TagCompliance: Tag, Cookie & Consent Audit
Overview
Audit marketing tags, cookies, consent and dataLayer events on any website. Detect GDPR pre-consent violations.
See every marketing tag, cookie, and consent signal on any website, the moment it fires. TagCompliance is a tag auditor for privacy, compliance, and analytics teams. The live view runs entirely in your browser; nothing leaves your machine unless you explicitly send a recorded journey to your account. Open it however you work: a toolbar popup, a docked side panel, or a panel inside Chrome DevTools, right next to Network and Application. Same live view in all three. WHAT YOU SEE The panel updates in real time across six tabs, plus a Network Domains view. TAGS. Every tag that fires, by name and vendor (1,650+ recognised, updated from a live feed), scored Low to Critical by the same engine as our full-site crawler. Each shows account ID, category, consent requirement, hit count, and request URL. Click for piggyback detection, page-context risk, and a parameter dump. Tags sending raw, unhashed PII (email, phone, name, ID) in their request are flagged PII. Search by name, vendor, category, or ID. CONSENT. CMP detection (OneTrust, Cookiebot, Didomi, Tealium, Silktide, and 40+ others) with per-category granted/denied choices, IAB TCF version, and Google Consent Mode v2 read two ways: the declared gtag() state, and the actual state on the wire (the gcs= signal on live Google pings), so you catch a site declaring one thing while Google receives another. A Consent Mode Simulator injects grant-all or deny-all and shows which tags re-fire, proving your gating works (clearly labelled; Reset restores the page). The headline signal is pre-consent violations: any tag that fired before the user answered the banner, shown on a red badge with the offending vendors named. COOKIES. First and third-party, with domain, party, Secure, HttpOnly, SameSite, and expiry. Cookies lasting over 13 months (the ePrivacy / CNIL ceiling) are flagged amber. Filter and search included. DATALAYER. All three data layers, labelled by source: GTM's window.dataLayer, the Adobe Client Data Layer (adobeDataLayer), and Adobe CEDDL (window.digitalData). Push layers show event name, relative time ("3s ago"), and expandable JSON; digitalData gets a live state card. PII-shaped keys are detected and highlighted (name, email, person IDs, address, DOB, postcode). A push that fires no tag is flagged "silent"; Persist keeps the log across navigations. Search, and copy the whole state as JSON in one click. STORAGE. Everything in localStorage and sessionStorage for the page, with the raw value shown like DevTools and a running size. Keys and values that look like personal data (name, email, person IDs, or a token carrying an address or DOB) are flagged, and one toggle filters to PII-only. Noisy framework caches collapse so the entries that matter surface first. Values never leave your browser. Filter by store or free-text. NETWORK DOMAINS. Every host the page contacted, including ones not matched to a known tag. Useful for spotting CDP, data-broker, or new-vendor activity. JOURNEY RECORDING The crawler can't reach pages behind a login, a completed checkout, or an admin dashboard. The extension can. Click Record, walk a real flow, click Stop. Every tag, cookie change, and dataLayer push is captured, segmented per step. Save locally as XLSX (no account) or send to your dashboard to sit alongside an automated full-site audit in one report. EXPORT CSV from any screen, scoped to the tab you're on: Tags, Cookies, DataLayer, Storage, or every section in one file. Filenames are <domain>-<screen>-<date>.csv. WHO IT'S FOR Privacy and compliance teams (GDPR, ePrivacy, CCPA). Marketing and analytics teams verifying GTM, Consent Mode v2, and the CMP before release. Agencies and consultants producing client-ready evidence. DPOs validating tagging without waiting on engineering. PRIVACY It walks the walk. The live tabs run entirely in your browser, with no telemetry and no usage tracking. Journey recording captures network requests, cookie metadata (name and domain only, never the value), and dataLayer/digitalData payloads; on Send to Dashboard, an allowlist strips values that look like personal data (email, phone, address, ID, DOB, postcode) before upload, so a site's PII never reaches our servers. Full policy: https://tagcompliance.com/privacy-policy.html NO ACCOUNT REQUIRED Live monitoring, CSV export, and local journey reports work without signing in. A free account is only needed to upload a journey or run a full automated audit. WORKS WITH Any site you can open in Chrome. No SDK, no tag-manager change, no cooperation from the site you're auditing. ABOUT A free companion to the TagCompliance platform, which adds full-site crawling (up to 10,000 pages), multi-session consent-mode validation, piggyback chain mapping, and an executive PDF. Learn more at https://tagcompliance.com. Support: https://tagcompliance.com/contact
5 out of 51 rating
Details
- Version1.8.44
- UpdatedJuly 15, 2026
- Size172KiB
- LanguagesEnglish (United Kingdom)
- Developer
- Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
TagCompliance: Tag, Cookie & Consent Audit has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
TagCompliance: Tag, Cookie & Consent Audit handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site