BlogCookieGap Is Live: Find the Cookie Violations Your Banner Is Hiding
Product Updates

CookieGap Is Live: Find the Cookie Violations Your Banner Is Hiding

CookieGap is now available. It checks what your site actually does with cookies before consent, after rejection, and in each region you serve, then watches for drift.

July 26, 2026·CookieGap Team

In November 2025, France's data protection authority fined the publisher of vanityfair.fr €750,000 over how the site handled cookies. Three things went wrong. Cookies that required consent were set the moment a visitor arrived, before they touched the banner. Some cookies were labelled "strictly necessary" when they were not. And when visitors clicked "Refuse all", new cookies were still written and existing ones were still read.

Look at that list again. Every one of those failures happened behind a working consent banner. Nothing on the page looked broken.

That gap is why we built CookieGap, and it is now available.

A banner is not compliance

Most teams treat the consent banner as the finish line. You install a consent platform, configure your categories, see the banner appear, and move on to the next ticket.

The banner is the interface, not the behaviour. Regulators do not audit whether a banner exists. They audit what happens to cookies and trackers around it. Those are two different questions, and they come apart more often than teams expect.

A 2026 study of 14,000 websites measured this. In the EU sample, 44% of sites set cookies before any consent was given, and roughly a quarter across all samples kept cookies in place after a visitor explicitly rejected them. That matches earlier work: a widely cited study of 680 consent popups on the UK's top 10,000 sites found only 11.8% met even a minimal reading of European legal requirements.

The three failures that keep showing up

Across the sites we have scanned, the same three problems account for most of the risk.

Cookies before consent. Analytics and advertising scripts fire on page load, before the visitor has agreed to anything. Usually this is a tag that was added outside the consent platform, or a category that was never wired to actually block anything.

Trackers that survive rejection. A visitor clicks "Reject all". The banner disappears. On the next page load, the trackers are back. This is the single most commonly missed violation we see, and it was one of the specific findings in the Condé Nast case. It is also the one nobody checks, because the banner behaves correctly and the failure only shows up after the page reloads.

Cookies labelled as necessary when they are not. The "strictly necessary" category is exempt from consent, which makes it a convenient place to put things. Marketing and analytics cookies sitting in that bucket are a straightforward finding for a regulator.

Where you scan from changes the answer

This is the part most audits miss entirely.

Cookie behaviour is frequently geographic. Plenty of European publishers show their consent banner only to visitors who appear to be in the EU or the UK. Check one of those sites from a server in the United States and you will find no banner at all. That result is accurate for a US visitor and close to useless for judging GDPR exposure. It runs the other way too: a US site may load different tags for a California visitor because of CCPA obligations, invisible from outside California.

So the location a scan runs from decides both which behaviour you observe and which law that behaviour gets judged against.

A default scan runs from one location and is graded against a global baseline, meaning worst-case exposure across GDPR, ePrivacy, and CCPA at once. That is a useful starting number and deliberately conservative. What it is not is a picture of what any particular visitor receives.

Paid plans scan from inside the region instead: the EU, the UK, California, the wider US, Brazil, or Canada. The scan is graded against the frameworks that actually apply there, so a European result is judged on GDPR and ePrivacy while a Texas result is judged against US state opt-out requirements rather than California's. In other words, you scan from where the law is enforced.

Every report says which jurisdiction it was graded against and why. You are never left guessing whether a grade reflects your EU visitors or a global worst case.

Free scans run from the default location. If you just need a few regions without a subscription, a one-time scan pack unlocks them.

Sites drift, so watch them

Passing an audit is a moment, not a state.

Someone in marketing adds a tag through a container you do not review. A consent category gets toggled during an unrelated fix. A vendor updates their script and it starts setting a cookie it did not set last quarter. None of these change how the banner looks, so none of them get noticed, and the site quietly stops being compliant somewhere between one deploy and the next.

Monitoring handles that. Add a domain, pick weekly, monthly, or quarterly, and each scheduled scan emails you the new grade and what changed. Pause a domain while you are mid-migration, or turn alerts off for one that is noisy. Monitoring is included on the Pro and Business plans, covering five and twenty domains.

What a scan gives you

A scan covers all three failures above: what loads before consent, what survives a rejection and a reload, and which cookies are miscategorised. It also confirms a reject option genuinely works rather than merely rendering.

You get a graded report with the findings, the legal basis for each, and what to change, scored across GDPR, ePrivacy, CCPA, US state opt-out requirements, LGPD, and PIPEDA. Most scans finish in under 30 seconds, and it works with all major consent management platforms without changing anything about your setup.

Start with your own site

Scan a domain free, no account needed, and see what your banner is actually doing. If the grade surprises you, the report will tell you exactly which cookie or tag caused it.

Then scan it again from the region your visitors are actually in. That is usually where the interesting findings are.

Sources

See where your site stands

Run a free CookieGap scan and get a compliance report in under a minute.

Scan your site free