Skip to main content

Three checks on your cookie banner, none of which need a consultant

A consent banner is one of the few things anyone can inspect from the outside in ninety seconds. Most are unedited plugin defaults describing a business that is not yours. Three checks, and the one you may not be able to fix.

A consent banner is one of the few compliance artefacts anyone can inspect from the outside. No access, no questions, no engagement. A regulator, a client doing due diligence on you, or a competitor can open your site and read what you claim about your own data handling in about ninety seconds.

Most of them are wrong, and for a dull reason: nobody edited the plugin. Consent tools ship with combined European and Californian wording, six cookie categories, and an Accept button. Install, publish, forget. What you have then published is a description of a business that is not yours.

Three checks. None of them takes longer than the coffee you are holding, and none requires a consultant.

1. Count the clicks it takes to refuse

Open your own site in a private window. Count the clicks to accept. Then count the clicks to refuse.

If accepting is one click and refusing is three — a settings link, a set of toggles, a save button — that gap is the finding. The principle regulators apply is that consent must be freely given, and a choice weighted towards yes is not a free choice. It is also the single most common defect we see, because the plugin default puts Accept on the bar and refusal behind a modal.

The fix is usually a checkbox in the plugin settings. The reason it is worth doing is not the regulator. It is that anyone assessing you will count those clicks too.

2. Read the categories out loud

Open the settings panel and read the category names as if they were a list of things your organisation does.

Most stock installations offer Necessary, Functional, Performance, Analytics, Advertisement and Others. If you run no advertising, an Advertisement category is not a harmless default. It tells a reader you did not look at your own notice — and the categories are not decorative: the plugin sets a cookie for each one, so you are also storing preferences about things that do not exist.

Cut the list to what is real. On most professional services sites that is two categories, sometimes one.

3. Compare the published list to what is actually set

This is the check almost nobody runs, and it is the one that finds things.

Open your site in a private window. Accept nothing. Then look at the cookies already present, and compare that list to the cookie table your own privacy notice publishes.

Two failures are common. The published list names cookies that are no longer set, because a plugin was removed and the entry stayed. And the cookies that are set do not appear on the list at all — typically analytics, because analytics was added by someone other than whoever wrote the notice.

Where you cannot identify a cookie, say so. A notice that admits an unknown is more defensible than one that guesses, and guessing is how a notice becomes untrue.

The one you may not be able to fix

If your site is on managed WordPress hosting, your host may inject its own scripts into every page — commonly Google Analytics and a traffic-measurement script of its own. They load before any consent choice is offered, they transfer visitor IP addresses and browsing activity at that moment, and they cannot be disabled from inside WordPress.

This matters more than it sounds. It means a reject button on your banner may stop nothing, and a banner that appears to offer a choice it cannot honour is worse than one that offers no choice at all: it converts a plugin default into a claim you made deliberately.

If that is your position, the honest response is to say so on the banner, in one sentence, and to ask your host in writing what the scripts collect, where it is processed and how long it is kept. Keep the answer. It belongs in your notice.

The question your board should ask

“When did someone last open our own website in a private window, click nothing, and check what we are already collecting?”

Not whether you are compliant. Not whether a consent tool is installed. The question is whether anybody has looked at the thing itself, recently, from the outside — because that is the only way this class of problem is ever found. Nobody reports it to you. There is no alert. It sits in the shop window until someone looks.

If the answer is that nobody has, that is not a crisis. It is a twenty-minute job for whoever owns the website, and a reasonable thing for a board to ask for once a year in writing.

These three checks are the ones we run first, and we ran them on this site before writing them down. Two of the three found something.

Leave a Reply

Your email address will not be published. Required fields are marked *

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.