End of Summer Savings · Get 10% off any legal service · Ends 31 August

Claim offer

How to Run a Cookie Compliance Audit for a UK Business Website

Alex Solo
byAlex Solo11 min read

Plenty of UK businesses think their cookie banner is “done” because a website plugin is live and visitors can click accept. That is often where the problems start. Common mistakes include dropping analytics cookies before consent, using vague banner wording, and listing cookies in a policy that does not match what the site actually sets. Another frequent issue is forgetting about third party tools, such as chat widgets, embedded videos, ad pixels and customer behaviour tracking.

A cookie compliance audit helps you work out what your website is really doing, what consent you actually need, and what needs fixing before complaints or regulatory attention land on your desk. If you run an ecommerce store, SaaS platform, lead generation site or service business in the UK, this guide explains how to review your cookies, banner, policy, internal processes and supplier setup in a practical way.

Overview

A cookie compliance audit is a structured review of the tracking technologies on your website and how you obtain consent for them. For most UK businesses, the main legal focus is whether non-essential cookies are set only after valid consent, and whether users are told clearly what those cookies do.

  • Identify every cookie and similar tracking technology used on your website and app
  • Separate essential cookies from analytics, advertising, personalisation and social media trackers
  • Check whether non-essential cookies are blocked until users actively opt in
  • Review banner wording, consent choices and whether users can reject as easily as accept
  • Compare your cookie policy and privacy notice against what your site actually does
  • Review third party tools, consent mode settings and supplier arrangements
  • Keep records of your audit, decisions, updates and testing

A cookie compliance audit means checking both the law and the technology, not just rewriting a policy page. It is part privacy compliance exercise, part website review, and part risk management.

In the UK, cookies and similar tracking technologies are mainly regulated through rules that sit alongside data protection law. In simple terms, if your website stores information on a user’s device, or accesses information already stored there, you usually need clear information and consent unless the cookie is strictly necessary for providing the service the user has asked for.

That distinction matters. A cookie used to keep items in a shopping basket may be essential. A cookie used to track visitor behaviour for analytics or advertising usually is not. The label in your software dashboard does not decide the legal position. You need to look at the function of the cookie in the real user journey.

For many businesses, the audit also overlaps with UK GDPR duties. If a cookie processes personal data, such as online identifiers, device IDs, IP-linked profiles or behavioural data, your privacy transparency and internal data governance matter as well. That means your cookie audit should connect with wider privacy work, including:

  • your privacy notice
  • records of data processing
  • third party processor arrangements
  • international data transfer checks where relevant
  • your customer terms if online tracking affects marketing, accounts or platform use

The legal problem is usually not the existence of cookies. The problem is how and when they are used.

This is where founders often get caught:

  • the website drops Google Analytics, Meta Pixel or ad cookies on page load before any user choice
  • the banner says “by continuing to browse, you agree” instead of asking for a clear opt in
  • the reject option is hidden, harder to use, or missing from the first layer
  • the cookie policy lists old tools that are no longer used, while missing new ones added by marketing or developers
  • embedded content, booking tools or chat plugins set cookies even though the main banner appears compliant
  • consent records are not kept, so the business cannot show what the user agreed to

Why this matters for startups and SMEs

Smaller businesses often rely on plug and play marketing tools, fast website builds and outsourced development. That makes cookie creep common. One new plugin can quietly add tracking you did not plan for.

If you are selling online, taking leads, running ads or using behavioural analytics before you spend money on setup or growth campaigns, the audit helps you avoid building your marketing around consent settings that are not legally sound. It also helps protect conversion data quality, because lawful consent design affects what data you can use.

A cookie audit will not replace wider legal basics for a digital business, but it sits alongside them. Depending on your setup, you may also need to review privacy documentation, customer terms, software supplier contracts, trade mark protection for your brand, and your business structure if you are still deciding how to operate in the UK market.

When This Issue Comes Up

A cookie compliance audit usually becomes necessary when your website changes, your marketing stack grows, or somebody realises the banner has been left on default settings. It should not be a one-off exercise done only after a complaint.

