Monitoring

Consent Studio Monitoring, the standing check on your consent implementation and weekly by default, opens your pages in a real browser and reports where the setup is not doing what you built it to do: a tag firing before the visitor’s answer arrives, a vendor whose integration is switched off, a cookie nobody has described.

  • Seven kinds of tracker
  • Runs unasked
  • Findings, not inventory

From €10 a month. No credit card, no per-visitor billing.

The Consent Studio dashboard listing the tracking technologies found on a site, with the vendor, platform and category of each.

The first person to notice is rarely you

Something new starts running on your site most months. The question is not whether it happens, it is who finds out and how long it takes to reach you.

  • The agency adds a tag and nothing needs approving
  • A vendor's script starts calling a second host
  • A visitor who notices closes the tab, or writes to a regulator
  • So the first message you get is a formal one

Tracker monitoring, the Consent Studio way

A site comes round again as soon as its last completed scan is a week old, with nothing to schedule. Each page is opened in a real browser, and what comes back is one digest of findings that each name the page they were found on.

  • It comes round every week, unasked

    A site is picked up again as soon as its last completed scan is a week old. Nothing is scheduled by hand and nothing has to be remembered, so the gap between something starting to run and somebody knowing about it is a week rather than however long it takes an outside party to write to you.

    • Recurring
    • Nothing to schedule
  • It sees what the page actually loaded

    Each page is opened in a real browser and every resource it pulls is recorded, plus a sweep of the images, frames, scripts and stylesheets in the markup. A script you approved that starts calling a second host after an update is a change in what the page loads, which is exactly what this measures.

    • Real browser
    • Every subresource
  • Findings, and each one names its page

    What comes back is a short list of things to decide about rather than an inventory of everything that exists, each finding naming the page that triggered it. They close themselves when the underlying problem goes away, and they arrive as one digest rather than an alert per page.

    • Not an inventory
    • Closes itself
    • One digest

What a scan actually does

It runs without being asked, reads your pages the way a visitor does, and only tells you about things that need a decision.

  1. It comes round on its own

    A site is picked up again as soon as its last completed scan is a week old. Nothing is scheduled by hand and nothing has to be remembered, which matters because the tag that gets added without telling anyone is the whole reason this product exists.

  2. It loads the page, it does not guess

    Each page is opened in a real browser and every resource it pulls is recorded, plus a sweep of the images, frames, scripts and stylesheets in the markup. A tag that only fires after a click on a cookie banner is a tag that a static source scan never sees.

  3. It refuses to trip over itself

    A scan already running is never doubled up, and a site is left alone for a few hours after any attempt. That is why a busy week does not produce four half-finished scans and four contradictory reports.

  4. Findings close themselves when you fix them

    Each finding names the page that triggered it and disappears once the underlying problem is gone, so the list is what is wrong now rather than a log of everything that ever was. What is left arrives as one digest rather than an alert per page.

Seven places a tracker can hide

Cookies are the only ones anybody checks by hand, and they are one of seven. A site can be storing an identifier in five other ways and firing beacons that store nothing at all.

  • Storage that survives the visit

    Cookies are the familiar one. Local storage, IndexedDB and cache storage do the same job with none of the visibility, and nothing in a browser tells a site owner they are being written. All four are read on every scan and listed by name.

    • Cookie
    • Local storage
    • IndexedDB
    • Cache storage
  • Storage that lasts one tab

    Session storage clears when the tab closes, which is exactly why it gets overlooked. It is still an identifier written to a visitor device without an answer, and a scan that stops at cookies never sees it.

    • Session storage
  • Things that leave no trace at all

    A tracking pixel stores nothing and a service worker sits between the page and the network. Neither shows up in a cookie inspector, so both are detected from what the page actually loaded rather than from what it stored.

    • Tracking pixel
    • Service worker

A scanner that cries wolf is worse than none

The list of things a page loads is mostly your own site. Something has to decide which of them are actually trackers, and getting that wrong has a cost that lands on you.

  • We got this wrong, and fixed the cause

    Matching on loose keywords once declared a customer stylesheet, two font files and an application script to be tracking pixels, because their hostname happened to contain the word analytics. Hosts are now matched on label boundaries, so a rule for one domain can never reach a different one that merely reads alike.

  • A false positive is a credibility problem

    Anything flagged here appears on your public cookie declaration and inside your banner, in a red badge. Your own fonts described to your own visitors as tracking is not a cosmetic defect, which is why the rules are one file with reasons attached rather than a carve-out per incident.

  • Missing one is caught somewhere else

    Anything that writes a cookie, storage or a worker is caught by those detectors, and every third-party script is recorded on its own. Pixel detection only has to catch beacons that leave no other trace, so it can afford to be strict rather than eager.

How Monitoring stands out

See how Monitoring compares with a standalone cookie scanner, row by row.

Monitoring compared with Standalone cookie scanners
FeatureMonitoringStandalone cookie scanners
What it is checked against
It reads your banner setup and names what is off.
A list of findings, with nothing to check them against.
What a finding tells you
AI recommendations name the error and the fix.
A finding you have to interpret yourself.
More than one site
Every domain in one dashboard, crawled separately.
One site at a time, one report each.
How it reaches you
Runs unasked, one digest, and says what to improve.
A report you have to remember to run.

