GDPR · Free checker
Free GDPR cookie checker
Complidar's free GDPR cookie checker loads your site with a real browser as an EU visitor and records which cookies and third-party trackers fire before anyone consents, then inspects your consent banner for the mechanics regulators actually punish. You get the list of pre-consent trackers, the banner findings, and an estimated exposure range in minutes, no account and no card. Enter a domain you own or are authorized to test and the scan starts.
What the cookie scan can and can't settle
The observable part is the part suits and regulators start from, and it is exactly what a scan is good at. The checker watches real network traffic to catch analytics and advertising tags (Google Analytics, the Meta Pixel, ad and retargeting cookies) that load before any consent is given, which under the ePrivacy rules is the core failure. It then reads the consent banner itself: whether refusing is as easy as accepting, whether boxes are pre-checked or consent is merely implied, and whether the cookies and trackers in use are disclosed. These repeat on every templated page, so a scan finds them at a scale manual review can't match.
It cannot decide whether GDPR applies to your business in the first place. That turns on whether you offer goods or services to people in the EU or UK or monitor their behavior, which is a counsel question that depends on facts a scan can't see. Complidar reports what is observable, which trackers fire and when, and what your banner and policy actually do, and marks what needs a lawyer. The checker is the first pass, not the last word, and it never replaces counsel.
Why the banner is where the fines land
Cookie-consent design is enforced aggressively under GDPR and the companion ePrivacy ('cookie') rules, and the enforcement is about interface mechanics, not abstract policy. In 2022 France's data protection authority, the CNIL, fined Google EUR 150 million and Meta EUR 60 million over cookie banners that made refusing harder than accepting, because neither offered a reject-all button as immediate as the accept button. The statutory ceiling sits far above that: GDPR fines reach up to EUR 20 million or 4% of global annual turnover, whichever is higher.
For a small business the realistic exposure is rarely the 4% headline number. It is a data protection authority complaint from an EU user, an order to stop processing, and the commercial cost of failing a customer's vendor diligence. All three start from the same visible failures the cookie checker surfaces: a tracker that fired before the click, or a banner with no equally easy way to say no.
What this checker looks for
- Third-party trackers and cookies that fire before consent for EU visitors, captured from real network traffic
- Whether the consent banner offers a 'reject all' as prominent and easy as 'accept all' (the CNIL enforcement pattern)
- Pre-checked consent boxes or implied-consent designs that aren't valid opt-in
- Cookie and tracker disclosure: whether what's running is actually named for the visitor
- Privacy-policy GDPR basics: lawful basis for processing, data-subject rights, and a controller contact
- Analytics and advertising tags (Google Analytics, the Meta Pixel and peers) loading ahead of the consent choice
Common questions
Is a cookie banner enough to be GDPR compliant?
Only if it works. Consent must be opt-in before non-essential trackers fire, refusing must be as easy as accepting, boxes can't be pre-checked, and the choice has to actually control the trackers. Banners that load Google Analytics before the click are extremely common and fail the core requirement. That mismatch is the first thing the cookie checker looks for.
What did the CNIL actually fine Google and Meta for?
In 2022 the CNIL fined Google EUR 150 million and Meta EUR 60 million over their cookie banners specifically: you could accept all cookies in one click, but there was no equally easy reject-all, so refusing took more effort than consenting. It was pure interface mechanics, and it's exactly the asymmetry a scan can see directly.
Does the GDPR even apply to my business?
That's a counsel question, not something a scan can answer. It depends on whether you offer goods or services to people in the EU or UK or monitor their behavior, which advertising trackers and analytics can constitute. What the checker settles is the observable half: which trackers fire before consent on your site, which is the fact pattern your lawyer needs to make the call.
Last updated 2026-06-28 · Informational, not legal advice: how to read this