Frequently asked questions

Everything you need to know about ConsentScan, GDPR cookie compliance, and what our grades mean.

What does ConsentScan actually check?

ConsentScan loads your website in a clean browser with no prior cookies or consent, then records every cookie set before any consent action is taken. It checks whether those cookies are strictly necessary (login sessions, shopping cart) or tracking/analytics cookies that require explicit consent under GDPR and the ePrivacy Directive.

How is the A–F grade calculated?

Each cookie found before consent is assessed for severity: tracking and advertising cookies (e.g. _ga, _fbp) score as high-risk violations; functional cookies score lower. Your grade reflects the number and severity of pre-consent cookies relative to pages scanned. An A means no consent violations found. An F means multiple high-risk trackers fire before any consent is given.

What if no consent platform (CMP) is detected?

If ConsentScan finds consent violations but no consent management platform (like OneTrust or CookieYes) is present, your grade is penalised by one band — because the absence of a CMP means there is no mechanism for visitors to give or withdraw consent at all, which is a fundamental GDPR requirement.

How many pages does a free scan cover?

A free scan covers your homepage plus up to 12 subpages, automatically selected to include contact, about, and other commonly visited pages. ConsentScan Pro scans up to 50 pages and supports continuous scheduled monitoring.

Is a B or C grade a legal problem?

It depends. A C or D grade typically indicates that some tracking cookies fire before consent — this is likely a GDPR violation. Whether it results in a fine depends on your jurisdiction, the nature of the cookies, and whether you can demonstrate remediation efforts. We strongly recommend consulting a privacy lawyer for a legal assessment.

Does the scan affect my website visitors or data?

No. The scan runs in a sandboxed browser on our servers and does not interact with your live visitor data. It simulates a brand-new visitor with no prior cookies or consent state.

I got an email report — what should I do with it?

Share it with your developer and your consent platform provider. The report lists every pre-consent cookie with the page it was found on and its risk level. Your developer and CMP provider should be able to use this to configure cookie blocking correctly.

What consent management platforms does ConsentScan detect?

ConsentScan detects 15+ CMPs including OneTrust, CookieYes, Cookiebot, TrustArc, Osano, Iubenda, Usercentrics, Didomi, Quantcast Choice, and more. If your CMP is not detected, let us know at hello@consentscan.io.

How is ConsentScan Pro different from the free scan?

Pro adds continuous scheduled monitoring (daily/weekly/monthly), a multi-site dashboard, trend history and regression alerts, white-label PDF reports, REST API access, and team members with role-based permissions. See the Products page for a full comparison.

Is the free scan really free?

Yes. The free scan has no account requirement and no credit card. It is rate-limited per IP to prevent abuse, but casual use is unlimited. We offer Pro for teams who need more.

Still have a question?

Email us and we'll get back to you the same day.

hello@consentscan.io →