1 finding · 4 warnings · 4 checks passed
Tools
fancnbcglobal50229149d3cfCNBC Phoenix webbbaaa56c88331088520724430400839749167196516018830P3C0162C5-40AE-4849-8BD6-72C843E9563F1140838234280700879Violations
GCM_002Do not write analytics or advertising cookies until the visitor has made a consent choice. Load GTM/GA4 tags behind a denied consent default and let the CMP's update unblock them.
GCM_008Affected: broken
Call gtag('consent', 'update') immediately after the visitor's choice, with the correct values for both accept and reject. Do not rely on a page reload: it creates duplicate pageviews and breaks session attribution.
GCM_010Affected: Adobe Experience Platform, Amazon Ads, Google Publisher Ads, Piano, Amplitude, comScore, Inc., DoubleVerify
After a rejection the listed tools must stop storing visitor IDs and sending measurement, or run only in a verified cookie-less mode.
GCM_001Call gtag('consent', 'default') with denied values before GTM or GA4 loads, so the initial consent state is explicit.
GCM_003Make both the accept and the reject button update the consent state through the GTM Consent API or gtag('consent', 'update').
GCM_009Affected: Adobe Experience Platform, Amazon Ads, Google Ads, Google Publisher Ads, Nielsen, Piano, Amplitude, DoubleVerify, Expert System, SpA, mParticle, Parse.ly, Sailthru, SecuredVisit, TV Squared
The listed tools stored a visitor ID or sent measurement before the visitor chose, without a verified cookie-less mode. Load them only after consent, or configure a documented cookie-less mode that sends no IDs.
GCM_012Affected: Microsoft Advertising (UET)
No cookie or visitor ID was stored, but the visitor's IP address and page address — personal data — reached the tool without consent (before the choice or after a rejection). To be Compliant under this check, load the tool only after consent.