hello@datascale.de+49 89 921 35 623tracked cookie-free · /openDEEN

Search services, integrations and blog posts.

DatascaleResourcesChecksPre-consent cookies

Check · C02 · Cookies & scripts before / after consent

Pre-consent cookies

Cookies set before the consent decision are a typical compliance finding.

What we check

Reads the Set-Cookie header of the first response, before any consent decision.

Why it matters

Cookies set before the consent decision are a typical compliance finding.

Common causes

  • Server-side session or load-balancer cookies (PHPSESSID, AWSALB) are harmless but belong in the documentation as essential.
  • A CDN or bot protection sets its own cookies, which are simply missing from the cookie documentation.
  • The backend writes affiliate or attribution cookies with the very first response, before any consent.
  • Server-side A/B testing assigns variant cookies before the consent decision.

The fix

Enable CMP tag-blocking; mark server-side session cookies (PHPSESSID etc.) as essential.

Matching template

CMP and GTM Consent QA Template

The repeatable test plan for default-denied, consent update and reject, across all four signals.

Get the QA template →

Check it yourself first

The Tracking Check tests this point along with all the others, in seconds.

Start the Tracking Check →
What does a failing "Pre-consent cookies" check mean?

Cookies set before the consent decision are a typical compliance finding. Enable CMP tag-blocking; mark server-side session cookies (PHPSESSID etc.) as essential.

How do you fix a failing "Pre-consent cookies" check?

Enable CMP tag-blocking; mark server-side session cookies (PHPSESSID etc.) as essential.

The fix, delivered

Wired up in days, not sprints.

Findings from the Tracking Check go into a ranked sequence with effort estimates in the Audit Sprint, every module with an acceptance criterion.