Methodology

How we test compliance software

Every tool we cover is installed on a real test site and evaluated against the same checklist. This page describes exactly what we check, so you can weigh our verdicts against your own priorities.

Test environment

Every tool runs on the same disposable test site: a small multi-page site wired to Google Analytics 4, a Meta Pixel, and a handful of common third-party embeds, so each tool is blocking and categorizing the same real tracking stack. We simulate visitor location with a combination of VPN endpoints and geo-header overrides to trigger EU, UK, and California banner variants on demand, and we test in current Chrome, Safari, and Firefox, plus one mobile browser, since banner rendering and script-blocking behavior can differ by browser.

What we check

01

Setup and time-to-live

We create a new account on each tool and measure the time from signup to a fully working, published consent banner on a test site, including whatever DNS, tag manager, or code-snippet steps are required to get there.

02

Script-blocking accuracy

We open the network panel and confirm analytics and advertising scripts are actually blocked pre-consent, not just visually hidden behind the banner. We check this for tags fired via a direct script embed, via Google Tag Manager, and via server-side tagging setups, since blocking behavior differs across all three.

03

Cookie and tracker scanning

We run each tool's auto-scan against the same test site and manually audit the results: does it correctly find and categorize first-party, third-party, and session cookies, and how many need manual re-categorization before the banner is accurate.

04

Consent signal standards

Where a tool claims IAB TCF v2.2 support, we validate the TC string it generates against the IAB validator. We also check Google Consent Mode v2 signal wiring (ad_storage, analytics_storage, ad_user_data, ad_personalization) and, where relevant, the Global Privacy Control (GPC) header.

05

Regulation coverage

We check behavior against GDPR/ePrivacy (opt-in by default, reject given equal visual weight to accept, no pre-checked boxes), UK PECR, and CCPA/CPRA (Do Not Sell/Share links, GPC honored as an opt-out signal), using VPN- and geo-header-simulated traffic from each region rather than trusting the vendor's claimed coverage.

06

Consent persistence and withdrawal

We accept, then later withdraw, consent for individual categories and confirm the underlying scripts actually stop firing on the next page load, not just that the preference toggle changed state. We also check that consent choices persist correctly across page navigation, subdomains, and repeat visits within the tool's stated retention window.

07

Consent logging and audit trail

We generate consent records as a test user and confirm the tool retains a timestamped, exportable log suitable for demonstrating compliance, since "we asked for consent" and "we can prove we asked" are different requirements.

08

Design and customization

We test how much control we have over banner placement, layout (banner vs. modal vs. corner popup), copy, and branding without needing custom CSS or code, and whether that customization survives the tool's own software updates.

09

Platform and CMS integration

Beyond a generic script tag, we test native integration paths where the vendor advertises them, WordPress and Shopify most commonly, and note any functionality gap between the native plugin and the manual embed.

10

Cross-device and performance impact

We check banner rendering on a real mobile device and at common breakpoints, run it through a Lighthouse pass to measure the added script weight and any layout shift the banner introduces, and do a pass with a screen reader and keyboard-only navigation to check basic accessibility.

11

Pricing at real-world scale

We evaluate pricing at the tier a small or mid-size business would actually use, not just the cheapest listed price, and flag which core features (multi-domain, geo-targeting, TCF support) are gated behind a paid or enterprise plan.

12

Support responsiveness

We file at least one real support request per tool, through the same channel a paying customer would use, and record response time and whether the answer actually resolved the issue.

What we don't do

  • We don't accept payment in exchange for a favorable review or a higher ranking.
  • We don't publish a verdict on a tool we haven't personally installed and tested.
  • We don't treat vendor-provided marketing claims as test results.

Retesting

Compliance tools update frequently. We re-test our top picks on a rolling basis and update the "last updated" date on each review when we do. If you find something out of date,let us know.

Limits of our testing

We are not a law firm, and passing our tests is not a legal compliance guarantee. Our scores reflect product behavior under our specific test conditions, not a legal opinion on your business's obligations.