hello@datascale.de+49 89 921 35 623tracked cookie-free · /openDEEN

Search services, integrations and blog posts.

DatascaleResourcesChecksPrivacy policy match

Check · C02 · Cookies & scripts before / after consent

Privacy policy match: does the policy describe what actually runs?

The scanner holds the visible text of the privacy policy against the detected tracking stack and lists every tool in use that the policy never mentions.

What gets tested

The scanner takes the detected tools from the scan, including the ones dug out of the CMP config and invisible in the HTML, and checks each against the visible text of the privacy policy. Matching is generous, via mention patterns ("Google Analytics" or "GA4", "Piwik" covers Matomo). Only what is completely absent gets listed.

Why it matters

The privacy policy ages faster than the stack. A new pixel is installed within an hour; nobody writes its paragraph. Three years later the policy explains the tools of 2019 while a tag manager actually runs through a server-side proxy and the CMP lists services the text never names. That discrepancy is visible from the outside, to every visitor and to any supervisory authority with five minutes to spare.

Common causes

  • Tools were added over time (pixels, heatmaps, a server-side migration), the policy was not.
  • The policy comes from a generator snapshot years old and still explains "Google Inc." and Privacy Shield.
  • The CMP lists services an agency once configured; nobody carried them into the policy.

The fix

Walk the listed tools through with your privacy counsel: what stays goes into the policy, processors and data flow included; what nobody needs anymore leaves the stack. Then keep both sides in sync: every stack change ships its policy paragraph in the same ticket.

Matching template

CMP and GTM Consent QA Template

The repeatable test plan for default-denied, consent update and reject, across all four signals.

Get the QA template →

Check it yourself first

The Tracking Check tests this point along with all the others, in seconds.

Start the Tracking Check →
What does the "privacy policy match" finding mean?

The scanner compared the detected tools (trackers, tag manager, CMP, server-side setup) against the visible text of the privacy policy. Listed is whatever runs but never appears in the text. The match is deliberately generous: a mention of "Facebook" is enough for the Meta pixel. What is still missing is very likely genuinely missing.

Is a missing tool automatically a legal violation?

The text match does not decide that, and it does not claim to. It surfaces a discrepancy between the technology and the policy, which typically appears when the stack evolves and the policy stands still. The legal assessment belongs to your privacy counsel.

Why does server-side tagging appear in the match?

When the scanner finds a custom loader on the site's own subdomain, measurement runs through a first-party endpoint, often hosted by a provider like stape. That provider is a data processor, and a policy that still describes only the direct-to-Google data flow no longer describes the real one.

The fix, delivered

Wired up in days, not sprints.

Findings from the Tracking Check go into a ranked sequence with effort estimates in the Audit Sprint, every module with an acceptance criterion.