A cookie audit identifies what the site stores or sends, why it does so, and whether the implementation matches the business's choices and notices. It should include third-party scripts and embedded tools, not just first-party code.
This is a technical checklist, not legal advice. Requirements depend on the business, audience, tools, and applicable rules.
Capture a clean visit
Test a new browser session before and after each consent choice. Record cookies, local storage, scripts, network destinations, purpose, vendor, duration, and page that caused the behavior.
Group by purpose
Separate necessary operation from analytics, personalization, advertising, chat, video, maps, testing, and other optional uses. Describe the purpose in language a visitor can understand.
Check consent behavior
Verify optional tools do not run before the relevant choice when required, that reject and accept paths are clear, and that a visitor can review or change the decision later.
The cookie consent guide and analytics privacy checklist cover governance.
Synchronize the notice
Compare the audit with the privacy policy, vendor list, retention, access, and data flow. Update the record after a plugin, tag manager, chat, analytics, map, or campaign change.
Document ownership and review
Keep the tool version, date, owner, evidence, exceptions, remediation, and next review visible. Retest high-risk pages such as forms, payments, accounts, and checkout.
Consent behavior not matching the banner or privacy notice? Ask Vertinus to audit the live scripts and choices.