GDPR · ePrivacy · Google Consent Mode v2 · TCF-aware signals
Know exactly what your consent stack does — before a regulator does.
Consent Validator checks your sites two ways: live consent validation — what actually fires before consent, on reject, and on accept — and a read-only Google Analytics 4 & Tag Manager configuration audit, including Consent Mode v2. Gaps surface before audits do.
No tag · No SDK · No DNS change · Evidence-backed report in minutes · Sign in
Sample dashboard — your first validation populates this view
example.com
Jun 11 · 14:32
Overall
74 / 100
Consent
68%
Analytics
80%
Visitor journey
Before Consent
2 problems
Reject
1 problem
Accept
Passed
Most consent implementations are never verified
Configuration looks correct. Runtime behavior often tells a different story.
Trackers fire before consent
Tags and pixels load before anyone clicks accept. Every visit creates exposure — and without monitoring, the first person to notice is often an auditor, not your team.
Compliant launches drift
A new GTM tag or third-party script can bypass your CMP overnight. What passed review last quarter may be out of compliance today, with no alert.
No audit trail when asked
When a regulator asks how rejection is enforced, a banner screenshot is not proof. You need a record of what actually ran in every consent state.
Three consent states. One validation run.
Each state is tested independently so you know enforcement holds at every step.
Nothing fires early
Requests, cookies, and storage writes are checked before any user interaction.
Rejection is enforced
Trackers, cookies, and storage writes are verified to actually stop after reject.
Only declared vendors unlock
Granted consent activates exactly the vendors you have declared — nothing extra.
Inside the app
What you get after sign-in
The same surfaces you saw in the sample — scoring, journey outcomes, and actionable findings. No separate marketing dashboard.
Two-module scoring
Consent and Analytics scored independently. Overall is their mean — missing modules never penalize the score.
Business-readiness pillars
Consent, Analytics, Conversions, and Privacy — technical findings translated for compliance teams.
Visitor journey
Before Consent → Reject → Accept on one timeline, with problem counts per state.
Issues & monitoring
Sites ranked by severity, plus scheduled drift checks and alerts after deploys.
Every layer of your consent stack
Checked against real browser behavior, not configuration alone.
Consent Banner Checks
Verify banner appearance, timing, and interaction handling
Cookie Analysis
Classify every cookie by purpose and catch mislabeled entries
Script Detection
Identify third-party scripts that load outside declared consent
Network Request Analysis
Audit outbound requests at every consent state
Consent Mode Validation
Verify Google Consent Mode v2 signal firing and value accuracy
Storage Inspection
Check localStorage and sessionStorage writes against declared policy
GA4
Confirm analytics activation aligns with granted consent
GTM
Validate tag firing rules across all consent states
Meta Pixel
Verify pixel triggers only after affirmative consent
GPC
Check Global Privacy Control signal recognition and response
Privacy Link Checks
Confirm accessible and accurate privacy and cookie policy links
Works with your existing consent setup
Consent Validator observes behavior — it doesn't replace your CMP.
Don't see your CMP? We validate observable behavior — if it's on your page, we'll find it.
Google Analytics integration
Connect Google Analytics for a read-only GA4 configuration audit
Optional. Link your own Google Analytics account and Consent Validator audits your GA4 setup — data retention, Google signals, Consent Mode defaults, and key events — against GDPR and Consent Mode v2 best practices. The core consent validation works without it.
Read-only, never modified
We request only the read-only Google Analytics scope (analytics.readonly) to read your GA4 configuration. We never change anything in your Google account and never read your visitors' analytics data.
You stay in control
Connect or disconnect anytime from Settings — disconnecting deletes the stored tokens immediately. Tokens are kept server-side and are never exposed to the browser.
Limited Use
Consent Validator's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Drill into audit-ready reports
Each validation opens a two-module report with findings, evidence, and export — PDF, share link, or JSON for your DPO or auditor.
example.com
Scanned Jun 11, 2026
Overall compliance
74 / 100
Consent validation
68%
Tests Before Consent, Reject, and Accept in a real browser.
Analytics validation
80%
Read-only GA4 and GTM audit when Google is connected.
Key findings
- Critical
Meta Pixel fires before consent
Gate the pixel behind your CMP accept action.
Before Consent
- Warning
ad_user_data missing from default update
Include all four Consent Mode v2 parameters in the update call.
Accept
- Warning
Non-essential cookie set pre-consent
Move _ga cookie creation behind affirmative consent.
Before Consent
Export PDF · Share link · Download JSON
Full sampleBuilt for compliance teams who need evidence, not assumptions.
Browser-based analysis
Validation runs in a real browser environment — the same way a regulator or user would see your site.
Privacy-first approach
We don't store your users' data. Validation observes your site's behavior, nothing more.
Actionable reports
Every finding includes a severity rating, what triggered it, and a concrete next step.
Export support
Reports are exportable as PDF and JSON, ready to share with legal, DPOs, or external auditors.
Continuous monitoring
Set up scheduled scans. Get alerted when consent behavior changes after a CMP update or new tag deployment.
Frequently asked questions
A cookie scanner inventories cookies on a page. Consent validation tests what actually happens in each consent state — before choice, after reject, and after accept — including trackers, storage, and Consent Mode signals.
See what's actually happening on your site.
Create an account, enter a URL, and get an audit-ready report in about a minute — no installation required.