Regulators fined Google €325M and SHEIN €150M over consent failures. Most sites make at least one of the same three mistakes. Paste your URL and find out in seconds — no sign-up, works on every platform.
The scan runs nine technical checks against your live page. The ones regulators actually fine for:
| Check | Why it matters |
|---|---|
| Pre-consent tracking | Analytics or ad cookies firing before the visitor clicks anything is the pattern behind the SHEIN €150M and American Express €1.5M decisions. |
| Consent Mode v2 | Google requires Consent Mode v2 signals for EEA ad personalisation since March 2024 — missing it quietly breaks Google Ads measurement. |
| Reject-button reality | A reject option that exists but doesn't stop trackers counts as a knowing violation after the CNIL benchmark decisions. |
| HTTPS & security headers | NIS2 and GDPR Art. 32 expectations — unencrypted pages fail basic technical compliance. |
| Privacy policy linking | ePrivacy requires clear information before consent; an unreachable policy undermines the whole legal basis. |
Want the full enforcement history? See the GDPR cookie fines tracker, or the complete EU cookie consent guide for 2026.