1. Map the journeys that matter
Trackers rarely fire only on the homepage. Audit the paths real visitors take: browsing products and checking out on a store, reading an article on a publisher, or reading company pages and a blog post on a corporate site.
2. Choose the jurisdictions
Rules differ by location. A useful audit runs from where your visitors are, for example California (CCPA/CPRA, CIPA, ECPA), Colorado, France and the UK, so you see the banner and tracking each audience sees.
3. Test every consent condition
- Before consent: what loads before the visitor makes a choice.
- Reject all: whether marketing requests stop after a refusal.
- Accept all: what you collect once consent is given.
- Global Privacy Control: whether the opt-out signal is honoured.
4. Record the evidence
For each step, capture screenshots, network requests, cookies and pixel payloads. Findings are only useful when they point to the exact journey, location, consent choice and request involved.
5. Separate findings from gaps
A finished browser session does not mean the journey was tested. Keep observed issues, items needing review, working controls and incomplete tests apart, so you know what was actually examined.
Automate it with The Privacy Pentest
Enter your domain and browser agents run these steps for you, then deliver a report with findings by journey and geography, severity and confidence, linked evidence, and recommended fixes.