1 finding · 4 warnings · 4 checks passed
Vendors
cjg7K8O8VLqJgof5kmhFz5aFTM4FtoQHnckauPaOGHX.y7939042599G-4PRCPPJEJZG-GNW0LC86SZG-Q7C756EV6GGTM-N6DFGS2GTM-TBMT2SFUA-169612499-1UA-7895305-110101729158319984806927407861284667215Violations
GCM_002Do not write analytics or advertising cookies until the visitor has made a consent choice. Load GTM/GA4 tags behind a denied consent default and let the CMP's update unblock them.
GCM_004Affected: analytics_storage
Accepting must set every consent purpose to granted, and rejecting must set it to denied, in the consent update.
GCM_010Affected: Criteo, Google Analytics 4, LinkedIn Insight, Google Universal Analytics
After a rejection the affected vendors must stop setting identifiers and sending measurement, or run only in a verified cookie-less mode.
GCM_001Call gtag('consent', 'default') with denied values before GTM or GA4 loads, so the initial consent state is explicit.
GCM_009Affected: Google Analytics 4, LinkedIn Insight, Google Universal Analytics
The affected vendors set an identifier or sent measurement that is not verifiably cookie-less before the visitor chose. Load them only after consent, or configure a documented cookie-less mode that sends no identifiers.
GCM_012Affected: Gemius
No identifier was observed, but the visitor's IP address and page context still reached a third party before consent. To be compliant under this check, load the vendor only after consent.