Cookie Audit
A cookie audit is a systematic review of all the cookies and similar tracking technologies that a website places on or reads from a visitor's device. It records details such as where each cookie comes from, what category it falls into, and how long it lasts, helping an organization understand how its site actually uses tracking. The results are typically used to check whether the site's practices align with applicable privacy and cookie rules.
A cookie audit is a structured discovery and documentation exercise that inventories every cookie, and generally other client-side technologies such as pixels, tags, SDKs, and local storage, set or accessed by a website, whether first-party or third-party. Practitioners typically record each item's source, purpose or category (for example strictly necessary, functional, analytics, or advertising), scope, and lifespan or expiry, and may map these findings against consent management configuration to identify gaps such as trackers firing before consent. It is commonly conducted as a recurring exercise, using manual review, automated scanning tools, or a combination, to support assessments against frameworks such as the EU GDPR and ePrivacy Directive, the UK regime, and US state laws including the CCPA and CPRA; scope and cadence vary by organization. An audit supports compliance efforts and record-keeping but does not by itself establish legal compliance, which depends on legal judgment and the specific facts and jurisdictions involved. Interpretations of what constitutes adequate coverage and categorization can differ, and this definition does not resolve those contested points.
Why it matters
A cookie audit gives an organization an accurate picture of what tracking technologies its website actually deploys, which is often more extensive than teams assume. Third-party tags, pixels, SDKs, and cookies can be introduced by marketing tools, embedded content, or vendor scripts without central oversight, and without an inventory it is difficult to know what is firing, from where, and when. Because EU rules under the ePrivacy Directive govern the placing of and access to information on a user's device, and the GDPR governs any personal data processed thereafter, an organization typically needs to understand its actual cookie behavior before it can assess whether its consent practices align with applicable law.
Audits are particularly useful for surfacing gaps between what a site says it does and what it actually does. For example, an audit may reveal analytics or advertising cookies firing before a user has given consent, or trackers that are not disclosed in the site's cookie notice. In most EU jurisdictions, non-essential cookies generally require prior, freely given, specific, informed, and unambiguous consent, so trackers that load before that affirmative action can indicate a compliance gap. In the UK the position is broadly similar, while US state frameworks such as the CCPA and CPRA more commonly rely on opt-out mechanisms, meaning the significance of a given finding depends on the jurisdictions involved.
It is important to keep the limits of an audit in view. An audit supports compliance efforts and record-keeping, but it does not by itself establish legal compliance, which depends on legal judgment and the specific facts and jurisdictions at issue. Interpretations of what counts as adequate coverage or correct categorization can differ, and an audit is a point-in-time snapshot that can quickly become outdated as a site changes.
Who it's relevant to
Inside Cookie Audit
Common questions
Answers to the questions practitioners most commonly ask about Cookie Audit.

