Privacy audit

How to run a website privacy audit

A privacy audit checks what data your website actually sends, to whom, and whether it respects the choices visitors make. Here is how to do it, and how to get evidence you can hand to counsel.

1. Map the journeys that matter

Trackers rarely fire only on the homepage. Audit the paths real visitors take: browsing products and checking out on a store, reading an article on a publisher, or reading company pages and a blog post on a corporate site.

2. Choose the jurisdictions

Rules differ by location. A useful audit runs from where your visitors are, for example California (CCPA/CPRA, CIPA, ECPA), Colorado, France and the UK, so you see the banner and tracking each audience sees.

3. Test every consent condition

  • Before consent: what loads before the visitor makes a choice.
  • Reject all: whether marketing requests stop after a refusal.
  • Accept all: what you collect once consent is given.
  • Global Privacy Control: whether the opt-out signal is honoured.

4. Record the evidence

For each step, capture screenshots, network requests, cookies and pixel payloads. Findings are only useful when they point to the exact journey, location, consent choice and request involved.

5. Separate findings from gaps

A finished browser session does not mean the journey was tested. Keep observed issues, items needing review, working controls and incomplete tests apart, so you know what was actually examined.

Automate it with The Privacy Pentest

Enter your domain and browser agents run these steps for you, then deliver a report with findings by journey and geography, severity and confidence, linked evidence, and recommended fixes.

Run a Privacy Pentest on your site