GDPR scanner

GDPR Scanner for Cookies, Trackers, and Consent Signals

Scan your website for cookies, tracker scripts, pixels, Google Consent Mode signals, and pre-consent network requests. Get a detailed cookie inventory and scan evidence in under a minute.

Technical checks only, not legal advice.

Need a broader website GDPR compliance check? Use the online GDPR validator to review cookie consent, tracker behavior, policy links, and consent evidence in one flow.

Detect common analytics and marketing trackers

The scanner identifies signals from Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, LinkedIn Insight Tag, TikTok Pixel, and similar third-party scripts that typically require consent review under GDPR and ePrivacy.

Inspect pre-consent behavior

A useful scanner doesn't stop at static HTML. GDPRChecker checks whether trackers or measurement endpoints fire network requests before a consent choice is made — the behavior most likely to attract regulatory attention.

Turn scan results into an action plan

Use scan findings to configure a consent banner, categorize cookies by purpose, publish a cookie declaration, and monitor for new trackers over time with scheduled scans.

What the scanner detects

  • Google Analytics (GA4) and Google Tag Manager signals
  • Meta Pixel, LinkedIn Insight Tag, and TikTok Pixel
  • Hotjar, FullStory, and session recording scripts
  • Pre-consent network requests and timing analysis
  • Google Consent Mode v2 default command detection
  • Cookie names, providers, and suggested categories
  • Third-party script sources with request metadata

What the GDPR scanner detects

The scanner loads your homepage as a first-time visitor and inspects every script, pixel, and network request. It identifies known analytics services (GA4, GTM), marketing pixels (Meta, LinkedIn, TikTok), session recording tools (Hotjar, FullStory), and tag management containers. For each detected signal, it records the provider, script source, and whether the request appeared before or after a consent interaction.

Tracker and cookie signals

Beyond domain matching, the scanner categorizes finds by type: analytics, marketing, functional, and unclassified. It checks for common cookie names set by third-party services and flags patterns like _ga, _fbp, _hjSession, and li_sugr. Each cookie is mapped to a known provider and suggested category so you can build or validate a cookie declaration quickly.

Pre-consent network request checks

The pre-consent check captures the timing of every third-party request relative to consent banner interaction. If Google Analytics collect hits, Meta Pixel PageView events, or GTM container loads fire before the visitor accepts or rejects cookies, the scanner flags them. It also checks whether Google Consent Mode v2 default commands (gtag consent.default) are set before tags load — a key signal for Google-specific compliance.

Scanner evidence and cookie inventory

Every scan produces timestamped evidence: detected scripts with source URLs, cookie names with domain and expiry metadata, a pre-consent timeline, and a cookie category map. This evidence feeds directly into the cookie inventory where you can review, re-categorize, and publish a cookie declaration. For managed sites, each scan is saved so you can compare results over time and demonstrate change history to auditors.

Detected signal vs why it matters

Detected signalWhat it meansWhy it matters for GDPR
Google Analytics (GA4) before consentGA4 collect hits fire before consent choice recordedPersonal data (IP, client ID) may be processed without legal basis
Meta Pixel PageViewPixel fires before visitor accepts cookiesMeta receives event data; consent is typically required under ePrivacy
Google Tag Manager without consent checkGTM container loads with all tags firing unconditionallyAny tag in the container can fire without consent — hard to audit
Google Consent Mode v2 missingNo gtag consent.default commands before tags loadGoogle treats missing consent signals as implied consent in some regions
Hotjar / session recordingSession recording script loads before consentRecords user interactions; requires explicit consent in most EU jurisdictions
Unknown third-party domainsNetwork requests to domains not in known tracker listsMay indicate shadow tracking or unvetted vendor scripts on the page

Frequently asked questions

What does a GDPR scanner detect?
A GDPR scanner inspects your website for cookies, tracker scripts, marketing pixels, analytics tags, pre-consent network requests, and consent banner signals. It identifies known services like Google Analytics, Meta Pixel, Hotjar, and Google Tag Manager, and reports whether they fire before or after a consent interaction. The output is a structured cookie and tracker inventory with evidence.
Can it scan tracker scripts?
Yes. GDPRChecker scans for JavaScript tracker scripts from Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, Hotjar, FullStory, and many other common third-party services. Each script is identified by its source URL, categorized by type, and checked for whether it fires before consent.
Does it detect pre-consent requests?
Yes. The scanner captures the timing of network requests during page load and flags any analytics, marketing, or advertising endpoint that fires before the visitor has made a consent choice. This is one of the most important signals for GDPR compliance and a core capability of the scanner.
Does it support Google Consent Mode v2?
Yes. When the scanner detects Google tags (GA4, GTM, Google Ads), it checks whether Google Consent Mode v2 default commands are set before tags load and whether the consent state is updated after user interaction. This helps verify that your Google implementation aligns with Google's EU user consent policy requirements.
How often should I scan my site?
Scan after every significant site change — new marketing tags, theme updates, GTM container changes, or third-party plugin installs can introduce new trackers silently. For managed sites, GDPRChecker supports scheduled weekly or daily scans with automated alerts when new cookies or scripts are detected, so you do not need to remember to run a scan manually.

Related GDPRChecker tools

GDPRChecker provides automated technical checks, templates, and operational guidance. It does not provide legal advice and does not guarantee compliance with GDPR, UK GDPR, ePrivacy, CCPA, PIPEDA, Law 25, or any other law.