Home · Business · Legal & Compliance · Data protection & GDPR
As of 13 August 2026, AI can only partly check your cookie banner for UK compliance.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsTermly generates privacy policies, terms and cookie consent that stay updated.
If this goes wrong, non-essential cookies may run before valid consent or the banner may misrepresent the purposes, leaving your organisation responsible for the breach.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the live website in a private browser window and save screenshots of the first cookie banner, its settings panel, its refusal path and its withdrawal control.
- Open the browser developer tools and record which cookies, local-storage items, pixels and network requests appear before consent, after refusal and after each consent category is accepted.
- Export the consent-management-platform configuration and cookie scan, including purposes, vendors, durations, default states, consent records and withdrawal settings.
- Gather the linked cookie notice and privacy notice, then paste the banner text, screenshots, configuration, scan and site context into the prompt.
- Ask the model to produce the evidence-based issue list, source citations, missing-evidence list and prioritised corrections without filling gaps from assumptions.
- Compare each cited requirement with the current ICO guidance, rerun the browser tests after changes and send unresolved or high-risk findings to your solicitor or data protection specialist before publishing.
Prompt
Review the following cookie banner and consent implementation for a UK website against the UK GDPR and PECR, using current ICO guidance where available. This is a compliance review, not a declaration that the site is legally compliant. Website purpose and audience: [DESCRIBE THE WEBSITE, ITS USERS AND ANY AGE OR VULNERABLE-USER CONSIDERATIONS] Banner wording and screenshots: [PASTE THE FULL BANNER TEXT AND ATTACH SCREENSHOTS] Consent-management-platform settings: [PASTE THE RELEVANT SETTINGS, INCLUDING DEFAULTS, CATEGORIES, PURPOSES, VENDOR LISTS, WITHDRAWAL METHOD AND CONSENT-LOGGING DETAILS] Cookies and similar technologies found on the live site: [PASTE THE COOKIE SCAN OR BROWSER-DEVELOPER-TOOLS EXPORT, INCLUDING NAME, DOMAIN, PURPOSE, PROVIDER, DURATION AND WHETHER EACH ITEM LOADS BEFORE CONSENT] Privacy and cookie information linked from the banner: [PASTE THE RELEVANT TEXT OR LINKS] Review requirements: 1. Separate strictly necessary technologies from non-essential analytics, advertising, personalisation and other technologies. 2. Check whether non-essential technologies appear to be blocked until valid consent, whether consent is freely given and specific, and whether refusing or withdrawing consent is as easy as accepting it. 3. Check the wording, button labels, category descriptions, purposes, vendor information, retention details and links for misleading or missing information. 4. Identify evidence that is missing and state exactly what live-site test would establish it. 5. For every finding, quote the relevant banner or implementation evidence, state the issue, explain the risk, and give a practical correction. 6. Distinguish clear issues, likely issues and questions requiring a solicitor or data protection specialist. Do not invent facts, cookies, vendors, legal sources or test results. 7. Cite the specific ICO guidance or other official UK source used for each legal conclusion, and say when a conclusion depends on facts that have not been supplied. 8. End with a prioritised list of changes and a separate list of tests I must run before publishing. Do not call the banner compliant merely because the wording looks acceptable. Do not treat this review as professional advice.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot establish what the live site actually sends or stores unless you perform and supply the browser tests.
- AI cannot decide disputed questions about legitimate interests, consent validity or the precise purpose of a technology without complete business and technical context.
- AI cannot transfer responsibility for the banner or certify that your organisation complies with UK GDPR and PECR.
- AI can miss changes in the consent-management platform, tag manager or third-party scripts after the review.
- AI cannot replace a solicitor or data protection specialist where the consequences of an incorrect compliance decision are serious.
What caps this at PARTLY: legal accountability, verification cost and judgement under ambiguity.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 2 |
| Verification | 1 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 6 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT check whether my cookie banner is UK compliant?
- Partly. It can review the wording, supplied cookie list and consent settings against UK GDPR and PECR, but it cannot prove what the live site does or accept responsibility for the result. This is not professional advice, and a serious case needs a solicitor or data protection specialist.
- What should a UK cookie banner include?
- It should explain the relevant purposes and give users a genuine choice about non-essential cookies and similar technologies. The exact requirements depend on what your site does, so check the banner, the linked information and the live technical behaviour together.
- Can AI tell if cookies load before consent?
- Not from banner wording alone. You need to test the live site with browser developer tools or a cookie scanner, then give the evidence to the model for interpretation.
- Do I need a solicitor to check my cookie banner?
- Not every wording or configuration change needs a solicitor, but your organisation remains responsible for the decision. Use a solicitor or data protection specialist for disputed consent questions, high-risk tracking, enforcement concerns or a review you need to rely on formally.
Nearby answers
- Can AI check my privacy notice for UK GDPR compliance?PARTLY
- Can AI create a data protection audit for my small business?NO
- Can AI draft a data processing agreement for my business?NO
- Can AI write a cookie policy for my UK business?PARTLY
- Can AI act as my business's data protection officer?NO
- Can AI check whether a supplier meets UK GDPR requirements?NO
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.