Waivern Consent Analyser Beta Test Release
AI-Enhanced Compliance Report
💬 Give Feedback

AI-Enhanced Compliance Report

https://www.wisetack.com  ·  CMP: Enzuzo CMP   ⚠ AI analysis incomplete
2 FAIL · 4 PASS · 5 MANUAL

Cookie disclosures are just the start of CCPA compliance

This tool checks whether your site meets CCPA/CPRA requirements around cookie consent and opt-out signals — but California’s privacy law imposes a broader set of obligations on businesses that collect personal information. Privacy notice requirements, consumer rights fulfilment (including the right to delete and the right to correct), data sharing agreements with service providers and contractors, and sensitive personal information handling are just a few of the areas this tool cannot assess.

If you’d like to understand your full CCPA/CPRA compliance position, Waivern combines automated scanning tools like this one with privacy professionals who know US state privacy law inside out. Our ongoing compliance support starts from just £200/month (ex. VAT) — whether you’re dealing with California alone or navigating the growing patchwork of US state privacy regulations.

Get in touch →
C3 analysis errors:

Consent State Screenshots — assessed by AI for K.1/K.2/K.3

Default Starting State
default_starting_state
Post Accept Baseline
post_accept_baseline
Post Optout State
post_optout_state

Detailed Findings

🤖 = AI-assessed  ·  👁 = Vision (screenshot)  ·  HIGH MEDIUM LOW = risk level from legal analysis

BAS. Default Tracking Baseline 0 FAIL   0 PASS   0 MANUAL
BAS.1 Advertising and analytics tracking active by default (opt-out right context)
ℹ INFO

0 advertising/tracking cookie(s) and 9 tracker global(s) active by default (GoogleAnalyticsObject, _hjSettings, _hsq, dataLayer, ga, google_tag_manager…). Under CCPA/CPRA, this is the default state consumers have the right to opt out of via the DNSSPI link or GPC signal. The presence of tracking by default is not itself a violation — the violation is failure to provide a working opt-out mechanism.

total_cookies_defaultad_tracking_cookiestracker_globals_activetracking_scripts_active
130['GoogleAnalyticsObject', '_hjSettings', '_hsq', 'dataLayer', 'ga', 'google_tag_manager', 'gtag', 'hj', 'lintrk']4
BAS.2 CCPA relationship classification: Sale, Sharing, and Service Provider vendors
ℹ INFO

SALE (§1798.140(ad)): 0 vendor(s) — none detected. SHARING/cross-context behavioural (§1798.140(ah)): 2 vendor(s) — LinkedIn Insight, LinkedIn Insight Tag. SERVICE PROVIDER (on-behalf processing): 1 vendor(s) — HubSpot (CRM/marketing). Sale and Sharing relationships are subject to the consumer opt-out right under CPRA §1798.120 and must be disclosed in the privacy policy.

sale_vendorssharing_vendorsservice_provider_vendorssale_cookie_countsharing_cookie_countservice_provider_cookie_count
[]['LinkedIn Insight', 'LinkedIn Insight Tag']['HubSpot (CRM/marketing)']072
Recommendation: Ensure all Sale and Sharing vendor relationships are disclosed in the privacy policy per Cal. Civ. Code §1798.100(a)(1). Data broker Sale relationships require written contracts limiting downstream use per §1798.100(d). Consider whether data broker relationships (LiveRamp, BlueKai, etc.) are necessary given CPRA opt-out exposure.
DNS. Do Not Sell or Share Link (CPRA §1798.135(a)) 0 FAIL   2 PASS   1 MANUAL
DNS.1 'Do Not Sell or Share My Personal Information' opt-out link present
✓ PASS

Opt-out link found: "Decline non-essential cookies" — placement: banner.

foundtextlocationhrefvia_cmp
TrueDecline non-essential cookiesbannerTrue
DNS.2 DNSSPI opt-out is clear and conspicuous (§1798.135(a) requirement)
✓ PASS

Opt-out available via CMP consent banner ("Decline non-essential cookies"). Banner-based opt-out is clear and conspicuous — CPRA permits the consent interface to serve as the opt-out mechanism.

foundtextlocationhrefvia_cmp
TrueDecline non-essential cookiesbannerTrue
DNS.3 'Limit the Use of My Sensitive Personal Information' link present (CPRA §1798.135(a)(2))
☐ MANUAL

No 'Limit the Use of My Sensitive Personal Information' link detected. Based on the site's apparent business type, SPI collection likelihood is assessed as LOW — this obligation likely does not apply unless the site collects precise geolocation, health, financial, biometric, or other sensitive data categories (CPRA §1798.140(ae)) as part of its core operations. Manual review recommended to confirm whether SPI is processed and whether this link is required.

lspispi_likelihood
{}LOW
Recommendation: Confirm whether you process any sensitive personal information categories per §1798.140(ae). If not (e.g. you only collect name, email, order history), this link is not required. If you do process SPI (e.g. precise location for delivery tracking), add the link alongside your DNSSPI link.
GPC. Global Privacy Control Compliance 2 FAIL   0 PASS   1 MANUAL
GPC.1 Site signals GPC opt-out receipt via US Privacy string or GPP
✗ FAIL

US Privacy string: (none). GPP: (none).

