检查清单

Which cookie consent test should you run first?

开始免费审计

Choose the first cookie consent test from the claim: pre-consent, Reject versus Accept, EU three-way, or GPC. A free US scan is not an EU or California result.

In brief

Pick the cookie consent test that matches the claim. Use a pre-consent checklist when tags may fire before a choice, Reject versus Accept when Reject looks ignored, EU fresh, Reject, and Accept for an EU or UK region, and a GPC pair for a California opt-out. Label cookies, requests, and screenshots. A banner image is not an audit. A free US-baseline scan is not an EU or California conclusion. This hub is a testing map, not legal advice.

Not legal advice

This hub maps which cookie consent test to run for a given claim. It is not legal advice, not a compliance certificate, and not a guarantee that any site meets GDPR, CPRA, ePrivacy, CIPA, or any other rule. ConsentProbe reports are technical observations. They do not replace counsel.

Last updated September 23, 2026. Each branch below stops after the choice of test and points at the guide that owns the steps.

Short answer

Pick the cookie consent test that matches the claim you need to check. If tags may fire before any choice, start with a pre-consent checklist. If the banner exists and Reject All looks broken, run a Reject versus Accept comparison. If you sell into the EU or UK and need a regional conclusion, use EU fresh, Reject, and Accept scenarios. If a California sale or share opt-out is the claim, use a GPC-off versus GPC-on pair.

Keep every run labeled, and attach cookies, requests, and screenshots so engineering or counsel can reproduce the finding. A banner screenshot alone is not an audit. ConsentProbe is an audit tool, not a CMP. A free US-baseline scan is not an EU or California or GPC conclusion. This hub maps which guide to open next. It is not legal advice and not a compliance certificate.

Decision tree

Read the row that matches the sentence you will actually defend. Then open the deep guide. Do not run every scenario because the table lists them.

Which test to run first, and which guide owns the steps.
Your situationRun this firstDeep guide
Pixels or cookies before any clickPre-consent checklistPre-consent checklist, then the storefront checklist or the Shopify pre-consent list
Banner present, and Reject may be ignoredReject versus Accept, and a fresh visitReject All leftovers; on Shopify, the Reject All storefront guide
EU or UK regional conclusionsEU fresh, Reject, and AcceptEU three-state audit
A CMP line that says the shop honors GPCGPC off versus GPC onGPC test, then the claims mismatch guide; on Shopify, the GPC honor test
Counsel or engineering need a reproducible packEvidence packEvidence pack, then how to read the report
Unsure whether you need an audit or another bannerPositioningCookie consent audit versus banner
California lawsuit-theory context, at a high levelA theory map, then a storefront testCIPA pen-register versus wiretap, then SB 690, then back to the pre-consent checklist

If tags may fire before a choice

Start with the pre-consent checklist. Load a clean profile, do not click Accept, and record cookies, storage, and third-party requests.

The storefront checklist is the longer pass for the same moment. On Shopify, the Shopify pre-consent checklist covers pixels, theme embeds, and app scripts. An unclicked banner does not show that those scripts waited.

If Reject All looks ignored

Run Reject versus Accept, with a fresh visit beside them and a clean profile per state. The Reject All leftovers guide is the network check. On Shopify, use the Reject All storefront guide, which also notes the Customer Privacy API limit.

If the question is whether Reject is as easy to reach as Accept, open the reject-ease guide and still check the network. The button and the request list are separate rows.

If the claim is an EU or UK region

Use the EU fresh, Reject, and Accept guide. Three labeled visits are the comparison. A free US-baseline scan is one non-California pass for report format, and it does not stand in for that trio.

A locale or a timezone is not a regional IP. The free versus paid guide says when the paid EU scenarios are the file you show.

If the claim is California or GPC

Run GPC off and GPC on. The GPC test guide covers Sec-GPC: 1. The GPC versus CMP claims guide covers a detected message that arrives after pixels have fired.

On Shopify, open the Shopify GPC honor test for theme Liquid, app embeds, customer events, and pixels. The Customer Privacy API records a preference and does not by itself block scripts. Paid California or GPC scenarios are the regional ConsentProbe path.

