Skip to main content
ComplicerAUDIT GRADE
MethodologyUse casesEU AI ActPricingBlogDocsSign inSTART FREE AUDIT
Cookie consent audit

Does your cookie banner actually work?

Most cookie consent banners look compliant but fail the one test that matters: clicking Reject All and verifying that trackers actually stop. ComplyTest automates this verification with 11 consent-specific rules — so you know for certain, not just on paper.

Test your cookie consent freeSee pricing

No credit card required. Results in minutes.

Ready to check your own exposure?

In our March 2026 audit, 4 of 4 leading compliance tools failed their own consent checks — most banners look compliant but fail the Reject test.

Run a free auditWe click Reject on your real banner and show you what happened.

Honest by design — we never overclaim what an audit can prove.Our methodology

The problem

Most cookie banners are decorative

A banner that shows an Accept button is not the same as a banner that enforces consent. The only way to know is to test it.

In our March 2026 audit, 4 of 4 leading compliance tools failed their own consent checks.

  • Cookiebot — sets cookies before consent is recorded on every page load.
  • Deque — analytics requests continue firing after clicking Reject All.
  • OneTrust — still running Google Consent Mode v1 instead of the required v2.
  • Monsido — no Reject button on the initial consent layer at all.

If the companies selling compliance tools are failing consent checks, the likelihood your banner is passing is lower than you think.

Legal requirements

What valid consent actually requires

Under GDPR Article 7 and the ePrivacy Directive, consent must meet six specific criteria to be legally valid.

Prior consent

No cookies may be set before the user has actively accepted. Loading trackers on page arrival — even for a fraction of a second — is a violation.

Equal choice

Accept and Reject buttons must be visually equivalent. Dark patterns like a prominent Accept button and a buried Reject link are prohibited.

Clear language

Consent must be freely given, specific, informed, and unambiguous. Legal jargon, passive opt-ins, and pre-ticked boxes do not qualify.

Granular control

Users must be able to accept or reject cookies by purpose category — analytics, marketing, preferences — independently of each other.

Easy withdrawal

Withdrawing consent must be as easy as giving it. A consent settings link must be persistently accessible, not buried in a cookie policy page.

Documented proof

You must be able to demonstrate that consent was obtained correctly. Timestamp, banner version, and user choice must be logged and retrievable.

The audit

ComplyTest's 11 consent rules

Each rule maps to a specific legal requirement from GDPR, the ePrivacy Directive, or EDPB guidance. Every rule produces a pass/fail result with evidence.

01

Reject button present

A clearly labeled Reject All or equivalent button is present on the initial consent layer — no additional clicks required.

02

No cookies before consent

Zero non-essential cookies or storage items are set before the user makes an active choice.

03

Third-party cookies blocked

Third-party tracking cookies from analytics, advertising, and social platforms are absent until explicit consent is granted.

04

Cookie expiration

Consent cookies expire within 12 months. Session cookies used for preference storage are verified as session-scoped.

05

Banner language

The consent notice uses plain, non-legalistic language. No pre-ticked boxes, vague "improve your experience" framing, or implied consent.

06

Withdrawal mechanism

A persistent link or button allows users to revisit and change their consent choices at any time.

07

Cookie descriptions

Each cookie category includes a plain-language description of purpose, provider, and data destination.

08

Visual parity

Accept and Reject actions are rendered at equal visual prominence — same button style, size, and placement.

09

Google Consent Mode v2

Sites using Google Analytics or Google Ads correctly implement Consent Mode v2 and pass denied signals on Reject.

10

Consent effectiveness

After clicking Reject All, no analytics or advertising scripts execute. Network requests to tracking endpoints are monitored and verified absent.

11

Consent record

Evidence that consent was recorded is present: a consent receipt cookie or server-side log with timestamp, banner version, and choice.

Rule 10 — Consent effectiveness

The test most tools skip

Displaying a Reject button is not enough. The only way to verify consent is working is to click Reject All and watch the network — do trackers actually stop firing?

ComplyTest runs a real browser, clicks Reject All, and monitors every outgoing network request for the next 10 seconds. If a request to Google Analytics, Meta Pixel, Hotjar, or any other tracker appears — you fail Rule 10.

Real browser execution — no simulation shortcuts

Network-layer verification, not just cookie inspection

Tested against 30+ known tracker domains

Result includes a timestamped network request log as evidence

complicer.com — consent effectiveness test

Test sequence

Load page
Banner detected
Click "Reject All"
Monitor network (10s)

Rule 10 — Fail

3 tracker requests detected after Reject All

google-analytics.com/collect
connect.facebook.net/en_US/fbevents.js
static.hotjar.com/c/hotjar-

Ready to check your own exposure?

Run a free auditWe click Reject on your real banner and show you what happened.

Honest by design — we never overclaim what an audit can prove.Our methodology

Keep exploring

GDPR compliance

The full picture beyond cookies — lawful basis, DSARs, and evidence.

EU AI Act

Are you in scope? Risk tiers, obligations, and deadlines explained.

Privacy & data protection

How your data is handled and what a real audit actually proves.

Know exactly where your consent banner stands

Run a free audit in minutes. Get pass/fail results for all 11 consent rules with network-level evidence — not guesses.

Test your cookie consent free

Free plan available. No credit card required.

ComplicerAUDIT GRADE

We test whether Reject actually works on your site — and seal the evidence you can hand to a regulator.

GDPR-ALIGNED · SHA-256 · Ed25519 · EU-W1
PRODUCT
Free scanUse casesMethodologyEU AI ActPricingDocsBlog
COMPANY
ContactSecurityTrust
LEGAL
PrivacyTermsSubprocessorsComplaint
EVIDENCE CHAIN INTACT · SHA-256 · Ed25519 · RFC 3161-READY© 2026 COMPLICER