Glossary

GDPR cookie audit

A GDPR cookie audit is a structured review of which cookies, pixels, and similar technologies load on your site or app, what they do, who sets them, and whether your legal basis — often consent for non-essential tracking — matches how they actually behave in a real browser session.

What the audit usually covers

  • Inventory — names, domains, lifetimes, first vs third party.
  • Purpose — analytics, advertising, functional, strictly necessary.
  • Legal basis — consent, legitimate interest, or contract as applicable.
  • Consent behavior — what loads before Accept vs after Reject.
  • Gaps — unknown vendors, stale documentation, tag manager drift.

Why spreadsheets alone fail

Vendor lists go stale the week marketing adds a pixel. A live scan captures what a visitor’s browser receives today — including tags injected through GTM or A/B tools you forgot to document. That evidence is what privacy teams and regulators expect when they ask whether your cookie policy is still true.

Running an audit with CookieComply

  • Open the URL in Chrome with the CookieComply extension (no site-wide script required).
  • Capture cookies before and after consent choices when you need pre-consent proof.
  • Review AI-assisted classifications and risk notes, then share a report with legal or clients.
  • Re-run after banner, CMP, or tag changes to show improvement.

Audit vs. CMP

A consent management platform collects and stores visitor choices on live traffic. CookieComply is the verification layer: it tells you whether those choices are reflected in what actually loads. Most mature programs use both — CMP for visitors, periodic audits for assurance.