PARTLY

As of 13 August 2026, AI can only partly audit your website cookies for PECR compliance.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededpower-user

Who has to check ita professional

What the alternative costsA purpose-built alternative is iubenda, which generates and maintains privacy and cookie compliance documents.

If the audit is wrong, non-essential cookies may run before valid consent or your records may fail to describe what the site actually does.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, power-user skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the website in a clean browser session and record the URL, visible consent banner, banner choices and links to the cookie policy.
    2. Run a cookie and tracking scan before making a consent choice, then export the complete results with names, domains, providers, purposes and load times.
    3. Repeat the test after accepting, rejecting and withdrawing consent for each available category, and save screenshots, network logs and the consent-management-platform settings.
    4. Gather the current cookie policy, tag-manager or developer documentation, vendor descriptions and the current ICO PECR guidance relevant to cookies and similar technologies.
    5. Paste the evidence and guidance into the prompt, then ask the model to separate observed behaviour, missing evidence, possible issues and remediation actions.
    6. Compare every table entry with the scan export and test logs, correct any invented or mismatched item, then send the unresolved legal findings and evidence to a UK data-protection solicitor or qualified privacy professional before publishing changes.

    Prompt

    Act as a UK privacy-audit assistant. Prepare a preliminary audit of the website cookies and tracking technologies using only the evidence and guidance I provide. This is not professional advice and you must not give a final legal sign-off.
    
    Website address: [WEBSITE ADDRESS]
    Business and website purpose: [SHORT DESCRIPTION]
    UK visitors and services affected: [DESCRIPTION]
    Cookie scan export: [PASTE OR ATTACH THE FULL EXPORT]
    Consent-management-platform settings and banner text: [PASTE OR ATTACH]
    Test results before consent, after accepting, after rejecting and after withdrawing consent: [PASTE OR ATTACH]
    Relevant scripts, tags, vendors and cookie purposes: [PASTE OR ATTACH]
    Current ICO PECR guidance or other authoritative material to use: [PASTE OR ATTACH]
    
    Produce:
    1. A table of every observed cookie or tracking technology, including name, domain, provider, purpose, category, duration, whether it is first-party or third-party, and the evidence for each entry.
    2. A separate table of observations about what loads before consent, after consent, after rejection and after withdrawal.
    3. A finding for each item marked supported observation, possible PECR issue, missing evidence or no issue apparent from the supplied evidence. Do not treat missing evidence as compliance.
    4. The exact evidence needed to resolve every uncertain finding.
    5. Practical remediation actions for the website owner, clearly separated from legal conclusions.
    6. A short list of questions that a UK data-protection solicitor or qualified privacy professional must answer before the audit is relied on.
    
    Do not invent cookie names, vendors, purposes, consent records, legal citations or test results. Do not assume that a cookie is exempt merely because it is labelled necessary or analytics. Quote or identify the supplied guidance for each legal assessment, state when the material is insufficient, and distinguish technical observations from PECR conclusions.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What caps this at PARTLY: legal accountability, verification cost and real time truth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output1
Inputs1
Verification1
Liability0
Effort delta1
Total4 / 10

FAQ

Can ChatGPT check my website cookies for PECR?
It can organise a cookie scan, consent tests and policy text into a preliminary audit. It cannot establish compliance from a URL alone or provide legal sign-off, so a UK data-protection solicitor or qualified privacy professional should check serious or uncertain findings.
Do I need consent for all cookies on my website?
Do not assume that every cookie is treated the same way, or that a cookie is exempt because it is called necessary or analytics. Classify each technology by what it does and how it is used, then obtain a professional view on borderline cases.
How do I check whether cookies load before consent?
Test the site in a clean browser before accepting any choice and record the cookies, network requests, local storage and tags that appear. Repeat after accepting, rejecting and withdrawing consent, because one test does not show how the complete consent flow behaves.
Is an AI cookie audit legally sufficient?
No. An AI audit is evidence organisation and a technical review aid, not legal sign-off, and this is not professional advice. A serious case needs a UK data-protection solicitor or qualified privacy professional to assess the findings and carry the decision.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.