Home / How to audit your own cookie banner in 20 minutes

How to audit your own cookie banner in 20 minutes

Most cookie banner violations are visible in 20 minutes with free tools. Check what fires before consent, test whether reject actually blocks trackers, confirm the choice persists, and verify you have records. The majority of sites fail at least one of these four checks.

Minutes 0 to 5: the tag check

Open your site in a fresh incognito window with the network tab open, and watch what loads before you touch the banner. Every analytics request, ad pixel, and heatmap beacon that fires pre-consent is a violation under GDPR and ePrivacy, assuming those tags are non-essential. Note each one. This single check catches the most common failure on the internet: the banner that asks while the tags already ran.

Use a tag scanner for the full picture, since some tags fire conditionally or after a delay. But the incognito network tab catches the big ones in seconds, and the big ones are what regulators notice.

Minutes 5 to 10: the reject test

Click reject, or choose "reject all" in the preferences, then watch the network tab again as you browse. Non-essential tags should stop completely. If analytics keeps firing after a reject, your banner is decoration: it records a choice and ignores it. This is worse than having no reject button, because it creates a false record of compliance.

Test the tricky paths too. Reload the page and confirm the rejected state holds. Visit a subpage directly, bypassing the homepage, and confirm the banner state carries over. Consent that only works on the page where it was given is not consent.

Minutes 10 to 15: the persistence and change check

Close the browser, come back tomorrow, and confirm your choice is remembered without being asked again. Then find the "cookie settings" or "privacy choices" link and confirm you can change your mind as easily as you made it. Withdrawing consent must be as easy as giving it; a site that makes reject a one-click banner and withdraw a five-step hunt through settings pages is not compliant.

Check the banner on mobile too. A surprising number of banners are unusable on small screens: the preferences buried, the reject button off-screen, the text unreadable. Mobile is where most of your visitors are.

Minutes 15 to 20: the records review

Ask your consent tool to show you the record of your test visit: what choice was recorded, when, and in what form. Under GDPR you need to be able to demonstrate consent, which means timestamped records tied to the version of the banner the visitor saw. If your tool cannot produce this, you have a documentation gap that matters the moment anyone asks questions.

Finally, read your own cookie policy with fresh eyes. Does it name the actual cookies and vendors your tag check found? Does it match what the banner claims? The policy and the banner disagree on a remarkable number of sites, and the disagreement is usually the policy describing last year's tags. Twenty minutes, four checks, and you know where you stand. The fixes take longer, but at least now you know what they are.

What to do with what you find

Fix in order of visibility. Pre-consent tags first, because they are the clearest violation and the easiest for anyone to spot. Then the reject button, because a broken reject is actively misleading. Then persistence and the change path, then the records and the policy. Each fix is small on its own; together they move a site from decoration to compliance.

Repeat the audit quarterly, or after any site change that touches tags: a new marketing tool, a redesign, a platform migration. Consent breaks silently when the site changes around it, and the twenty-minute check is cheap insurance. Put it on the calendar next to the other recurring maintenance, and it stops being a project and starts being a habit.

Get a free consent audit of your website

Free consent audit