__usprivacy__gppnote
(not detected)(not detected)No __usprivacy or __gpp cookie or API detected with GPC header active. Site may not be recognising the Sec-GPC: 1 header or navigator.globalPrivacyControl JS property.
Recommendation: Configure the CMP to read the Sec-GPC: 1 request header and the navigator.globalPrivacyControl JS property (set to true) and treat them as an automatic opt-out of sale and sharing. CPRA §1798.135(b) prohibits requiring additional consumer action when a valid opt-out signal is present. CMP platforms (OneTrust, Sourcepoint, Didomi) have built-in GPC support that must be explicitly enabled.
GPC.2 Advertising/tracking cookies suppressed after GPC opt-out vs default baseline
☐ MANUAL

Default (no opt-out): 0 advertising/tracking cookie(s). After GPC opt-out signal: 0 advertising/tracking cookie(s). No advertising cookies detected in the default baseline — cannot assess suppression.

default_baseline_ad_cookiesafter_gpc_signal_ad_cookiescookies_suppressed
000
GPC.3 Advertising pixel scripts (Meta, TikTok, LinkedIn etc.) suppressed after GPC opt-out
✗ FAIL

Default baseline pixels: ['_hsq', 'lintrk']. After GPC opt-out: ['_hsq', 'lintrk']. Pixels still active after GPC opt-out: ['_hsq', 'lintrk']. These constitute 'sharing' for cross-context behavioural advertising under CPRA §1798.140(ah).

default_ad_pixelsafter_gpc_ad_pixelspixels_suppressedpixels_still_activegtm_gtag_present
['_hsq', 'lintrk']['_hsq', 'lintrk'][]['_hsq', 'lintrk']True
Recommendation: Advertising pixel scripts (Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, etc.) must not execute when GPC is active. Configure your tag manager or CMP to suppress these tags when navigator.globalPrivacyControl is true.
GPC.4 Third-party tracking script load — default vs after GPC opt-out (informational)
ℹ INFO

Default baseline: 4 tracking script(s) active. After GPC opt-out: 4 tracking script(s). Reduction of 0. Script-level suppression is informational — scripts may be loaded but not execute tracking functionality depending on runtime logic.

default_tracking_scriptsafter_gpc_tracking_scriptsscripts_suppressed
440
USP. IAB US Privacy / GPP Framework 0 FAIL   0 PASS   2 MANUAL
USP.1 IAB US Privacy / GPP framework participation (opt-out signalling infrastructure)
ℹ INFO

No IAB opt-out signalling framework detected with GPC active. Sites using a CCPA-compliant CMP (OneTrust, Sourcepoint, Didomi) should emit a USP or GPP string that reflects the consumer's current opt-out status, including when the GPC signal is present.

__usprivacy_string__gpp_stringframework_detecteddecoded
(not present)(not present)No IAB opt-out framework detected(see above)
Recommendation: Implement an IAB GPP-compliant CMP to provide industry-standard opt-out signalling. The GPP (Global Privacy Platform) string communicates the consumer's opt-out status to ad tech vendors downstream in the supply chain. Without this, downstream partners may continue processing data for advertising even after an opt-out.
USP.2 __usprivacy string signals opt-out when GPC header is active
☐ MANUAL

__usprivacy during GPC session: None. No __usprivacy string detected during GPC session.

us_privacy_during_gpcopt_out_bit
(not detected)(n/a)
Recommendation: When the Sec-GPC: 1 header is present, the __usprivacy string should be set to 1YN- or 1YY- (opt-out bit = 'Y' at position 3). CPRA §1798.135(b) and the IAB US Privacy Technical Specification both require businesses to reflect GPC opt-out in the US Privacy string.
USP.3 __usprivacy string signals opt-out after manual DNSSPI opt-out flow
☐ MANUAL

Before opt-out click: (none). After opt-out click: (none). No string detected post-click.

us_privacy_before_clickus_privacy_after_clickopt_out_button_clicked
(not detected)(not detected)True
Recommendation: After a consumer clicks the DNSSPI link and confirms their opt-out, the __usprivacy string should update to reflect the opted-out state (position 3 = 'Y'). Cal. Civ. Code §1798.135(a)(1) requires the opt-out to take effect within 15 business days of the request.
OPT. Opt-Out Flow 0 FAIL   2 PASS   1 MANUAL
OPT.1 DNSSPI link leads to a functional opt-out destination
✓ PASS

Opt-out available via CMP consent banner ("Decline non-essential cookies") and confirmed functional — opt-out button was successfully clicked in automated testing. CPRA permits the CMP consent interface to serve as the opt-out mechanism.

mechanismbutton_textopt_out_clicked
CMP bannerDecline non-essential cookiesTrue
OPT.2 Opt-out completable without requiring account creation or login
✓ PASS

Opt-out button found and clicked automatically — no login required.

opt_out_button_clicked
True
OPT.3 Opt-out preference is recorded and honoured on reload
☐ MANUAL

No unambiguous advertising cookies or pixels detected in the baseline — cannot assess opt-out efficacy via state comparison. Opt-out button was clicked. Manual review of the CMP audit log is recommended.

us_privacy_beforeus_privacy_afterbaseline_ad_cookiespost_optout_ad_cookiesbaseline_pixelspost_optout_pixelsopt_out_clicked
(not detected)(not detected)02['_hjSettings', '_hsq', 'hj', 'lintrk']['_hjSettings', '_hsq', 'hj', 'lintrk']True
🔒

Cookie disclosures are just the start of CCPA compliance

This tool checks whether your site meets CCPA/CPRA requirements around cookie consent and opt-out signals — but California’s privacy law imposes a broader set of obligations on businesses that collect personal information. Privacy notice requirements, consumer rights fulfilment (including the right to delete and the right to correct), data sharing agreements with service providers and contractors, and sensitive personal information handling are just a few of the areas this tool cannot assess.

If you’d like to understand your full CCPA/CPRA compliance position, Waivern combines automated scanning tools like this one with privacy professionals who know US state privacy law inside out. Our ongoing compliance support starts from just £200/month (ex. VAT) — whether you’re dealing with California alone or navigating the growing patchwork of US state privacy regulations.

Get in touch →
Component 3 — AI analysis via Claude  ·  ← Home