Skip to main content

Cookie Scanner

Header-based cookie review guide for GDPR Article 7 and ePrivacy review

Design-Partner PreviewManual Review RequiredCSV Export

What is Cookie Scanner?

The Cookie Scanner analyzes response headers and first-load website signals to detect visible cookies and suggest categories, giving teams a documented starting point for GDPR Article 7 and ePrivacy Directive reviews.

CCO/CPO Value: Surface first-pass cookie findings, review likely categories, and export audit-ready documentation faster than a fully manual review.

GDPR Article 7 Requirements for Cookies

7(1) Proof of Consent

You must be able to demonstrate that consent was obtained. Our scanner helps you document likely consent-relevant cookies; consent records still need to come from your banner or CMP.

7(2) Clear Request

Consent must be presented in plain language, distinguishable from other matters. Scanner output helps you review likely cookie purposes before publishing banner copy.

7(3) Easy Withdrawal

Withdrawal must be as easy as giving consent. Our system provides preference center for one-click withdrawal.

7(4) No Bundling

Don't condition service on unnecessary data processing. Scanner identifies which cookies are truly necessary vs. optional.

Cookie Categories (Suggested Classification)

The scanner suggests categories using header analysis and common naming patterns:

Necessary (No Consent Required)

Essential for website functionality - these can be set without consent.

sessioncsrfxsrfauthtoken

Functional (Consent Recommended)

Enhance user experience but not essential - consent recommended.

langlanguagelocaletimezonepreferences

Analytics (Consent Required)

Track user behavior for insights - explicit consent required.

_ga_gid_gat__utm*amplitude

Marketing (Consent Required - High Risk)

Used for targeted advertising - explicit opt-in consent required before setting.

_fbp_fbc_gcl_*IDEfr

Quick Start Guide (5 Steps)

  1. 1
    Navigate to Cookie Scanner
    Open the Cookie Scanner workspace if it is enabled for your design-partner account.
  2. 2
    Enter Website URL
    Enter the full URL of the website you want to scan (e.g., https://example.com)
  3. 3
    Run Scan
    Click "Scan Website" to collect first-pass cookie findings and suggested categories for review
  4. 4
    Review Results
    Review suggested categories, likely third-party indicators, and operator guidance before you update your consent records.
  5. 5
    Export Report
    Download CSV report for audit documentation and consent banner configuration

Understanding Scan Results

Total Cookies

Total number of cookies detected in response headers and first-load signals.

Third-Party Cookies

Cookies set by external domains - higher compliance risk, explicit consent required.

Categories Found

Number of unique categories (necessary, functional, analytics, marketing).

Recommendations

Compliance recommendations based on detected cookies and GDPR requirements.

CSV Export Format

Exported CSV contains the following columns for audit documentation:

ColumnDescription
nameCookie name
categoryAuto-detected category
isThirdPartytrue/false
domainCookie domain
expiresExpiration date
secureSecure flag status
httpOnlyHttpOnly flag status
scannedAtScan timestamp

GDPR Article 7 Compliance Checklist

Common CCO/CPO Questions

How often should I re-scan websites?
We recommend quarterly scans at minimum. Scan after any major website update, new third-party integration, or marketing campaign that adds tracking pixels.
Can I scan competitor websites?
Current launch scope is your own public properties only. Use scanner output as an input to compliance review, then confirm final classifications manually before updating consent records.
What if the scanner misses a cookie?
Some cookies are set dynamically after user interaction. We recommend also using browser DevTools (F12 → Application → Cookies) for thorough manual verification.
How do I handle cookies from CDNs?
CDN cookies (Cloudflare, Akamai, etc.) are typically classified as necessary if they're for performance/security. Our scanner identifies these and provides appropriate categorization.
Can I integrate scan results with my consent banner?
Yes. Export the CSV and use it as evidence when updating your consent management platform. Banner configuration remains operator-managed in the current launch.