This translation has not been editorially reviewed yet. The German version is authoritative. German version →
Data protection & cookies: what exactly is checked
Rule set dsgvo-v1. Every subtopic leads to its checkpoints with weight and explanation; the list comes from the audit engine itself.
Before consent
Cookies, third-party servers, embeds, fonts and libraries before anyone has consented.
6 articles
The banner
Refusal on the first level, refusal acts, revocation, consent signal, no dark patterns.
6 articles
Basic principles
HTTPS, the privacy policy from each page, duration of cookies.
3 articles
Bildnachweise
- Before consent: Daria Nepriakhina, CC0
- The banner: Hermes Rivera, CC0
- Basic principles: Sylwia Bartyzel, CC0
What is measured
This audit area rates from findings and measured values, not from a countable set of rules. That is why this page lists which signals are collected.
What is loaded before consent
All requests to third-party servers that are triggered before each consent — Fonts, cards, videos, counting pixels.
Whether “reject” works technically
The reviewer clicks "Reject" and reloads the page. It is measured whether the same third-party requests run afterwards.
Cookies before consent
Which cookies are set before a choice is made and how long they apply.
Establishment of the consent banner
Whether “reject” is equally achievable or only after intermediate steps.
Good to know
- We examine technology, not legal texts — this is not legal advice.
- What matters is what is loaded before consent.
- Whether a “rejection” works technically, is measured, not believed.







