
GDPR cookie consent: trackers before consent
At a glance
EU-01CriticalGDPR Art. 83(5)(a); ePrivacy Art. 5(3)
Peeky looks for analytics, advertising and other non-essential trackers that load before a visitor has answered the cookie banner.
Last checked against the source:
The rule
Article 5(3) of the ePrivacy Directive, in the text inserted by Directive 2009/136/EC, allows the storing of information, or the gaining of access to information already stored, in a user’s terminal equipment only on condition that the user “has given his or her consent, having been provided with clear and comprehensive information” about the purposes of the processing. It does not stop technical storage for the sole purpose of carrying out the transmission of a communication, or storage “strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.”
The wording covers any storage of, or access to, information on the device. It is not limited to cookies, and it has no size threshold. A tag that reads a device identifier is within it in the same way a cookie is.
The consent the directive asks for is the GDPR’s consent. The EDPB notes that references to Directive 95/46/EC are read as references to the GDPR, and that this includes the references to consent in Directive 2002/58/EC (Guidelines 05/2020, para. 7; GDPR Art. 94(2)). Article 4(11) defines consent as an “unambiguous indication of the data subject’s wishes” given “by a statement or by a clear affirmative action”, and it must be freely given, specific and informed. Article 7(1) puts the burden of showing that consent was given on the controller, and Article 7(3) requires withdrawal to be as easy as giving it.
Timing is the point of this check. The EDPB’s view is that “consent must always be obtained before the controller starts processing personal data for which consent is needed” (para. 90), and that scrolling or swiping through a page “will not under any circumstances satisfy the requirement of a clear and affirmative action” (para. 86). The CNIL’s 2020 guidelines take the same line on continued browsing and add that refusing must be as easy as accepting.
Penalties sit in two layers. The directive leaves them to the Member States, which must lay down rules that are “effective, proportionate and dissuasive” (Art. 15a), so the ePrivacy side is sanctioned under national law. The GDPR side is separate: Article 83(5)(a) places “the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9” in the upper tier, with a ceiling of EUR 20 million or 4% of worldwide annual turnover. The check’s citation lists Art. 83(4)/(5); the consent conditions are in paragraph 5.
What PeekWell checks and how
EU-01 asks one question: did anything that is not strictly necessary load before the visitor answered the banner? The scan answers it from what the browser did, not from what the site says it does.
The scan opens a public page in a fresh browser context with no saved choices, the way an ordinary visitor’s browser would. It records every network request and every cookie written as the page loads, without touching the banner. The request domains and cookie names are then compared with a maintained list of tracker signatures, grouped by purpose: analytics, advertising and session replay. A match that appears before any consent event becomes a finding, and the requests themselves are the evidence.
The decision is made by code from that evidence. A language model may help write the explanation in the report, but it never decides that a tracker fired. Severity starts at critical and scales with the number and type of trackers seen.
The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. It does not read your contracts or decide what a tag is for beyond the category on its list, and a list only knows the trackers on it. Collection that happens on a server, or inside an app, is outside what a browser visit can see. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
For an authority this is one of the easiest facts to establish, because it can be observed from outside with a clean browser. In procedure PS/00080/2023 the AEPD opened a website with its history and cookies cleared, took no action on the page, and recorded Google Analytics performance cookies (_ga and _gid) and a targeting cookie in use. The decision, which also covers privacy-notice and design-pattern findings, includes EUR 5,000 under Article 22.2 of Spain’s LSSI for the cookie setup.
The same pattern runs through the decisions listed below. The CNIL’s SHEIN decision records cookies placed before visitors interacted with the banner, and a Refuse all button that did not stop them. The Romanian authority ordered the cookie setup reconfigured so that cookies need prior consent.
For a company the practical consequences are of three kinds. Authorities can check the facts themselves, as the AEPD did here after a complaint reached it. Consent has to be demonstrable under Article 7(1), so a banner that is present but not wired to the tags proves little. And data that reaches an advertising or analytics vendor before the visitor chose has already left; fixing the banner afterwards does not recall it.
Smaller companies and larger companies
The rule has no size threshold, and the same facts decide it for a five-person startup and for a listed group. What differs is how the problem arises and how it shows up.
In a small company the site is often built from a template or a hosted builder. Someone in marketing adds Google Analytics, an advertising pixel and a chat widget, and a banner plugin is switched on. The banner is real, but one of the tags was pasted straight into the theme, so it loads on every visit before the banner is answered. There is often no privacy team to notice, so a complaint may be how it comes to light, as it did in Romania. Smaller companies are within reach of authorities: the Romanian decision listed below ended in a fine of 10,000 lei and an order to correct the setup.
