Mutual consent verifiedListed PlottersInspection with every delivery

GDPR Tests: Does Your Cookie Banner Do What It Promises?

Refusing cookies should really prevent trackers from running. It’s a simple statement, and that’s exactly what doesn’t seem to be working: the banner displays correctly, and a tracking script still runs.

Métablock for managing the consent banner in Mr Suricate, reusable in all scenarios

They trust us

Retail, banking, manufacturing, transportation, and services: Our clients run nearly 3 million scenario simulations per month on their critical workflows.

The banner appears, and the plotter starts up anyway

A tag added directly to the code for a campaign test, a third-party script that loads another script, a social media integration implemented by a team that wasn’t familiar with the rule. The consent banner is there, and it’s configured correctly, but it doesn’t control everything that triggers on the page. This is a compliance issue, and it goes unnoticed without verification.

Mouse icon

The refusal has been verified for real

The script blocks cookies, then lists what still loads. This is the check that no one ever does—and it's the one that matters.

Purple Rectangles Icon

A tracker that doesn't start after acceptance means lost data. Both scenarios are checked.

Purple Gear Icon

Withdrawal of Consent

What happens when the user changes their mind. This is a requirement, and it’s rarely tested.

Purple API Test Icon

Compliance is eroded by the accumulation of small changes. Monitoring keeps pace with the release of new versions.

Integrates with your pipeline without rewriting it

Your consent checks are triggered from your CI, run on your production environments, and feed back into the systems where your teams are already working. No retooling required.

1 Triggering Your tools stay in control
  • GitLab
  • Jenkins
  • Microsoft Azure
  • API Call
  • Planning
2 ExecutionMr SuricateYour scripts run on your production environments
  • Web Tour
  • Native iOS and Android Apps
  • Real Mobile Farms
  • APIs and Internal Feeds
3 Restitution The results are delivered right to your workplace
  • Jira
  • Slack
  • SMS
  • Webhook
  • API
And maintenance that stands the test of time
  • Reusable blocksA change updates all scenarios that use it
  • AI-Assisted CorrectionSuggested corrections for scenarios with errors
  • Grouping IncidentsSimilar anomalies are processed only once

How Automated, Line-by-Line Validation Makes a Difference

Without consent verification
With Mr Suricate
We are verifying the configuration of the consent tool.
We check what is actually being sent from the page.
A manually added tag is not included in the banner.
It appears on the list of unauthorized tracers.
The inspection is performed once, during setup.
It is redone with every delivery.
Withdrawal of consent is never tested.
It's just another scenario.
This is a legal issue, but it violates the code.
The report is technical, dated, and enforceable internally.
The discrepancy is discovered during an inspection.
We find out on the day he shows up.
ResultThe list of trackers that are shipped despite a rejection, verified with each delivery rather than during an audit.
PRACTICAL GUIDE · 2026 EDITIONSoftware Quality and Testing: The Essential GuideThe fundamentals of functional testing, common pitfalls, and a method for building test coverage that stands the test of time.
Download the guide
“With Mr Suricate, we’ve automated label verification, secured our data, and gained the reliability we need to make strategic decisions without errors. Plus, it’s fun!”

Xavier ValetHead of Data Analytics, HelloWork

Support that ends whenever you want

Mr Suricate replace your QA team—it enhances it. You decide what to handle in-house and what to outsource: creating test scenarios, running them, or maintaining them over time.

  1. 1Identification of critical paths, front-end and back-end
  2. 2Writing Tests Without Code
  3. 3Continuous monitoring and alerts
  4. 4Scenario Maintenance and Development
ResultYou gain broader coverage without increasing your teams’ workload. And if you’d rather delegate everything, QA outsourcing takes over.

YOUR QUESTIONS

Frequently Asked Questions

The most common questions we get about compliance testing.

What exactly does a GDPR test check for?

The actual behavior of the page based on the user's choice: which trackers are triggered after a refusal, which ones after acceptance, and what happens when consent is withdrawn. The audit focuses on the actual requests and cookies set, not on the declared configuration.

Does this replace the advice of a legal professional or a DPO?

No. The test establishes a factual finding: this tracker was sent even though the user had refused. The legal classification and the decision remain the responsibility of your DPO. In practice, the technical finding is what is most often missing.

Does it work with any consent solution?

Yes, because the test depends not on the tool but on its effect. The script interacts with the banner just as a user would, and then observes the page. The result is the same regardless of the provider.

How often should you run it?

With every production release. Compliance issues almost always stem from successive additions that, taken individually, seemed harmless: a campaign tag, a review widget, a share button.

Can we also check the lifespan of cookies?

Cookies that have been set are detected at runtime, which allows you to verify their presence and their declared characteristics. This is a useful supplement to the inventory maintained by your DPO, which tends to diverge from reality over the course of several months.

What do we check when it comes to consent?

The banner should appear, close, and—most importantly—the user’s selection should produce the expected result. The scenario rejects the submission, then verifies that no tracking tags are sent. It accepts the submission and verifies that events resume normally.

Are the major consent platforms covered?

Yes. The banners for the three most common solutions are controlled using reusable blocks that are set up once and called upon in all your scenarios. Changing the solution only requires modifying a single block.

What's the connection to the tagging plan?

It's straightforward. Verifying consent without verifying what is sent afterward proves nothing. The banner check and the verification of tracking requests occur within the same scenario, which makes it possible to determine what was sent, when, and with what consent.

Does this replace a legal audit?

No. We do not assess the compliance of your processing activities, nor do we draft your privacy notices. We provide technical evidence that the observed behavior matches what your documentation states—which is precisely what is missing during an audit.

Do you only believe what you see?

A 30-minute demo of your own app. You'll see one of your workflows automated in real time, without writing any code.