Website Cookie Audit: Ensure GDPR and Privacy Compliance
A cookie audit inventories every cookie your website sets, categorises them by purpose, and ensures your consent mechanism complies with GDPR, CCPA, and ePrivacy regulations.
What Is a Cookie Audit
A cookie audit is a systematic inventory of every cookie and tracking technology your website uses. It documents what each cookie does, who sets it, how long it lasts, and whether it requires user consent. The audit ensures your website complies with privacy regulations like GDPR, CCPA, and the ePrivacy Directive.
Most website owners have no idea how many cookies their site sets. Third-party tools, analytics platforms, advertising pixels, chat widgets, and social media embeds all drop cookies — often without your knowledge. A cookie audit brings transparency to this hidden tracking.
Why Cookie Compliance Matters
- Legal fines: GDPR fines for cookie violations have reached millions of euros. French regulators fined Google €150M and Facebook €60M for cookie consent failures. Smaller businesses face proportional penalties.
- User trust: Privacy-conscious users check cookie policies. A transparent, compliant approach builds trust. Dismissive or deceptive cookie practices damage your brand.
- Browser changes: Safari and Firefox already block third-party cookies by default. Chrome is depreciating third-party cookies. Your tracking strategy needs to adapt.
- Legal exposure: Privacy lawsuits from individuals and advocacy groups are increasing. Non-compliant cookie practices create unnecessary legal risk.
Types of Cookies
- Strictly necessary: Essential for the website to function — session cookies, authentication, shopping cart, security tokens. These don't require consent under GDPR.
- Functional: Remember user preferences like language, region, or display settings. Generally considered low-risk but technically require consent.
- Analytics: Track user behaviour for site improvement — Google Analytics, Hotjar, Mixpanel. Require consent in most jurisdictions.
- Marketing/advertising: Track users across websites for targeted advertising — Facebook Pixel, Google Ads, retargeting cookies. Always require explicit consent.
How to Audit Your Cookies
- Scan your website: Use a cookie scanning tool (Cookiebot, CookieYes, or browser DevTools) to detect all cookies set on every page of your site.
- Document each cookie: For every cookie found, record: name, provider, purpose, type (first-party or third-party), duration, and category (necessary, functional, analytics, marketing).
- Identify unknowns: Some cookies come from third-party scripts you didn't intentionally add. Investigate every unknown cookie and determine if it's still needed.
- Check third-party scripts: Review every embedded script, widget, and plugin. Each one may set cookies or use other tracking technologies (localStorage, fingerprinting).
- Update your cookie policy: Your cookie policy must list every cookie with its purpose and duration. Vague descriptions like "we use cookies to improve your experience" are insufficient.
- Test your consent mechanism: Verify that non-essential cookies are only set AFTER the user gives consent. Test by rejecting cookies and checking that analytics and marketing scripts don't fire.
GDPR Cookie Requirements
- Prior consent: Non-essential cookies must not be set until the user explicitly consents. Pre-ticked boxes or "by continuing to browse you accept" banners are not valid consent.
- Granular choice: Users must be able to accept or reject cookies by category. An all-or-nothing approach doesn't satisfy GDPR requirements.
- Easy withdrawal: Users must be able to change their cookie preferences at any time, as easily as they gave consent.
- No cookie walls: You generally cannot deny access to your website if users reject non-essential cookies (with some exceptions for paid content).
- Consent records: You must be able to demonstrate that consent was given — store consent records including timestamp, version of the policy, and choices made.
Cookie Consent Implementation
- Consent Management Platform (CMP): Use a dedicated CMP like Cookiebot, OneTrust, CookieYes, or Osano. These handle scanning, categorisation, consent collection, and blocking automatically.
- Script blocking: Non-essential scripts must be blocked until consent. Most CMPs do this by changing script types to text/plain until the user consents, then rewriting them to text/javascript.
- Google Consent Mode: If you use Google Analytics or Google Ads, implement Consent Mode v2. This allows Google to model conversions even when users decline cookies.
- Server-side tracking: For analytics accuracy, consider server-side tracking through Google Tag Manager server-side or similar solutions. This reduces dependence on client-side cookies.
Cookie Audit Tools
- Cookiebot: Scans your entire site monthly, categorises cookies, generates a compliant consent banner and cookie policy. Free for small sites (under 100 pages).
- CookieYes: Similar to Cookiebot with a free tier. Good for WordPress sites with a dedicated plugin.
- Chrome DevTools: Application → Cookies shows all cookies for the current page. Network tab shows which requests set cookies. Free and always available.
- BuiltWith: Shows what technologies a website uses, including tracking and analytics tools. Useful for identifying what might be setting cookies.
Get Your Free Website Audit
Find out what's holding your website back. Our 72-checkpoint audit reveals exactly what to fix.
Start Free AuditNo credit card required • Results in 60 seconds
Or get free SEO tips delivered weekly