Skip to content

How It Works

We check what happens before you click "Accept."

Most cookie banners are just for show. We test if yours actually works.

When someone visits your website, something important should happen: nothing. At least not until they click "Accept."

No data collection. No tracking. No information sent to companies they've never heard of.

That's what the law requires. But on most websites, it's not what happens.

We test what actually happens. In those critical first seconds before anyone clicks anything.

What We Actually Test

Every scan works the same way. We visit your website exactly like a first-time customer would:

  • Fresh start.No cookies from previous visits. No browsing history. No logged-in accounts. Just a clean slate.
  • No clicking.We don't click "Accept" or interact with anything. We just arrive and watch.
  • Real browser.Not a simple technical ping. An actual browser loading your full page, just like your visitors do.

Then we watch. If your website sends visitor information to other companies before they've given permission, we see it. And we tell you.

The Scoring System

Our scoring is simple. And strict.
Because the law is strict.

100 is the only acceptable score.

That's not us being harsh. That's what GDPR requires: no data collection before consent. We just measure whether your website does that.

ScoreWhat It Means
100Clean. Nothing fires before consent.
80-99Minor issues. Something slipped through.
50-79Significant problems. Multiple violations detected.
Below 50Critical. Your cookie banner isn't doing its job.

There's no curve. There's no "good enough."

If your website loads Google Analytics before a visitor clicks "Accept," that's a violation. The law doesn't care what your cookie banner says. It cares what actually happens.

What Hurts Your Score

Not everything affects your score equally.

High impact:

  • Advertising tools (Meta Pixel, Google Ads, TikTok) loading before consent
  • Marketing cookies placed before permission is given

Medium impact:

  • Analytics running before consent (Google Analytics is the most common)
  • Data sent to tracking companies before any click

Low impact:

  • Non-essential cookies from your own website

No impact (these are allowed):

  • Payment services (Stripe, PayPal) that are necessary to run your shop
  • Security services (Cloudflare, spam protection) that keep your site safe
  • Essential technical services your site needs to function

The law allows what's strictly necessary. Everything else requires consent first.

Why Most Cookie Banners Fail

You installed a cookie banner. You thought you were compliant. So why does your score say otherwise?

The banner loads too slowly.

Your tracking scripts start running before the cookie banner even appears. The tracking wins the race.

Third-party apps ignore it.

That Shopify app you installed? That WordPress plugin? They often inject their own tracking code that your cookie banner can't control.

It's set up wrong.

The banner is there, but it's not configured correctly. This is more common than you'd think.

Conflict of interest.

Some companies that make cookie banners also partner with advertising networks. They're not motivated to block everything.

We don't sell cookie banners. We don't partner with advertisers. We just tell you what your website actually does.

How to Fix Common Problems

Found issues? Here's where to start. You don't need to be technical. You need to know what to ask your web developer.

Analytics loading too early

Google Analytics is the most common violation we see. Your cookie banner probably isn't blocking it properly.

What to ask your developer: "Can you verify that Google Analytics only loads AFTER someone clicks Accept? Test it, don't assume."

Alternative: Switch to privacy-friendly analytics like Fathom or Plausible. They're designed to work without consent requirements.

Advertising tools firing before consent

Meta Pixel, Google Ads, and TikTok tracking often start running before your cookie banner has a chance to block them.

What to ask your developer: "Make sure all advertising scripts load only after consent, not on page load."

Quick win: Remove tracking pixels you're not actively using. If you haven't looked at your TikTok ads dashboard in six months, remove the pixel.

Apps and plugins you forgot about

That plugin you installed two years ago? It might be injecting tracking code you don't even know about.

What to do: Look at every app and plugin installed on your site. Remove anything you don't actively use. For the ones you keep, check if they have a "respect cookie consent" setting.

Social media embeds

Embedding Facebook posts or Twitter feeds on your page? They start tracking visitors the moment they load. Before any click.

What to do: Remove them entirely, or replace with simple links. If you must have them, ask your developer about "click to load" embeds that only activate when someone chooses to interact.

Fonts from Google

This one surprises people. Google Fonts, used on millions of websites, sends visitor data to Google servers.

What to ask your developer: "Can we self-host our fonts instead of loading them from Google?" This is usually a simple fix.

Our Independence

GDPR Scanner is:

  • Not connected to any cookie banner company
  • Not connected to any advertising or tracking company
  • Not paid to adjust scores
  • Built in Finland, inside the EU, under EU law

We have no financial reason to show you anything other than the truth.

What We Don't Do

Being clear about our limits is part of being honest.

Not in scopeWhy
What happens after consentWe test the moment before. That's where violations happen.
Privacy policy reviewWe test technical behavior, not legal documents.
Security testingWe're a privacy scanner, not a security scanner.
Logged-in areasWe scan as a first-time visitor. That's where consent matters.

Limitations

Every automated scan has boundaries. We're honest about ours.

  • Point in time. Websites change. Your score reflects the moment we scanned. Something could change tomorrow.
  • Technical detection only. We measure what happens. We don't determine legal compliance. That's for lawyers.
  • Not legal advice. We show you data. What you do with it is up to you and your legal counsel.

Our scans are indicators, not legal judgments. But they're accurate indicators. Often the first honest look at what your website actually does.

The Standards We Follow

Our testing methodology aligns with:

  • GDPR (General Data Protection Regulation): Articles 6 and 7 on consent
  • ePrivacy Directive: Article 5(3) on cookies and tracking
  • European Data Protection Board guidelines on consent
  • French data authority (CNIL) recommendations on cookies

We don't publish exactly how we detect violations. That would help people cheat. Researchers interested in our methodology can contact us.

Something seem wrong with your score? Scan again. It's free.

Fixed an issue and want to verify? Run another scan. We update results within minutes. During busy periods, always within 24 hours.

Not sure what to fix? Our reports show exactly what's loading on your site, so you know what to ask your developer.

Questions? Contact us at contact@gdprscanner.eu

Stay Ahead of Privacy Regulations

Be the first to hear about our innovative new features. We respect your time. No spam, just valuable updates.

Built in Finland, EU. Privacy that pays off.