检查清单

How do you audit cookies across EU fresh, reject, and accept visits?

开始免费审计

Compare EU fresh, Reject All, and Accept All: cookies, storage, and third-party requests. A free US-baseline scan is not this audit or a GDPR certificate.

In brief

An EU-oriented cookie audit compares three labeled visits to the same URL: a fresh load with no Accept, a visit after Reject All, and a visit after Accept All. Marketing tags on fresh should not behave as if the visitor already chose. After Reject All, ads and analytics should stay quieter than after Accept. Record cookies, requests, and screenshots for each state. A free US-baseline scan is not that EU comparison. This page is testing guidance, not a GDPR certificate.

Not legal advice

This article explains how to compare fresh, Reject All, and Accept All browser visits for cookie and tracking behavior. It is not legal advice, not a GDPR or ePrivacy certificate, and not a determination that any site meets EU or UK law.

ConsentProbe findings are technical observations tied to requests, cookies, and screenshots. Readers should consult their own counsel for regulatory obligations. Nothing on this page is a certificate you can attach to a filing.

Short answer

Run three labeled visits to the same URL. Fresh means load the page and do not click Accept. Reject means click Reject All, then navigate once. Accept means a new clean profile and Accept All. Capture cookies, storage, third-party requests, and screenshots for each state.

On fresh, marketing and non-essential tags should not behave as if the visitor already consented. After Reject All, ads and analytics fan-out should stay off relative to Accept All. After Accept All, record the tags the banner claims to enable. That run is the comparison baseline. It is not a trophy.

A free US-baseline ConsentProbe scan is one clean US-context visit for report format. It is not an EU fresh, reject, and accept conclusion. Paid EU scenarios exist for that comparison. The free versus paid guide states the scope in one place.

Why three states

One Accept screenshot proves a banner rendered. It does not prove the choice changed the browser. Three labeled runs show whether fresh is already busy, whether Reject differs from Accept, and what Accept turned on so the quiet reject run has something to differ from.

A single fresh visit is one cell in that grid. A single reject visit without an accept baseline is hard to read: quiet can mean the tags waited, or it can mean the tags never load on that URL. The CMP claims guide frames the same idea as a sentence in the banner versus the wire. This page owns the three-state comparison those sentences usually need.

Prep for an EU-context test

Do not relabel a US visit as an EU result. Locale and timezone are not a regional IP. If you will describe the pack as EU, the browser context has to be EU, or you use a paid EU scenario that records that context.

Prep for a three-state EU-oriented audit. Technical setup only.
PrepDetail
IsolationA clean profile per state when you can. Do not reuse the Accept profile for Reject.
URLThe same storefront URL. Note the locale and the domain.
RegionAn EU-context network and browser if you claim EU results. A US visit is not GDPR proof.
TimingSimilar load conditions. Skip a logged-in account unless that path is in scope.
LabelsWrite Fresh, Reject, or Accept on every artifact.

Side-by-side protocol

Record the same surfaces on every row. The red flag is a pattern across rows, not a single cookie name you dislike.

Fresh, Reject, and Accept. What to record and what usually indicates a wiring problem.
StateVisitor actionWhat to recordCommon red flag
FreshLoad. No Accept.Cookies, storage, third-party ad and analytics requests, banner UI.Marketing pixels or cookies before any choice.
RejectClick Reject All, then navigate once.The same surfaces.The network matches Accept. Reject was ignored.
AcceptNew clean profile. Accept All.The same surfaces.Use this only as the consented baseline for diffs.

Vendor worksheet

Copy this table into the pack and fill one row per host or cookie. Present or absent is enough for a first pass. Add the request URL when a host needs a second look. The sample row is a blank pattern, not a result from a shop.

Fill-in vendor diff. Replace the sample row. Do not treat an empty cell as a pass.
Vendor host or cookieFreshRejectAccept
(fill in, for example a pixel host)present or absentpresent or absentpresent or absent

How the rows map to ConsentProbe

Paid EU scenarios run the consent states side by side and attach findings to a request, a cookie, or a screenshot. The product story for that path includes fresh, reject-all, and accept-all. This page does not invent extra unpaid states.

A free US-baseline visit previews report format on one non-California pass. Say that once, and link the free versus paid guide, before anyone pastes a US file into an EU note.

California and Global Privacy Control are a different pair: GPC off versus GPC on. The GPC test guide covers the signal. Do not mix that pair into an EU reject conclusion.

Evidence pack fields

Include the URL, the timestamp, a region or context note, the state label, a cookie table, key request URLs, screenshots, and an optional HAR with secrets removed.

Hand engineering or counsel that pack. Do not write that the site passed GDPR. The pre-consent checklist is the shared field list when a layer is missing. The Reject All guide is the deeper read when reject matches accept. The pre-Accept guide is the deeper read when fresh is already full of marketing tags.

DIY versus paid EU scenarios

Both columns produce technical observations. Neither column is a legal determination.

Manual three-run audit versus ConsentProbe paid EU scenarios.
DIY three runsConsentProbe paid EU
ControlYou choose the profiles and the URLLabeled fresh, reject, and accept scenarios
ConsistencyProfiles are easy to mixThe same evidence types repeat
Evidence linkingYou attach files by handFindings link to a request, cookie, or screenshot
Legal meaningNone without counselNone. The pack stays technical.

FAQ

What is an EU fresh versus reject versus accept cookie audit?

Three labeled visits that compare cookies and third-party requests across no choice, Reject All, and Accept All.

What should Reject All change?

Marketing, ads, and analytics fan-out should not match Accept. If it does, the wiring failed. The Reject All guide walks that failure in more detail.

Is a clean fresh visit enough for GDPR?

No single visit is a certificate. Fresh is one state in a comparison. This page is not legal advice.

Does a free US ConsentProbe scan equal this audit?

No. A free US-baseline visit does not run the EU fresh, reject, and accept set. See the free versus paid guide.

Do I need Accept All if I only care about Reject?

Accept is the comparison baseline. Without it, a quiet reject run is harder to interpret.

What do I give counsel?

State-labeled evidence packs: cookies, requests, and screenshots. A banner image is not the pack.

Limits of this page

This article explains how to compare fresh, Reject All, and Accept All browser visits. It is not legal advice, not a GDPR or ePrivacy certificate, and not a determination that any site is lawful in the EU or the UK. ConsentProbe findings stay tied to requests, cookies, and screenshots. Talk to your own counsel about regulatory obligations.

Related guides

Read the free versus paid guide before you quote a region, and the pre-consent checklist for the shared pass order.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

欧盟首次、拒绝与接受审计 | ConsentProbe