Automated Rescan
An automated rescan is a repeat scan of a website that runs automatically, rather than being started by hand each time, to check for cookies, trackers, or other issues. In a cookie compliance context, it is typically used to re-check a site after changes have been made, so an organization can confirm whether previously flagged problems still appear. It is a supporting tool for monitoring and does not by itself determine whether a site is legally compliant.
An automated rescan is a scheduled or event-triggered repeat scanning process that re-executes a prior scan without manual initiation. Drawing on the general concept of a rescan as a repeat validation activity performed after remediation to verify that a previously identified weakness no longer appears, and on the concept of automated scanning as automated analysis performed without per-run human action, an automated rescan combines both: it periodically or automatically re-inventories a target (for example, cookies, pixels, local storage, SDKs, or other tracking technologies observed on a site) to detect changes, confirm remediation, or surface newly introduced items. The evidence available describes rescan and automated scanning as general concepts and does not provide cookie-consent-specific implementation details, so the precise triggers, coverage, and detection scope depend on the particular tool and configuration. An automated rescan supports ongoing monitoring and record-keeping but does not replace legal assessment of whether identified technologies require consent under applicable frameworks such as the EU ePrivacy rules, the GDPR, the UK regime, or US state privacy laws.
Why it matters
Websites are not static. Marketing teams add new tags, third-party vendors update their scripts, and content management changes can introduce cookies, pixels, local storage entries, or SDKs that were not present when a site was last reviewed. A one-time scan captures only a single moment, so previously verified findings can drift out of date as the site evolves. An automated rescan addresses this gap by re-checking the site on a schedule or in response to a trigger, helping organizations notice when new tracking technologies appear or when items they believed were remediated resurface.
In a cookie compliance context, this matters because obligations under frameworks such as the EU ePrivacy rules, the GDPR, the UK regime, and various US state privacy laws generally attach to what actually runs on a user's device. If a newly introduced analytics or advertising cookie fires before consent in a jurisdiction that requires prior opt-in, that exposure exists regardless of whether anyone manually re-checked the site. Automated rescanning supports ongoing monitoring and can feed record-keeping about what was observed and when, which may be useful when demonstrating diligence to a data protection authority.
It is important not to overstate what an automated rescan achieves. Detecting a cookie or tracker is not the same as determining whether it is lawful. Whether a given technology requires consent, qualifies as strictly necessary, or falls under an opt-out rather than opt-in regime depends on legal assessment of the specific facts and the applicable jurisdiction. An automated rescan is a supporting tool; it does not by itself establish compliance, and its coverage and accuracy depend on how the underlying scanner is configured.
Who it's relevant to
Inside Automated Rescan
Common questions
Answers to the questions practitioners most commonly ask about Automated Rescan.
