the same as consent that works.

The banner can look perfect while the tags fire the moment the page loads - before anyone clicks "accept". In the EU that's a real liability. We watch the actual order of events and tell you what fired, and when.

Home / Consent & GDPR check

What we check

⏱️

Tags firing before consent

We measure when each platform fires relative to the consent decision. Anything that sends data before "accept" is flagged - the single most common GDPR gap.

🔧

Consent Mode v2 wiring

Are ad and analytics tags actually gated by consent state, or is the integration cosmetic? We check the signal, not just the banner.

🚦

gcs signal correctness

If gcs says G100 (denied) but data still flows, consent is being ignored. We catch that contradiction.

🔐

PII leaking into tracking

Email or phone in URLs or event parameters is a ToS breach and a GDPR problem at once. We surface it.

Measured the right way: we evaluate duplicates and firing after the consent window too, so a legitimate consent re-fire isn't reported as a false alarm. You see real problems, not noise.

Why it matters beyond compliance

This is not legal advice. We technically verify when tags fire, which consent signals are sent, and whether data is transmitted before the visitor’s choice.

Consent that's wired wrong doesn't just risk a fine - it quietly corrupts your data. Tags blocked when they shouldn't be lose conversions; tags firing when they shouldn't inflate them. Either way your reports and your bidding learn from the wrong numbers.

Check your consent setup

The free scan already flags consent timing on your homepage. The full audit walks the whole journey.