Your cookie banner says one thing. Your browser does another.

Almost every privacy enforcement action against a website starts the same way: someone opens the site with developer tools running and watches what loads before anyone clicks "Accept". The banner is not the evidence. The network log is.

The rule that catches most sites

Under EU law the principle is narrow and unforgiving: storing information on, or reading information from, a visitor's device requires prior consent unless it is strictly necessary to deliver the service the visitor asked for. Analytics is not strictly necessary. Advertising pixels are not strictly necessary. A/B testing is not strictly necessary.

The word that does the work is prior. A tag that fires while the banner is still on screen has already broken the rule, no matter what the visitor clicks a second later. And this is exactly the failure mode that a consent management platform does not fix by itself — a CMP blocks what it has been told to block. Anything loaded by a hard-coded script tag, injected by a third-party tag manager, or added by a marketing colleague last quarter runs outside its control.

Why this keeps being found

What PrivaScan measures

PrivaScan is a product of Talivio Technology OÜ, the company that also publishes Talivio News.

What a scan does not do

It is worth being precise, because the opposite claim is common in this market. PrivaScan is a detection and reporting tool. It does not make an organisation compliant and it does not sign off a legal position. It reports what a browser actually observed, on the pages it visited, at the time it visited them. Whether a given tracker is lawful in your specific context — what your legal basis is, what your notice says, what your contracts allow — remains a legal assessment.

What the scan removes is the excuse of not knowing. In practice most findings are not disputed once someone looks at the network log; they were simply never looked at.

See PrivaScan →

Legal background

  • Regulation (EU) 2016/679 (GDPR)
  • Directive 2002/58/EC (ePrivacy), as implemented in national law — the source of the prior-consent rule for terminal equipment
  • European Data Protection Board guidance on consent and on tracking techniques
  • Law No. 6698 on the Protection of Personal Data (KVKK), Türkiye

This page is not legal advice. Whether and how these rules apply to your organisation should be confirmed with your own counsel or data protection officer.