Logo Logo
Cookiebot

Try our free compliance test to check if your website's use of cookies and online tracking is GDPR/ePR compliant.

The test also shows what data your website collects and which third parties it shares with, a requirement under the CCPA.

Cookiebot's cookie scanner makes real compliance with GDPR and CCPA a reality.

Updated June 2, 2020.


The Internet has more dimensions than you can see.

Even your own website has dimensions that are not immediately visible to you, and these secret grey spaces hide trackers and intruders that see everything and remember all.

Here, no privacy exists.

But there is a way to make these dimensions visible, and to cast a light on the hundreds of potential trackers that lie in hiding on your website and invade your users’ privacy.


What is a cookie scanner?


A cookie scanner is a software technology that scans websites to detect which cookies and trackers are in operation on the domain.

Data protection laws like the EU’s GDPR and California’s CCPA require websites to know what personal data it collects from its users – and for the most part, personal data collection is done through cookies.

A cookie scanner is therefore a vital tool for compliance with GDPR, CCPA and more data protection laws across the world.


Cookiebot's cookie scanner


Our unmatched cookie scanner forms the cornerstone of Cookiebot’s consent management platform.

Cookiebot’s cookie scanner finds all cookies and trackers – even the hidden trojan horses – so that your website can become compliant and protect user privacy.

Cookiebot’s cookie scanner –

Learn more about GDPR and cookie consent

Learn more about CCPA and cookies

Try Cookiebot free for 30 days… or forever if you have a small website.



Cookiebot's cookie scanner is unmatched.



How does Cookiebot's cookie scanner work?


The Cookiebot cookie scanner simulates human beings and their behavior online in order to lure out and detect all of the cookies and trackers in hiding on a given website.

Cookiebot’s cookie scanner cheats the trackers into thinking that a real person is scrolling on the website, and in that way baits them to come out form their hiding and show themselves.


What are cookies?

Cookies are small text files that a website places on your browser. When people visit your website, cookies collect data about them.

Necessary cookies serve your website’s most basic functions.

Preference cookies remember user choices of language, currency setting or log-in details for optimal user experience.

Statistics cookies track users and collect different information about them and their online behavior and is used to inform website owners on the analytics of their site.

Marketing cookies harvest data for third-party companies that assemble comprehensive profiles on people and use these to target them with advertisement. This is known as behavioral advertisement and is a multi-billion-dollar industry.


Cookiebot’s cookie scanner performs fully-rendered simulations of multiple users (7-8 on average) visiting a website and their behavior on that website, which includes scrolling up to 10,000 subpages, clicking all links, menu points and buttons, moving cursors around, as well as playing and pausing embedded video and audio content.

Basically, the cookie scanner exhausts all of the technically possible options on a website through simulated user interaction. Sort of like rustling a bush to see all the insects crawl out of their hiding.



Cookiebot's cookie scanner is by far the best and most thorough in the industry, enabling real compliance with GDPR and CCPA the world over.

Cookie scanners are like an x-ray of your website, revealing what’s hidden.



During these simulated sessions, the website cookie scanner monitors all network traffic between the website and the “browsers” of the simulated users, as well as any traffic sent to other websites. 

Our cookie scanner uses this data to identify all the trackers that are present.

Once our cookie scanner has scanned a domain and all of its subpages, Cookiebot catalogues all of the identified trackers by their –

  1. technical properties,
  2. type and expiry period,
  3. exact location within the source code,
  4. third party providers,
  5. and purpose.

The purpose of a tracker – is not something that the cookie scanner alone can determine, which is why the Cookiebot research team is constantly working on classifying trackers according to information provided by the third-parties themselves, either on their websites or in response to our direct inquiries.

If no such information is forthcoming, the tracker will be categorized on the basis of its technical properties and the available knowledge about the business model for the third-party company controlling the tracker. The next time the cookie scanner encounters this tracker, it will categorize it accordingly.

Finally, this vast knowledge that the cookie scanner generates is stored in Cookiebot’s cookie repository of more than 22 million trackers, which have been classified and ascribed more than 3,500 unique purpose descriptions.


What kind of cookies does Cookiebot's cookie scanner find?


The Cookiebot cookie scanner finds all cookies and online trackers technology present on a domain.

This is a crucial and defining feature that we are very proud of at Cookiebot.

Our cookie scanner is unmatched in the industry, and finding the trackers is, of course, the prerequisite for real compliance with data protection laws like the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

Of the most common tracking technologies that our web cookie scanner finds are –

All of these trackers can be found on a website, even if the website owner is not aware of their presence.

They usually sneak their way in through analytical tools, social media links, embedded videos, and many other website add-ons.


Why use Cookiebot's cookie scanner?


If your website has users from inside the EU, you are required to be compliant with the GDPR.

If your website has California residents among its users, you may be required to obtain compliance with the CCPA.

Using a cookie scanner is a vital tool in order to become compliant with data protection laws like the GDPR and CCPA. In fact, it’s technically impossible to be CCPA or GDPR compliant without it.

Why?

Because both laws require that you inform users of what cookies and trackers your website uses, what data you collect and who you pass it on to (e.g. third parties like Google and Facebook).


Cookie scanners for GDPR compliance

GDPR compliance entails that –

Learn more about the GDPR


EDPB guidelines on valid consent

The European Data Protection Board (EDPB) is the leading supervisor of the GDPR, responsible for adopting guidelines and issuing decision on how the GDPR is to be interpreted and enforced by national data protection authorities in each EU member country.

