The Compliance Tools page runs two automated checks against your own site and keeps every result as history, so you can see whether your setup improves over time. You will find it in your dashboard under Compliance > Compliance Tools for each site.
The page opens on a Dashboard tab summarising both tools - latest score, last run, and how many of the day's runs are left - alongside a short list of guides. The Consent Mode v2 and GDPR Scan tabs run each check and show its full report; the History tab lists every past run.
Both checks visit your site's domain exactly as it is saved in Kukie.io - you do not enter a URL. Each check loads your live site in a real browser, so it reflects what your visitors actually get.
The Google Consent Mode v2 check
This check verifies your Google Consent Mode v2 setup:
- Consent defaults - whether a consent default command fires before any Google tags load. This ordering is the foundation of a correct setup.
- All seven parameters - including
ad_user_dataandad_personalization, which Google requires for advertising features in the EEA. - Configuration -
wait_for_update, region scoping,ads_data_redactionandurl_passthrough. - Google Tag Manager and gtag.js - whether your Google tags are present and wired to consent.
Reading the score
The score runs from 0 to 100. Critical problems (such as missing defaults for a required parameter) cost the most, warnings less, informational notes very little. The overall status tells you where you stand at a glance:
- Implemented - Consent Mode v2 is set up correctly.
- Needs attention / Partially implemented - Consent Mode is present but something should be fixed. Open the issues list for the exact reason.
- Not implemented - no Consent Mode was found. If you use Google Ads or Google Analytics, enable Google Consent Mode v2 in your banner settings.
The GDPR compliance scan
This scan audits your site across six categories, each scored separately:
- Cookie consent banner (25 points) - is a banner present, with both an Accept and a Reject option, and no pre-ticked checkboxes?
- Pre-consent cookies (25 points) - are non-essential cookies set before the visitor has made a choice?
- Third-party trackers (20 points) - do analytics or marketing scripts load before consent?
- HTTPS & security (10 points) - HTTPS and recommended security headers.
- Privacy policy (10 points) - is a privacy policy present, and does it cover the expected GDPR topics?
- Google Consent Mode (10 points) - if you use Google tags, are they consent-aware?
Reading the grade
The combined score maps to a grade: A (90-100) strong compliance, B (75-89) mostly compliant with minor issues, C (50-74) significant gaps, D and F serious risks. Open each category card to see exactly what was found and which issues cost points - each card also explains what the category measures and how it is weighted.
How the audit verifies a Kukie banner
Kukie's banner renders inside a closed shadow root - deliberately sealed off from the page, which is what makes it tamper-resistant, but it also means an external audit cannot click around inside it. Instead, the audit reads the configuration your CDN bundle embeds in the page: the same flags that decide whether the Reject All and Preferences (Customise) buttons render. A fully enabled Kukie banner therefore scores the full 25/25; if either button is switched off in your Banner Editor, the audit reports that honestly and the Recommended actions point you to the exact setting.
How the privacy policy check works
The scan looks for a policy four ways: the privacy-policy link configured in your Kukie banner texts, links anywhere on the page (matched in every major EU language, including for example "Политика за лични данни" or "Datenschutz"), your sitemap, and direct probes of common paths such as /privacy-policy or /politika-za-lichni-danni. If your site has a policy but the scan reports none, set its URL in Banner Editor > Texts and add a footer link. If you have no policy yet, the site's Legal Documents page can generate one for you.
History
Every run is saved to the site's history - unlike the free public tools on kukie.io, which keep nothing tied to you. The History tab shows both tools together, newest first, with the score and outcome of each run. Click View on any completed entry to open its full report again. Organisation owners and admins can delete entries one at a time, or tick several and use Delete Selected.
A few practical notes:
- Each tool can run 10 times per site per day, and one check per tool runs at a time.
- Anyone with access to the site can run checks and view results. Deleting a history entry requires an organisation owner or admin, like other destructive actions.
- History is kept until you delete it. Deleting a site removes its history with it.
- A check usually finishes in under two minutes. If your firewall blocks automated visitors, the check may fail - the result will say so.
