Platform-agnostic technical privacy

Website Privacy & Consent Audit

You do not need to be on Shopify or WordPress. PlainPrivacy can review custom websites and other CMS or ecommerce stacks when the live implementation can be observed and, where remediation is requested, the relevant configuration or code can be accessed.

Technical assessment and implementation support. PlainPrivacy does not provide legal advice.

Audit method
01

Observe the live implementation

02

Compare consent states

03

Document evidence and priorities

04

Implement and retest when requested

Scope

What we investigate on any website stack

The review starts with actual browser behavior, then follows the evidence into the CMP, tag manager, CMS, plugins, apps or custom code involved in that behavior.

01

Consent banner & CMP

Test the visible consent experience, categories, accept/reject behavior, preference changes and withdrawal mechanism.

02

Cookies & browser storage

Inventory cookies, localStorage, sessionStorage and other browser-side identifiers across consent states.

03

Pixels, scripts & requests

Inspect analytics, advertising, embeds and other third-party requests rather than relying only on scanner output.

04

Tag managers & analytics

Review GTM, GA4, Google Ads, Meta Pixel and comparable tracking tools where present.

05

CMS, apps & custom code

Trace tracking introduced by plugins, apps, themes, embeds or custom JavaScript and identify controls that are bypassed.

06

Regional behavior

Where required, test configured regional experiences and document differences in consent or opt-out behavior.

Evidence

What the review is based on

Findings are grounded in observable website behavior and the configuration available within the agreed scope.

  • Fresh browser sessions and controlled consent journeys
  • Cookies and browser storage
  • Network requests and third-party domains
  • CMP/tag-manager state where available
  • Platform/configuration review within agreed access
  • Screenshots and reproducible findings

Deliverables

What you receive

The output is designed to be usable by business owners, developers, agencies and privacy advisers.

  • Prioritized technical findings
  • Cookie/tracker/vendor inventory
  • Consent-state and withdrawal findings
  • Implementation recommendations
  • Optional remediation support
  • Post-fix verification

How it works

Investigate first. Change only what the evidence supports.

The initial review establishes the current behavior. Recommended changes are then scoped, implemented only when agreed, and retested afterward.

1

Review

Confirm the platform, regions, consent system and tracking stack that need to be tested.

2

Test

Run controlled browser journeys and inspect consent, storage, requests and tracking behavior.

3

Prioritize

Separate working controls from technical issues and identify the fixes that matter most.

4

Fix & verify

When implementation support is requested, apply agreed changes and repeat the relevant tests.

Request a technical review

Need evidence of what your website is actually doing?

Tell us about the website, platform, consent setup and current concern. We will suggest an appropriate technical scope.

Request Your Technical Audit