Practical guides

Test tracking consent in real website journeys

A visible banner does not establish that the website applies people’s choices. Acceptance testing examines actual loading and the tasks available in each state. This operational method accompanies an assessment of rules applicable to the site; it does not provide certification.

Go to the method

Review diagram: initial state, choice, verification and evidence.
Editorial method diagram without customer data.

Inventory uses before cookies

Begin with actual pages and actions: watching a video, using a map, submitting enquiries, subscribing or ordering. Identify scripts, pixels, embeds and contacted services. For each, record purpose, owner, activation point and configuration. An external request alone does not establish tracking; it identifies an element to examine.

The French CNIL distinguishes consent-dependent trackers from potentially exempt uses. Classification depends on actual purpose and conditions. Do not classify an entire service as exempt based only on its provider name. Validate purposes and keep configuration records supporting the decision. Other jurisdictions require their own applicable assessment.

Build four test states

Prepare a fresh session without prior choices, then test rejection, acceptance by purpose where offered, and withdrawal of an earlier choice. Record page, browser, time, action and result. Compare relevant network loading and storage in each state. Existing histories or preferences can invalidate a trial.

In the initial state, examine services requiring prior permission. After rejection, navigation and intended alternatives should remain usable. After acceptance, verify that activated services match the chosen purposes. After withdrawal, check subsequent loading and documented retention rules; withdrawal does not automatically establish deletion of all historical data.

Compare interface and behaviour

The CNIL’s official FAQ discusses ways to express or decline choices in its French context. Record action count, clear labels, access to settings and understanding of purpose. Test keyboard operation, zoom and narrow screens.

Compare public information, the service inventory and live configuration. A removed provider still activated by an older tag is a defect. A save button that closes the interface without applying choices needs behavioural testing rather than another interface screenshot.

Preserve alternatives to external content

For maps, videos and widgets, describe what visitors can do when loading is unavailable. A text address or standalone explanation preserves essential information. A voluntary external link can help when its destination is clearly labelled. Do not replace a declined service with another third party creating the same issue.

Test unavailable JavaScript and content blocking when relevant to your audience. These trials reveal dependencies without establishing their legal classification. For forms, verify that error messages and useful contacts remain readable when external components are unavailable.

Keep review records and repeat after changes

Record each defect with consent state, steps, expected behaviour, observed result and required evidence. Avoid screenshots containing credentials, personal information or confidential parameters. Assign findings to the person responsible for the website or relevant service.

Repeat states after new tags, changed players, analytics changes or consent-manager work. Today’s verified setup can change on the next release. Use the acceptance log to record findings and status. The measurement guide helps examine which events are needed.

Content updated on October 2, 2026

Acceptance matrix to adapt to your project

These proposed checks use synthetic cases. Decide the required behaviour with the team, record the result and assign unresolved gaps before release.

Test cases, expected outcomes and useful evidence
CaseExpected outcomeEvidence to retain
Fresh session without a choice.Services requiring prior permission remain inactive before the required action.Relevant service inventory and loading observations.
Rejection followed by a video page.The choice is respected and a useful alternative remains available.Page, steps, state and screenshot without sensitive data.
Acceptance of a purpose followed by withdrawal.Subsequent loading follows the updated choice.Compare observations before and after withdrawal.

Frequently asked questions

Does every website need a consent banner?

It depends on actual trackers and uses under applicable rules. Inventory and classify components before choosing an interface. A website or external network request alone does not establish what requires permission.

Is testing rejection sufficient?

No. Include a fresh session, offered acceptance choices and withdrawal. Verify actual behaviour on pages and actions using third-party services, then repeat after changes.