Skip to content

This translation has not been editorially reviewed yet. The German version is authoritative. Deutsche Fassung →

Tracking cookies before consent: the most serious finding

The check loads the page without clicking anything, and looks at which cookies get set in the process. A cookie with a tracking purpose before any consent is the most serious finding in this audit area — it carries the greatest individual weight.

  • The cause is rarely intentional. Usually a tool loads its tracking tag before the consent banner has even decided whether it's allowed to — the order in the source code decides, not the intent behind the setting.
  • Cookies the check can't assign to any category are explicitly reported as "not classifiable" and do NOT count in the assessment. An unknown name isn't proof of tracking, and a finding based on suspicion would be a false positive.
  • What always needs checking is the state before any interaction. Anyone measuring after consent is given is measuring the wrong moment.

FAQ

Which cookies may be set with no consent?

Ones that are technically required to run the site — a session identifier, or remembering the consent decision itself, say. Anything used for analytics or advertising needs consent beforehand.

Why does the check report cookies as "not classifiable"?

Because the name alone doesn't allow a clear classification. They're named so you can classify them yourself, but they don't feed into the assessment — a finding based on suspicion would be worse than an open question.

Does a cookie from your own subdomain count as third-party?

For the consent question, what matters isn't the domain but the purpose. Even a self-set analytics cookie requires consent.

Deutsche Fassung — mit allen Prüfpunkten dieses Themas