Free tool

Free Cookie Consent Checker

We open your site in a real browser and watch what actually loads before anyone clicks: the trackers that fire, the cookies that get set, and whether refusing is as easy as accepting. A static scanner reads your markup and cannot see any of it.

GDPR and ePrivacy · CCPA and GPC in 12 US states · a real browser, not a static fetch

The check runs from our servers, not your browser. We open the page in a real browser once, click nothing, and record what loaded. We keep the host you checked, your IP address and your browser string to prevent abuse, and Cloudflare Turnstile verifies the request. We never store the page itself, its cookies' values, or anything it displayed.

Example result

1 of 4 checks passed on this one URL

example.com, illustrative. Run a check for your own.

  • CriticalTwo known trackers loaded before anything was clicked
  • CriticalThree cookies scoped to other hosts were already set
  • WarningRefusing needs a second screen, accepting is one click
  • PassA privacy policy is linked on this page
  • InfoGPC signal sent, and what still loaded with it set

Illustrative, for a fictional site. Your own report replaces this panel when you run a check.

Your report will show

  • Tracking before a consent choice

    Known trackers that loaded even though the page shows a consent banner.

  • Cookies set before any interaction

    Cookies scoped to other hosts, already in the jar when the page finished loading.

  • Refusing is as easy as accepting

    Whether a banner exists, and whether refusing takes one click or a second screen.

  • A privacy policy is linked

    Whether a link on this page references a privacy policy.

  • Global Privacy Control signal

    What still loaded with a GPC signal set, and what that does and does not tell you.

One page load, nothing clicked. No score and no grade: counts only.

The short answer

The one-paragraph version, before the detail.

A cookie consent checker loads a page the way a visitor would and records what happens before anyone agrees to anything: which third-party domains are contacted, which cookies are already in the jar, and whether the consent banner offers a way to refuse that is as easy as the way to accept. It is a measurement of behaviour rather than of code, because consent obligations are about what your site actually does in the first second. It cannot tell you whether you are compliant, and nothing that runs in one second can: it tells you what a regulator or a complainant would see if they looked.

The difference

Why a real browser, not a static scan

Consent behaviour happens after the page loads, which is exactly where a static checker stops looking.

A static scanner fetches your HTML and reads it. That is enough to find a script tag, and it is not enough to find a tracker: modern tags are injected by a tag manager, loaded from inside another script, or fired by a consent platform milliseconds after the page settles. None of that exists in the markup a static fetch receives, so a static checker reports a clean page and a visitor's browser does something else entirely.

Cookies have the same problem in a sharper form. A cookie set by JavaScript, or by a third-party response header on a sub-resource, is never in the document at all. The only way to know what is in the jar is to have a jar, which means running a browser, letting the page finish, and looking.

So that is what this does. One load, nothing clicked, and a list of what already happened. Because nothing is clicked, everything observed is by definition pre-consent: that is an observation rather than an inference, and it is the one claim a single load supports completely. Read the region-by-region breakdown for 2026.

What a static scan misses

  • Tags injected at runtimeA tag manager writes the script element after the document parses. It is never in the HTML.
  • Cookies set by scriptNothing in the markup says a cookie exists. Only a real cookie jar can answer that.
  • Which domains were contactedA request to an analytics endpoint carries the page address and identifiers whether or not the response is used.
  • Whether a Reject control existsBanners are rendered by script, often inside a frame. There is no banner in the source to read.

Enforcement

What regulators check in 2026

Six things that have actually been enforced, with who enforced them. Whether any of it binds you depends on your sector and where you operate, and nothing here is legal advice.

  • 01

    Tracking that fires before the click

    The most common finding in regulator sweeps and academic audits alike: a banner asking for consent while analytics and advertising tags have already loaded. Published studies of sites showing a banner put it at roughly seven in ten. A banner that appears after the tracking is a notice, not a choice.

    Regulator sweeps and published academic audits

  • 02

    Refusing has to be as easy as accepting

    One click to accept and a settings screen to refuse is the asymmetry regulators went after first. In January 2022 France's CNIL fined Google 150 million euros and Meta 60 million euros for exactly that shape of banner. EDPB Guidelines 05/2020 are the standard they applied.

    CNIL decisions, January 2022; EDPB Guidelines 05/2020

  • 03

    Global Privacy Control is law, not a courtesy

    Twelve US states now require a business to honour an opt-out preference signal sent by the visitor's browser. There is no banner to click and no interface to design: the signal arrives with the request, and ignoring it is the violation.

    State privacy acts currently recognising an opt-out preference signal

  • 04

    And it is being enforced

    California's first CCPA enforcement action fined Sephora 1.2 million dollars in 2022, ignoring Global Privacy Control among the failures cited. In 2025 Tractor Supply settled for 1.35 million dollars, the largest CCPA penalty so far. Both are opt-out signal cases.

    California Attorney General settlements, 2022 and 2025

  • 05

    From January 2026, California asks you to say so

    Updated CCPA regulations require a business to display whether it has processed a consumer's opt-out preference signal. Honouring the signal quietly stops being enough: the site has to show that it did.

    CCPA regulations, in force 1 January 2026

  • 06

    Consent must be prior, and withdrawable

    Under the ePrivacy Directive in the EU and PECR in the UK, storage that is not strictly necessary needs consent BEFORE it happens, not alongside it. Withdrawing has to be as easy as giving, which means a banner that never comes back is its own problem.

    ePrivacy Directive Art. 5(3); PECR Reg. 6

By region

What is required where

The EU and UK ask for consent before tracking. California and the other opt-out states ask you to honour a signal instead. A site with visitors in both has to do both.

Cookie consent obligations by region
ObligationEuropean UnionUnited KingdomCaliforniaGPC states
Consent modelOpt inOpt inOpt outOpt out
Consent needed before non-essential storageAppliesAppliesDoes not applyDoes not apply
A visible consent interface is expectedAppliesAppliesNotice at collectionNotice at collection
Refusing must be as easy as acceptingAppliesAppliesDoes not applyDoes not apply
A browser opt-out signal must be honouredDoes not applyDoes not applyAppliesApplies
Primary instrumentePrivacy Art. 5(3), GDPRPECR Reg. 6, UK GDPRCCPA and CPRAState privacy acts

The twelve states currently recognising a browser opt-out preference signal are the ones this tool's GPC check is aimed at. Coverage changes as new state acts commence, so treat this as orientation rather than as advice, and check your own obligations.

Full compliance scan

See your real Privacy score.

This page is one load of one URL. A scan reads every page across six dimensions and 49 documented rules, scores Privacy properly, and gives you the exact fix for each finding, mapped clause by clause to the instruments your auditors cite.

Not ready to pick one? Or scan your site free first. No account, up to 5 pages.