Checklist

Magento / Adobe Commerce pre-consent checklist

Start a free audit

Check Magento and Adobe Commerce cookies and scripts before Accept. Theme, extensions, and tag managers can load early. Compare Fresh with Reject.

In brief

On Magento and Adobe Commerce, marketing and analytics scripts often enter through the theme, layout updates, marketplace extensions, a tag manager, and payment or review widgets. A pre-consent checklist records cookies, storage, and network requests before Accept, then checks whether Reject All holds. ConsentProbe can store Fresh and Reject packs. A free US-baseline scan is not an EU or California legal conclusion. This checklist is testing guidance, not legal advice.

Not legal advice

This checklist explains how to observe Magento and Adobe Commerce storefront tags, cookies, and requests relative to Accept and Reject. It is not legal advice, not an Adobe Commerce admin or tag-manager install tutorial, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow.

Last updated September 25, 2026. Admin labels and layout handles change, so this page names surfaces a browser can see. It does not list admin menu clicks. The pre-consent checklist owns the platform-agnostic pass. The before-Accept audit owns the longer method. Shopify, WooCommerce, and BigCommerce have sibling checklists. This page stays on Magento and Adobe Commerce.

Short answer

On Magento and Adobe Commerce, marketing and analytics scripts often enter through the theme, layout updates, marketplace extensions, tag managers, and payment or review widgets. Inventory those entry points, then run Fresh and Reject on the live storefront URL. A cookie consent checklist asks what cookies, storage, and network requests appear on a clean visit before Accept, and whether Reject All holds on a second clean visit.

An installed extension can still send requests on Fresh. A CMP app in the admin is a claim. The storefront visit is the record. Treat category labels as claims and compare them with the labeled packs.

Use the platform-agnostic checklist for the method that is not tied to one cart. Shopify, WooCommerce, and BigCommerce each have a sibling page. Keep their steps on those pages. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP. This checklist is testing guidance, not legal advice.

Where scripts usually enter

Read each row as something a browser test can catch. This page does not configure the theme, an extension, or a container. Those jobs stay in the admin and with the team that owns the code.

Common Magento and Adobe Commerce entry points, and the Fresh red flag.
SurfaceWhy it shows up in a browser testRed flag on Fresh
Theme, layout, and CMS blocksScripts can land in the first HTMLAds or analytics hosts before a choice
Marketplace extensions and appsThird-party JavaScript can load outside the CMP storyThird-party hosts before a choice, with a CMP app already installed
Tag managerA container can fan out tags on the first loadMarketing tags on Fresh. The GTM guide is that check
Payment, review, and chat widgetsThese widgets often set third-party cookiesIDs written before Accept

Fresh and Reject on the live URL

Run the homepage and one product or cart URL when those templates inject their own tags. Do not click Accept on the first pass. The platform-agnostic checklist and the before-Accept audit hold the wider method. After a fix, repeat the same URLs. The retest guide owns the pass and fail criteria.

  1. Use a clean profile. Load the homepage, and one product or cart URL if those templates inject tags. Do not click Accept.
  2. Capture cookies, storage, and Network. Label the pack Fresh.
  3. Open a new clean profile. Click Reject All. Navigate again. Label the pack Reject.
  4. Compare the two packs. Write one finding sentence per mismatch.
  5. Retest the same URLs after a fix, and keep the Fresh and Reject labels.

What to send with the finding

Send the template you loaded, homepage or product, next to the host or cookie name. If you know the layout update, CMS block, or extension name, include it. If you only have the Network row, send that. One sentence per mismatch is enough for the first handoff.

Shopify, WooCommerce, and BigCommerce each have a checklist for a different cart. Keep those steps on those pages.

When extension sprawl gets slow

Sorting theme scripts, extensions, and widgets by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install a CMP, does not configure Adobe Commerce, and does not issue a certificate.

FAQ

What is a Magento pre-consent checklist?

A Fresh and Reject observation list for cookies and pixels before Accept, aimed at the live Magento or Adobe Commerce URL.

Does installing a CMP stop Magento extensions from firing?

Only when the storefront runtime matches. Check Fresh and Reject in the browser. An installed extension can still send requests before a choice.

Is Adobe Commerce different from Magento open source here?

The observation is the same. Entry points can differ by edition and by the extensions installed. Run the check on the URL customers open.

Where is the platform-agnostic checklist?

The pre-consent checklist is the pass that is not tied to one cart. Shopify, WooCommerce, and BigCommerce stay on their own pages.

Does a free US scan prove GDPR for EU shoppers?

No. A free US-baseline scan is not an EU legal conclusion. See the free versus paid guide.

Is this legal advice?

No. This is a technical checklist. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This page is a Magento and Adobe Commerce pre-consent checklist for theme, extension, tag-manager, and widget surfaces. It is not legal advice, not an admin hardening guide, and not a certificate. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the pre-consent checklist for the platform-agnostic pass and the before-Accept audit for the longer method. Shopify, WooCommerce, and BigCommerce are sibling pages. The GTM guide covers a container that fans out early. The retest guide covers a pass after a fix.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Magento pre-consent checklist | ConsentProbe