Website Cookie Audit: Inventory, Consent and Opt-Out Tests

Audit cookies, pixels, local storage and similar technologies across page states, then test UK/EU consent or California opt-out behaviour within the correct scope.

Updated

Published by AuditWeb

What Is a Cookie Audit

A cookie audit records each storage or access technology, its provider, purpose, data, duration, recipients and behaviour before and after a user's choice. It includes cookies, local storage, pixels, tags, SDKs and device fingerprinting where applicable.

The output is a dated technical inventory plus test evidence. Legal counsel or the responsible privacy team must decide which laws apply and whether the observed behaviour complies with them.

Why Cookie Evidence Matters

  • Notices: Compare the live technologies and recipients with the cookie and privacy information shown to users.
  • Choice: Verify that accept, reject, category and withdrawal controls change actual network and storage behaviour.
  • Change control: Detect new tags or vendors introduced through a tag manager, plugin, embed or deployment.
  • Jurisdiction: Separate UK PECR or EU ePrivacy consent questions from California sale-or-sharing opt-outs and from personal-data processing under GDPR.

How to Classify Technologies

Classify from the technology's actual purpose and operation rather than its vendor label. A tool may create several identifiers with different purposes and retention periods.

  • Service delivery: Record whether the technology is essential to a service the user requested. Convenience to the operator does not by itself make a technology strictly necessary.
  • Preferences: Record the requested feature, identifier, expiry and whether the relevant regulator treats that use as exempt.
  • Measurement: Record data fields, identifiability, recipients and configuration. Do not assume every analytics implementation has the same consent status.
  • Advertising: Record profiling, cross-site or cross-context use, sale or sharing, and downstream recipients. Assess consent and opt-out duties separately by jurisdiction.

How to Audit Cookies

  1. Define the sample: Include the home page, landing pages, account and checkout flows, embedded media, logged-in states and routes with different tag-manager rules.
  2. Capture a clean visit: Clear site data or use a fresh browser profile. Save cookies, local and session storage, IndexedDB entries and network requests before interacting with a banner.
  3. Exercise every choice: Repeat the same routes after accept all, reject all, category choices, withdrawal and any recognised browser privacy signal.
  4. Trace each item: Record name, domain, first or third party, setter request, purpose, data, expiry, recipients and the code or tag that created it.
  5. Reconcile documents: Compare the evidence with the consent interface, privacy notice, cookie information, vendor contracts and internal processing record.
  6. Retest changes: Verify the original requests no longer fire when blocked and that essential user tasks still work.

Jurisdiction Boundaries

Cookie law is not one global rule. Identify the user's location, the operator, the technology and the processing purpose before interpreting a result.

  • United Kingdom: PECR regulates storing information on or accessing information from a device. The ICO's April 2026 guidance describes current exceptions and how UK GDPR consent relates to PECR.
  • European Union: National laws implement the ePrivacy rules and GDPR may govern related personal-data processing. Check the relevant member-state authority and current EU law.
  • California: CCPA is not a general prior-cookie-consent regime. Covered businesses must provide required notices and honour rights such as opting out of sale or sharing, including qualifying Global Privacy Control signals.
  • Other locations: State and national privacy laws differ in scope, thresholds, definitions and signals. Do not copy an EU banner and label the site globally compliant.
  • Interface: Check that required information appears before the choice and that labels describe the result without pre-ticked controls or misleading emphasis.
  • Blocking: Inspect network requests and storage before consent. A consent-mode signal or server-side tag does not remove the need to assess the underlying collection and disclosure.
  • Rejection and withdrawal: Confirm that rejecting or withdrawing stops the covered processing and removes identifiers where the implementation promises removal.
  • Opt-out signals: Send Global Privacy Control and confirm that a covered California sale or sharing flow changes as required.
  • Records: Check that the organisation can show the notice version and choice without storing more personal data than needed.

Cookie Audit Tools and Limits

  • Browser developer tools: Use Application or Storage panels and the Network panel to trace a specific state. Preserve a HAR only after checking that it does not expose personal data or secrets.
  • Automated crawlers: Use a scanner to widen route coverage. Dynamic tags, geolocation, login states and delayed interactions can escape a crawl.
  • Consent platforms: A CMP can manage choices and scripts but cannot guarantee correct categorisation, legal scope or vendor behaviour. Test the live result.
  • Tag-manager preview: Trace triggers and consent conditions in a controlled environment. Compare preview output with actual browser requests.

Use the ICO's current storage and access technologies guidance for UK checks and the California Attorney General's CCPA guidance for sale, sharing and Global Privacy Control. The GDPR website audit covers the wider personal-data map.

Check Your Page HTML

Review titles, canonical links and other on-page signals from pasted HTML. Download your findings for follow-up.

Open HTML Checker

No signup required • Pasted HTML stays in your browser