No signup for basic results

Free GDPR Cookie Consent Checker

Wondering “am I GDPR compliant?” Start with the visible risk: your cookie banner. Scan any public page for common consent-banner, CMP, tracker, HTTPS, and privacy-policy gaps in under a minute.

Checks live signalsBanner, CMP, trackers, policy link.
Built for triageFind gaps before a buyer, DPO, or regulator does.
No fake certaintyAutomated results are a first pass, not legal advice.

Live free scan

Check your site now

Paste a public URL to check for a consent banner, CMP signal, tracking scripts, HTTPS, and privacy-policy link. Basic results show here without signup.

Open full checker

Search-intent answer

What does a GDPR cookie consent checker tell you?

A cookie consent checker does not certify compliance. It shows whether the public page exposes the minimum signals a reviewer expects to see: a banner or preference layer, a recognizable consent management platform, clear privacy links, secure delivery, and tracking scripts that may require opt-in controls.

The useful output is a fix list. If the scan sees trackers but no banner, a banner but no policy link, or a CMP that appears disconnected from tags, you have a concrete starting point for engineering and privacy review.

Compliance basics

What a compliant cookie consent banner needs

A good banner is more than a pop-up. It is the visible control surface for a consent system that blocks, records, honors, and proves user choices.

Prior choice before optional cookies

Non-essential analytics, advertising, retargeting, and personalization tags should wait until the visitor makes an informed opt-in choice for that purpose.

Equally visible accept, reject, and settings paths

A banner that makes acceptance obvious but hides rejection creates both user-trust risk and audit risk. The safe pattern is a clear primary choice plus granular settings.

Specific purposes and named vendors

The banner and linked policy should explain what each category does, which vendors receive data, and why storage or access is requested.

Withdrawal that works after the first visit

Visitors need a persistent way to reopen choices and withdraw consent, and tag firing must actually change when consent is withdrawn.

Evidence for customers and auditors

Record banner version, policy version, timestamp, region logic, selected purposes, and downstream suppression so diligence reviewers do not have to trust screenshots.

Common failures

Cookie consent mistakes this scan helps surface

  • Google Tag Manager, analytics, pixels, heatmaps, or chat widgets load before consent is stored.
  • The reject action is missing, visually muted, or buried behind extra clicks while accept is one tap.
  • Cookie categories are vague, pre-ticked, or bundled so users cannot choose specific purposes.
  • The privacy or cookie policy link is missing from the banner or does not match the actual vendors on the page.
  • Consent logs exist in the CMP but are not tied to tag-manager rules, data warehouse suppression, or vendor exports.
  • A redesign or new marketing campaign adds tags without retesting the banner and consent mode behavior.

One conversion path

Turn the scan into an audit trail customers can trust

The free checker gives you the first-pass signal. The GDPR Consent Self-Audit Toolkit gives you the worksheet, evidence checklist, and remediation tracker to assign owners and document the fixes.

Instant download

$29

Buy the $29 consent toolkit

For teams that need evidence, owners, and retesting steps after the free scan.

FAQ schema included

Free GDPR cookie consent checker FAQ

Is this free GDPR cookie consent checker legal advice?

No. It is a technical screening tool that highlights consent-banner and tracking signals to review. Use legal counsel or a qualified privacy reviewer for final compliance decisions.

Can an automated checker prove I am GDPR compliant?

No automated scan can prove GDPR compliance because consent also depends on purpose wording, user choices, records, withdrawal paths, vendor contracts, and how tags behave after a choice.

What does the checker look for?

It checks whether a public page appears to expose a cookie banner, recognized consent management platform, common tracking scripts, HTTPS, and a privacy-policy link in the initial page response.

What should I fix first if the checker finds gaps?

Start by blocking non-essential tracking before opt-in, making reject and settings choices easy to find, linking the banner to a clear privacy or cookie policy, and keeping proof of the user's consent state.

Do I need a cookie banner if I only use analytics?

Often yes for EU visitors when analytics or similar scripts are not strictly necessary. The exact setup depends on the tool, configuration, jurisdiction, and legal basis.