Skip to content
Transparency

What We Detect — And What We Don't

We believe honest transparency about capabilities and limitations builds more trust than inflated claims. Here is exactly what GDPR Privacy Monitor checks, our confidence levels, and what falls outside our scope.

What We Detect

Check CategoryWhat We Look ForConfidence
Pre-consent trackingCookies, trackers, and scripts active before user consent interaction
HighHigh (Verified CMP) / Medium (Compatible CMP)
Cookie classificationCategorization into necessary, analytics, marketing, functional
HighHigh for 5,000+ known cookies; "unclassified" for unknown cookies
CMP detectionConsent banner presence and CMP type identification
HighHigh: CookieYes, Cookiebot. Medium: OneTrust, iubenda, Complianz, Didomi, Quantcast + 15 others
Reject flow verificationWhether "Reject" actually stops tracking cookies and third-party requests
HighHigh for Verified CMPs with known reject selectors
Banner accessibilityKeyboard navigation, color contrast, touch targets, ARIA labels (WCAG)
HighHigh (browser DOM measurements)
Visual prominenceWhether reject is equally prominent as accept (dark pattern detection)
MediumMedium (CSS sampling, may vary by viewport)
Cookie wall detectionWhether content is blocked until consent is given
MediumMedium (heuristic-based)
Google Consent Mode v2Detection and mismatch analysis between declared consent state and observed behavior
HighHigh (runtime interception)
Data flow mappingThird-party data destinations, organizations, and adequacy status
MediumMedium (45% of domains unmapped)
External font loadingGoogle Fonts and other CDN IP leaks before consent (LG München ruling)
HighHigh (URL pattern matching)
Mixed contentHTTP resources loaded on HTTPS pages (security of processing)
HighHigh (network request analysis)
Insecure cookiesTracking cookies without Secure flag or appropriate SameSite
HighHigh (cookie attribute inspection)
Browser fingerprintingPre-consent fingerprinting-sensitive API calls (Canvas, WebGL, fonts)
MediumMedium (compound scoring of intercepted signals)
Evidence collectionHAR network log, page screenshots, banner screenshots
HighHigh (100% coverage on successful scans)
Preference center analysisSecond-layer category toggles, pre-selected optional categories
HighHigh for Verified CMPs
DPA enforcement contextHistorical enforcement fines and cases mapped to detected findings
HighHigh (structured enforcement database, 22+ jurisdictions)

What We Don't Detect (Honest Limitations)

LimitationWhyWhat We Do Instead
Server-side trackingCannot see server-to-server data transfersWe detect client-side indicators and note the limitation in the report
Geotargeted bannersWe scan from EU (Germany); may miss geo-specific configurationsWe note viewport and location in every report for transparency
Mobile app consentWe scan websites, not native mobile appsMobile viewport scanning available for responsive sites
Legal policy qualityWe do not assess privacy policy text quality in depthAI-powered policy gap detection identifies missing disclosures vs runtime behavior
Cookie purpose accuracySome cookies lack reliable classification in public databasesWe label as "unclassified" with honest scoring rather than guessing
Dynamic SPA timingSingle-page apps may load consent banners late or asynchronouslyWe use adaptive waiting strategies and report "could not detect" when uncertain
Post-scan changesWebsites change after we scan themContinuous monitoring catches regressions; each report is timestamped
Cross-origin iframe bannersSome CMPs render banners in cross-origin iframes that cannot be inspectedWe detect CMP signals and report banner visibility uncertainty

Our Philosophy

"Cannot determine" > false positive

When we are not confident about a finding, we say so. We will never manufacture false positives to inflate detection numbers. An honest "cannot determine" is more valuable than a confident wrong answer.

Risk Score, not Compliance Score

Our 0–100 score indicates technical risk, not legal compliance status. A low score means fewer technical risk indicators were found — it does not certify GDPR compliance. Only legal counsel can determine compliance.

Independent auditor

We do not sell consent banners, CMP software, or cookie solutions. This means we have no conflict of interest — we can tell you honestly when your CMP is misconfigured, even if it's a popular one.

Evidence-first reporting

Every finding is backed by HAR network data and screenshots. You can verify any finding independently using the evidence pack we provide. No black-box scoring — full transparency.

See it in action on your site

Run a free scan and see exactly what we detect on your website, with full evidence and a transparent risk score breakdown.

Run a free scan
What GDPR Privacy Monitor Detects — And What It Doesn't | Honest Scanning Transparency