Checklist
What belongs in a cookie consent audit evidence pack?
Label one URL and one consent state: cookies, request URLs, screenshots, and an optional HAR. A banner image shows the controls and is not the whole pack.
In brief
A cookie consent evidence pack is one labeled file per URL and consent state. Keep the URL, time, region note, state name, cookie table, request URLs, screenshots, and an optional HAR with secrets removed. A banner image shows the controls. The cookie table and the request list show what the browser stored and sent. A free US-baseline visit is one report-format pass, not an EU or California pack. This page lists those files. It is not legal advice.
Not legal advice
This article lists the files that belong in a cookie consent audit evidence pack: a labeled record of cookies, requests, and screenshots for one URL and one consent state. It is not legal advice. It is not a certificate that a pack makes a store meet GDPR, CPRA, or any other rule. It is not a substitute for counsel.
Short answer
Build one file for each URL and each consent state you intend to talk about. Write the final URL, the time, a region or context note, and the state name. Add a cookie and storage table, the request URLs under review, screenshots of the banner and of the network or application panel, and an optional HAR with query values and bodies removed.
A banner image shows which controls were on screen. The pack also keeps the cookies and the requests from that same labeled state. Send engineering or counsel the set. The folder does not, by itself, show that a store meets a statute.
Fields on every file
Use the same columns on every state so a reviewer can line the files up. Empty cells stay empty. Do not fill a missing export with a guess.
| Field | What to write |
|---|---|
| URL | The final URL after redirects, plus the domain you meant to open. |
| Time | Clock time and timezone, so two runs can be ordered. |
| Context | Region or network note, and whether the visit was logged in. A locale setting is not a regional IP. |
| State | Fresh, Reject All, Accept All, GPC off, or GPC on. One name per file. |
| Cookies and storage | Name, host, and whether it appeared before or after the click. |
| Requests | Host, path, and whether the request was before or after the click. |
| Screenshots | The banner before the click, and the network or application panel for that state. |
| HAR, optional | Export only after query values, bodies, and session tokens are removed. |
One file per state
When the question is an EU-style choice, keep three files for the same URL: fresh, Reject All, and Accept All. Use a clean profile for each one. Do not reuse the Accept profile for Reject. The three-state guide owns that comparison. Fresh shows the page before a choice. Reject shows what remained after Reject All and one navigation. Accept is the baseline those two files are compared with.
A California Global Privacy Control question uses a different pair: GPC off and GPC on. The GPC test guide covers the signal, including the Sec-GPC header. Do not drop that pair into an EU reject file and call the result one pack.
A free US-baseline ConsentProbe visit is one non-California pass that shows report format. It is not an EU fresh, reject, and accept pack, and it is not a California GPC pair. The free versus paid guide states that scope in one place. Say it on the folder before anyone pastes a US file into an EU note.
How to assemble the folder
Keep the browser profile, the URL, and the observation window stable inside a single state. Change the state only by starting the next file.
- Open a clean profile, load the URL, and do not click Accept. Save cookies, request URLs, and screenshots. Name the file Fresh.
- Open another clean profile. Click Reject All, navigate once, and save the same surfaces. Name the file Reject.
- Open another clean profile. Click Accept All and save the same surfaces. Name the file Accept. Use it as the comparison baseline.
- If the question is Global Privacy Control, save two files instead, GPC off and GPC on, and keep them out of the EU reject file.
- Remove query values, request bodies, and session tokens before you email or ticket the folder.
What to leave out
A pack gets weaker when it mixes a screenshot, a legal conclusion, and a file from the wrong region.
| Leave out | Why |
|---|---|
| A banner crop with no state name | A reviewer cannot tell which visit it came from. |
| Raw query values and session tokens | The pack is for review. It is not a way to replay a login. |
| A line that the store passed GDPR or CPRA | The files are observations. Counsel reads them. |
| A US-baseline file labeled as an EU result | A locale or a timezone does not prove the network region. |
Point each finding at a file
A useful finding names the state and points at one cookie row, one request URL, or one screenshot. Circle hosts that appear in more than one state file. That circle is the conversation with engineering. The banner copy can sit beside it.
The CMP claims guide is where a sentence on the banner gets checked against the wire. The report-reading guide walks scope, scenario, finding, and evidence number. This page only fixes the file list those reads depend on. The pre-consent checklist is the pass order when a layer is missing. The Reject All guide is the deeper read when the reject file matches the accept file.
A folder or a ConsentProbe report
Both columns are technical records. Neither column is a legal determination. ConsentProbe is an audit of what the browser did. It does not replace a CMP.
| DIY folder | ConsentProbe report | |
|---|---|---|
| State label | You name the file | The scenario name on the run |
| Artifacts | Cookie export, request URLs, screenshots, optional HAR | A finding linked to a request, a cookie, or a screenshot |
| Region | You write the network note | A free US-baseline visit is still one US-context pass |
| Sample | Your own files | The public sample report shows the shape |
| Legal meaning | None without counsel | None. The pack stays technical. |
FAQ
What is a cookie consent evidence pack?
The labeled cookies, request URLs, and screenshots for one URL and one consent state, plus an optional HAR with secrets removed.
Is a banner screenshot enough?
No. The screenshot shows the controls. The pack also needs the cookie table and the request URLs from that state.
Do I have to include a HAR?
No. Add a HAR when a host needs a second look, and strip query values and bodies first. Cookies, requests, and screenshots are the core.
Can Reject and Accept share one file?
No. One state name per file. Mixed clicks cannot be compared later.
Does a free US-baseline visit produce an EU pack?
No. That visit is one non-California pass for report format. See the free versus paid guide before you quote a region.
Who should receive the pack?
The person who will change the tag, and counsel if they asked for the technical record. This page is not legal advice.
Limits of this page
This article lists the files that belong in a cookie consent audit evidence pack. It is not legal advice, not a certificate under GDPR, CPRA, or any other rule, and not a reason to skip counsel. A labeled folder is still an observation of one set of visits.
Related guides
Read the report guide before you hand the folder over, the three-state guide when the files are fresh, reject, and accept, and the free versus paid guide before you name a region.
- How do you read a cookie audit report?
- What is the difference between a cookie consent audit and a cookie banner?
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- Pre-consent audit checklist: what to verify before Accept
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- How do you audit cookies across EU fresh, reject, and accept visits?
- Reject All Still Tracking: What to Check After You Say No
- How do you test a Shopify cookie banner's Reject All button?
- ConsentProbe sample report
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.