How to Verify Your Website's Cookie Compliance
Showing a cookie banner is not the same as being compliant. What actually matters is whether tracking cookies wait for permission, whether refusing is as easy as accepting, and whether you can prove a visitor agreed. This guide walks through the checklist, how to test it by hand in your browser, and how to verify the whole flow automatically in one scan.
Why verification matters#
Enforcement is not theoretical. European regulators have moved well past writing rules and now issue real penalties over how cookie banners are built and what loads behind them. Verifying your own site matters because the fines land on the design details, not on whether a banner exists at all.
The scale of the gap is well documented. A study of the top 10,000 websites across dozens of countries found that while roughly 67 percent display some form of cookie banner, only around 15 percent meet basic compliance requirements. Having a banner is common, but having one that actually holds up is rare, which is exactly why checking your own site is worth the few minutes it takes.
France's data protection authority, the CNIL, has been the most active. It fined Google and Amazon in 2020 for placing advertising cookies on visitors' devices without consent, and it has kept up the pressure since. In 2024 alone the CNIL issued 331 corrective measures, and in December 2024 it sent formal notices to sites over banners built with dark patterns, meaning interface tricks that push a visitor toward accepting. In the United Kingdom the Information Commissioner's Office, or ICO, enforces the local implementation of the ePrivacy Directive and has repeatedly pressed sites over banners that do not comply.
The European Data Protection Board, or EDPB, the EU body whose guidance binds national regulators, has stated in its binding guidelines that consent is not freely given when the interface steers visitors toward acceptance. National courts now apply that directly. In the Austrian ORF case, ruled in October 2024 and later confirmed, the court held that a Reject option shown in a less conspicuous colour is not enough, and that Accept and Reject must carry equal prominence on the banner's first layer. In Germany, the Hanover Administrative Court ruled on 19 March 2025 that a site must offer a clear "reject all" button and that manipulative designs are not allowed. A banner that technically offers a choice but nudges hard toward one answer is now routinely treated as no valid choice at all.
A banner is not the same as compliance
Many sites assume that showing any cookie banner satisfies the law. Regulators look instead at whether consent is genuinely free, which depends on how the banner is designed and, just as important, on what loads before anyone clicks. A polished banner sitting on top of trackers that already fired is a common and expensive mistake.
The compliance checklist#
Verification comes down to a concrete set of checks you can work through against your own site. They fall into two groups. The first is about how consent behaves, and the second is about transparency and keeping things tidy over time.
How consent behaves
- No non-essential cookies before consent. Analytics and marketing cookies must not appear in the browser until the visitor has actively agreed. If they load on page open, the site is already non-compliant no matter how good the banner looks.
- A reject option as easy as accept. The banner needs a clear way to decline that is as visible and takes as few clicks as accepting, since regulators treat a hidden or buried refusal as no real choice at all.
- A real consent mechanism. A framework such as Google Consent Mode v2, which adjusts how Google tags fire based on the visitor's choice, or the IAB Transparency and Consent Framework (TCF), an industry standard for recording advertising consent, shows that choices are actually enforced rather than decorative.
Transparency and hygiene
- A clear cookie policy that is linked. The banner should link to a page that lists what cookies you set, who receives the data, and how long each one lasts, so a visitor can actually read what they are agreeing to.
- Cookies categorized by purpose. Grouping cookies into necessary, analytics, and marketing lets a visitor accept some and refuse others, which is what specific consent means in practice.
- Reasonable lifetimes and asking again. Consent does not last forever. The CNIL recommends refreshing consent roughly every six months, judged case by case and commonly cited as somewhere between six and thirteen months, rather than treating one click as permanent, and each cookie's expiry date should match its stated purpose.
If you want the full legal reasoning behind these points rather than the short version, our companion guide on GDPR cookie consent requirements walks through what each rule demands and why.
How to check it yourself#
You can verify most of this by hand in about ten minutes using your browser's developer tools, the inspection panel every major browser opens with F12 or by right clicking a page and choosing Inspect. The trick is to look at cookies twice, once before you interact with the banner and once after.
- 1Open the site in a fresh private window so no old cookies remain.
- 2Before you touch the banner, open the Application tab in Chrome or Edge, or the Storage tab in Firefox, and expand Cookies. Anything listed there was set before you consented. A session cookie is fine, but an analytics cookie whose name starts with
_ga, or a third-party marketing cookie, means the site sets non-essential cookies too early. - 3Click Accept and watch the list grow. The new entries are the cookies that correctly waited for permission, and the contrast between the two lists is the most revealing test you can run.
- 4Reload and look at the banner itself. A Reject or Refuse control should be as prominent as Accept, not a faint link.
- 5Follow the cookie policy link and confirm it actually describes the cookies you just watched appear.
Cookies before vs after consent
// Paste this in the DevTools Console to list the cookies this page can read.
document.cookie.split(';').map(c => c.trim())
// This only lists cookies that are NOT marked HttpOnly.
