A cookie audit is the foundational step for any website’s GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your cookie consent banner is operating blind – asking users to consent to technologies you cannot fully describe.
What Is a Cookie Audit?
A cookie audit is a systematic inventory of all cookies, local storage objects, pixel trackers, fingerprinting scripts, and other tracking technologies present on a website. It identifies what data each technology collects, who controls it, how long it persists, and what purpose it serves.
The ePrivacy Directive (2002/58/EC), as interpreted by the CJEU in the Planet49 case (C-673/17), requires informed, specific consent for all non-essential cookies. An inventory provides the factual basis for deciding whether consent is required and for explaining the actual uses. Set review frequency according to changes and risk; the Directive does not prescribe a universal six-month audit schedule.
How Do You Discover All Cookies on Your Website?
Discovery is the most technically demanding phase. Cookies are set through multiple mechanisms, and no single method captures all of them.
Manual browser inspection
Open your website in Chrome or Firefox with developer tools active. Clear all cookies, load the homepage without consenting, record which cookies appear, then accept all cookies and navigate through all major page templates and functional flows. Check the Application tab (Chrome) or Storage tab (Firefox) for cookies, local storage, session storage, and IndexedDB entries. Also test refusal, granular choices and withdrawal, recording the page, consent state, time and relevant network requests.
Automated scanning and network analysis
Automated scanners can supplement manual inspection, but their coverage depends on crawl limits, consent states, authentication and supported interactions. Check these conditions in the selected tool; a clean scan is not evidence that every page and delayed script was exercised.
Inspect network responses as well as browser storage, including Set-Cookie headers and HttpOnly cookies. Server-to-server tracking requires a separate review of server configuration and data flows; it cannot be ruled out by a browser-only scan.
Cookie Classification and Documentation
The following categories can organize an inventory, but labels do not determine the legal exemption. Assess the actual purpose and the applicable national implementation of Article 5(3).
Strictly necessary cookies may be exempt where storage or access is strictly necessary to provide a service explicitly requested by the user; the separate communication-transmission exemption also applies. Document why a particular session, authentication or load-balancing use meets the test. Functional or preference cookies need a purpose-specific assessment: a user-requested language preference may qualify, while optional tracking does not become necessary by being labelled functional. Analytics cookies generally require consent, but some national guidance allows narrowly configured audience measurement to be exempt. The CNIL explains the conditions and limits; aggregated reporting alone does not establish an exemption. Marketing cookies used for behavioural advertising require prior consent under the applicable rules.
Required documentation fields
For each cookie, document: the exact name, provider/domain, category, purpose description, duration, type (HTTP cookie, local storage, pixel), data collected, third-party access, and cross-site tracking status. This documentation feeds directly into your cookie consent mechanism and must match the information presented to users. Investigate discrepancies that may make the information inaccurate or leave a consent-requiring purpose outside the recorded choice.
Conducting a Gap Analysis
The gap analysis compares discovered cookies against your current cookie policy and consent banner. Common findings include marketing tags deployed by agency partners without the site operator’s knowledge, development and testing cookies left active in production environments, browser fingerprinting scripts that do not use traditional cookies but serve identical tracking purposes, and third-party embeds (YouTube videos, social media widgets) that silently deploy their own tracking cookies on your domain.
For each cookie requiring consent, verify that it is not set before consent is obtained, is correctly categorized in your CMP, matches the documented purpose, and that refusing consent actually prevents it from being set. The hidden productivity drain of cookie banner management compounds when the banner configuration does not match actual cookies on the site.
Third-party cookie risk assessment
For each third-party cookie, assess whether a data processing agreement exists, whether data transfers outside the EEA are documented, and whether the provider has updated their cookie behavior since your last audit. Determine the provider’s actual role and transfer recipients rather than assuming every third party is a processor or every domain identifies a transfer destination.
Ongoing Cookie Monitoring Tools
A one-time cookie audit is necessary but insufficient. When selecting a consent management platform, verify the scanning frequency and coverage included in the actual offer. If you use Google Tag Manager or similar, implement governance controls: require approval for new tag deployments, verify consent-dependent tag behaviour, and review the container after relevant changes.
Automated compliance testing tools visit your site, decline all cookies, and verify no non-essential cookies are set. Running a scoped check after relevant deployments can reveal regressions; document the tested journeys and limitations.
Consequences of an Incomplete Audit
An incomplete inventory can leave optional tags active before consent, misdescribe recipients or omit changes to purposes. Preserve the evidence for each finding and verify the correction in the affected consent states.
Cookie compliance connects directly to your broader GDPR compliance checklist. Invalid consent can undermine processing that relies on it. Separately assess transparency, purpose limitation and any consent exemption; one inventory defect does not automatically prove every listed infringement.
Frequently Asked Questions
How many cookies does a typical website have?
There is no useful universal count for assessing your site. Measure your own pages, embedded services and consent states, and explain the purpose of each observed technology.
Can I use Google Analytics without a cookie audit?
Inspect your actual Google Analytics configuration, tags and data flows before relying on a consent mechanism. The audit supplies the facts needed for the information and consent assessment; buying an audit report is not itself a legal permission to run analytics.
Do strictly necessary cookies need to be in the audit?
Yes. All cookies must be audited and documented. While strictly necessary cookies do not require consent, assess applicable information duties, including GDPR transparency where personal data is processed. A cookie containing no personal data is not subject to GDPR merely because it is a cookie.
How long does a cookie audit take?
Estimate the work from page templates, authenticated areas, embeds, interactions and consent states. Pilot a representative flow before committing to a schedule; classification and verification still require review after an automated scan.
FAQ
What is a cookie audit and why is it required?
A cookie audit identifies and categorises all cookies set by a website — first-party, third-party, essential, analytics, advertising. It helps establish the facts needed for informed consent and exemption decisions. The legal duties concern the actual storage, access, information and choice; they do not impose one named audit format.
How often should a cookie audit be performed?
Review after relevant script, vendor or feature changes and choose a documented periodic schedule for unchanged parts of the site. There is no universal six-month legal interval. Keep evidence of the states tested and recheck the specific behaviour after correction.
What categories must cookies be classified into?
Necessary, preference, analytics and advertising are useful working labels. The legal assessment follows the actual purpose and national exemption conditions; provide sufficiently granular choices for distinct purposes requiring consent, rather than assuming a fixed four-category taxonomy satisfies the law.
What tools can be used to audit cookies?
Browser DevTools (Application > Cookies), Cookiebot scanner, OneTrust Cookie Compliance, CNIL’s CookieViz, or commercial crawl-based scanners. Dynamic cookie audits that scan under different consent states catch cookies that fire before consent is given — a common compliance issue.