What happens when this goes wrong, and when it doesn't.
The record below is real: sourced regulatory enforcement actions against other companies, not our own client work. Below that, two illustrative examples show what an audit looks like when it resolves the same failure before a regulator finds it.
Real cases. Real fines. Not hypothetical.
Every one of these started with a business that assumed its cookie banner already covered it.
Tractor Supply Co.
$1.35M fineWhat was foundIts opt-out link did not actually stop data sharing, and the site ignored the Global Privacy Control signal until mid-2024.
A working opt-out link and a working one are not the same thing. This is exactly what our audit tests for, not just whether the link exists.
Shein
€150M fineWhat was foundAdvertising cookies fired before visitors interacted with the consent banner, and Reject All did not stop new tracking.
Pre-consent blocking has to happen at the network level, not the banner level. This is the exact failure our banner product is built to prevent.
Todd Snyder
$345K fineWhat was foundA mid-size clothing retailer mishandled opt-out requests the same way most small sites still do today.
This wasn't a large enterprise. Mid-size retailers are squarely in scope, and this is the size of business we audit most often.
Sourced from public regulatory enforcement announcements. These are third-party enforcement actions cited for context, not engagements we performed.
Two examples of what our own engagements look like.
Composite examples built from patterns we see repeatedly, not a specific named client.
Mid-size DTC apparel retailer
What was foundMeta Pixel and TikTok Pixel both fired on page load, before the consent banner had been interacted with. No signed data processing agreement existed with either vendor.
What was fixedRebuilt the tag manager so every non-necessary tracker is consent-gated, tested Reject in a real browser (not just read from source), and got both vendor agreements signed.
Passed a follow-up scan with zero before-consent findings, moved to the Banner + Scanner subscription.
Regional healthcare services site
What was foundFull audit underway: initial scan surfaced six third-party trackers and no visible consent tool. Vendor inventory and opt-out testing in progress.
What was fixedNot yet — findings are still being confirmed before we scope the fix.
Full report and prioritized fix list expected within the audit's 1–2 week window.