Skip to content

Scan rule · RSC-PRV-002

US tracking without visible consent

Privacy (GDPR)Severity: Medium

Detects analytics and pixel scripts with third-country transfer in the shipped markup.

Why this matters

Analytics and tracking services based in the US typically set identifiers and transmit usage data as soon as the page loads. Under the GDPR this generally requires prior, active consent — not merely a notice banner running alongside.

In practice the scan very often finds both at once: the tracking script starts immediately on load, and the cookie banner appears only afterwards or offers no real reject option. The consent is then ineffective, because the transfer already happened.

A sensible order: load tracking only after active consent, make rejecting as easy as accepting — or switch to an analytics tool that works without personal data and is hosted in the EU. This is a technical assessment, not legal advice.

Scan tier

External scan (anonymous)

How to fix it

Load trackers only after granular consent, or switch to an EU alternative.

Scan your own app for free