Browser-level tracking evidence

Cookie & Tracker Technical Audit

A scanner-generated cookie list is useful, but it does not always explain when a technology runs, what third party receives data or whether the consent choice actually controls it. PlainPrivacy combines inventory work with live browser testing.

Technical assessment and implementation support. PlainPrivacy does not provide legal advice.

Audit method
01

Observe the live implementation

02

Compare consent states

03

Document evidence and priorities

04

Implement and retest when requested

Scope

More than a cookie scan

The audit compares scanner output with what the browser actually stores and sends during real page loads and consent journeys.

01

Cookies

Identify first- and third-party cookies observed during the tested journeys and the consent state in which they appear.

02

Local & session storage

Review browser storage identifiers that may not appear in a conventional cookie report.

03

Pixels & scripts

Identify analytics, advertising and other third-party scripts/pixels that execute on the site.

04

Network requests

Inspect third-party domains and browser requests to understand actual data flows visible from the client side.

05

Consent categories

Compare the CMP categories with the technologies they are expected to control.

06

Consent-state behavior

Test fresh visit, accept, reject, granular preferences and later withdrawal/change of consent.

Evidence

What the review is based on

Findings are grounded in observable website behavior and the configuration available within the agreed scope.

  • Observed cookie/storage inventory
  • Third-party domain inventory
  • Network request evidence
  • Before-consent behavior
  • Accept/reject comparisons
  • Consent withdrawal retest

Deliverables

What you receive

The output is designed to be usable by business owners, developers, agencies and privacy advisers.

  • Evidence-based tracker inventory
  • Mismatch between scanner and browser findings
  • Consent-control findings
  • Prioritized remediation list
  • Developer-friendly implementation notes
  • Optional post-fix verification

How it works

Investigate first. Change only what the evidence supports.

The initial review establishes the current behavior. Recommended changes are then scoped, implemented only when agreed, and retested afterward.

1

Review

Confirm the platforms, regions, consent system and tracking stack that need to be tested.

2

Test

Run controlled browser journeys and inspect consent, storage, requests and tracking behavior.

3

Prioritize

Separate working controls from technical issues and identify the fixes that matter most.

4

Fix & verify

When implementation support is requested, apply agreed changes and repeat the relevant tests.

Request a technical review

Need evidence of what your website is actually doing?

Tell us about the website, platform, consent setup and current concern. We will suggest an appropriate technical scope.

Request Your Technical Audit