Several founder moments tend to trigger the need for an audit.

Before you launch a new website or app

A pre-launch review is the best time to do it. Once your site is live, bad consent settings may already be collecting data in a way that creates risk.

Before you launch online, check:

  • whether the site sets any non-essential cookies on arrival
  • whether your consent management platform is correctly configured
  • whether your cookie categories match the actual tools installed
  • whether your policy text reflects the final build, not an old template

When marketing adds new tools

New ad tech is a common source of non-compliance. Paid media agencies, CRM consultants and growth teams often install scripts quickly because they want attribution data.

That becomes a legal issue when a new tag goes live before anyone checks:

  • what data it collects
  • whether it needs opt in consent
  • whether it sends data to another provider
  • whether the privacy notice and cookie policy need updating

When your business starts selling online

Ecommerce websites often use more tracking than service websites. Basket tools, recommendation engines, remarketing tags, payment widgets and fraud detection tools all need review.

If you are setting up to start a business in the UK and plan to sell online, cookie compliance should sit alongside other website legal requirements, including:

  • business registration and business structure decisions
  • website terms and conditions
  • privacy notice
  • consumer law compliance
  • brand protection and trade mark checks

When you get a complaint, regulator query or customer challenge

If a user says your site tracks them before consent, treat that as a prompt to investigate quickly. The same applies if you receive supplier alerts, developer warnings or internal questions from your team.

Do not assume your cookie platform provider is responsible for legal accuracy. The tool helps implement choices, but your business remains responsible for how the site works.

During funding, due diligence or supplier negotiations

Data privacy questions often come up before you sign a major customer contract, investment documents or an acquisition deal. Buyers and counterparties may ask how you handle consent, analytics, data retention and third party tracking.

A documented cookie compliance audit can help you answer those questions with more confidence, especially if your product depends on online user data.

Practical Steps And Common Mistakes

The most effective audit starts with evidence, not assumptions. You need to know what technologies are firing on the site before you decide what legal labels to apply.

Start with a technical scan of your website, then compare it with what your developers, agencies and internal teams say is installed. Look across public pages, account areas, checkout flows, landing pages and embedded tools.

Your inventory should capture:

  • cookie name or tracker identifier
  • provider
  • purpose
  • duration
  • whether it is first party or third party
  • whether it involves personal data
  • whether it loads before or after consent
  • which page or script triggers it

A common mistake is reviewing only the homepage. Many cookies load later in the user journey, especially at checkout, on booking pages, or when a user opens a chat function.

2. Decide which cookies are strictly necessary

The legal test is functional, not convenient. A cookie is not “essential” just because it helps your business understand users better or improves campaign performance.

Strictly necessary cookies are usually limited to tools required to deliver a service the user has actively requested. Examples may include:

  • session management for logged in users
  • shopping basket memory
  • security and fraud prevention tools that are genuinely necessary
  • load balancing where needed to provide the service

Analytics, advertising, personalisation and many A/B testing tools generally need consent. Businesses often stretch the essential category too far, especially where marketing teams are keen to preserve data collection.

This is often the most important part of the audit. A banner can look polished while the site still sets non-essential cookies immediately.

Test your site in a clean browser session and check what happens:

  • before any click
  • after rejecting non-essential cookies
  • after accepting only some categories
  • after changing preferences later

Look carefully at tag managers, embedded media, social sharing plugins and consent mode settings. One badly configured tag manager can undermine the whole setup.

A common mistake is assuming “default denied” settings are working without verification. Another is treating scripts as blocked when they still pass identifiers or pings that need review.

4. Review the banner wording and user choices

Valid consent needs to be clear, informed and freely given. The user should take a real positive action to accept non-essential cookies.

Your banner should usually avoid wording that implies consent through silence or continued browsing. It should also avoid design tricks that push users toward acceptance.

Check whether your first layer gives users a fair and visible choice, including:

  • an accept option
  • a reject option for non-essential cookies
  • a way to manage preferences by category
  • plain language about why cookies are used

This is where many SMEs slip. They use default templates with a bright “accept all” button and a hidden settings link, or they bury the real detail several clicks away.

