A consent banner is one of the few compliance artefacts anyone can inspect from the outside. No access, no questions, no engagement. A regulator, a client doing due diligence on you, or a competitor can open your site and read what you claim about your own data handling in about ninety seconds.
Most of them are wrong, and for a dull reason: nobody edited the plugin. Consent tools ship with combined European and Californian wording, six cookie categories, and an Accept button. Install, publish, forget. What you have then published is a description of a business that is not yours.
Three checks. None of them takes longer than the coffee you are holding, and none requires a consultant.
1. Count the clicks it takes to refuse
Open your own site in a private window. Count the clicks to accept. Then count the clicks to refuse.
If accepting is one click and refusing is three — a settings link, a set of toggles, a save button — that gap is the finding. The principle regulators apply is that consent must be freely given, and a choice weighted towards yes is not a free choice. It is also the single most common defect we see, because the plugin default puts Accept on the bar and refusal behind a modal.
The fix is usually a checkbox in the plugin settings. The reason it is worth doing is not the regulator. It is that anyone assessing you will count those clicks too.
2. Read the categories out loud
Open the settings panel and read the category names as if they were a list of things your organisation does.
Most stock installations offer Necessary, Functional, Performance, Analytics, Advertisement and Others. If you run no advertising, an Advertisement category is not a harmless default. It tells a reader you did not look at your own notice — and the categories are not decorative: the plugin sets a cookie for each one, so you are also storing preferences about things that do not exist.
Cut the list to what is real. On most professional services sites that is two categories, sometimes one.
3. Compare the published list to what is actually set
This is the check almost nobody runs, and it is the one that finds things.
Open your site in a private window. Accept nothing. Then look at the cookies already present, and compare that list to the cookie table your own privacy notice publishes.
Two failures are common. The published list names cookies that are no longer set, because a plugin was removed and the entry stayed. And the cookies that are set do not appear on the list at all — typically analytics, because analytics was added by someone other than whoever wrote the notice.
Where you cannot identify a cookie, say so. A notice that admits an unknown is more defensible than one that guesses, and guessing is how a notice becomes untrue.
The one you may not be able to fix
If your site is on managed WordPress hosting, your host may inject its own scripts into every page — commonly Google Analytics and a traffic-measurement script of its own. They load before any consent choice is offered, they transfer visitor IP addresses and browsing activity at that moment, and they cannot be disabled from inside WordPress.
This matters more than it sounds. It means a reject button on your banner may stop nothing, and a banner that appears to offer a choice it cannot honour is worse than one that offers no choice at all: it converts a plugin default into a claim you made deliberately.
If that is your position, the honest response is to say so on the banner, in one sentence, and to ask your host in writing what the scripts collect, where it is processed and how long it is kept. Keep the answer. It belongs in your notice.
The question your board should ask
“When did someone last open our own website in a private window, click nothing, and check what we are already collecting?”
Not whether you are compliant. Not whether a consent tool is installed. The question is whether anybody has looked at the thing itself, recently, from the outside — because that is the only way this class of problem is ever found. Nobody reports it to you. There is no alert. It sits in the shop window until someone looks.
If the answer is that nobody has, that is not a crisis. It is a twenty-minute job for whoever owns the website, and a reasonable thing for a board to ask for once a year in writing.
These three checks are the ones we run first, and we ran them on this site before writing them down. Two of the three found something.
