Case Files

What happens when this goes wrong, and when it doesn't.

The record below is real: sourced regulatory enforcement actions against other companies, not our own client work. Below that, two illustrative examples show what an audit looks like when it resolves the same failure before a regulator finds it.

The record

Real cases. Real fines. Not hypothetical.

Every one of these started with a business that assumed its cookie banner already covered it.

Retail — farm & rural supply

Tractor Supply Co.

California Privacy Protection Agency · September 2025$1.35M fineWhat was found

Its opt-out link did not actually stop data sharing, and the site ignored the Global Privacy Control signal until mid-2024.

The takeaway

A working opt-out link and a working one are not the same thing. This is exactly what our audit tests for, not just whether the link exists.

Fashion e-commerce

Shein

CNIL, France · September 2025€150M fineWhat was found

Advertising cookies fired before visitors interacted with the consent banner, and Reject All did not stop new tracking.

The takeaway

Pre-consent blocking has to happen at the network level, not the banner level. This is the exact failure our banner product is built to prevent.

Apparel retailer

Todd Snyder

California Privacy Protection Agency · May 2025$345K fineWhat was found

A mid-size clothing retailer mishandled opt-out requests the same way most small sites still do today.

The takeaway

This wasn't a large enterprise. Mid-size retailers are squarely in scope, and this is the size of business we audit most often.

Sourced from public regulatory enforcement announcements. These are third-party enforcement actions cited for context, not engagements we performed.

How an audit resolves this

Two examples of what our own engagements look like.

Composite examples built from patterns we see repeatedly, not a specific named client.

Composite example — not an actual client

Mid-size DTC apparel retailer

What was found

Meta Pixel and TikTok Pixel both fired on page load, before the consent banner had been interacted with. No signed data processing agreement existed with either vendor.

What was fixed

Rebuilt the tag manager so every non-necessary tracker is consent-gated, tested Reject in a real browser (not just read from source), and got both vendor agreements signed.

Outcome

Passed a follow-up scan with zero before-consent findings, moved to the Banner + Scanner subscription.

Composite example — not an actual client

Regional healthcare services site

What was found

Full audit underway: initial scan surfaced six third-party trackers and no visible consent tool. Vendor inventory and opt-out testing in progress.

What was fixed

Not yet — findings are still being confirmed before we scope the fix.

Outcome

Full report and prioritized fix list expected within the audit's 1–2 week window.