On May 4, 2020, the EDPB adopted guidelines on valid consent that clarify how websites who process personal data of individuals inside the EU are supposed to obtain the prior consent of users.

The EDPB guidelines specify that –

Learn more about the EDPB guidelines on valid consent


Cookie scanners for CCPA compliance

CCPA compliance means that you must - 

Learn more about the CCPA


Cookie scanners as explorative tools


But the cookie scanner technology is about more than just data law compliance.

In the recent year, the cookie scanner technology has shown itself to be an important explorative tool in investigative journalism – as a revealer of the hidden things of the Internet that invade our private lives and democratic institutions.


Cookie scanner reveals ad tech surveillance of EU government websites

Earlier in 2019, we at Cookiebot released a report on the ad tech surveillance of public sector websites in major EU nation states, in which we used our cookie scanner technology to analyze tracking that occurred during simulated visits to thousands of pages across official government websites and public health service websites in all 27 EU member states.

Cookiebot found over 100 advertising technology companies systematically and invisibly tracking EU citizens when they visit their governments online. Our cookie scan report made news headlines globally, including TechCrunch, BBC and Financial Times.



Cookiebot cookie scanner reveals third party tracking on EU government websites

Read the full Cookiebot report here.



Cookie scanners and the ad tech industry


Cookie scanners, like our Cookiebot scanner, reveal the third-party trackers that harvest user data for the purpose of profiling: the method by which cookies and trackers on websites harvest user data in order to collect data points of personal information and assemble them in comprehensive profiles on users, ranging from your political beliefs and geographical location to eye color and health, sexual orientation and financial information, and so on.

These profiles are used in what is known as behavioral advertisement.


Contextual ads versus behavioral ads

Contextual ads work by presenting advertisement relevant to a particular search inquiry. You go on Google and enter something into their search engine, and Google will display ads that are relevant to your search. If you searched for rock-climbing shoes, ads for rock-climbing shoes will appear.

No big deal.

Behavioral ads, on the other hand, are non-search ads, i.e. they don’t require the context of your particular search inquiry to serve you advertisement online. Rather, they are based on collected and accumulated information about you as a person and served to you on your preferred social media platforms, as ads in online papers and magazines, and countless other websites you visit every day.



Cookiebot's cookie scanner is cutting edge technology and the best in the industry.

Cambridge Analytics was found to have 5,000 data points on every American.



Big Ad Tech is a multi-billion-dollar industry relying on the collection and selling of data about human beings and their individual and collective behavior – the commodification and monetization of private inner lives for the benefit of a small group of the wealthiest companies on Earth.

However, 45 percent of companies using behavioral ads saw no significant benefit from them, and 23 percent said they actually caused a decline in revenue, as reported in the New York Times recently in an opinion piece by Gabriel Weinberg, the chief executive and founder of the search engine, web browser company and Google-alternative DuckDuckGo.

Perhaps behavioral advertisement isn’t the miracle that Google and Facebook seem to be promising. Perhaps our data, mined and harvested and commodified, is just for the benefit of the powerful companies themselves. In which case, protecting privacy online becomes a no-brainer.

That is what our cookie scanner does. It protects privacy.

Try Cookiebot free for 30 days... or forever if you have a small website.


FAQ


What is a cookie scanner?

A cookie scanner is a technology used by websites to monitor and detect the cookies and trackers in operation. Cookies often collect and process personal data on users, when they visit a website. A cookie scanner helps websites be compliant with data protection laws like the EU’s GDPR and California’s CCPA that require websites to know what kind of personal data they collect, how and for what purposes.


How does a cookie scanner work?

A cookie scanner works by simulating real-life users on a website. A cookie scanner will simulate scrolling, clicking, playing videos, browsing subpages and all other interactions that real-life users are able to do. By simulating real-life users, a cookie scanner activates all cookies and trackers that are in operation on a website and then detects all their technical properties for the website owner to inform its users about.


What are cookies?

Cookies are small text files that are stored on a user’s browser when they visit a website. Some cookies are necessary cookies that only last for as long as the user’s session on the domain, but most cookies are persistent, stay in activation for years and collect personal data on visitors that can be used to create profiles for behavioral marketing schemes and other things that can infringe on user privacy.


Do I need a cookie scanner?

If your website has cookies – which it most likely has – then you need to scan your website. Knowing what cookies and trackers are in operation on your website is a requirement of data protection laws like the EU’s GDPR and California’s CCPA. Without a cookie scanner, you most likely will not know about the hidden trojan horses that are loaded secretly within other cookies, nor will you know the technical specifications of each cookies that the laws also require you to inform your website’s users of.


Resources


Learn more about the General Data Protection Regulation (GDPR)

Learn more about EDPB guidelines on valid consent in the EU

Learn more about the California Consumer Privacy Act (CCPA)

Read the full Cookiebot report on “Ad Tech Surveillance on the Public Sector Web”

Gabriel Weinberg, founder of DuckDuckGo, with an opinion piece in NY Times on the failure of behavioral advertisement.

General Data Protection Regulation (GDPR) official law text

California Consumer Privacy Act (CCPA) official law text

Make your website’s use of cookies and online tracking compliant today

Try for free