GDPRChecker

Home / Knowledge Base / What Does a Cookiebot Scan Check? Results, Coverage and Limits

Website Compliance

What Does a Cookiebot Scan Check? Results, Coverage and Limits

Learn what a Cookiebot scan inventories, why scan coverage varies, and which runtime consent checks you still need before treating a website as compliant.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

August 2026

Reading time

4 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

Introduction

Explain what a Cookiebot scan can discover, what an inventory crawl cannot prove, and how to verify consent behavior independently on a live website.

This guide is written for website owners, privacy teams, marketers, and developers reviewing Cookiebot scan results.

What it means

Quick answer: a Cookiebot scan crawls reachable HTML pages and looks for detectable cookies and tracking technologies. Its official documentation lists HTTP and JavaScript cookies, local storage, IndexedDB, pixel tags, and other tracker types. The report can include category, provider, type, first-found URL, initiator, source, and tag-manager path where available.

Cookiebot says its scanner follows navigable content such as static and dynamic pages, links, embedded videos, pop-ups, and other interactive elements. Review the discovered URL list because sitemap quality, duplicate URLs, regional delivery, login barriers, and unlinked journeys can change coverage.

Coverage depends on the pages reached, regional delivery, authentication, delayed interactions, tag-manager rules, and whether a technology appears only after a user action.

An inventory result does not by itself prove that every non-essential request is blocked before consent or that Reject, granular choices, withdrawal, and repeat visits work correctly.

Validate the live consent flow in separate clean sessions and inspect network requests, cookies, local storage, pixels, iframes, and consent signals in every important state.

Reconcile the observed inventory with banner categories, the cookie declaration, privacy disclosures, vendors, purposes, retention, and the team's tag register.

Repeat both inventory and runtime tests after CMP, tag-manager, CMS, plugin, campaign, or application releases because scan findings are a time-specific snapshot.

Teams evaluating a replacement can use the Iubenda vs Cookiebot comparison to separate scanner coverage from consent enforcement, policy tooling, pricing, and migration effort.

Why it matters

Cookie discovery and consent enforcement answer different questions. Discovery asks what technology exists; runtime verification asks whether the website respects a visitor's choice before and after interaction.

Using both layers helps teams avoid a common false positive: a complete-looking cookie declaration paired with scripts that still initialize too early or remain active after rejection or withdrawal.

Common mistakes

  • Treating a successful inventory crawl as a GDPR certificate or legal conclusion.
  • Scanning only the home page while ignoring checkout, account, blog, campaign, embedded-media, and authenticated templates.
  • Testing only after Accept and never testing untouched, Reject, granular choice, withdrawal, expiry, or returning-visitor states.
  • Reviewing cookies but ignoring requests, local and session storage, pixels, iframes, SDKs, and server-side destinations.
  • Assuming an unknown item is harmless instead of identifying its owner, purpose, trigger, legal basis, and retention.
  • Failing to rescan after a tag, plugin, CMP, CMS, or marketing release changes production behavior.

What a Cookiebot scan checks—and what needs separate verification

AreaWhat the scan can showWhat to verify separately
Cookies and storageDetected HTTP/JavaScript cookies, local storage, IndexedDB, and other supported tracker typesItems triggered only in unreached regions, sessions, forms, accounts, or journeys
Pixels and embedded technologyDetected pixels, scripts, iframes, images, videos, initiators, and sourcesWhether every custom integration stays blocked in each consent state
Pages and discoveryReachable HTML pages and a discovered URL listAuthenticated areas, unlinked routes, campaign variants, checkout completion, and application states
ClassificationNecessary, preferences, statistics, marketing, or unclassified inventory entriesWhether each purpose, provider, category, retention period, and legal basis is correct
Prior-consent findingsPotential cookies or trackers observed before consent during the crawlUntouched, Reject, granular choice, Accept, withdrawal, expiry, and repeat visits in clean sessions
Compliance conclusionTechnical evidence from a time-specific automated crawlLegal sufficiency, contracts, rights handling, security, governance, and future regressions

Practical checklist

  1. List representative URLs for every template, market, language, authenticated state, and high-risk user journey.
  2. Run the Cookiebot inventory scan and export or record each detected technology, provider, category, page, and unknown item.
  3. Open a clean browser session and capture requests, cookies, storage, pixels, and consent signals before touching the banner.
  4. Repeat the capture after Reject, granular choices, Accept, withdrawal, consent expiry, and a returning visit.
  5. Compare observed behavior with CMP configuration, tag-manager triggers, cookie declarations, privacy policy, vendor list, purposes, and retention periods.
  6. Assign every mismatch to an owner, fix high-risk pre-consent activity first, and preserve timestamped evidence of the retest.
  7. Schedule rescans after relevant releases and at a recurring cadence to catch configuration drift.

How GDPRChecker helps

Use the GDPR compliance checker as an independent technical check alongside Cookiebot to observe production requests, storage, trackers, and consent-state behavior rather than relying only on CMP configuration.

Scanner findings are technical evidence, not legal certification. Legal bases, contracts, rights handling, retention, security, and policy wording still require accountable review.

FAQ

What does a Cookiebot scan check?
It primarily crawls reachable pages to identify detectable cookies and related website technologies, then supports inventory and categorization. Exact coverage depends on crawl reach, geography, interactions, and site behavior.
Does a Cookiebot scan prove GDPR compliance?
No single automated scan proves GDPR compliance. A scan is useful technical evidence, but consent enforcement, disclosures, legal bases, contracts, retention, rights handling, and governance also need verification.
Why can a Cookiebot scanner miss a cookie or tracker?
A technology may require login, scrolling, video playback, a form action, a particular region, a campaign parameter, or a delayed tag-manager trigger that the crawl did not encounter.
Should I test the site before accepting cookies?
Yes. Start with a clean session and inspect the untouched state, then test Reject, granular choices, Accept, withdrawal, expiry, and returning visits separately.
What should I do with unknown cookies?
Identify the script or vendor that creates them, document purpose and retention, confirm the correct consent category and legal basis, then update controls and disclosures before retesting.
How often should I run another scan?
Rescan after changes to the CMP, tag manager, CMS, plugins, campaigns, embeds, or application code, and use a recurring schedule that matches the site's release frequency and risk.
How often does Cookiebot scan a website?
Cookiebot's official support documentation describes an automatic first scan after a domain is added and recurring monthly scans, with daily scanning available in some configurations. Confirm the current schedule in your account and run an additional independent check after important releases.

GDPRChecker guides are educational resources and do not constitute legal advice. Use them to understand technical and operational privacy requirements, and consult qualified counsel for legal interpretation.

Check Your Website in Under 60 Seconds

  • No signup required
  • GDPR-focused checks
  • Cookie banner detection
  • Privacy policy verification