What would the privacy regulator's robot see on your site?
Enter your site's address. We load it in a real browser, refuse the cookies, and tell you what fires anyway.
A visitor opens a site. The banner asks for their choice. Watch what fires before they answer, and what fires after they refuse.
A visitor arrives. The banner shows. They haven't clicked anything yet.
Three trackers fire anyway. Google, Meta and Hotjar already have their identifier.
They click Refuse. The banner disappears.
Two fire again. The refusal isn't enforced. That's what the regulator's robot writes down.
You put the three scripts on hold until the choice. One line each.
The same visitor comes back. The banner shows. Nothing fires.
They refuse.
Nothing fires. Only the session cookie, which is exempt, is there.
What stops the trackers takes one line per script, in your consent manager.
The banner is visible. The violation isn't. The regulator's robot sees it. Your site may be in this position.
Bannerpresent
Refusefirst level
Trackersbefore the choice
Trackersafter refusal
Cookiesset outright
Noticeidentity
Hostnamed
Rightsexercise
Retentionperiods
Bannerpresent
Refusefirst level
Trackersbefore the choice
Trackersafter refusal
Cookiesset outright
Noticeidentity
Hostnamed
Rightsexercise
RetentionperiodsNine points, and one robot that verifies them without waiting for a complaint. Yet nineteen sanctions out of twenty-three in 2026 start with a complaint: one unhappy visitor is enough.
What exactly does this scan check?
What the regulator's robot checks. It loads your page in a real browser, touches nothing, and counts the trackers that fire. Then it refuses, like a visitor, and counts again. Alongside, it reads your legal notice and privacy policy, looking for what the law requires.
Am I really at risk?
Since January 2026, the French regulator (CNIL) issues fast-track sanctions capped at €20,000, averaging around €6,000. A third of the businesses inspected are small companies, and cookies are the top ground. Nineteen sanctions out of twenty-three start with a complaint: one unhappy visitor is enough.
My banner is there. Why is the score low?
Because a banner isn't enough. The most common flaw is a tracker firing before the click, or firing anyway after a refusal. The banner is visible, the violation isn't. That's precisely what this scan measures.
What does the score measure?
Thirteen checks in four categories, out of 100. Consent (banner, first-level refuse, nothing before the choice, nothing after a refusal), cookies set outright, the legal notice (identity, host, publication director) and the privacy policy (rights, how to exercise them, retention). A check with nothing to examine leaves the calculation.
Does a good score mean I'm compliant?
No. This scan looks at what a visitor and a robot can see. It judges neither the substance of your processing, nor your contracts with processors, nor your records. It's the first filter, the one that stops the most common complaints.
Scan of example.com
0,0 sYour score is building.
Each category adds the points it earns, and shows the ones you're missing.