Free tool
Free Cookie Consent Checker
We open your site in a real browser and watch what actually loads before anyone clicks: the trackers that fire, the cookies that get set, and whether refusing is as easy as accepting. A static scanner reads your markup and cannot see any of it.
The check runs from our servers, not your browser. We open the page in a real browser once, click nothing, and record what loaded. We keep the host you checked, your IP address and your browser string to prevent abuse, and Cloudflare Turnstile verifies the request. We never store the page itself, its cookies' values, or anything it displayed.
Example result
1 of 4 checks passed on this one URL
example.com, illustrative. Run a check for your own.
- CriticalTwo known trackers loaded before anything was clicked
- CriticalThree cookies scoped to other hosts were already set
- WarningRefusing needs a second screen, accepting is one click
- PassA privacy policy is linked on this page
- InfoGPC signal sent, and what still loaded with it set
Illustrative, for a fictional site. Your own report replaces this panel when you run a check.
Your report will show
Tracking before a consent choice
Known trackers that loaded even though the page shows a consent banner.
Cookies set before any interaction
Cookies scoped to other hosts, already in the jar when the page finished loading.
Refusing is as easy as accepting
Whether a banner exists, and whether refusing takes one click or a second screen.
A privacy policy is linked
Whether a link on this page references a privacy policy.
Global Privacy Control signal
What still loaded with a GPC signal set, and what that does and does not tell you.
One page load, nothing clicked. No score and no grade: counts only.
The short answer
What is a cookie consent checker?
The one-paragraph version, before the detail.
A cookie consent checker loads a page the way a visitor would and records what happens before anyone agrees to anything: which third-party domains are contacted, which cookies are already in the jar, and whether the consent banner offers a way to refuse that is as easy as the way to accept. It is a measurement of behaviour rather than of code, because consent obligations are about what your site actually does in the first second. It cannot tell you whether you are compliant, and nothing that runs in one second can: it tells you what a regulator or a complainant would see if they looked.
The difference
Why a real browser, not a static scan
Consent behaviour happens after the page loads, which is exactly where a static checker stops looking.
A static scanner fetches your HTML and reads it. That is enough to find a script tag, and it is not enough to find a tracker: modern tags are injected by a tag manager, loaded from inside another script, or fired by a consent platform milliseconds after the page settles. None of that exists in the markup a static fetch receives, so a static checker reports a clean page and a visitor's browser does something else entirely.
Cookies have the same problem in a sharper form. A cookie set by JavaScript, or by a third-party response header on a sub-resource, is never in the document at all. The only way to know what is in the jar is to have a jar, which means running a browser, letting the page finish, and looking.
So that is what this does. One load, nothing clicked, and a list of what already happened. Because nothing is clicked, everything observed is by definition pre-consent: that is an observation rather than an inference, and it is the one claim a single load supports completely. Read the region-by-region breakdown for 2026.
What a static scan misses
- Tags injected at runtimeA tag manager writes the script element after the document parses. It is never in the HTML.
- Cookies set by scriptNothing in the markup says a cookie exists. Only a real cookie jar can answer that.
- Which domains were contactedA request to an analytics endpoint carries the page address and identifiers whether or not the response is used.
- Whether a Reject control existsBanners are rendered by script, often inside a frame. There is no banner in the source to read.
Enforcement
What regulators check in 2026
Six things that have actually been enforced, with who enforced them. Whether any of it binds you depends on your sector and where you operate, and nothing here is legal advice.
01
Tracking that fires before the click
The most common finding in regulator sweeps and academic audits alike: a banner asking for consent while analytics and advertising tags have already loaded. Published studies of sites showing a banner put it at roughly seven in ten. A banner that appears after the tracking is a notice, not a choice.
Regulator sweeps and published academic audits
02
Refusing has to be as easy as accepting
One click to accept and a settings screen to refuse is the asymmetry regulators went after first. In January 2022 France's CNIL fined Google 150 million euros and Meta 60 million euros for exactly that shape of banner. EDPB Guidelines 05/2020 are the standard they applied.
CNIL decisions, January 2022; EDPB Guidelines 05/2020
03
Global Privacy Control is law, not a courtesy
Twelve US states now require a business to honour an opt-out preference signal sent by the visitor's browser. There is no banner to click and no interface to design: the signal arrives with the request, and ignoring it is the violation.
State privacy acts currently recognising an opt-out preference signal
04
And it is being enforced
California's first CCPA enforcement action fined Sephora 1.2 million dollars in 2022, ignoring Global Privacy Control among the failures cited. In 2025 Tractor Supply settled for 1.35 million dollars, the largest CCPA penalty so far. Both are opt-out signal cases.
California Attorney General settlements, 2022 and 2025
05
From January 2026, California asks you to say so
Updated CCPA regulations require a business to display whether it has processed a consumer's opt-out preference signal. Honouring the signal quietly stops being enough: the site has to show that it did.
CCPA regulations, in force 1 January 2026
06
Consent must be prior, and withdrawable
Under the ePrivacy Directive in the EU and PECR in the UK, storage that is not strictly necessary needs consent BEFORE it happens, not alongside it. Withdrawing has to be as easy as giving, which means a banner that never comes back is its own problem.
ePrivacy Directive Art. 5(3); PECR Reg. 6
By region
What is required where
The EU and UK ask for consent before tracking. California and the other opt-out states ask you to honour a signal instead. A site with visitors in both has to do both.
| Obligation | European Union | United Kingdom | California | GPC states |
|---|---|---|---|---|
| Consent model | Opt in | Opt in | Opt out | Opt out |
| Consent needed before non-essential storage | Applies | Applies | Does not apply | Does not apply |
| A visible consent interface is expected | Applies | Applies | Notice at collection | Notice at collection |
| Refusing must be as easy as accepting | Applies | Applies | Does not apply | Does not apply |
| A browser opt-out signal must be honoured | Does not apply | Does not apply | Applies | Applies |
| Primary instrument | ePrivacy Art. 5(3), GDPR | PECR Reg. 6, UK GDPR | CCPA and CPRA | State privacy acts |
The twelve states currently recognising a browser opt-out preference signal are the ones this tool's GPC check is aimed at. Coverage changes as new state acts commence, so treat this as orientation rather than as advice, and check your own obligations.
FAQ
Straight answers.
Including the one this tool deliberately cannot answer.
Do I legally need a cookie banner?
What is pre-consent tracking?
Does my Reject button need to be as easy as Accept?
What is Global Privacy Control?
Full compliance scan
See your real Privacy score.
This page is one load of one URL. A scan reads every page across six dimensions and 49 documented rules, scores Privacy properly, and gives you the exact fix for each finding, mapped clause by clause to the instruments your auditors cite.
Not ready to pick one? Or scan your site free first. No account, up to 5 pages.