Why trackers still fire before consent, and how to stop them
The CIPA problem, how tag managers hide the source, and what auto-blocking actually does.
Key takeaways
- A cookie banner does not block anything by itself. If pixels are hard-coded, loaded by a tag manager or injected by a plugin, they usually fire before the visitor clicks.
- Tag managers hide the source: the page shows one container script, and the Meta, TikTok or ad pixels load from inside it.
- In California, pixels and session replay that run without consent have fueled a wave of lawsuits under the Invasion of Privacy Act (CIPA), which allows statutory damages of $5,000 per violation.
- You can check your own site in five minutes with the browser's network tab. Fixing it takes consent-aware tag triggers, Consent Mode, and auto-blocking for everything else.
The problem in one sentence
Many websites show a consent banner and load their trackers at the same time, so by the time a visitor clicks Reject, the Meta pixel, Google Ads tag and session recorder have already sent data.
That gap is invisible to the business. The banner looks right, the privacy policy reads well, and nobody opens the browser's developer tools to watch what actually leaves the page. Regulators and plaintiff firms do.
Why trackers fire before the visitor chooses
There are five common causes, and most sites have more than one.
- Hard-coded scripts. A pixel pasted into the site header years ago runs on every page load, before any banner code has a chance to act.
- Tag manager triggers. Tags set to fire on All Pages or on page view run as soon as the container loads, regardless of consent.
- Platform integrations. Store apps, WordPress plugins and marketing integrations inject their own pixels, often without appearing in your tag manager at all.
- Embeds. Video players, maps, chat widgets and review carousels set cookies and call home the moment they render.
- Load order. A banner that loads asynchronously or after other scripts cannot stop what has already executed.
The fix is different for each cause, which is why a single setting rarely solves it.
How tag managers hide the source
Google Tag Manager and similar tools load one container script and then insert every configured tag from inside it. If you view the page source, you see the container. The Meta pixel, the TikTok pixel and the LinkedIn Insight Tag only appear at runtime.
That creates two problems. A scanner that only reads HTML reports the site as clean. And a blocker that only matches script tags in the page cannot tell the container apart from the tags inside it: block the container and you lose every tag, including the ones that are allowed.
Tag managers do have tools for this. Google Tag Manager supports consent settings on each tag (opens in a new tab), so a tag can require a consent type before it fires. They only work if every tag is configured, including the ones added by someone who left the company two years ago.
The legal exposure
In Europe
Under the ePrivacy Directive and the GDPR, non-essential trackers need prior consent. A tracker that fires before the visitor chooses is unlawful even if the banner is perfect. Our guide to GDPR cookie consent covers the rules in full.
In California
The California Invasion of Privacy Act was written for phone wiretaps, but plaintiffs now use it against websites. Claims usually rely on two sections:
- Penal Code section 631 (opens in a new tab), the wiretapping provision, against chat widgets and session replay tools that capture what visitors type or do.
- Penal Code section 638.51 (opens in a new tab), which restricts pen register and trap and trace devices, against pixels and trackers that collect identifying information about visitors. Private suits under this section are set to end if SB 690 becomes law (see below).
The draw is section 637.2 (opens in a new tab), which allows statutory damages of $5,000 per violation without proof of actual harm. Courts have split on many of these claims. In August 2026 the Legislature passed SB 690 (opens in a new tab), which, if the Governor signs it, lets only the Attorney General bring section 638.51 claims over website and app tracking from January 1, 2027, including in many pending cases. Section 631 claims are unaffected. Check the current status with counsel. The consistent defense under either section is consent obtained before any tracking starts.
Under U.S. privacy laws
California's CCPA treats sharing data with ad platforms as something consumers can opt out of, and requires businesses to honor Global Privacy Control (opens in a new tab) signals. In 2022 the California Attorney General settled with Sephora for $1.2 million (opens in a new tab) in part for failing to process those signals. See our CCPA page for the U.S. rules.
Check your own site in five minutes
You do not need special tools. Use a private browser window so no earlier consent is stored.
- Open the site in a private window and open the developer tools on the Network tab before the page finishes loading.
- Do not click the banner.
- Filter requests for common tracker hosts: facebook.com/tr, google-analytics.com, googleadservices.com, doubleclick.net, analytics.tiktok.com, px.ads.linkedin.com, clarity.ms, hotjar.
- Check the Application tab for cookies such as _ga, _gcl_au, _fbp and _ttp.
- Click Reject all, reload, and repeat. Nothing marketing-related should appear.
- If you serve Europe, repeat using a VPN in an EU country, since your banner may behave differently by region.
If step 3 shows requests before you touched the banner, you have trackers firing before consent. The request's initiator column shows which script started it, which is usually the fastest way to find the tag or plugin responsible.
What auto-blocking actually does
Auto-blocking is a script that loads before your other scripts and holds known trackers until the visitor has consented to their category. Good implementations do four things:
- Recognize trackers by where they load from, including ones inserted dynamically by a tag manager or plugin.
- Hold each one in a waiting state instead of letting it run, then release it when its category is accepted.
- Send Google Consent Mode (opens in a new tab) signals so Google tags adjust to the choice rather than being blocked outright.
- Remember the choice and apply it on every page.
It has limits worth knowing. It works best when it loads first, ahead of the tag manager. It recognizes known vendors, so an obscure or self-hosted tracker may need a manual rule. And server-side tagging, where data is sent from your server rather than the browser, is outside what any browser script can see.
The ComplyMo cookie manager combines auto-blocking with Consent Mode v2 and a region-aware banner, and it flags trackers it sees firing without consent so you can fix the source instead of guessing.
A fix list, in order
- Load the consent script first, synchronously, at the top of the head, before the tag manager.
- Remove hard-coded pixels from theme files and move them into the tag manager, or let auto-blocking hold them.
- Add consent requirements to every tag in your tag manager, starting with advertising and session replay.
- Turn on Consent Mode v2 for Google tags.
- Audit plugins and apps for their own pixels and disable the ones you do not use.
- Gate embeds such as video players and chat until the relevant category is accepted, or use privacy-enhanced embed modes.
- Re-test after every change using the five-minute check above, and keep a note of what you found and fixed.
Want the checking done continuously? Start a free trial and ComplyMo will alert you when a tracker fires without consent on any of your sites.
This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your obligations with counsel.

