Skip to main content

Methodology

How ConsentSignals scans work

Automated technical indicators for human legal review — not legal advice.

Same measurement logic we ship in product — written for DPOs and agencies who need to explain the method to counsel.

What a scan is

What we do

ConsentSignals runs an automated technical audit on a URL you submit. We compare what third-party scripts do under multiple consent choices (not only Accept vs Reject), estimate how child-directed the site appears, map findings to regulatory frameworks, and produce a tamper-evident PDF on paid plans.

What we do not do

We do not determine legal compliance, certify accessibility, issue fines, or replace a DPO or lawyer. Do not scan third-party sites without permission. Signed PDFs are evidence for human review.

What you can scan

Public site scans

Best for marketing pages, storefronts, and public landing pages. A headless browser loads the URL and runs the full pipeline: consent-differential audit, tracker enrichment, audience classification, regulatory mapping, and optional signed PDF. Bot walls, geo-gated CMPs, and heavy SPAs can limit coverage.

Logged-in scans (your domains)

For apps and dashboards you operate: verify domain ownership via DNS, attest you are authorised, and paste session cookies from browser DevTools (never stored in our database). Pro and Agency support deep scan — scroll a feed or dashboard to capture lazy-loaded trackers. We do not automate username/password, OAuth, or MFA.

Authorisation & third parties

ConsentSignals supports agencies auditing client sites (with DNS verification or written authorisation). We are not a regulator and cannot certify platforms without cooperation and lawful authorisation. Scanning sites you do not control may violate their terms and our Acceptable Use Policy (see Terms).

What we measure

Consent-differential audit

Each scan runs a 8-session consent matrix: Accept All, Reject / Disagree All, Essential-only, Analytics-only, Withdraw marketing (Accept then revoke), GPC/DNT signal, Returning user (Reject cookies), and a passive baseline. We compare which third-party domains and cookies are active in each isolated session. Trackers in both Accept and Reject may run before or regardless of consent; trackers on Essential-only or Analytics-only when they should not are flagged as granular-leaky or marketing-leaky. Multi-session consent-differential audit (Method I): set arithmetic across Accept, Reject, Essential-only, Analytics-only, Withdrawal, GPC, Returning-user, and passive recordings.

CMP effectiveness

After all consent sessions we classify each third-party domain and produce a measured effectiveness summary (effective, partial, ineffective, or no CMP). This is independent of your OneTrust/Cookiebot/Didomi dashboard — we observe network requests and cookies, not vendor configuration.

Audience classification

We combine readability, visual design signals, colour patterns, and COPPA-style statutory factors into an estimated child-appeal score. This is a regulatory audit signal for site operators — not a parental content-rating or “safe for children” score.

Regulatory mapping

Findings are matched to our Regulatory Knowledge Base (RKB). Citations indicate possible relevance for your compliance team — they are not violations, fines, or legal advice.

Honest boundaries

Timing and variability

A full scan typically 5–12 minutes depending on site speed, trackers, and cookie-banner behaviour. Re-scanning the same URL may differ if the site, CMP, geography, or third-party scripts change.

Headless Chromium coverage

Each consent session is one headless Chromium browser. That is the right tool for Accept / Reject / Consent Mode on the wire. It is not a complete picture of every visitor. We always disclose three gaps: (1) one region per scan — CMP banners and tags often differ by jurisdiction; re-scan with another geo if your users are not only there; (2) one A/B variant — experiment platforms may serve a different GTM container or CMP to other visitors; (3) server-side / CAPI — Meta Conversions API, server-side GTM, and other server-to-server forwarding are not fully visible. Hostname hints are follow-up, not proof of a leak or of a clean bill.

Technical limitations

Bot blocking, login-only pages, and heavy SPAs can limit coverage. LLM explanations are constrained and audited but may use template fallbacks. EAA mode runs WCAG-oriented checks — not a conformity assessment.

Misuse prevention

Every scan requires an authorisation attestation. Anonymous scans are rate-limited and blocked for major third-party platforms. We are a B2B compliance tool — not drive-by reconnaissance or a parental-control service.

What we cannot see

  • ×We are not a CMP — we do not install banners, store consent records, or host vendor lists
  • ×Server-side / CAPI tracking invisible to browser sessions (we may hint; we do not replace CAPI)
  • ×Geo-gated CMP banners and tag sets — each scan uses one region profile
  • ×A/B or multivariate experiments — headless Chromium typically sees one variant
  • ×Shadow pixels inside widgets the CMP authorised
  • ×Every possible per-category toggle a human might choose (we approximate Essential-only, Analytics-only, and post-Accept withdrawal)
  • ×CMP consent-log timestamps without a read-only API or export upload
  • ×DSAR / subject-access portals, EUDI wallet relying-party flows, or consumer parental-control apps
  • ×Legal verdicts — evidence for your DPO and counsel only