As of 13 August 2026, AI can only partly audit your website cookies for PECR compliance.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededpower-user
Who has to check ita professional
What the alternative costsA purpose-built alternative is iubenda, which generates and maintains privacy and cookie compliance documents.
If the audit is wrong, non-essential cookies may run before valid consent or your records may fail to describe what the site actually does.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, power-user skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the website in a clean browser session and record the URL, visible consent banner, banner choices and links to the cookie policy.
- Run a cookie and tracking scan before making a consent choice, then export the complete results with names, domains, providers, purposes and load times.
- Repeat the test after accepting, rejecting and withdrawing consent for each available category, and save screenshots, network logs and the consent-management-platform settings.
- Gather the current cookie policy, tag-manager or developer documentation, vendor descriptions and the current ICO PECR guidance relevant to cookies and similar technologies.
- Paste the evidence and guidance into the prompt, then ask the model to separate observed behaviour, missing evidence, possible issues and remediation actions.
- Compare every table entry with the scan export and test logs, correct any invented or mismatched item, then send the unresolved legal findings and evidence to a UK data-protection solicitor or qualified privacy professional before publishing changes.
Prompt
Act as a UK privacy-audit assistant. Prepare a preliminary audit of the website cookies and tracking technologies using only the evidence and guidance I provide. This is not professional advice and you must not give a final legal sign-off. Website address: [WEBSITE ADDRESS] Business and website purpose: [SHORT DESCRIPTION] UK visitors and services affected: [DESCRIPTION] Cookie scan export: [PASTE OR ATTACH THE FULL EXPORT] Consent-management-platform settings and banner text: [PASTE OR ATTACH] Test results before consent, after accepting, after rejecting and after withdrawing consent: [PASTE OR ATTACH] Relevant scripts, tags, vendors and cookie purposes: [PASTE OR ATTACH] Current ICO PECR guidance or other authoritative material to use: [PASTE OR ATTACH] Produce: 1. A table of every observed cookie or tracking technology, including name, domain, provider, purpose, category, duration, whether it is first-party or third-party, and the evidence for each entry. 2. A separate table of observations about what loads before consent, after consent, after rejection and after withdrawal. 3. A finding for each item marked supported observation, possible PECR issue, missing evidence or no issue apparent from the supplied evidence. Do not treat missing evidence as compliance. 4. The exact evidence needed to resolve every uncertain finding. 5. Practical remediation actions for the website owner, clearly separated from legal conclusions. 6. A short list of questions that a UK data-protection solicitor or qualified privacy professional must answer before the audit is relied on. Do not invent cookie names, vendors, purposes, consent records, legal citations or test results. Do not assume that a cookie is exempt merely because it is labelled necessary or analytics. Quote or identify the supplied guidance for each legal assessment, state when the material is insufficient, and distinguish technical observations from PECR conclusions.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot discover every request, tag or storage mechanism from a single page or an incomplete scan.
- AI cannot decide disputed PECR classifications without understanding the technology, purpose, consent flow and current regulatory interpretation.
- AI cannot confirm that the consent mechanism behaves consistently across browsers, devices, pages and later visits.
- AI cannot provide legal sign-off or take responsibility for the organisation's compliance decision.
- AI cannot keep the audit accurate when vendors, scripts, cookie purposes or regulatory guidance change.
What caps this at PARTLY: legal accountability, verification cost and real time truth.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 1 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 4 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT check my website cookies for PECR?
- It can organise a cookie scan, consent tests and policy text into a preliminary audit. It cannot establish compliance from a URL alone or provide legal sign-off, so a UK data-protection solicitor or qualified privacy professional should check serious or uncertain findings.
- Do I need consent for all cookies on my website?
- Do not assume that every cookie is treated the same way, or that a cookie is exempt because it is called necessary or analytics. Classify each technology by what it does and how it is used, then obtain a professional view on borderline cases.
- How do I check whether cookies load before consent?
- Test the site in a clean browser before accepting any choice and record the cookies, network requests, local storage and tags that appear. Repeat after accepting, rejecting and withdrawing consent, because one test does not show how the complete consent flow behaves.
- Is an AI cookie audit legally sufficient?
- No. An AI audit is evidence organisation and a technical review aid, not legal sign-off, and this is not professional advice. A serious case needs a UK data-protection solicitor or qualified privacy professional to assess the findings and carry the decision.
Nearby answers
- Can AI act as my business's data protection officer?NO
- Can AI build a data protection policy for my UK business?PARTLY
- Can AI check whether an AI tool creates UK GDPR risks for my business?NO
- Can AI check whether my international data transfers comply with UK GDPR?NO
- Can AI check my email marketing consent process under UK PECR?PARTLY
- Can AI check my privacy notice for UK GDPR compliance?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.