检查清单
How do you audit cookies across EU fresh, reject, and accept visits?
Compare EU fresh, Reject All, and Accept All: cookies, storage, and third-party requests. A free US-baseline scan is not this audit or a GDPR certificate.
In brief
An EU-oriented cookie audit compares three labeled visits to the same URL: a fresh load with no Accept, a visit after Reject All, and a visit after Accept All. Marketing tags on fresh should not behave as if the visitor already chose. After Reject All, ads and analytics should stay quieter than after Accept. Record cookies, requests, and screenshots for each state. A free US-baseline scan is not that EU comparison. This page is testing guidance, not a GDPR certificate.
Not legal advice
This article explains how to compare fresh, Reject All, and Accept All browser visits for cookie and tracking behavior. It is not legal advice, not a GDPR or ePrivacy certificate, and not a determination that any site meets EU or UK law.
ConsentProbe findings are technical observations tied to requests, cookies, and screenshots. Readers should consult their own counsel for regulatory obligations. Nothing on this page is a certificate you can attach to a filing.
Short answer
Run three labeled visits to the same URL. Fresh means load the page and do not click Accept. Reject means click Reject All, then navigate once. Accept means a new clean profile and Accept All. Capture cookies, storage, third-party requests, and screenshots for each state.
On fresh, marketing and non-essential tags should not behave as if the visitor already consented. After Reject All, ads and analytics fan-out should stay off relative to Accept All. After Accept All, record the tags the banner claims to enable. That run is the comparison baseline. It is not a trophy.
A free US-baseline ConsentProbe scan is one clean US-context visit for report format. It is not an EU fresh, reject, and accept conclusion. Paid EU scenarios exist for that comparison. The free versus paid guide states the scope in one place.
Why three states
One Accept screenshot proves a banner rendered. It does not prove the choice changed the browser. Three labeled runs show whether fresh is already busy, whether Reject differs from Accept, and what Accept turned on so the quiet reject run has something to differ from.
A single fresh visit is one cell in that grid. A single reject visit without an accept baseline is hard to read: quiet can mean the tags waited, or it can mean the tags never load on that URL. The CMP claims guide frames the same idea as a sentence in the banner versus the wire. This page owns the three-state comparison those sentences usually need.
Prep for an EU-context test
Do not relabel a US visit as an EU result. Locale and timezone are not a regional IP. If you will describe the pack as EU, the browser context has to be EU, or you use a paid EU scenario that records that context.
| Prep | Detail |
|---|---|
| Isolation | A clean profile per state when you can. Do not reuse the Accept profile for Reject. |
| URL | The same storefront URL. Note the locale and the domain. |
| Region | An EU-context network and browser if you claim EU results. A US visit is not GDPR proof. |
| Timing | Similar load conditions. Skip a logged-in account unless that path is in scope. |
| Labels | Write Fresh, Reject, or Accept on every artifact. |
Side-by-side protocol
Record the same surfaces on every row. The red flag is a pattern across rows, not a single cookie name you dislike.
| State | Visitor action | What to record | Common red flag |
|---|---|---|---|
| Fresh | Load. No Accept. | Cookies, storage, third-party ad and analytics requests, banner UI. | Marketing pixels or cookies before any choice. |
| Reject | Click Reject All, then navigate once. | The same surfaces. | The network matches Accept. Reject was ignored. |
| Accept | New clean profile. Accept All. | The same surfaces. | Use this only as the consented baseline for diffs. |
Vendor worksheet
Copy this table into the pack and fill one row per host or cookie. Present or absent is enough for a first pass. Add the request URL when a host needs a second look. The sample row is a blank pattern, not a result from a shop.
| Vendor host or cookie | Fresh | Reject | Accept |
|---|---|---|---|
| (fill in, for example a pixel host) | present or absent | present or absent | present or absent |
How the rows map to ConsentProbe
Paid EU scenarios run the consent states side by side and attach findings to a request, a cookie, or a screenshot. The product story for that path includes fresh, reject-all, and accept-all. This page does not invent extra unpaid states.
A free US-baseline visit previews report format on one non-California pass. Say that once, and link the free versus paid guide, before anyone pastes a US file into an EU note.
California and Global Privacy Control are a different pair: GPC off versus GPC on. The GPC test guide covers the signal. Do not mix that pair into an EU reject conclusion.
Evidence pack fields
Include the URL, the timestamp, a region or context note, the state label, a cookie table, key request URLs, screenshots, and an optional HAR with secrets removed.
Hand engineering or counsel that pack. Do not write that the site passed GDPR. The pre-consent checklist is the shared field list when a layer is missing. The Reject All guide is the deeper read when reject matches accept. The pre-Accept guide is the deeper read when fresh is already full of marketing tags.
DIY versus paid EU scenarios
Both columns produce technical observations. Neither column is a legal determination.
| DIY three runs | ConsentProbe paid EU | |
|---|---|---|
| Control | You choose the profiles and the URL | Labeled fresh, reject, and accept scenarios |
| Consistency | Profiles are easy to mix | The same evidence types repeat |
| Evidence linking | You attach files by hand | Findings link to a request, cookie, or screenshot |
| Legal meaning | None without counsel | None. The pack stays technical. |
FAQ
What is an EU fresh versus reject versus accept cookie audit?
Three labeled visits that compare cookies and third-party requests across no choice, Reject All, and Accept All.
What should Reject All change?
Marketing, ads, and analytics fan-out should not match Accept. If it does, the wiring failed. The Reject All guide walks that failure in more detail.
Is a clean fresh visit enough for GDPR?
No single visit is a certificate. Fresh is one state in a comparison. This page is not legal advice.
Does a free US ConsentProbe scan equal this audit?
No. A free US-baseline visit does not run the EU fresh, reject, and accept set. See the free versus paid guide.
Do I need Accept All if I only care about Reject?
Accept is the comparison baseline. Without it, a quiet reject run is harder to interpret.
What do I give counsel?
State-labeled evidence packs: cookies, requests, and screenshots. A banner image is not the pack.
Limits of this page
This article explains how to compare fresh, Reject All, and Accept All browser visits. It is not legal advice, not a GDPR or ePrivacy certificate, and not a determination that any site is lawful in the EU or the UK. ConsentProbe findings stay tied to requests, cookies, and screenshots. Talk to your own counsel about regulatory obligations.
Related guides
Read the free versus paid guide before you quote a region, and the pre-consent checklist for the shared pass order.
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- Pre-consent audit checklist: what to verify before Accept
- Reject All Still Tracking: What to Check After You Say No
- Pre-Consent Cookie Audit: A Storefront Checklist
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- What is Global Privacy Control, and how do you test it on a storefront?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。