Book a Demo

Compliance report

Know where your consent setup needs work.

Review your consent setup by jurisdiction, separate urgent issues from warnings and passed checks, and turn each finding into a practical next step.

cookiechimp.com/compliance-report

Example report

Regional Compliance Report

Simulated findings for four commonly reviewed jurisdictions.

Passing Checks
175
of 190
Needs Attention
14
of 37
Total Jurisdictions
37
Compliance Rate
92%

EU (GDPR + ePrivacy Directive Art. 5(3))

EU/EEA Opt-in

Banner displayed to users: European visitors banner
2 Issues

ePrivacy governs cookies; GDPR governs personal data.

Issues to resolve

  • Missing: Granular purpose and service-level consent controls
    Set 'Preferences control level' to 'Category and services' in Banner Designer preferences modal settings to allow users to consent to individual services
  • Missing: Equally prominent accept and reject buttons
    Enable 'Equal weight buttons' option in Banner Designer appearance settings
  • Obtains prior consent before placing non-essential cookies
  • Provides clear mechanism to accept all cookies
  • Provides clear mechanism to reject non-essential cookies
  • Provides accessible link to privacy policy
  • Consent valid for 6 months (within 6 month maximum)
  • Granular purpose and service-level consent controls
  • Equally prominent accept and reject buttons
Prior consent required
Purpose granularity
Equal prominence buttons
No pre-checked boxes
Dark patterns prohibited
Proof of consent required
Local storage covered
Default state: Off (Non-Essential Cookies)
Cookie walls: Restricted
Consent lifespan: 6 months
First Layer (Banner)
  • Concise Purpose Summary
  • Accept All Button
  • Reject All Button Or Link
  • Manage Preferences Button
  • Link Privacy Policy
  • Controller Identity
Second Layer (Preferences Modal)
  • Granular Purpose Toggles
  • Vendor List If Applicable
  • Retention Periods If Known
  • Third Country Transfers Notice If Applicable
  • Legal Basis Per Purpose If Applicable
Withdrawal mechanism:
Persistent Floating Icon Or Footer Link
Children's Privacy

Parental consent required for children under age 13-16 (member-state dependent) when processing personal data including tracking cookies. Sites targeting children must obtain verifiable parental consent for non-essential cookies.

Sensitive Data

Consent typically required for processing sensitive data; avoid inferring without a lawful basis.

Required Consent Fields
  • Timestamp ISO
  • User Choices By Purpose
  • Policy Version
  • Jurisdiction Detected
  • Consent UI Version
Retention period: 18 months
Re-consent trigger:
New Purpose Or Material Change

EDPB 2022 guidance on dark patterns: Cookie banners must not have misleading button hierarchy, confusing language, or manipulative design. "Reject All" button required on first layer with equal prominence to "Accept All". Cookie walls are non-compliant unless equivalent service offered without tracking. Information must be provided in user's language (translation required). French CNIL and other DPAs actively enforce against deceptive cookie interfaces.

  • Strictly Necessary
  • Security Fraud Prevention
  • Load Balancing

UK (UK GDPR + PECR)

United Kingdom Opt-in

Banner displayed to users: European visitors banner
1 Warning

PECR governs cookies; UK GDPR governs personal data.

Issues to resolve

  • Missing: Consent records retained for at least 18 months for audit purposes
    Increase 'Consent log retention' in Account Settings or export consent logs for external storage
  • Obtains prior consent before placing non-essential cookies
  • Provides granular consent controls at category and service level
  • Provides clear mechanism to accept all cookies
  • Provides clear mechanism to reject non-essential cookies
  • Provides accessible link to privacy policy
  • Provides equally prominent accept and reject options
  • Consent records retained for at least 18 months for audit purposes
Prior consent required
Purpose granularity
Equal prominence buttons
No pre-checked boxes
Dark patterns prohibited
Proof of consent required
Local storage covered
Default state: Off (Non-Essential Cookies)
Cookie walls: Restricted
Consent lifespan: 6 months
First Layer (Banner)
  • Concise Purpose Summary
  • Accept All Button
  • Reject All Button Or Link
  • Manage Preferences Button
  • Link Privacy Policy
Second Layer (Preferences Modal)
  • Granular Purpose Toggles
  • Vendor List If Applicable
  • Retention Periods If Known
Withdrawal mechanism:
Persistent Floating Icon Or Footer Link
Children's Privacy

Age Appropriate Design Code (Children's Code) requires heightened protections for services likely to be accessed by children. No behavioral advertising cookies without clear necessity. Parental consent required for under-13. High privacy settings by default for child users.

