Skip to content

This translation has not been editorially reviewed yet. The German version is authoritative. Deutsche Fassung →

Data protection

May cookies be set before consent is given?

Cookies that make visitors recognisable may only be set after the visitor has given consent. Our check therefore opens your website in a completely fresh browser, one where nobody has ever clicked anything, and reads out what cookies are already present at that exact moment. The report, in the "Data protection" audit area, names every tracking cookie found, with its name and provider.

How the cookie check works

The checker starts a browser with no history: no stored cookies, no prior consent. Then it loads your homepage and deliberately leaves the consent banner untouched. Anything already in the cookie store at that point was set without consent. An everyday example: if a cookie called "_ga" is already present after loading, Google Analytics tagged the visitor before they could decide. This exact sequence is what the check measures. It's a technical examination of what actually happens in the browser — it doesn't replace legal advice, but it makes visible what legal counsel could otherwise only guess at.

Tracking cookies, necessary cookies, and unknown cookies

The check sorts every cookie it finds into one of three classes. Only cookies with a known tracking pattern count as a violation — "_ga" from Google Analytics, "_fbp" from the Facebook pixel, or "_hj" from Hotjar, for instance. Necessary cookies pass with no penalty: a shop's session identifier, the shopping cart, the consent banner's own storage. Cookies that can't be matched to any pattern are marked "unclassifiable" — flagged for manual review, but with no point deduction. This honesty is deliberate: the check only claims violations it can prove with certainty.

Why the order makes the difference

A consent banner alone isn't enough — what matters is what happens before the click. Many websites show a banner and still set tracking cookies immediately on loading. To the visitor, that looks correct, but technically the choice has already been made: recognition began before they could accept or reject. For findings like this, the audit report points to the relevant rules on the duty to obtain consent. Whether a specific cookie is permissible in your particular case is for your legal counsel to determine — the check provides the solid technical stock-take for that.

  • Open your website in a private browser window and check the browser settings for what cookies are set before any click.
  • Ask your agency to start Google Analytics, the Facebook pixel, and similar services only after consent.
  • Have your consent tool set up to block tracking scripts until the visitor has made a choice.
  • Repeat the test after every change to the website — new plugins often bring new cookies with them.
  • Clarify cookies listed as "unclassifiable" in the report together with your agency.

FAQ

Which cookies are allowed without consent?

Technically necessary cookies: the session identifier, a shop's shopping cart, or the storage where the banner records the visitor's decision. The check treats such cookies as necessary and deducts no points. Whether a specific cookie is genuinely necessary in your case remains a legal question for your legal counsel.

What is a tracking cookie?

A small identifier that the browser stores and sends along on every subsequent visit. It lets a service recognise the same visitor again and track their behaviour across many pages. Well-known examples are "_ga" from Google Analytics and "_fbp" from the Facebook pixel — the check recognises both by name.

Is a cookie banner enough to allow cookies to be set?

The banner alone isn't enough — the order has to be right. Tracking cookies may only be created after the visitor has given consent. If the website sets them already on loading and shows the banner just for decoration, the check reports exactly that: cookies before consent, with name and provider in the report.

Why don't unknown cookies count as a violation?

Because the check only claims what it can prove. A cookie with no known tracking pattern can be harmless — a setting of your own system, for instance. It's therefore marked "unclassifiable", with the recommendation to review it manually. It doesn't factor into the assessment.

Deutsche Fassung dieser Seite