Checklist

Are first-party analytics cookies allowed before Accept?

Start a free audit

Audits show whether first-party analytics cookies fired before Accept. They do not decide legal permission. First-party names the domain, not a free pass.

In brief

Allowed is a legal question. A cookie audit shows whether a first-party analytics-style cookie or ID appeared before Accept. First-party only names the domain. Advertising first-party IDs use the same before-choice timing test. ConsentProbe lists those findings with the request, cookie, and screenshot. A free US-baseline scan is not an EU or California legal conclusion. This page is testing guidance, not legal advice.

Not legal advice

This FAQ explains how to observe first-party analytics cookies and similar first-party storage that fire before Accept. It is not legal advice, not a ruling that any cookie is permitted or forbidden, and not a GDPR, ePrivacy, CPRA, or other certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow.

Last updated September 24, 2026. The first-party versus third-party guide owns the party labels. The pre-consent storefront checklist owns the full before-Accept protocol. The pre-consent audit checklist owns the multi-step pass. This page stays on the analytics-before-Accept question.

Short answer

Allowed is a legal question. A cookie audit records whether a first-party analytics-style cookie or ID appeared before the visitor clicked Accept. First-party means the cookie sits on your site's own domain. That domain match does not make the cookie necessary, and it does not grant permission.

Treat advertising or marketing first-party IDs the same way you treat third-party pixels for timing. Note whether they fired before a choice, and list them apart from analytics-looking names. In a clean profile, load the page without clicking the banner, sort cookies by domain, flag those names, and keep a screenshot.

ConsentProbe can list those first-party findings with the request, the cookie, and the screenshot. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP. This page is testing guidance, not legal advice and not a permission ruling.

Observation versus legal permission

Keep the two questions in different columns. The runtime test can fill the first and the third. Counsel fills the middle. Stay with present before Accept in the notes you hand engineering. Leave permitted, necessary, and lawful off the ticket unless a lawyer wrote them.

What a pre-Accept audit can record, and what it leaves to counsel.
QuestionWho answers itWhat you capture
Did a first-party analytics-style cookie or ID appear before Accept?Runtime test or auditCookie name, domain, timestamp, and the related request
Is that cookie permitted, necessary, or lawful in this jurisdiction?Counsel or the compliance policyOutside what a ConsentProbe report claims
Did an advertising first-party ID also fire before a choice?The same runtime testThe same surfaces, with the purpose signal you can actually see

Analytics-looking names and ads-looking names

Analytics-style first-party names look like measurement or session analytics and they sit on your domain. List them. Do not clear them because the domain matches the shop. A placeholder such as example_measure_id on shop.example is only an illustration. Replace it with the name in your cookie table.

Advertising or marketing first-party IDs are ads or attribution values written on your domain, or in close site context, before a choice. Use the same timing test you would use for a third-party pixel. Note the ones that appear before the click, then keep that list separate from the analytics-looking names.

A purpose label inside the CMP is a claim. Network timing and the cookie list are what this pass verifies. When you need the broader first-party versus third-party definitions, open that guide. This FAQ stays on the before-Accept analytics question.

Five-step check before Accept

Stop after these five steps if you only need the analytics-before-Accept inventory. Open the full before-Accept audit for the longer protocol, and the pre-consent checklist when you also want Reject and an accept baseline.

  1. Use a clean browser profile. Do not click Accept or Reject.
  2. Load the storefront once. Open Application, then Cookies, and sort by domain.
  3. Flag first-party names that look like analytics IDs or advertising IDs.
  4. In Network, find the first-party or tagged requests that set those values.
  5. Screenshot the cookie list and the key requests. Write one finding sentence per distinct name.

When hand-sorting the names gets slow

Sorting first-party analytics names by hand is slow once the theme, the apps, and the templates change. ConsentProbe runs on the URL and stores a labeled pre-consent Fresh inventory. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims you will show. The free versus paid guide draws that line. ConsentProbe does not install a CMP and does not approve cookies for counsel.

FAQ

Are first-party analytics cookies allowed before Accept?

Permission is a legal call. An audit shows whether they fired before Accept. The audit does not grant or deny permission.

Does first-party mean the cookie is fine before Accept?

No. First-party only describes the domain. Timing before Accept still belongs in the test.

How do advertising first-party cookies differ in this check?

Use the same timing test. Note whether ads-looking first-party IDs appear before a choice, then list them separately from analytics-looking names.

Where do I learn first-party versus third-party labels?

Open the first-party versus third-party guide. It covers the party labels. This page does not repeat that taxonomy.

Does a free US-baseline decide EU or California permission?

No. A free US-baseline scan shows report format. It is not an EU or California legal conclusion. See the free versus paid guide.

Is this legal advice?

No. These are technical observations. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This page tells you how to observe first-party analytics-style cookies and ads-looking first-party IDs before Accept. It is not legal advice, not a permission ruling, and not a certificate under GDPR, ePrivacy, CPRA, or any other rule. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the first-party versus third-party guide for party labels, the before-Accept audit for the full protocol, and the pre-consent checklist for the pass order.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

First-party analytics before Accept | ConsentProbe