How-to guide

How to detect tracking before consent

To detect tracking before consent, review a fresh page load before any consent interaction and compare observed tracking requests, cookies, and consent-surface evidence. CertScore.ai automates this review as a public website risk signal for teams to investigate.

By CertScore.ai

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan

1. Define a repeatable starting point

Record the exact public URL, date, browser, region, and the tag-manager or CMP version being reviewed. Use a fresh browser profile with no stored consent for each independent test. Do not log in, enter personal information, or interact with account or checkout controls.

A baseline ends when a consent interaction occurs. Keep an untouched baseline separate from Accept and Reject sessions so a prior choice cannot explain later requests. Record unavailable pages or blocked access as limitations.

2. Observe the initial page load

For a manual check, open the browser Network panel before loading the target and keep the request log. Inspect requests, initiators, response timing, and cookies or storage while leaving the consent banner untouched. A third-party domain alone does not establish a tracking purpose.

With CertScore, enter the public URL in the scanner and read the completed report. Confirm the scan context and coverage before interpreting the pre-consent findings. Use the retained evidence attached to each finding rather than inferring behavior from a banner screenshot.

3. Separate requests, stored values, and purpose

A request shows communication; a cookie snapshot shows stored state. Record the vendor classification, request timing, cookie name/domain/path or storage origin/key, and the evidence reference. Review unclear vendor purposes with the implementation owner.

Check both the tag manager and scripts embedded directly in templates. Embedded media, analytics, advertising, and replay integrations can have different triggers. Do not classify every third-party service as non-essential solely because it is external.

4. Build a useful evidence record

For each observation, record: target URL; date and region; baseline or action session; request or storage identity; observed purpose; timestamp; report evidence reference; coverage limitation; owner; and next action. Omit raw cookie values, personal data, and sensitive query strings from shared tickets.

Open the sample report to see how evidence is presented. Its observations belong to that sample scan and should never be copied into a finding about a different site.

5. Diagnose the configuration and retest

Ask the implementation owner to compare the observed request with consent-category mappings, tag firing rules, consent defaults, and hard-coded integrations. Verify the intended behavior before changing a rule; an essential service may need different handling from advertising.

After the change, repeat the same starting conditions in a fresh session. Compare the affected requests and storage activity, not just the overall score. Record a blocked or incomplete retest as inconclusive. Extend manual review to important templates and regions beyond the scanned surface.

Keep the conclusion within the evidence

No observed tracking means none was observed within the tested scope; it does not establish that tracking never occurs. A banner being visible is not proof that tags wait for consent. A scan is evidence for review, not a legal compliance determination.

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan
CertScore.ai automated findings may contain errors. Always review the underlying evidence. CertScore.ai does not provide legal advice, certification, or compliance determinations.