DEV Community

LXSAIHUB
LXSAIHUB

Posted on

Your cookie banner doesn't actually block trackers. I checked.

Here's a check worth running on your own site: load it with a clean browser profile, dismiss the cookie banner — or ignore it entirely — and then open DevTools and look at the network tab. On a meaningful fraction of sites I've tested this way, including ones built by people who genuinely care, analytics and ad trackers fire regardless. The banner is a UI element. Whether anything is actually blocked before consent is a different question, answered by code nobody reviewed in months.

The gap between consent theater and consent

Implementing consent properly is fiddly: the tag manager fires scripts by default until someone configures them not to; a marketing embed added last quarter reintroduced a tracker; the consent script itself loads after the analytics script and the race resolves wrong. Each individual slip is invisible. Together they mean the site's actual behavior diverges from its privacy policy, and that divergence — not the aesthetic of your banner — is what regulators care about.

GDPR obligations here aren't exotic: lawful basis for what you collect, consent that's real before non-essential trackers run, data collection that matches what you claim. The hard part is knowing your current state.

Scanning beats remembering

PrivScan scans your site for common GDPR and consumer-privacy gaps — cookies, consent behavior, trackers, and data-collection practices — and produces a privacy readiness score with article references for each finding, plus a prioritized remediation checklist for your team. The references matter: "your consent mechanism has gap X" lands very differently when it comes with the actual article and recital it implicates.

The remediation checklist is what made this usable for me. A score without a list produces anxiety; a list ordered by what to fix first produces a sprint task.

What it is not

It's not a lawyer and doesn't produce a compliance certificate — no scan can, and anyone selling you "GDPR certified by scanner" is overselling. Site scans see what's observable from your pages and their behavior; they can't audit your backend data retention or your subprocessor contracts, which are half of real GDPR posture. Findings are a prioritized starting point for your DPO or counsel, not a substitute for either.

The five-minute audit

Run your own site through PrivScan and pay attention to one specific class of finding: trackers that fire before or without consent. Everything else on the report is worth reading, but that class is the one where most sites' reality diverges most sharply from their banner's promise. If your site comes back clean on it, you're ahead of most — I'd genuinely like to know what your consent stack is, because it'd be one of the good ones.

FAQ

What is PrivScan?

PrivScan scans your site for common GDPR and consumer-privacy gaps — cookies, consent behavior, trackers, and data-collection practices — and produces a privacy readiness score with article references for each finding, plus a…

Why does "The gap between consent theater and consent" matter?

Implementing consent properly is fiddly: the tag manager fires scripts by default until someone configures them not to; a marketing embed added last quarter reintroduced a tracker; the consent script itself loads after the…

What about "Scanning beats remembering"?

The remediation checklist is what made this usable for me. A score without a list produces anxiety; a list ordered by what to fix first produces a sprint task.

References

  • GDPR full text — Article 6 legal bases and consent requirements behind the tracker disclosures this tool checks.

Top comments (0)