Most cookie compliance conversations focus on the tools a business intentionally deploys: analytics platforms, advertising pixels, personalisation engines. What receives far less attention is the secondary layer of data collection introduced by third-party scripts — code loaded by other scripts, by tag management systems, or by embedded content, often without a direct decision having been made to include it.
A single marketing or analytics tag can trigger dozens of additional requests from third-party domains. Each of these may set its own cookies, collect its own data, and operate under its own terms — none of which were explicitly reviewed or consented to by your organisation or your users. This is a compliance gap that audits based on self-declaration alone rarely catch.
Why This Matters Under GDPR
GDPR places responsibility on data controllers to understand and account for all processing that occurs on their behalf. If a third-party script sets a tracking cookie before consent is given, or outside the categories your banner describes, the liability sits with the website operator. Regulators have increasingly focused enforcement on exactly these kinds of uncontrolled script behaviours, particularly where advertising technology is involved.

The Importance of Dynamic Scanning
Identifying third-party cookie activity requires active scanning of your website in a live browser environment — not a manual review of your tag manager configuration. Automated scanners capture what actually fires, including scripts triggered by other scripts, and map each cookie to its source, category, and persistence. This gives a realistic picture of your compliance exposure rather than an assumed one.
How Digital Analytics Lab Helps
Digital Analytics Lab conducts comprehensive cookie audits using dynamic scanning tools that capture the full picture of what fires on your website, including secondary and tertiary script activity. We map every cookie to its source and category, identify gaps between what your banner declares and what actually runs, and provide a clear remediation plan — ensuring your compliance position reflects reality, not assumptions.