// To see every cookie, open the Application tab (Chrome, Edge) or the
// Storage tab (Firefox), then Cookies, where each cookie's domain,
// expiry, and SameSite value are shown in full.One caveat with the console command. It only reports cookies that are not marked HttpOnly, a flag that hides a cookie from JavaScript so that scripts cannot read it. The Application or Storage tab shows every cookie including those, which is why it stays the more complete view. While you are there, it is worth confirming that any login cookies carry the right protective flags, a topic covered in how to secure cookies.
How to verify it automatically#
Manual checks are useful, but they capture one page in one browser on one day. Automated verification does the same before and after comparison consistently, and it does not forget to check a page you rarely visit. That consistency is what turns an occasional audit into ongoing confidence.
A scanner can open the page in a real browser, record every cookie set before any interaction, simulate a visitor accepting consent, record the cookies again, work out which consent framework is present, and flag any third-party cookie that appeared before consent was given. Because it runs the same way every time, it catches a regression the moment a new tag or plugin starts loading trackers early, long before a regulator or a customer would notice.
SiteSecurityScore's Cookie Consent & Privacy check does exactly this in a single pass. It loads your site, watches what happens before and after consent, and reports the cookies and trackers it finds along with whether a recognised consent framework is in place. You can run it against any page with a free scan.
If you want to check the security of the cookies themselves rather than the consent flow, the Cookie Security Checker focuses on the protective flags. For the wider legal picture, our GDPR compliance overview goes beyond cookies into the rest of what the regulation asks for.
Common compliance mistakes#
Even sites that mean well tend to trip over the same handful of problems, and most of them come from focusing on the banner while ignoring what the page actually loads. The one below is the trap worth naming first, because it makes every other control meaningless.
A banner that fires trackers anyway
The most common failure is a banner that looks compliant while the analytics and advertising scripts have already run on page load. Clicking Reject then changes nothing, because the cookies are set before the visitor ever sees a choice. Always confirm what loads before consent, not just what the banner promises.
The rest of the list tends to show up together, since they usually come from the same rushed setup or a banner left untouched for a year.
- Analytics or advertising tags placed in the page head so they fire before the banner appears, which is the reject that changes nothing described above.
- An Accept all button styled in a bright colour while Reject is a faint text link or hidden behind an extra Manage preferences step, which regulators treat as a nudge rather than a free choice.
- Treating continued scrolling or further browsing as agreement, which the EDPB has said does not count as valid consent.
- No way to withdraw consent later, even though the law requires that changing your mind be as easy as giving permission in the first place.
- A cookie policy that still lists cookies the site no longer uses, or leaves out new ones, so the disclosure no longer matches what actually loads.
One newer trap is worth naming. Some sites now offer only a choice between consenting to tracking or paying a fee, an approach known as consent-or-pay, and in its Opinion 08/2024 the EDPB found that for large online platforms this generally does not yield valid, freely given consent unless the site also offers an equivalent free alternative, such as a version funded by contextual advertising that shows ads based on the page rather than a tracked profile, judged case by case.
FAQ#
What is cookie compliance?
Cookie compliance means handling the cookies your website sets in the way privacy laws require. In the European Union that means the GDPR and the ePrivacy Directive, which together require you to get a visitor's consent before storing or reading any cookie that is not strictly necessary to run the service. Strictly necessary cookies, like the one that keeps a user logged in, are exempt. Analytics and marketing cookies are not, so they must wait for a clear opt-in.
How do I know if my cookie banner is compliant?
A banner is compliant when refusing is as easy as accepting, when no non-essential cookies load until the visitor agrees, when cookies are grouped by purpose so choices are specific, and when a linked policy explains what each cookie does. If your banner shows a bright Accept button next to a buried or greyed out Reject, or if analytics cookies appear before anyone clicks, it is not compliant regardless of how it looks.
What does 'cookies before consent' mean and why is it a problem?
Cookies before consent means non-essential cookies, usually analytics or advertising, are written to the browser the moment the page loads, before the visitor has agreed to anything. It is a problem because the ePrivacy Directive requires consent before those cookies are stored, so setting them first breaks the law even if a banner appears afterward. It also makes any Reject button meaningless, since the cookies are already there.
Do I legally need a cookie banner?
If your site serves visitors in the European Union or the United Kingdom and sets any cookie that is not strictly necessary, then yes, you need a way to get consent, which in practice is a banner or similar prompt. Sites that set only strictly necessary cookies, such as a session cookie for a login, do not need consent for those. The trigger is the type of cookie, not the banner itself.
How often should I re-check cookie compliance?
Check whenever you add or change anything that can set cookies, such as a new analytics tool, an embedded video, a chat widget, or a marketing tag, because each one can start loading trackers before consent. Beyond that, a scheduled review every few months is wise, since a single plugin update or tag manager change can reopen a gap. Automated monitoring removes the guesswork by flagging a regression as soon as it appears.
References
Related articles
Verify Your Cookie Compliance in One Scan
Run a free scan to see which cookies your site sets before consent, whether a real consent framework is in place, and whether refusing is as easy as accepting.