Cookie Scanner
A cookie scanner is a tool that automatically visits a website and creates a list of the cookies and similar tracking technologies it uses, such as pixels and tracking scripts. It helps website operators find out what is running on their site so they can describe these technologies to users and manage consent. The scan typically produces a report of what was detected, though the results depend on how and when the scan is run.
A cookie scanner is an automated tool that crawls a website to detect and inventory the cookies, pixels, and tracking scripts it sets, generating an audit report of the technologies identified. Such tools support compliance activities under the ePrivacy regime (which governs the placing of and access to information on a user's device) and the GDPR (which governs any subsequent processing of personal data) by providing the underlying inventory needed for cookie notices, categorization, and consent configuration. Scanners often attempt to classify detected items (for example, as strictly necessary versus analytics, advertising, or functional), but automated categorization is not authoritative and requires review, since classification determines whether prior consent is generally required in most EU and UK contexts. Scope and limitations should be noted: results reflect only the states, pages, and conditions encountered during a given crawl and may miss cookies or trackers set dynamically, after user interaction, by third-party SDKs, or via techniques such as fingerprinting or local storage. A cookie scanner supports but does not replace legal judgment or a compliance assessment, and detection alone does not establish the lawfulness of any given technology.
Why it matters
Website operators cannot describe or manage tracking technologies they are not aware of. Before drafting a cookie notice, categorizing technologies, or configuring a consent management platform, an operator needs an accurate inventory of the cookies, pixels, and tracking scripts running on their site. A cookie scanner provides a starting point for that inventory, which is why these tools are commonly used in preparation for compliance work under the ePrivacy regime (which governs the placing of and access to information on a user's device) and the GDPR (which governs any subsequent processing of personal data).
The categorization a scanner produces has direct compliance consequences. Whether a given technology is treated as strictly necessary or as analytics, advertising, or functional generally determines whether prior consent is required in most EU and UK contexts. Because automated categorization is not authoritative, relying on a scanner's labels without review can lead an operator to obtain consent incorrectly, or to omit consent where it is generally required. The scanner supports this judgment but does not make it.
Operators should also understand what a scan does not capture. Results reflect only the pages, states, and conditions encountered during a particular crawl, and may miss cookies or trackers set dynamically, after user interaction, by third-party SDKs, or through techniques such as fingerprinting or local storage. Treating a single scan report as a complete or definitive record of a site's tracking behavior can create a false sense of assurance, which is why scans are typically repeated and reviewed rather than run once.
Who it's relevant to
Inside Cookie Scanner
Common questions
Answers to the questions practitioners most commonly ask about Cookie Scanner.

