Checklist
Pre-consent audit checklist: what to verify before Accept
Check what the browser does before Accept: a clean load, storage, Reject All plus one navigation, an accept baseline, and a labeled evidence pack. Technical record only, not a legal verdict.
In brief
A pre-consent audit checks what the browser does before the visitor accepts cookies. Load the site in a clean profile, do not click Accept, and record cookies, storage, and third-party requests. Then click Reject All or the equivalent, navigate once, and confirm marketing tags stay off. Keep screenshots labeled by step. A banner in the UI is not proof. The network log is. This checklist is technical evidence, not legal advice.
Not legal advice
This checklist is a technical workflow for Shopify and DTC storefronts. It is not legal advice. It does not classify a cookie as strictly necessary, and it does not say that a banner meets any statute. Pass and fail in the table are observable wire checks for engineering. Counsel still owns the legal reading.
Short answer
A pre-consent audit checks what the browser does before the visitor accepts cookies. Load the site in a clean profile, do not click Accept, and record cookies, storage, and third-party requests. Then click Reject All, or the equivalent control, navigate once, and confirm marketing tags stay off.
Keep screenshots labeled by step. A banner in the UI is not proof. The network log is. Do the fresh and storage passes before any reject or accept click, each in its own clean profile when the action changes.
Prep
Use a clean browser profile with no leftover cookies or storage. Cover the homepage and one key template, such as a product page. Write down the CMP name and the exact Reject label you will click. State the region you actually tested.
A free US-baseline visit is a format and wiring record outside California. It is not an EU reject conclusion or a California GPC conclusion. Read the free versus paid guide before you extend the pack.
Checklist
Fill one row per pass. A row with no file is not done. Pass means the wire matches the choice. Fail means the wire does not.
| Step | Action | Pass | Fail |
|---|---|---|---|
| A Fresh | Load, no click | No marketing pixels before a choice | Ads pixels before a choice |
| B Storage | Cookies and localStorage | Only storage you can justify as essential for that load | Analytics or ads identifiers already present |
| C Reject | Reject All, then navigate once | Marketing stays off on the next page | The next page looks the same as Accept |
| D Accept | New profile, then Accept | Expected vendors appear after the choice | Still looks like the fresh baseline |
| E Evidence | Save the artifacts | Table, URLs, and screenshots labeled by step | Banner-only screenshot |
How to run the five passes
About 15 minutes is enough for two URLs when the profiles are already clean. Isolation matters more than a long export. One reused profile can carry an earlier accept into pass A.
- A Fresh. Open a new profile. Load the homepage. Wait for the banner. Do not click Accept, Reject, settings, or close. Repeat on the key template if that URL is in scope. Screenshot the untouched banner and export Network.
- B Storage. In that untouched profile, list cookies and localStorage for the shop host and every other origin. Note the request or script that set each key. A first-party host can still hold an analytics or ads identifier.
- C Reject. New profile. Click Reject All or the equivalent. Record the label. Treat the click as verified only when the banner state or a preference value changes. Navigate once. Recapture cookies, storage, and third-party requests.
- D Accept. A third clean profile. Accept, then recapture the same layers. This row is the baseline for what expected vendors look like after a choice. If pass C matches this row, reject did not change the wire.
- E Evidence. Save the filled table, the URLs, and screenshots named by step. Include timestamps and whether reject or accept was verified. Remove query values that carry identifiers before you share the pack.
Party labels, Shopify, and CMP claims
First-party versus third-party is a host label, not a permission. Read the first-party guide before you drop a shop-domain key from pass B. Analytics and ads identifiers on your own host still fail that row when they appear before a choice.
On Shopify, app pixels, custom pixels, and theme code can set storage or send requests before Accept. Shopify privacy settings can gate some pixel callbacks. They do not replace passes A through E on the public URL. Use the Shopify pixel testing guide for theme and pixel checks, then keep this table on the live storefront.
A CMP line that says optional tags wait for consent is a claim. Pass C is the runtime check. If marketing after Reject looks like Accept, the banner copy is not the evidence. Read the runtime audit versus CMP guide before you rewrite the sentence in the banner.
FAQ
Is the CMP enough?
Only if passes A through C pass. A banner that says tags wait for consent does not prove the network log. If ads pixels show up before a choice, or reject matches accept, the CMP screen is not the result.
How long does this take?
About 15 minutes for two URLs, the homepage and one key template, when you start from clean profiles and you already know the Reject label.
Does this prove a GDPR or CIPA result?
No. The pack is technical evidence of what the browser stored and sent. It is not a legal conclusion under GDPR, CIPA, or any other statute.
What should I send engineering?
The filled table plus the files: request lists, cookie and storage tables, and screenshots labeled by step. Include the URL, the region you tested, and whether the reject click produced an observable change.
Which ConsentProbe run matches this table?
A free US-baseline visit can store one pre-choice technical record outside California. Use a paid EU pack for fresh, reject, and accept, or a paid California pack for GPC, when the claim needs that region. The report stays a technical record, not legal advice.
Save the labeled scenarios
ConsentProbe stores scenario-labeled cookies, requests, and screenshots, with evidence links inside the report. Use the free US-baseline visit for format. Use the regional products when you need EU or California conclusions from the matching scenarios. Do not describe a US-baseline file as an EU reject result.
Related guides
Read the longer pre-consent checklist, the reject leftovers page, the first-party inventory, the runtime audit versus CMP guide for pass C, and the Shopify pixel testing guide with this table.
- Pre-Consent Cookie Audit: A Storefront Checklist
- Reject All Still Tracking: What to Check After You Say No
- First-party vs third-party cookies before consent: what should you check?
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- Runtime Audit vs CMP: What Each One Measures
- Testing Shopify Pixels Before Consent
- ConsentProbe methodology
- Sample report
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.