Skip to content
Merlin Tools

Does tracking fire before consent?

Does your site load Google Analytics or the Meta Pixel before the visitor says yes? Find out in seconds: it's the breach data protection authorities pursue most often.

Genuinely free. No sign-up, no email, no limits, no cookies. We don't store the URL you analyse.

Loading the security check…

What this tool checks

We read your home page's HTML, exactly what the server sends every visitor, and look for three things. First, the common tracking tools, from Google Analytics 4 to the Meta Pixel, Hotjar, Microsoft Clarity, and the LinkedIn and TikTok pixels. Second, whether a consent management platform is present (the «cookie banner»: Cookiebot, OneTrust, Usercentrics and the like). Third, whether the tracking scripts look held back pending consent or set to fire straight away.

That last point is the decisive one. The law doesn't just ask you to show a banner: it asks that tracking cookies aren't written until the user agrees. This is where most sites slip, often without knowing, because the banner is there, it's visible, and everything looks fine.

The other checks are on the tools page.

Frequently asked questions

Isn't having a cookie banner enough?

No. That's the most common misconception. Under the GDPR and the ePrivacy rules, the banner must also block tracking cookies until the user agrees (so-called prior blocking). A banner that appears while Google Analytics has already fired protects nobody, and it's exactly the scenario regulators pursue most often.

Which cookies need consent?

Profiling and tracking cookies: third-party analytics like Google Analytics, advertising pixels like Meta's, session-recording tools like Hotjar or Clarity. Strictly necessary technical cookies don't need consent, but they still have to be declared in the cookie policy.

Do Google Fonts and embedded YouTube need consent?

They're an in-between case: not marketing trackers, but they still send the visitor's IP address to third-party servers. Google Fonts can be self-hosted; YouTube has its youtube-nocookie variant; maps have privacy-respecting alternatives. Some European authorities have already acted on Google Fonts loaded directly.

Does this tool tell me for certain that I'm compliant?

No, and it says so plainly. The analysis is static: we read the page's HTML without loading it in a browser, so we don't see the cookies actually written. We detect strong hints (trackers present, no banner, prior blocking not configured), not proof. For a legal assessment, speak to a privacy professional.