Sensitive Data

Consent or other lawful basis as applicable

Required Consent Fields
  • Timestamp ISO
  • User Choices By Purpose
  • Policy Version
  • Jurisdiction Detected
Retention period: 18 months
Re-consent trigger:
New Purpose Or Material Change

As of Data (Use and Access) Act 2025, first-party analytics cookies for site improvement may be exempt from consent. However, third-party tracking and advertising cookies still require opt-in consent. "Reject All" button must be equally prominent to "Accept All". Higher fines now apply: up to £17.5M or 4% global turnover for PECR violations.

  • Strictly Necessary
  • Security Fraud Prevention
  • Load Balancing
  • First Party Analytics For Site Improvement

California (CPRA/CCPA Regs)

United States - California Opt-out GPC

Banner displayed to users: North America banner
1 Issue

Covers 'sharing' for cross-context behavioral advertising.

Issues to resolve

  • Missing: Global Privacy Control (GPC) signal recognition
    Enable GPC integration in Integrations settings to automatically honor opt-out signals
  • Provides a clear mechanism to opt out of non-essential cookies
  • Provides ability to manage granular cookie preferences
  • Provides accessible link to privacy policy
  • Keeps non-essential cookies off when a visitor opts out
  • Global Privacy Control (GPC) signal recognition
Prior consent required
Purpose granularity
Equal prominence buttons
No pre-checked boxes
Dark patterns prohibited
Proof of consent required
Local storage covered
Default state: Mixed
Cookie walls: Discouraged
First Layer (Banner)
  • Notice Of Collection Link
  • Link Do Not Sell Share
  • Link Limit Use of Sensitive PI If Applicable
  • Manage Preferences Button
Second Layer (Preferences Modal)
  • Category Level Disclosures
  • Sensitive Data Limit Mechanism If Applicable
Withdrawal mechanism:
Do Not Sell Share Link And Preference Center
Children's Privacy

California Age-Appropriate Design Code Act (2024) requires businesses with online services likely accessed by children to: configure privacy settings to highest level by default for child users, provide prominent privacy information, and not use personal information for purposes that present heightened risk without safeguards. Includes restrictions on profiling and behavioral advertising to minors.

Sensitive Data

Right to limit use/disclosure of sensitive PI.

Required Consent Fields
  • Timestamp ISO
  • Opt Out Status
  • Policy Version
  • Jurisdiction Detected
  • Gpc Signal Status
Re-consent trigger:
Not Required Generally

California requires businesses that 'sell' or 'share' personal information (which includes most advertising and many analytics cookies used for cross-context behavioral advertising) to automatically honor opt-out preference signals such as Global Privacy Control (GPC). This is mandatory under Cal. Code Regs. tit. 11 § 7025 — not optional. Provide a 'Do Not Sell or Share My Personal Information' link and, where sensitive personal information is used beyond the purposes permitted by § 7027, a 'Limit the Use of My Sensitive Personal Information' link; these may be combined into a single 'Your Privacy Choices' link with the opt-out icon. A notice at collection must be presented at or before the point of collection. Opt-out methods must be symmetrical and free of dark patterns — opting out must be at least as easy as opting in. The CPPA and California Attorney General actively enforce: the Sephora settlement ($1.2M, 2022) penalized failure to honor GPC and to disclose sales, and 2025 CPPA enforcement actions targeted non-compliant opt-out flows and excessive data collection in opt-out webforms.

Canada (PIPEDA - Federal)

Canada (excluding Quebec) Opt-out

Banner displayed to users: North America banner
Compliant

Federal and substantially similar private-sector privacy laws allow opt-out consent for online behavioral advertising where OPC conditions are met; express opt-in remains required for sensitive, unexpected, or higher-risk processing.

  • Provides granular consent controls at category and service level
  • Provides a clear mechanism to opt out of non-essential cookies
  • Provides ability to manage granular cookie preferences
  • Provides accessible link to privacy policy
  • Consent valid for 12 months (within 12 month maximum)
  • Retains consent records for 18 months for audit purposes (meets 18 month requirement)
Prior consent required
Purpose granularity
Equal prominence buttons
No pre-checked boxes
Dark patterns prohibited
Proof of consent required
Local storage covered
Default state: Mixed
Cookie walls: Discouraged
Consent lifespan: 12 months
First Layer (Banner)
  • Concise Purpose Summary
  • Manage Preferences Button
  • Link Privacy Policy
  • Opt Out Mechanism
Second Layer (Preferences Modal)
  • Granular Purpose Toggles
  • Retention Periods If Known
  • Third Party Disclosures If Applicable
Withdrawal mechanism:
Persistent Floating Icon Or Footer Link
Children's Privacy

Enhanced consent mechanisms for minors.

