An anonymized sample of a consent-focused beacon audit: which trackers fire before consent is given, and what the report flags.
Illustrative sample. The company, domain, and every identifier below are fictional and anonymized — this is what a consent-focused audit looks like, not a real site's data. Plain-language orientation, not legal advice.
Northwind Traders, a fictional mid-size B2B software company at shop.northwind.example. Consent banner present (fictional CMP "ConsentCo"). Method: static scan plus a first-visit browser render with no consent given — any marketing tracker firing in that state is firing pre-consent.
| Tracker | Embedded via | Fires pre-consent? | Finding |
|---|---|---|---|
| ConsentCo CMP | Direct script | Yes (required) | Present on all pages — good |
Meta Pixel (100000000000001) | Hardcoded in base template | Yes | Pre-consent firing — bypasses the CMP |
| Google Analytics 4 | Via GTM, consent-gated | No | Correctly held until consent |
| LinkedIn Insight Tag | Via GTM, consent-gated | No | Correctly held until consent |
Hotjar (3000001) | Hardcoded on pricing/signup | Yes | Pre-consent firing — session replay before consent |
| reCAPTCHA | Direct, form pages | Yes | Security use — documented exception |
Re-render after the fix: zero marketing trackers fire pre-consent. GDPR & CCPA consent basics · what audits can and can't verify.