Your GDPR Audit Is Wrong — Here's an Actual Process That Works
I run 17 storefronts across 16 countries on a single VPS. When you operate at that scale, you can’t afford to guess whether your sites are GDPR-compliant — a fine on one storefront in Germany can close the whole operation. So I built a process.
What follows is the audit I run on every new site before launch. It catches about 90% of violations in 10 minutes, and the first three phases are automated.
The problem with most GDPR checklists
Every GDPR checklist I’ve read falls into one of two traps:
-
Written by lawyers who’ve never opened DevTools. “Ensure your privacy policy includes Article 13 disclosures.” OK, sure, but how do I verify my cookie banner is actually blocking Google Analytics? They don’t tell you because they don’t know how.
-
Written by CMP vendors who want you to buy their product. “If it passes our tool, you’re compliant!” Their tool doesn’t check post-rejection behavior — the thing that gets you fined.
This process is different. I’m a developer who runs production systems, not a lawyer who writes opinions. Everything here is testable.
Phase 1: Verify pre-consent silence (2 min)
The most common GDPR fine trigger: a tracking request fires before the user touches the consent banner. This is automatic liability.
How I check:
Open your site in incognito. DevTools → Network tab. Filter by third-party requests. Do not interact with the banner.
What you’re looking for: any request to a tracking domain before consent. Google Analytics, Facebook, Hotjar, LinkedIn, TikTok, HubSpot, any analytics or marketing CDN.
The scanner automates this: My GDPR checker opens your site in a headless Chromium, monitors all network requests, and flags any tracking domain that fires before consent. It also checks cookies and localStorage because some trackers write data without making network requests.
Phase 2: Analyze the banner (2 min)
If your banner passes Phase 1 (nothing fires), now check whether the consent it collects is actually valid.
The three things that matter:
-
Reject must be as easy as accept. Same size, same color, same screen. If “Accept All” is a blue button and “Reject All” is grey text, you have a dark pattern. The CNIL fined publishers for this in 2024.
-
No pre-ticked checkboxes. Planet49 (CJEU, 2019) established that pre-ticked boxes ≠ consent. Every cookie category must start unchecked. If your CMP defaults to “all on,” it’s broken.
-
Per-purpose toggles. “Accept All / Reject All” with no per-category toggles is not granular consent. Users must be able to accept analytics but reject marketing. Three toggles minimum.
Phase 3: Verify post-rejection (2 min)
This is where most audits stop, and it’s where the expensive mistakes live.
Click “Reject All” on your banner. Then refresh the page.
Still in incognito. Still in DevTools → Network tab.
What you’re checking:
- Did any trackers fire after the refresh? If rejection isn’t blocking, you’ll see requests.
- Did the banner reappear? If rejection wasn’t remembered, the banner shows again — and it means your CMP isn’t persisting the user’s choice.
- Is the rejection stored? Check Application → Cookies. Look for
OptanonConsent,euconsent-v2,cookie_consent, orcookielawinfo-checkbox-*. One of these should be present with the user’s preference.
The scanner verifies this automatically. It clicks the reject button, waits 3 seconds for any lazy-loaded trackers, then re-checks the network log. I tested 7 CMPs this way — only 3 passed →
Phase 4: Check legal pages (1 min)
Open these pages in incognito. Do not interact with the consent banner first — they must load without consent:
- Privacy policy. Must list what you collect, why, how long you keep it, and users’ rights (access, rectification, erasure, portability, objection). “Last updated” date. DPO contact or EU rep.
- Cookie policy. Must list every cookie by name, purpose, and duration. Not “we use cookies for analytics.” Specifics.
- Impressum. Required if you serve German users (§5 TMG). Full name, address, contact, commercial register number.
If no cookies are present on the site, you don’t need a cookie policy. The scanner detects whether cookies are actually being set.
Phase 5: Find the rights mechanisms (1 min)
Users have five rights under GDPR. Your site should have a visible way to exercise them:
- Access (Art 15): How do users get a copy of their data?
- Erasure (Art 17): How do users request deletion?
- Portability (Art 20): Can users export their data?
- Rectification (Art 16): Can users correct inaccurate data?
- Objection (Art 21): Can users opt out of processing?
“Contact us” is sufficient for all of these if the contact works and responds within 30 days. Email address in privacy policy counts. A form is better.
Phase 6: Spot the embedded trackers (1 min)
Things that load third-party scripts even when you don’t think about them:
- Google Fonts sends your visitor’s IP to Google’s CDN. Fix: self-host the font files (5 minutes, zero downside).
- reCAPTCHA loads Google scripts and sends user data to Google. Fix: switch to hCaptcha or Cloudflare Turnstile.
- YouTube embeds fire YouTube’s tracking scripts. Fix: click-to-load placeholder (
youtube-nocookie.comhelps but doesn’t fully solve it). - Google Maps loads Google scripts. Fix: static image + link to Google Maps.
- Twitter/Instagram embeds load tracking. Fix: screenshot + link to original post.
These are the “nobody told me this was tracking” category. I’ve found all of them on production sites that otherwise passed every consent check.
The fix order that matters
If you found multiple failures, fix in this order:
- Pre-consent tracking (Phase 1) — immediate liability, no gray area
- No reject button or hidden reject (Phase 2.1) — explicit DPA enforcement target
- Pre-ticked boxes (Phase 2.2) — CJEU precedent, you will lose if challenged
- Post-rejection tracking (Phase 3) — catches broken CMP implementations
- Privacy policy (Phase 4.1) — Article 13-14 requirement, “contact us” is sufficient
- Third-party embeds (Phase 6) — self-host Google Fonts takes 5 minutes
A missing “data portability” form in your privacy policy (Phase 5) is worth fixing, but it won’t get you fined. Firing Google Analytics before consent will.
Automate this
I was tired of running this audit manually across 17 storefronts, so I built a scanner that handles Phases 1-3 automatically. It runs in 15 seconds and produces a pass/fail report for each check. Free, open source, no account.
If you use Google services, Consent Mode v2 is a prerequisite for Phase 1 to pass →
Last verified: June 2026. Tested against Chromium 130, Playwright, and a test site with 14 known trackers.