3 findings · 2 warnings · 4 checks passed
Vendors
G-HLZSNE9Z0CViolations
GCM_002Do not write analytics or advertising cookies until the visitor has made a consent choice. Load GTM/GA4 tags behind a denied consent default and let the CMP's update unblock them.
GCM_008Affected: broken
Call gtag('consent', 'update') immediately after the visitor's choice, with the correct values for both accept and reject. Do not rely on a page reload: it creates duplicate pageviews and breaks session attribution.
GCM_010Affected: Google Analytics 4
After a rejection the affected vendors must stop setting identifiers and sending measurement, or run only in a verified cookie-less mode.
GCM_001Call gtag('consent', 'default') with denied values before GTM or GA4 loads, so the initial consent state is explicit.
GCM_003Make both the accept and the reject button update the consent state through the GTM Consent API or gtag('consent', 'update').
GCM_009Affected: Google Analytics 4
The affected vendors set an identifier or sent measurement that is not verifiably cookie-less before the visitor chose. Load them only after consent, or configure a documented cookie-less mode that sends no identifiers.