Site Map & Tracker Audit Digital Interactif Sign in with Google
10 of 10 free runs left Sign in for 50 free runs
Home › Guides › GDPR & CCPA Tracker Consent Basics

GDPR & CCPA tracker consent basics

What GDPR and CCPA require before marketing trackers fire, what valid consent looks like technically, and how a beacon audit supports compliance.

Plain-language orientation for marketers and site owners — not legal advice. Privacy law is jurisdiction- and fact-specific; involve counsel for decisions.

The core rule

Under the EU's GDPR (and the UK GDPR), non-essential trackers — marketing pixels, advertising cookies, most analytics — generally need the visitor's prior consent before they fire. Under California's CCPA/CPRA, the model is different: businesses must honor the consumer's right to opt out of the sale or sharing of personal information (including via the Global Privacy Control signal), and provide clear notice. Both regimes punish the same failure mode: trackers firing when the law says they shouldn't.

GDPR: prior, informed, revocable consent

CCPA/CPRA: opt-out and notice

What valid consent looks like technically

Consent must gate execution, not just visibility. The banner can render while tags stay blocked; what matters is that no marketing or analytics script fires, no tracking cookie is set, and no beacon request leaves the browser until the visitor's choice permits it. The critical failure mode is trackers firing before consent: a pixel hardcoded in the page template loads on every visit regardless of the banner, and tag managers whose tags aren't bound to consent state do the same.

How a beacon audit supports compliance

More on consent banners and beacon audits.

Typical gaps an audit surfaces

Found gaps? Work the full audit method or clean up the dead pixels.

Run a free audit on your own site.
Enumerate every URL, audit each page, and scan for 40+ marketing trackers — no sign-up needed to try.
Audit my site