Does your site set tracking cookies before consent?
Type your address. The check opens your homepage as a first-time visitor who has not clicked anything yet, and shows which cookies and tracking scripts appear before consent.
What the check looks at
- Cookies from the server
- What the server sets on the first visit, split into likely necessary, tracking and not recognised.
- Tracking scripts
- Google Analytics, Tag Manager, Google Ads, Meta Pixel, LinkedIn, TikTok, Hotjar, Clarity and more, and whether each loads at once or waits for consent.
- Consent tool
- Cookiebot, CookieYes, OneTrust, Complianz, Usercentrics, iubenda and others, and whether they hold scripts back.
- Google Consent Mode
- Whether Google tags get a denied default, and get it before they start.
- Videos and maps
- YouTube and Google Maps players that load together with the page.
- What it cannot see
- Cookies written later by scripts, and what is inside a Google Tag Manager container. The check does not run JavaScript.
What “before consent” means
Someone opens your site for the first time and sees the banner, but has not clicked yet. If their browser already holds a _ga or _fbp cookie, or has loaded Meta Pixel, your site has stored something on their device without consent. A banner beside analytics that already runs changes nothing.
Without consent you may store only what the site needs to do what the visitor asked: a cart or login session, form protection, load balancing, the banner choice. The Article 29 Working Party listed these exemptions in Opinion 04/2012 and noted that analytics, even your own, is not among them.
What the rules say
Article 5(3) of the ePrivacy Directive (2002/58/EC) requires consent for storing or reading information on a user’s device, unless it is strictly necessary for a service they asked for. In Poland the rule is Article 399 of the Electronic Communications Law (Prawo komunikacji elektronicznej), in force since 10 November 2024, which replaced the Telecommunications Law; its Article 400 points to the data protection rules, that is the GDPR, for that consent.
In its March 2025 bulletin the Polish data protection authority (UODO), following the European Data Protection Board, reminds that cookie consent must be freely given, informed, unambiguous and given by an active step. A pre-ticked box is not consent (EU Court of Justice, Planet49, C-673/17). Under the Board’s Guidelines 2/2023 the same rule also covers tracking pixels.
How to fix it
The consent tool has to hold scripts back, not just show a banner. In Cookiebot and similar tools, turn on automatic blocking or tag scripts with a consent category; Complianz on WordPress does this itself for scripts it knows. In Google Tag Manager, set Consent Mode to denied by default before the container starts, and require consent for non-Google tags such as Meta Pixel. Show videos and maps as an image that loads the player on click.
Then run this check again and open the site in a private window: before clicking anything, press F12, open the Application tab and the cookie list. Only the necessary ones should be there.
Sources
- Directive 2002/58/EC, Article 5(3) (EUR-Lex)
- Polish Electronic Communications Law, Articles 399 and 400 (Journal of Laws 2024 item 1221, ISAP, in Polish)
- UODO bulletin, March 2025: cookies (PDF, in Polish)
- EDPB, Guidelines 2/2023 on the technical scope of Article 5(3) (PDF)
- Article 29 Working Party, Opinion 04/2012, WP194 (PDF)
- EU Court of Justice, judgment of 1 October 2019, C-673/17 Planet49
Questions
Can Google Analytics run before consent?
Usually not: _ga cookies serve statistics, not the working of the site. Consent Mode with a denied default is different: Google tags load but write no analytics or ad cookies until consent. In advanced mode they still send cookieless measurements to Google, so ask your data protection officer whether that works for you.
I have a cookie banner. Why do scripts load at once?
A banner only asks. An ordinary script in the page runs straight away unless the consent tool holds it back. Some tools do that inside the browser, which this check cannot see, so then it says “possibly”, not “yes”.
The check found nothing. Is my site fine?
Nothing in the server response or the homepage code tracks before consent. The check cannot see cookies that scripts write later, or other pages, so to be sure look at the cookie list in a private window (F12) before clicking.
Can I use this result as proof of GDPR compliance?
No. It is a technical observation of one homepage visit, not legal advice or an audit. Use it to find what to fix and to brief your developer; leave the compliance assessment to your data protection officer or a lawyer.
Other free tools
The full scan runs 20+ checks in about 90 seconds.
Free, no account. You get a plain-language report and a brief for your developer.
Go to the full scan