Skip to content

Free tools

Does your site set tracking cookies before consent?

Type your address. The check opens your homepage as a first-time visitor who has not clicked anything yet, and shows which cookies and tracking scripts appear before consent.

The check loads your homepage once and reads the cookies in the server response and the HTML. It runs no scripts, clicks nothing and does not store the page.

What the check looks at

Cookies from the server
What the server sets on the first visit, split into likely necessary, tracking and not recognised.
Tracking scripts
Google Analytics, Tag Manager, Google Ads, Meta Pixel, LinkedIn, TikTok, Hotjar, Clarity and more, and whether each loads at once or waits for consent.
Consent tool
Cookiebot, CookieYes, OneTrust, Complianz, Usercentrics, iubenda and others, and whether they hold scripts back.
Google Consent Mode
Whether Google tags get a denied default, and get it before they start.
Videos and maps
YouTube and Google Maps players that load together with the page.
What it cannot see
Cookies written later by scripts, and what is inside a Google Tag Manager container. The check does not run JavaScript.

What “before consent” means

Someone opens your site for the first time and sees the banner, but has not clicked yet. If their browser already holds a _ga or _fbp cookie, or has loaded Meta Pixel, your site has stored something on their device without consent. A banner beside analytics that already runs changes nothing.

Without consent you may store only what the site needs to do what the visitor asked: a cart or login session, form protection, load balancing, the banner choice. The Article 29 Working Party listed these exemptions in Opinion 04/2012 and noted that analytics, even your own, is not among them.

What the rules say

Article 5(3) of the ePrivacy Directive (2002/58/EC) requires consent for storing or reading information on a user’s device, unless it is strictly necessary for a service they asked for. In Poland the rule is Article 399 of the Electronic Communications Law (Prawo komunikacji elektronicznej), in force since 10 November 2024, which replaced the Telecommunications Law; its Article 400 points to the data protection rules, that is the GDPR, for that consent.

In its March 2025 bulletin the Polish data protection authority (UODO), following the European Data Protection Board, reminds that cookie consent must be freely given, informed, unambiguous and given by an active step. A pre-ticked box is not consent (EU Court of Justice, Planet49, C-673/17). Under the Board’s Guidelines 2/2023 the same rule also covers tracking pixels.

How to fix it

The consent tool has to hold scripts back, not just show a banner. In Cookiebot and similar tools, turn on automatic blocking or tag scripts with a consent category; Complianz on WordPress does this itself for scripts it knows. In Google Tag Manager, set Consent Mode to denied by default before the container starts, and require consent for non-Google tags such as Meta Pixel. Show videos and maps as an image that loads the player on click.

Then run this check again and open the site in a private window: before clicking anything, press F12, open the Application tab and the cookie list. Only the necessary ones should be there.

Questions

Can Google Analytics run before consent?

Usually not: _ga cookies serve statistics, not the working of the site. Consent Mode with a denied default is different: Google tags load but write no analytics or ad cookies until consent. In advanced mode they still send cookieless measurements to Google, so ask your data protection officer whether that works for you.

I have a cookie banner. Why do scripts load at once?

A banner only asks. An ordinary script in the page runs straight away unless the consent tool holds it back. Some tools do that inside the browser, which this check cannot see, so then it says “possibly”, not “yes”.

The check found nothing. Is my site fine?

Nothing in the server response or the homepage code tracks before consent. The check cannot see cookies that scripts write later, or other pages, so to be sure look at the cookie list in a private window (F12) before clicking.

Can I use this result as proof of GDPR compliance?

No. It is a technical observation of one homepage visit, not legal advice or an audit. Use it to find what to fix and to brief your developer; leave the compliance assessment to your data protection officer or a lawyer.

Other free tools

Read more

The full scan runs 20+ checks in about 90 seconds.

Free, no account. You get a plain-language report and a brief for your developer.

Go to the full scan