Introduction
Fix a consent banner that displays but does not block cookies. Diagnose why scripts still fire despite the banner and implement enforcement.
What it means
The consent banner appears correctly but non-essential cookies and tracking requests continue to fire regardless of whether the user clicks Accept or Reject. The banner controls UI state only and is not connected to script execution.
This is a cosmetic banner — it creates the appearance of compliance without providing actual consent enforcement. Scanners detect this by observing network behavior after user interaction.
Why it matters
Regulators and compliance scanners treat this issue as a technical indicator that consent processes may not match stated policies. It is one of the most common findings in automated GDPR audits across all website categories.
Fixing this issue typically produces the largest single improvement in compliance scores, because it addresses the most heavily weighted scanning criteria.
Common mistakes
- Assuming the banner UI alone is sufficient — scanner findings are based on network and script behavior, not visual inspection.
- Testing only with an already-consented browser session, which hides the pre-consent behavior.
- Fixing the homepage but not campaign landing pages, subdomains, or localized variants.
Practical checklist
- Verify your CMP or runtime guard uses blocking mode, not notice-only mode. Configure blocking rules for each consent category.
- Ensure the blocking script loads before any analytics or marketing tags in the HTML head — check with View Source.
- Wire GTM triggers to consent state so that analytics and marketing tags only fire when the matching category is granted.
- Test Reject in a private window: click Reject all, navigate to two internal pages, and confirm zero tracking requests on subsequent pages.
- Run a compliance scan after fixes to confirm the issue is resolved.
- Document the fix date and rescan result for audit evidence.
How GDPRChecker helps
GDPRChecker flags banner not blocking cookies as a high-severity finding in scan reports. The scanner loads your page as a first-time EU visitor and reports the specific network request, script source, or missing element that triggered the finding.
After implementing the fix, rescan your site with GDPRChecker to confirm the finding is cleared and your compliance score improves.