What it finds, and what it tells you

Not a list of what exists on your site. A list of what is wrong with it, each one naming the page it came from.

  • Consent Mode firing too late

    Google Consent Mode has to initialise before any tag runs. Set too late and scripts fire without a proper answer, which costs you both the compliance position and the accuracy of the measurement you were trying to protect.

    • Load order
  • A vendor running with its integration off

    Facebook code on the page while the Meta Pixel integration is switched off in Consent Studio means the consent answer never reaches it. The same check covers Shopify, WordPress and Webflow.

    • Meta
    • Shopify
    • WordPress
    • Webflow
  • Two banners writing conflicting records

    A Wix site showing both our banner and Wix's own has two things writing consent state to the same API, which produces records that disagree with each other. The fix is one setting, and the finding says which.

    • Wix
  • Cookies with nothing written about them

    A cookie declaration is only useful if a visitor can read what each entry does. Anything found without a description in a language you have activated is listed, so the gap is visible before somebody else finds it.

    • Per language
  • A banner that is not there

    The simplest and most expensive one. If no Consent Studio banner is found on a page that should have it, that is the first thing the scan says, rather than a clean report on a site that is not protected at all.

    • Install check
  • When we cannot reach you, we say so

    A blocked scanner, a timeout or a certificate problem is reported as exactly that. What it never does is come back with zero trackers found and let you read that as good news.

    • No access
    • Timeout
    • SSL
Timo Leser
Most people find out what is running on their site when somebody else tells them. We built Monitoring so that somebody is us, and so you hear it in the week it happens.
Timo Leser, Business Development Lead

One price, and all three products in it

Every plan carries Web CMP, Launcher and Monitoring. The tier you pick changes the depth, not the toolset, and nothing is metered by pageview.

Essential

€10/month

For a single site that has to be compliant, and stay that way.

  • Unlimited pages and displays
  • 200,000 consent actions a month
  • The full stack, not a starter tier
Try Essential for FreeNo credit card required. 7 day free trial.
  • Professional

    €36/month

    For growing teams that run on data, and the agencies serving them.

    Try Professional for Free
  • Enterprise

    From €250/month

    For a volume, or an obligation, a standard plan cannot answer.

    Explore Enterprise
  • Agencies & Resellers

    Buy at a partner rate and resell client sites at your own price.

    Discover Partner Programme
  • Public Sector

    Government, healthcare and education run on Enterprise.

    See Enterprise

Trusted by organisations that take privacy seriously


  • Philips, the Dutch electronics group, using Consent Studio for cookie consent
  • Gemeente Leiden, a Dutch municipality running Consent Studio on its public websites
  • Erasmus Universiteit Rotterdam, managing cookie consent with Consent Studio
  • America Today, a fashion retailer using Consent Studio across its webshop
  • Van Vulpen, an infrastructure contractor using Consent Studio for cookie consent
  • EuroParcs, a European holiday park operator running Consent Studio on its booking sites
  • Optica, a Dutch opticians chain using Consent Studio for consent management
  • Movisie, the Dutch social policy institute, managing cookie consent with Consent Studio
  • Jeans Centre, a Dutch fashion retailer using Consent Studio for cookie consent
  • Mondiaen, a Tilburg primary school foundation, running Consent Studio across its school websites
  • Nederlands Jeugdinstituut, the Dutch national youth institute, running Consent Studio on its websites
  • Fiterman Pharma, a pharmaceutical company using Consent Studio for cookie consent
  • Eddie Rockets, a hospitality group managing cookie consent with Consent Studio
  • Veneta, a kitchen retailer using Consent Studio for consent management
  • MS Mode, a fashion retailer running Consent Studio across its European webshops

Frequently asked questions about Monitoring

How often does the scan run?

A site is picked up again as soon as its last completed scan is a week old. It is not a fixed day of the week, and nothing needs to be scheduled by hand. On Professional and above you can also run one on demand.

Does it only find cookies?

No. It reports seven kinds: cookies, local storage, session storage, IndexedDB, cache storage, tracking pixels and service workers. Two of those store nothing at all, so they are detected from what the page loaded rather than from what it left behind.

How many pages of my site are scanned?

There is no page cap on any plan. Essential scans the pages known for your site; Professional and above can discover them from your sitemap, which is what keeps a large site current without anyone maintaining a list.

Will it flag my own files as trackers?

It is written hard against exactly that. Hosts are matched on label boundaries rather than as substrings, generic patterns are matched against the path only, and static assets are never pixels unless the host is a known tracker. That set of rules exists because a looser version once flagged a customer stylesheet and two font files.

What happens if the scanner cannot reach my site?

You are told which of the three it was: access blocked, a timeout, or a certificate problem. It never reports zero trackers found for a site it could not read.

Do findings pile up over time?

No. Each one closes itself when the underlying problem is gone, and each names the page that triggered it. What you are looking at is what is wrong now.

Get Started with the Full Consent Stack

Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.

Read the documentation

Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.

Which privacy policy?

We publish two, and they cover different audiences. Pick the one that describes you.