Free scan
Checklist

A website tracking compliance checklist for non-technical owners

Published August 15, 2026 · 9 min read · RegSentry blog

"Is my website compliant?" is usually asked as a yes/no question, and it doesn't have a yes/no answer — compliance depends on which laws apply to your business, and that's ultimately a question for a lawyer. But underneath the legal question sits a set of technical facts that you can establish yourself, without writing a line of code, and those facts are what everything else rests on: what tools run on your site, what they transmit, and when they transmit it relative to visitor consent. This checklist walks you through establishing them, in order.

Check 1: Inventory every third-party tool on your site

You cannot assess what you haven't listed. The goal is a complete list of every third-party script your site loads: analytics, advertising pixels, chat widgets, session-replay tools, embedded forms, review widgets, font and video embeds. Two realities make this harder than it sounds: tools accumulate over years (added by past marketers, agencies, and plugins nobody remembers), and several install themselves through platform integrations rather than your website's code.

How to do it without code: run a scan (ours is free and lists every recognized tracker), then sanity-check against your own accounts — your Tag Manager container if you have one, your site platform's app/plugin list, and your marketing team's tool subscriptions. The list is done when nothing on your site surprises you.

Check 2: Flag the high-risk categories

Not all trackers carry equal weight. Rank your inventory:

For each high-risk tool, ask the honest question: do we use this? Replay tools especially are often installed during a redesign and never opened again. The tracker you delete is the only one that can never misfire.

Check 3: Verify consent timing — the check that actually matters

Having a cookie banner is not the test. The test is whether trackers wait for the banner's answer. In our scanning of 3,891 small-business sites, 61% fired at least one tracker before consent — and the sites with a recognized consent platform fired at 74%, worse than the 57% for sites with none. Load your site in a private window, don't answer the banner, and see what fires anyway (our step-by-step verification guide shows exactly how, or the free scan does it for you). Then repeat after clicking Reject. Both must come back clean.

Check 4: Confirm the paperwork matches reality

Your privacy policy should accurately describe the tools you actually run — a policy listing tools you removed, or missing tools you added, is worse than unhelpful. If you operate where opt-out rights apply, the opt-out mechanism must work, and honoring browser-level signals like Global Privacy Control is part of the current enforcement landscape — the California AG's $1.2M Sephora settlement (a CCPA action) centered on undisclosed data sharing and failure to honor opt-out signals. Which disclosures and mechanisms your business needs is a legal question; that your policy shouldn't contradict your network traffic is not.

Check 5: Know which laws are in play for your situation

You don't need to become a privacy lawyer, but you should know the map. California's CIPA § 631 (the wiretapping statute behind the demand-letter wave) and CCPA/CPRA reach any site with California visitors — which, on the internet, is effectively any site. Several other states have all-party-consent or comprehensive privacy statutes with their own wrinkles. Our plain-language state guides cover California CIPA, CCPA/CPRA, Pennsylvania, Florida, Massachusetts, Texas, Colorado, Virginia, and Washington's MHMDA.

Your industry changes the stakes too. Sites where visitors type sensitive information — patient forms, legal intakes, financial applications — carry more sensitive data into any recording that happens. See the industry-specific guides for healthcare providers, law firms, dental practices, financial services, insurance agencies, ecommerce, med spas, and home services, among others.

Check 6: Fix what you found — in this order

  1. Remove what you don't use. Fastest fix, zero regression risk.
  2. Gate what you keep. Every remaining tracker loads only after consent: enable your consent platform's blocking mode, wire Google Consent Mode with denied defaults, set per-tag consent requirements in Tag Manager, and bring hardcoded snippets under the consent platform's control.
  3. Kill the duplicates. Tools installed twice — once gated, once via a forgotten plugin or platform channel — are a recurring source of "we fixed it but it still fires."
  4. Re-verify. Repeat Check 3 after the changes. A fix that isn't re-tested is a hypothesis.

Check 7: Document, then keep it true

Save dated evidence: the scan that found the problems, the changes you made, the clean re-scan. If a demand letter ever arrives, a documented history of finding and fixing issues promptly is the good-faith record you'll want to have. And schedule re-checks — quarterly at minimum, and after any new tool, plugin, or agency engagement — because tracking setups drift constantly (we wrote up why drift happens separately). This last check is the one that turns a one-time cleanup into an answer that stays true.

If someone else runs your website

Many owners reading this don't touch their site directly — an agency, a freelancer, or a platform does. The checklist still works; it just becomes a set of questions you ask instead of tasks you do. Ask your web person for the tracker inventory (Check 1) and compare it against a scan — gaps between "what we installed" and "what actually loads" are exactly where problems hide. Ask who can add tags to the site and whether new tags are required to respect the consent banner (Check 6). And put the verification in your own hands: the ten-minute browser test and the free scan need no access to your site's code, which means you can independently confirm what you're being told. "Our agency handles that" is a fine answer to who does the work — it's not an answer to what the site transmits, and the second question is the one a demand letter asks.

The honest summary

Nobody can hand you a certificate that says "compliant." What you can have, after an afternoon of work, is: a complete tracker inventory, verified consent timing, paperwork that matches reality, awareness of which laws touch your situation, and dated documentation of all of it. That's what "is my website compliant?" looks like when it's answered properly — and it's more than most of the sites receiving demand letters ever had.

Check where you stand — free

Checks 1 through 3 — the inventory and the consent-timing verification — are exactly what our free scan automates: a real browser visits your site, waits at the unanswered banner, and reports every tracker that fired anyway.

See what fires on your site before visitors consent — free, 30 seconds, no signup.

Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.

If you'd rather have the site watched continuously — with an email the moment a new tracker appears — that's what monitoring is for ($99/mo, cancel anytime).