In a larger company there are more moving parts. A tag manager holds dozens of tags owned by different teams and agencies, the site spans several domains and apps, and a release can change which tags fire and in what order. Consent state has to carry across all of it, and the company has to be able to show it did. Scale also changes the stakes: the CNIL noted that around 12 million French residents visit shein.com each month.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Infinite Styles Services Co. Limited (SHEIN)
The CNIL found that several cookies, particularly for advertising, were placed on visitors' devices as soon as they arrived on shein.com, before they interacted with the banner. It also found that Refuse all, or withdrawing consent, did not stop new cookies being placed.
Read the CNIL (France) publication about Infinite Styles Services Co. Limited (SHEIN)
Smaller companies
Urban Home Development S.R.L.
After a complaint, the authority found that the company's website did not show the identity of the operator and installed cookies that were not technically necessary before users gave consent. It ordered the cookie setup and privacy policy corrected.
Read the ANSPDCP (Romania) publication about Urban Home Development S.R.L.
How to fix it
The order of events matters more than the tool you use. These steps fit most consent tools and tag managers, and step 4 follows Google’s own consent mode guide.
- See what loads first. Open your site in a private window with the browser’s network tab open. Do not touch the banner. Write down every third-party request and cookie that appears.
- Block by default in your consent tool. Mark analytics, advertising, session replay and chat as blocked until the visitor accepts. Most consent tools have a per-category setting for this. A category left on allowed is one way a banner can exist while tags still run.
- Start tags from the consent tool’s callback. In a tag manager, fire each tag on the consent tool’s accept event rather than on page load. Pasted scripts in the theme, a plugin or the page template need the same treatment, or they need to go.
- Set Google’s consent mode to denied before any Google tag. Google’s guide asks for the default call on every page before any command that sends measurement data, and says defaults will not work if the order is wrong. Then update the state when the visitor accepts.
- Re-scan. Clear cookies and storage, reload, and run a scan again. The finding should disappear once nothing non-essential loads before the choice.
gtag('consent', 'default', {
ad_storage: 'denied',
ad_user_data: 'denied',
ad_personalization: 'denied',
analytics_storage: 'denied',
});
Consent mode changes what Google’s tags store and send. Whether it satisfies a given authority is a question for your legal adviser, and Peeky reports only what it sees.
Questions
Can a website set cookies before the visitor accepts?
Only the ones the site needs to work, like a login or a shopping basket. Analytics, advertising and similar cookies wait until the visitor says yes.
The rule is in Article 5(3) of the ePrivacy Directive. It makes two exceptions, for sending the message itself and for what is strictly necessary to give the visitor a service they asked for. The rule has the wording.
What counts as a non-essential cookie?
Anything the site could work without. Usually that means analytics, advertising, session replay and social tracking. A login cookie or a basket is essential, because the visitor asked for that feature.
The line is drawn by purpose, not by name. Two cookies with the same name can fall on different sides of it.
Does scrolling count as consent?
No. The European Data Protection Board says scrolling or swiping through a page will not under any circumstances be a clear affirmative action. The visitor has to click or tick something that means yes, and the choice has to come before the tracking starts.
What does the ePrivacy Directive say about cookies?
Article 5(3) says a site may store information on a visitor's device, or read it, only if the visitor has given consent after clear and comprehensive information. The exceptions are narrow. Each country writes its own penalties, so the amounts differ from one authority to the next.
How does Peeky check for trackers before consent?
Peeky opens your public page in a clean browser with no saved choices and writes down every request and cookie that appears before anyone touches the banner. It never clicks Accept and never signs in. How a scan works has the full path.
Filed with
The rule
ePrivacy Directive 2002/58/EC, Art. 5(3), as amended by Directive 2009/136/EC
Read the rule (ePrivacy Directive 2002/58/EC, Art. 5(3), as amended by Directive 2009/136/EC)A case
Infinite Styles Services Co. Limited (SHEIN)
Read the decision (Infinite Styles Services Co. Limited (SHEIN))Sources
- Directive 2009/136/EC, Official Journal L 337, Art. 2(5) (replaces Art. 5(3) and adds Art. 15a of Directive 2002/58/EC)
- Regulation (EU) 2016/679 (GDPR), Official Journal L 119
- EDPB, Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1, adopted 4 May 2020
- CNIL, Cookies et autres traceurs: lignes directrices modificatives et recommandation (deliberations 2020-091 and 2020-092, 17 September 2020)
- CNIL, Cookies placed without consent: SHEIN fined 150 million euros by the CNIL
- ANSPDCP (Romania), press release of 27 May 2024 on Urban Home Development S.R.L.
- AEPD (Spain), resolution in procedure PS/00080/2023 (Chatwith.io Worldwide, S.L.)
- Google Tag Platform, Set up consent mode on websites
Last checked against the source:
For information only. Not legal advice.


