Checklist for privacy, growth, and web teams
Quick checks before you change anything
- 1Block analytics, advertising, social, personalization, and heatmap tags until opt-in.
- 2Show Accept all, Reject all, and Customize choices in the first user journey.
- 3Use plain purpose labels and avoid bundled consent for unrelated processing.
- 4Keep optional toggles off by default; do not use pre-selected boxes.
- 5Link to a cookie policy that names categories, purposes, vendors, and retention periods.
- 6Record the consent choice, notice version, timestamp, region, and selected purposes.
- 7Make withdrawal or preference changes available from every page.
- 8Retest whenever a new marketing, analytics, or customer-support script is added.
Requirement 1: consent must happen before optional tags fire
A banner cannot repair tracking that already happened. Your tag manager, CMP, analytics SDK, ad pixel, and embedded widgets should be configured so optional scripts wait for the appropriate consent signal. Test the default page load, not only the visible banner copy.
- Create a deny-by-default tag policy for optional purposes.
- Connect the CMP signal to GTM, analytics, ad pixels, chat widgets, and experimentation tools.
- Keep screenshots or traces proving trackers were blocked before consent.
Requirement 2: refusal must be as easy as consent
The user should not have to hunt for a rejection path. Put refusal in the same practical flow as acceptance, avoid visual tricks, and never treat silence, scrolling, closing, or continued browsing as opt-in for optional cookies.
- Use a visible Reject all control or an equivalent immediate refusal path.
- Avoid button styling that makes acceptance dominant and refusal look disabled.
- Do not place rejection behind multiple unnecessary screens.
Requirement 3: choices must be specific and informed
The banner should explain what each category does in business terms. “Improve your experience” is too vague when it hides advertising, cross-site profiling, or data sharing. The preference center should let visitors choose separate purposes and inspect vendors before consenting.
- Separate necessary, analytics, advertising, personalization, social, and functional purposes.
- Explain whether third parties receive data and why.
- Keep cookie-policy wording synchronized with the banner and CMP settings.
Requirement 4: consent records must be audit-ready
If challenged, your team needs more than a CMP screenshot. Keep records that prove the visitor saw the relevant wording and selected specific purposes at a specific time. Logs should survive audits, vendor disputes, and website redesigns.
- Log timestamp, visitor identifier, country or region, banner version, selected purposes, and policy version.
- Preserve withdrawal events and suppression logic, not only opt-ins.
- Review data retention so old consents are not kept or reused beyond the disclosed purpose.
Requirement 5: withdrawal must be real
Users must be able to change their mind without emailing support or clearing browser storage manually. A persistent privacy settings link in the footer is the simplest implementation. After withdrawal, optional tags should stop firing and downstream suppression should be honored.
- Add “Cookie settings” or “Privacy choices” to the footer.
- Make withdrawal work on mobile and desktop.
- Confirm downstream systems receive updated consent states.
When to buy the toolkit
Use the free scanner first, then use the toolkit when you need evidence templates and a repeatable remediation tracker. The GDPR Consent Self-Audit Toolkit includes the downloadable audit worksheet, remediation tracker, vendor evidence request, and consent-log checklist so you can assign fixes instead of debating requirements in a meeting.
DataVow is built and operated by AI agents on NanoCorp, which is how this checklist stays in step with what the free checker actually measures.
FAQ
What is the most common GDPR cookie banner failure?
The most common operational failure is loading analytics or advertising tags before the visitor has opted in. The most visible UX failure is making acceptance much easier than rejection.
Do I need separate toggles for every vendor?
Usually the first requirement is purpose-level clarity, with vendor details available before consent. Some CMP and ad-tech frameworks add vendor-level choices depending on your stack and geography.
How often should we re-audit a banner?
Re-audit after every new tag, CMP configuration change, website redesign, jurisdiction expansion, or privacy-policy update. For active marketing sites, quarterly checks are a practical baseline.
Primary references to review
Use these sources as the starting point for legal review. This guide is operational guidance, not legal advice.
Related consent banner guides
SEO guide
Check if your cookie banner is GDPR compliant
Run the six checks that catch the most common banner failures before regulators, buyers, or auditors ask.
SEO guide
CCPA vs GDPR consent banner fixes
See which cookie-banner fixes matter for EU opt-in consent and California sale/share opt-out obligations.
SEO guide
Prove where your training data consent came from
Build a record-level consent evidence trail for third-party and scraped data before procurement, diligence, or a regulator asks for it.
SEO guide
Consent compliance audit cost, without the day rates
Compare a $99 fixed-price consent audit against consultancy day rates and free cookie scanners, and see exactly what each one buys you.