Each item in your Compliance Check is tied directly to real regulatory requirements and enforcement trends. These checks are designed to protect your business from regulatory risk, consumer complaints, and potential legal exposure. Below is a summary of each check, why it runs, and what it protects you from.
Why we check this: We ensure your site displays a cookie banner to inform users before data is collected.
What this protects you from: If users are not notified before tracking begins, it can result in violations of "notice at collection" requirements and claims related to unauthorized data collection. The banner ensures users are informed before any tracking occurs, which is a foundational compliance requirement.
Why we check this: We review whether your banner provides users with a clear and equal ability to accept or decline tracking.
What this protects you from: If it is easier to accept than to decline, this can be characterized as a deceptive design pattern, which may invite regulatory scrutiny, consumer protection claims, and increased litigation risk. Providing equal choice ensures users can make real, informed decisions about their data — a growing area of regulatory focus.
Why we check this: We verify that your website includes a privacy policy that is accessible to users.
What this protects you from: Without a visible privacy policy, users are not informed about how their data is collected or used. This can lead to regulatory violations, consumer complaints, and increased legal exposure. A privacy policy is the foundation of transparency and a required element of compliance.
Why we check this: We confirm that your privacy policy has been updated within the last 12 months.
What this protects you from: Outdated policies can misrepresent your current data practices. If your data usage has changed or your disclosures are no longer accurate, this creates risk of claims related to misleading or incomplete disclosures. Keeping your policy current is a key part of maintaining accurate and trustworthy transparency with users.
Why we check this: We confirm that users have a clear way to exercise their privacy rights, such as the right to access, delete, or opt out of the sale or sharing of their personal information.
What this protects you from: If users cannot easily submit privacy requests, it can result in noncompliance with applicable privacy laws, missed or delayed responses to user requests, and escalations or complaints. This check ensures your business can properly receive and respond to user rights requests as required.
Why we check this: We verify that your site detects and honors browser-level opt-out signals such as GPC.
What this protects you from: GPC is treated as a legally valid opt-out request under laws including the CPRA. Ignoring it can result in noncompliance, enforcement risk, and claims that user preferences are being disregarded. Supporting GPC ensures you are honoring user choices automatically and at scale, without requiring users to submit individual opt-out requests.
Why we check this: After simulating a visitor selecting "Reject All" in your consent banner, we continue monitoring your site to see whether any non-essential trackers keep running anyway.
What this protects you from: Privacy laws like the CPRA require that when a visitor opts out, that choice is actually honored — not just acknowledged by the banner. If trackers continue to fire after a visitor rejects consent, it can result in noncompliance with opt-out requirements, consumer complaints, and claims that your site's privacy practices don't match what your banner and privacy policy promise. This check confirms that "Reject All" does what it says.
When we run the Reject All Check, we simulate a visitor clicking "Reject All" on your consent banner, then analyze what happens afterward. Here's what each result means:
✅ Pass
Your site is working as expected. After a visitor rejects consent, no non-essential trackers are loading. Your CMP is correctly blocking third-party services when visitors opt out.
❌ Fail
Non-essential trackers are still loading after a visitor rejects consent. This means your CMP isn't fully configured to honor the reject-all choice — these trackers should be blocked but aren't. We recommend reviewing your CMP settings for the flagged services.
⚠️ Warning
We detected trackers loading after reject-all that we couldn't automatically classify as essential or non-essential. These require your manual review to determine whether they should be blocked. They may be legitimate (e.g., security or infrastructure services) or they may need to be added to your CMP's block list.
Why we check this: We monitor your site before any consent banner interaction and flag any non-essential requests. We break out these request into two groups: Trackers posing a known CIPA risk must not load before consent, and Trackers posing a known CIPA risk must not load before consent. The trackers with CIPA risk (e.g., Google Analytics, Meta Pixel) are ones cited in California Invasion of Privacy Act (CIPA) lawsuits.
What this protects you from: CIPA claims are built around the idea that tracking technology deployed before a visitor has consented amounts to unauthorized interception of their communications under California's two-party consent standard. Pre-consent tracking from known litigation-pattern trackers is one of the most common fact patterns cited in these suits. This check surfaces that exposure flags risk so you can address it.
Pass:
What it means: No tracking technologies were detected prior to visitor consent.
Details: Your site successfully prevents all cookies, scripts, and trackers from firing on the initial page load until the visitor actively makes a consent selection.
Warning (Passed with Warnings):
What it means: The check passed overall, but non-essential trackers with no confirmed CIPA risk were present before consent and may require consent.
Details: This outcome acts as a "passed with caveats" status. While these trackers do not pose a confirmed CIPA violation risk, they were detected prior to a visitor making a choice. We recommend reviewing these items to determine if consent should be required or if they need to be reclassified in your implementation.
Fail:
What it means: Non-essential tracking technologies with known CIPA risk loaded prior to consent being given.
Details: The scan found definitive evidence that trackers fired on the first page load before the visitor made a consent choice. Because unconsented non-essential tracking is a primary trigger for CIPA litigation, these findings require immediate attention and remediation.
Trackers flagged by the CIPA Check and Reject All Check are classified — Essential, Analytics, Marketing, and Personalization — using Osano's own database of trackers, alongside Disconnect.me's. As with all scan results, these labels reflect Osano's default classification and should be cross-referenced against how each tracker is actually configured in your own implementation. Please note that these labels do not necessarily reflect the tracker's current classification in your live implementation.
Results are available in your App Dashboard and as an exportable list, so you can see exactly what fired after rejection and address it directly.