Does your cookie banner actually work?
Most cookie consent banners look compliant but fail the one test that matters: clicking Reject All and verifying that trackers actually stop. ComplyTest automates this verification with 11 consent-specific rules — so you know for certain, not just on paper.
No credit card required. Results in minutes.
Ready to check your own exposure?
In our March 2026 audit, 4 of 4 leading compliance tools failed their own consent checks — most banners look compliant but fail the Reject test.
Honest by design — we never overclaim what an audit can prove.Our methodology
The problem
Most cookie banners are decorative
A banner that shows an Accept button is not the same as a banner that enforces consent. The only way to know is to test it.
In our March 2026 audit, 4 of 4 leading compliance tools failed their own consent checks.
- Cookiebot — sets cookies before consent is recorded on every page load.
- Deque — analytics requests continue firing after clicking Reject All.
- OneTrust — still running Google Consent Mode v1 instead of the required v2.
- Monsido — no Reject button on the initial consent layer at all.
If the companies selling compliance tools are failing consent checks, the likelihood your banner is passing is lower than you think.
Legal requirements
What valid consent actually requires
Under GDPR Article 7 and the ePrivacy Directive, consent must meet six specific criteria to be legally valid.
Prior consent
No cookies may be set before the user has actively accepted. Loading trackers on page arrival — even for a fraction of a second — is a violation.
Equal choice
Accept and Reject buttons must be visually equivalent. Dark patterns like a prominent Accept button and a buried Reject link are prohibited.
Clear language
Consent must be freely given, specific, informed, and unambiguous. Legal jargon, passive opt-ins, and pre-ticked boxes do not qualify.
Granular control
Users must be able to accept or reject cookies by purpose category — analytics, marketing, preferences — independently of each other.
Easy withdrawal
Withdrawing consent must be as easy as giving it. A consent settings link must be persistently accessible, not buried in a cookie policy page.
Documented proof
You must be able to demonstrate that consent was obtained correctly. Timestamp, banner version, and user choice must be logged and retrievable.
The audit
ComplyTest's 11 consent rules
Each rule maps to a specific legal requirement from GDPR, the ePrivacy Directive, or EDPB guidance. Every rule produces a pass/fail result with evidence.
Reject button present
A clearly labeled Reject All or equivalent button is present on the initial consent layer — no additional clicks required.
No cookies before consent
Zero non-essential cookies or storage items are set before the user makes an active choice.
Third-party cookies blocked
Third-party tracking cookies from analytics, advertising, and social platforms are absent until explicit consent is granted.
Cookie expiration
Consent cookies expire within 12 months. Session cookies used for preference storage are verified as session-scoped.
Banner language
The consent notice uses plain, non-legalistic language. No pre-ticked boxes, vague "improve your experience" framing, or implied consent.
Withdrawal mechanism
A persistent link or button allows users to revisit and change their consent choices at any time.
Cookie descriptions
Each cookie category includes a plain-language description of purpose, provider, and data destination.
Visual parity
Accept and Reject actions are rendered at equal visual prominence — same button style, size, and placement.
Google Consent Mode v2
Sites using Google Analytics or Google Ads correctly implement Consent Mode v2 and pass denied signals on Reject.
Consent effectiveness
After clicking Reject All, no analytics or advertising scripts execute. Network requests to tracking endpoints are monitored and verified absent.
Consent record
Evidence that consent was recorded is present: a consent receipt cookie or server-side log with timestamp, banner version, and choice.
Rule 10 — Consent effectiveness
The test most tools skip
Displaying a Reject button is not enough. The only way to verify consent is working is to click Reject All and watch the network — do trackers actually stop firing?
ComplyTest runs a real browser, clicks Reject All, and monitors every outgoing network request for the next 10 seconds. If a request to Google Analytics, Meta Pixel, Hotjar, or any other tracker appears — you fail Rule 10.
Real browser execution — no simulation shortcuts
Network-layer verification, not just cookie inspection
Tested against 30+ known tracker domains
Result includes a timestamped network request log as evidence
Test sequence
Rule 10 — Fail
3 tracker requests detected after Reject All
Ready to check your own exposure?
Honest by design — we never overclaim what an audit can prove.Our methodology
Know exactly where your consent banner stands
Run a free audit in minutes. Get pass/fail results for all 11 consent rules with network-level evidence — not guesses.
Test your cookie consent freeFree plan available. No credit card required.