Skip to content
Legiscope
Menu
Data Privacy

Cookie Audit: How to Map Your Website's Cookies

Step-by-step guide to conducting a GDPR-compliant cookie audit. Covers discovery, classification, documentation, gap analysis, and ongoing monitoring.

A cookie audit is the foundational step for any website’s GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your cookie consent banner is operating blind – asking users to consent to technologies you cannot fully describe.

A cookie audit is a systematic inventory of all cookies, local storage objects, pixel trackers, fingerprinting scripts, and other tracking technologies present on a website. It identifies what data each technology collects, who controls it, how long it persists, and what purpose it serves.

The ePrivacy Directive (2002/58/EC), as interpreted by the CJEU in the Planet49 case (C-673/17), requires informed, specific consent for all non-essential cookies. An inventory provides the factual basis for deciding whether consent is required and for explaining the actual uses. Set review frequency according to changes and risk; the Directive does not prescribe a universal six-month audit schedule.

How Do You Discover All Cookies on Your Website?

Discovery is the most technically demanding phase. Cookies are set through multiple mechanisms, and no single method captures all of them.

Manual browser inspection

Open your website in Chrome or Firefox with developer tools active. Clear all cookies, load the homepage without consenting, record which cookies appear, then accept all cookies and navigate through all major page templates and functional flows. Check the Application tab (Chrome) or Storage tab (Firefox) for cookies, local storage, session storage, and IndexedDB entries. Also test refusal, granular choices and withdrawal, recording the page, consent state, time and relevant network requests.

Automated scanning and network analysis

Automated scanners can supplement manual inspection, but their coverage depends on crawl limits, consent states, authentication and supported interactions. Check these conditions in the selected tool; a clean scan is not evidence that every page and delayed script was exercised.

Inspect network responses as well as browser storage, including Set-Cookie headers and HttpOnly cookies. Server-to-server tracking requires a separate review of server configuration and data flows; it cannot be ruled out by a browser-only scan.

The following categories can organize an inventory, but labels do not determine the legal exemption. Assess the actual purpose and the applicable national implementation of Article 5(3).

Strictly necessary cookies may be exempt where storage or access is strictly necessary to provide a service explicitly requested by the user; the separate communication-transmission exemption also applies. Document why a particular session, authentication or load-balancing use meets the test. Functional or preference cookies need a purpose-specific assessment: a user-requested language preference may qualify, while optional tracking does not become necessary by being labelled functional. Analytics cookies generally require consent, but some national guidance allows narrowly configured audience measurement to be exempt. The CNIL explains the conditions and limits; aggregated reporting alone does not establish an exemption. Marketing cookies used for behavioural advertising require prior consent under the applicable rules.

Required documentation fields

For each cookie, document: the exact name, provider/domain, category, purpose description, duration, type (HTTP cookie, local storage, pixel), data collected, third-party access, and cross-site tracking status. This documentation feeds directly into your cookie consent mechanism and must match the information presented to users. Investigate discrepancies that may make the information inaccurate or leave a consent-requiring purpose outside the recorded choice.

Conducting a Gap Analysis

The gap analysis compares discovered cookies against your current cookie policy and consent banner. Common findings include marketing tags deployed by agency partners without the site operator’s knowledge, development and testing cookies left active in production environments, browser fingerprinting scripts that do not use traditional cookies but serve identical tracking purposes, and third-party embeds (YouTube videos, social media widgets) that silently deploy their own tracking cookies on your domain.

For each cookie requiring consent, verify that it is not set before consent is obtained, is correctly categorized in your CMP, matches the documented purpose, and that refusing consent actually prevents it from being set. The hidden productivity drain of cookie banner management compounds when the banner configuration does not match actual cookies on the site.

For each third-party cookie, assess whether a data processing agreement exists, whether data transfers outside the EEA are documented, and whether the provider has updated their cookie behavior since your last audit. Determine the provider’s actual role and transfer recipients rather than assuming every third party is a processor or every domain identifies a transfer destination.

A one-time cookie audit is necessary but insufficient. When selecting a consent management platform, verify the scanning frequency and coverage included in the actual offer. If you use Google Tag Manager or similar, implement governance controls: require approval for new tag deployments, verify consent-dependent tag behaviour, and review the container after relevant changes.

Automated compliance testing tools visit your site, decline all cookies, and verify no non-essential cookies are set. Running a scoped check after relevant deployments can reveal regressions; document the tested journeys and limitations.

Consequences of an Incomplete Audit

An incomplete inventory can leave optional tags active before consent, misdescribe recipients or omit changes to purposes. Preserve the evidence for each finding and verify the correction in the affected consent states.

Cookie compliance connects directly to your broader GDPR compliance checklist. Invalid consent can undermine processing that relies on it. Separately assess transparency, purpose limitation and any consent exemption; one inventory defect does not automatically prove every listed infringement.

Frequently Asked Questions

How many cookies does a typical website have?

There is no useful universal count for assessing your site. Measure your own pages, embedded services and consent states, and explain the purpose of each observed technology.

Inspect your actual Google Analytics configuration, tags and data flows before relying on a consent mechanism. The audit supplies the facts needed for the information and consent assessment; buying an audit report is not itself a legal permission to run analytics.

Do strictly necessary cookies need to be in the audit?

Yes. All cookies must be audited and documented. While strictly necessary cookies do not require consent, assess applicable information duties, including GDPR transparency where personal data is processed. A cookie containing no personal data is not subject to GDPR merely because it is a cookie.

Estimate the work from page templates, authenticated areas, embeds, interactions and consent states. Pilot a representative flow before committing to a schedule; classification and verification still require review after an automated scan.

FAQ

A cookie audit identifies and categorises all cookies set by a website — first-party, third-party, essential, analytics, advertising. It helps establish the facts needed for informed consent and exemption decisions. The legal duties concern the actual storage, access, information and choice; they do not impose one named audit format.

Review after relevant script, vendor or feature changes and choose a documented periodic schedule for unchanged parts of the site. There is no universal six-month legal interval. Keep evidence of the states tested and recheck the specific behaviour after correction.

What categories must cookies be classified into?

Necessary, preference, analytics and advertising are useful working labels. The legal assessment follows the actual purpose and national exemption conditions; provide sufficiently granular choices for distinct purposes requiring consent, rather than assuming a fixed four-category taxonomy satisfies the law.

What tools can be used to audit cookies?

Browser DevTools (Application > Cookies), Cookiebot scanner, OneTrust Cookie Compliance, CNIL’s CookieViz, or commercial crawl-based scanners. Dynamic cookie audits that scan under different consent states catch cookies that fire before consent is given — a common compliance issue.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

International transfers require the appropriate Chapter V route. Adequacy decisions, including the EU–US Data Privacy Framework for covered recipients, fall under Article 45. Standard Contractual…

April 30, 2026
03Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — a useful reminder to examine whether the organisation supports the DPO’s actual tasks and…

July 7, 2026
04Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
05Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
06Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

Cassie (Syrenis) is positioned by its maker around consent and preference management, with publicly advertised ROPA and data-subject rights capabilities as well. If you are looking for an…

July 9, 2026
07Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026
08Data Privacy

Cookie Banner Compliance: What Actually Meets the Law

A cookie banner is only effective when the choices it presents control the actual storage, access and tracking behaviour. Review both the interface and the implementation, including tags loaded by…

March 28, 2026