Consent Validator
HomeFeaturesPricingDocumentation
Sign inGet Started

GDPR · ePrivacy · Google Consent Mode v2 · TCF-aware signals

Know exactly what your consent stack does — before a regulator does.

Consent Validator checks your sites two ways: live consent validation — what actually fires before consent, on reject, and on accept — and a read-only Google Analytics 4 & Tag Manager configuration audit, including Consent Mode v2. Gaps surface before audits do.

Get StartedView sample report

No tag · No SDK · No DNS change · Evidence-backed report in minutes · Sign in

Sample dashboard — your first validation populates this view

example.com

Jun 11 · 14:32

Overall

74 / 100

Consent

68%

Analytics

80%

Visitor journey

  • Before Consent

    2 problems

  • Reject

    1 problem

  • Accept

    Passed

2 critical1 warning

Most consent implementations are never verified

Configuration looks correct. Runtime behavior often tells a different story.

Trackers fire before consent

Tags and pixels load before anyone clicks accept. Every visit creates exposure — and without monitoring, the first person to notice is often an auditor, not your team.

Compliant launches drift

A new GTM tag or third-party script can bypass your CMP overnight. What passed review last quarter may be out of compliance today, with no alert.

No audit trail when asked

When a regulator asks how rejection is enforced, a banner screenshot is not proof. You need a record of what actually ran in every consent state.

Three consent states. One validation run.

Each state is tested independently so you know enforcement holds at every step.

Before Consent

Nothing fires early

Requests, cookies, and storage writes are checked before any user interaction.

Cookies2 unauthorized
TrackersAll blocked
Reject

Rejection is enforced

Trackers, cookies, and storage writes are verified to actually stop after reject.

Ad pixelStill firing
Local storageCleared
Accept

Only declared vendors unlock

Granted consent activates exactly the vendors you have declared — nothing extra.

Consent ModeGranted
Tracking IDsValidated

Inside the app

What you get after sign-in

The same surfaces you saw in the sample — scoring, journey outcomes, and actionable findings. No separate marketing dashboard.

Two-module scoring

Consent and Analytics scored independently. Overall is their mean — missing modules never penalize the score.

Business-readiness pillars

Consent, Analytics, Conversions, and Privacy — technical findings translated for compliance teams.

Visitor journey

Before Consent → Reject → Accept on one timeline, with problem counts per state.

Issues & monitoring

Sites ranked by severity, plus scheduled drift checks and alerts after deploys.

Every layer of your consent stack

Checked against real browser behavior, not configuration alone.

Consent Banner Checks

Verify banner appearance, timing, and interaction handling

Cookie Analysis

Classify every cookie by purpose and catch mislabeled entries

Script Detection

Identify third-party scripts that load outside declared consent

Network Request Analysis

Audit outbound requests at every consent state

Consent Mode Validation

Verify Google Consent Mode v2 signal firing and value accuracy

Storage Inspection

Check localStorage and sessionStorage writes against declared policy

GA4

Confirm analytics activation aligns with granted consent

GTM

Validate tag firing rules across all consent states

Meta Pixel

Verify pixel triggers only after affirmative consent

GPC

Check Global Privacy Control signal recognition and response

Privacy Link Checks

Confirm accessible and accurate privacy and cookie policy links

Works with your existing consent setup

Consent Validator observes behavior — it doesn't replace your CMP.

OneTrust
Cookiebot / Usercentrics
CookieYes
Didomi
Axeptio
Consentmanager
TrustArc
Custom / bespoke

Don't see your CMP? We validate observable behavior — if it's on your page, we'll find it.

Google Analytics integration

Connect Google Analytics for a read-only GA4 configuration audit

Optional. Link your own Google Analytics account and Consent Validator audits your GA4 setup — data retention, Google signals, Consent Mode defaults, and key events — against GDPR and Consent Mode v2 best practices. The core consent validation works without it.

Read-only, never modified

We request only the read-only Google Analytics scope (analytics.readonly) to read your GA4 configuration. We never change anything in your Google account and never read your visitors' analytics data.

You stay in control

Connect or disconnect anytime from Settings — disconnecting deletes the stored tokens immediately. Tokens are kept server-side and are never exposed to the browser.

Limited Use

Consent Validator's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we handle Google data

Drill into audit-ready reports

Each validation opens a two-module report with findings, evidence, and export — PDF, share link, or JSON for your DPO or auditor.

example.com

Scanned Jun 11, 2026

Overall compliance

74 / 100

Consent validation

68%

Tests Before Consent, Reject, and Accept in a real browser.

Analytics validation

80%

Read-only GA4 and GTM audit when Google is connected.

Key findings

  • Critical

    Meta Pixel fires before consent

    Gate the pixel behind your CMP accept action.

    Before Consent

  • Warning

    ad_user_data missing from default update

    Include all four Consent Mode v2 parameters in the update call.

    Accept

  • Warning

    Non-essential cookie set pre-consent

    Move _ga cookie creation behind affirmative consent.

    Before Consent

Export PDF · Share link · Download JSON

Full sample

Built for compliance teams who need evidence, not assumptions.

Browser-based analysis

Validation runs in a real browser environment — the same way a regulator or user would see your site.

Privacy-first approach

We don't store your users' data. Validation observes your site's behavior, nothing more.

Actionable reports

Every finding includes a severity rating, what triggered it, and a concrete next step.

Export support

Reports are exportable as PDF and JSON, ready to share with legal, DPOs, or external auditors.

Continuous monitoring

Set up scheduled scans. Get alerted when consent behavior changes after a CMP update or new tag deployment.

Frequently asked questions

A cookie scanner inventories cookies on a page. Consent validation tests what actually happens in each consent state — before choice, after reject, and after accept — including trackers, storage, and Consent Mode signals.

No. Scans load your public URL in an isolated browser session. There is no tag to install, no SDK, and no impact on real visitor traffic.

Findings map to GDPR, ePrivacy, and Google Consent Mode v2 requirements. Where your site exposes IAB TCF signals, we report TCF availability and related consent-string behaviour. Reports are structured for compliance teams and auditors.

Custom implementations are supported. We validate observable behavior — if it appears on your page, we test it across all three consent states.

CMP dashboards show configuration. We verify runtime behavior — what fires, when, and whether rejection is actually enforced on your live site.

Yes. Weekly Monitor and higher plans include scheduled scans with drift detection and alerts when compliance changes.

Create an account, enter a public URL, and run a validation. No tag installation, DNS changes, or engineering work required.

No. Validations are billed per scan or included in a monitoring plan. Single scans start at $29; see Pricing for plan details.

See what's actually happening on your site.

Create an account, enter a URL, and get an audit-ready report in about a minute — no installation required.

Get StartedTalk to us

Product

  • Features
  • Pricing
  • Run a Scan
  • Sample Report

Resources

  • Documentation
  • Blog

Company

  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 Consent Validator

XGitHub