Your cookie policy should reflect the website as it exists today. If your policy is copied from a template or has not been updated since a redesign, it may be inaccurate.

Check that the policy explains:

  • what cookies and similar technologies you use
  • the purpose of each category
  • who sets them
  • how long they last
  • how users can manage preferences
  • how the policy connects with your broader privacy notice

A common mistake is overloading the policy with technical labels that mean little to ordinary users. Another is using descriptions so broad that they do not really tell the user what happens to their data.

6. Review third party suppliers and embedded services

Third party tools are often the hidden problem. A video player, booking widget, chat service, payment platform or affiliate tool may set cookies through code you did not directly write.

Check your agreements and supplier information where relevant. You want to understand:

  • what the provider collects
  • whether it acts on your instructions or for its own purposes
  • whether data is shared internationally
  • whether any settings can reduce tracking until consent is given

This review should also feed into your wider contracts and privacy compliance work. If a provider processes personal data for your business, you may need suitable data processing clauses in place.

7. Keep evidence of the audit and your decisions

Documentation matters. If somebody later asks what your business did to address cookie compliance, you should be able to show a dated review process.

Keep records such as:

  • cookie scans and screenshots
  • testing results
  • internal decisions on essential versus non-essential cookies
  • updates made to your consent platform
  • policy revisions
  • developer or agency instructions

Many businesses fix the banner but keep no record of why changes were made. That makes future reviews harder and weakens internal accountability.

The audit should become part of your website governance, not a forgotten one-off. New landing pages, plugins, analytics tools and campaign tags should trigger a privacy check before deployment.

A practical internal process can include:

  • approval steps before new scripts go live
  • a named owner for the cookie inventory
  • scheduled retesting after website updates
  • coordination between marketing, developers and legal or compliance support

Without that process, websites drift out of compliance very quickly.

Common mistakes businesses make

Most cookie issues are operational rather than theoretical. The same patterns appear again and again.

  • relying on a plugin without checking how the site behaves
  • classifying analytics cookies as essential because the business values the data
  • forgetting mobile, subdomains, checkout pages or logged in areas
  • copying another company’s cookie policy
  • ignoring embedded third party services
  • failing to update notices after a redesign or marketing stack change
  • treating cookie compliance as separate from broader privacy, contracts and governance

FAQs

No. Strictly necessary cookies may not require consent, but many analytics, advertising and personalisation cookies do. The key question is whether the cookie is genuinely necessary to provide the service the user requested.

No. A banner is only one part of compliance. Your website also needs correct technical blocking, accurate cookie information, aligned privacy wording and a process for managing future changes.

Often, standard analytics cookies will require consent if they are not strictly necessary. The answer can depend on how the tool is configured and what data it collects, so it is worth checking carefully rather than assuming analytics is low risk.

You should review cookies whenever you redesign the site, add new tracking tools, change agencies or launch new online features. Even without major changes, periodic checks are sensible because websites and integrations change over time.

Does this only matter for ecommerce websites?

No. Service businesses, SaaS providers, publishers, lead generation sites and brochure websites can all use non-essential cookies. If your site has analytics, marketing tags, social plugins, embedded media or user accounts, you may need an audit.

Key Takeaways

  • A cookie compliance audit checks what tracking your website actually uses, whether consent is needed, and whether your banner and policies match the reality.
  • For UK businesses, the main risk is allowing non-essential cookies to load before valid user consent.
  • You should review not only obvious cookies, but also third party widgets, embedded content, tag managers and scripts added by marketing or developers.
  • Your cookie policy and privacy notice need to be accurate, current and written in clear language.
  • Documentation and ongoing change control matter, especially before you sign supplier deals, launch online campaigns or spend money on setup.
  • Cookie compliance works best when it is tied into wider legal basics such as privacy governance, customer terms and supplier contracts.

If your business is dealing with cookie compliance audit and wants help with privacy notices, website terms, data processing arrangements, consent wording, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.

Official Sources to Check

Rules and regulator guidance can change. Check the current official material most relevant to this issue before relying on the article:

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.