Privacy

Nothing is stored on a visitor's device before they agree to it

privacy.cookies-before-consent

Why this matters

UK law treats putting anything on a visitor's device — a cookie, or a record kept in the browser's own storage — as something that needs permission first, unless it is genuinely required to deliver what the visitor asked for. Analytics does not count as required, however anonymous it is, and the Information Commissioner's Office has said so repeatedly. This is one of the few things a website audit finds where the risk is a regulator rather than a lost sale.

Who fixes it

You can, usually

Roughly how long

1–3 hours

Care needed

Low risk to change

How to fix it

In your consent tool, set every analytics, advertising and chat tag to load only after consent — most tools install with the tags firing immediately and the banner as decoration. If you use Google Tag Manager, that means consent mode with the defaults set to denied, not a trigger that fires on page view. Then reload the page in a private window and check the cookie list is empty before you click anything.

Before you start

  • Access to whatever loads your tags — the consent tool, or the tag manager

How we score it

Failing this check takes up to 25 points off your privacy score. It is a fact about your site rather than a measurement, so it reads the same on every scan until you change something.

Does your site pass this one?

This check runs on every scan, along with the other 106. Free, no account, and you see the evidence for each result.

Check my site

Other privacy checks

See all 107 checks