If you need a pack, a banner decision, or a theory map

When engineering or counsel asked for files they can reproduce, build the evidence pack: one URL, one state name, cookies, request URLs, and screenshots. The report-reading guide walks scope, scenario, finding, and evidence number.

When the question is whether to buy another banner, read the audit versus banner guide. A CMP stores a choice. An audit records what the browser did. ConsentProbe does the second job.

For California website-tracking theories, read the CIPA pen-register versus wiretap page and the SB 690 note, then return to the pre-consent checklist. This hub does not restate those pages.

What every serious run shares

The scenario changes. The file shape does not. A reviewer should be able to line two states up without guessing which click produced which export.

  • One clean profile per consent state. Do not reuse the Accept profile for Reject or for GPC on.
  • The exact button text, or the GPC enable method, written on the file.
  • A cookie table, a third-party request list, and screenshots from that same state.
  • A finding sentence that points at one of those surfaces. The evidence pack guide is the field list.
  • Region honesty. A free US-baseline visit is not an EU or California conclusion. See the free versus paid guide.

Free US scan versus paid EU or California

Start free when you are learning the report shape or hunting an obvious pre-consent load. Use a paid scenario when the sentence you will show names the EU, the UK, or California, or when you want the labeled pack without building a HAR by hand.

Findings stay linked to a request, a cookie, or a screenshot. A regional scenario name does not turn the report into a certificate, and the audit does not replace a CMP.

Match the claim to the scan. A free US-baseline visit stays a format pass.
Claim you wantFree US-baselinePaid path
Learn the report format, or spot an obvious pre-consent loadUsefulOptional
EU Reject All compared with AcceptNot enoughEU fresh, Reject, and Accept scenarios
California or GPC behaviorNot enoughCalifornia or GPC scenarios, with the GPC guides
A shareable pack for engineering or counselYou can build the folder by handLabeled findings tied to a request, a cookie, or a screenshot

Shopify shortcut

Pre-consent on Shopify is the Shopify pre-consent checklist. Reject All is the Shopify Reject All guide. If someone calls the Customer Privacy API a firewall, read the API limits guide: the API records consent, and theme or pixel scripts still load unless their own code waits. GPC is the Shopify GPC honor test, two clean visits with Sec-GPC confirmed on the second file.

Reject ease is a separate check

If Reject is harder to reach than Accept, open the reject-ease guide and screenshot the controls. That page reads a public CNIL note about design. It does not decide that a banner meets French or EU law.

Then compare cookies and requests after Reject with the same surfaces after Accept. The Reject All guides own that network half. UI ease and runtime blocking stay in different files.

FAQ

Which cookie consent test should I run first?

Match the claim. Pre-consent when tags may fire early, Reject versus Accept when the button looks ignored, the EU three-way for an EU or UK conclusion, or a GPC pair for a California opt-out signal. Use the table on this page.

Is a cookie banner enough?

A banner collects a choice. An audit keeps labeled cookies, requests, and screenshots. Read the audit versus banner guide and the evidence pack guide.

When is the free US scan enough?

When you are learning the report format or spotting an obvious pre-consent load. It is not an EU Reject conclusion or a California or GPC conclusion. See the free versus paid guide.

When do I need paid EU or California scenarios?

When those regional claims are what you will show counsel, a partner, or engineering. A locale setting does not replace that scenario.

Where do Shopify merchants start?

The Shopify pre-consent checklist, the Shopify Reject All guide, and the Shopify GPC honor test. Open the API limits guide if someone treats Customer Privacy as a script blocker.

Is this hub legal advice?

No. It is a testing map. It is not a compliance certificate and not a substitute for counsel.

Limits of this page

This hub maps which cookie consent test to run, and which guide owns the steps. It is not legal advice, not a compliance certificate, and not a guarantee that any site meets GDPR, CPRA, ePrivacy, CIPA, or any other rule. ConsentProbe reports remain technical observations tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California conclusion.

Related guides

Start with the published cluster: the EU three-state audit, the audit versus banner page, the CIPA theory map, and the Shopify Reject All guide. Then open the evidence pack, the reject-ease note, the pre-consent checklist, and the free versus paid guide.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

先选哪一种 Cookie 同意测试 | ConsentProbe