Sensitive Data

Explicit consent required for sensitive personal information.

Required Consent Fields
  • Timestamp ISO
  • Opt Out Status
  • User Choices By Purpose
  • Policy Version
  • Jurisdiction Detected
Retention period: 18 months
Re-consent trigger:
Material Change Or New Purpose

For Canada outside Quebec, model the default banner as opt-out when online behavioral advertising is limited to non-sensitive data, purposes are clearly explained at or before collection, the opt-out is easy, immediate, and persistent, and users are told who is involved. Keep an opt-in flow for sensitive data, unexpected tracking, location tracking, children, or processing that creates meaningful residual risk of significant harm.

Example Regional Compliance Report with simulated findings for GDPR, UK GDPR, CCPA/CPRA, and PIPEDA.

Regional overview

Review every relevant jurisdiction

  • Review each jurisdiction
  • Use one consistent report structure
  • See overall status at a glance

Prioritised findings

Prioritise the findings that matter

  • Start with urgent issues
  • Review contextual warnings
  • Keep passed checks visible

Remediation

Turn findings into fixes

  • Follow clear next-step guidance
  • Apply targeted regional changes
  • Review again after each change
Recurring monitoring

Stay current as your website and regulations change.

CookieChimp runs scheduled scans, refreshes your Compliance Report, and alerts your team when tracking or requirements need attention.

Set the schedule

Choose weekly or monthly monitoring.

Step 01

Scan for website changes

Check tracking before and after consent.

Step 02

Refresh compliance findings

Keep the Compliance Report aligned with regulatory changes.

Step 03

Get alerts and take action

Know what changed, resolve issues, and confirm fixes.

Step 04

Explore the product

See how the pieces work together.

Start with evidence, turn it into the right consent experience, then connect and improve the rest of your stack.

01 Discover

Know what's running

Find the services collecting data and turn them into a governed vendor inventory.

02 Configure

Apply the right rules

Use regional guidance to deliver the right consent experience to every visitor.

03 Improve

Connect and measure

Keep the rest of your stack aligned and understand how consent performs.

All Our Powerful Features

We offer a wide range of features to help you comply with privacy regulations and improve your user experience.

Included in all plans
Paid plans only
Banner Customization
  • GDPR, CCPA/CPRA, VCDPA, LGPD & more
  • Ready-to-use banner templates
  • Opt-in banner templates
  • Opt-out banner templates
  • Popup layout / Force consent
  • Custom HTML, CSS, JavaScript banners
  • Custom CSS
  • Edit content, colors & branding
  • Multilingual support & auto-translation
  • Explicit & implicit consent
  • Unlimited banners
  • Install on multiple domains
  • Custom logo & branding
  • Live banner preview
Consent Record Keeping
  • Consent records & audit trail
  • Consent export & API
  • Google Consent Mode
  • Global Privacy Control
  • Do Not Track (DNT)
  • Cookie declaration
Auto Vendor Management
  • Auto vendor & storage item scanner
  • Automatic categorization & autofill
  • Vendor & storage item blocking
  • Weekly scanning schedule
  • Monthly scanning schedule
User Experience
  • Unlimited webpages
  • Granular consent control
  • User consent expiration
  • Renew user consents
  • Cross-domain consent sharing
  • Cross-device consent sharing
  • Auto translation
  • Geotargeting
  • Unlimited geolocation banner rules
  • Install on multiple domains
  • Iframe blocking
  • Target specific regions
  • Privacy policy embeddings
Analytics & Reports
  • Opt-in & opt-out statistics
  • Regional compliance report
  • Consent log retention
  • Export all data
  • API access to all data
Integrations
  • WordPress plugin
  • Google Tag Manager
  • Microsoft UET consent mode
  • Custom integration services
Account & Security
  • Two-factor authentication
  • Organisation groups
  • Multi-user access
Support
  • Comprehensive knowledge base
  • Email & live chat support
  • Scheduled call support
  • Dedicated account manager
  • Implementation & data migration support