“Using a consent management platform doesn’t get you off the hook.”
DateCompany and regulatorWhat the action concernedAmount
Consent and opt-outs
Sep 2025Tractor SupplyCalifornia Privacy Protection AgencyThe site gave visitors no working way to opt out of sharing, including through Global Privacy Control.$1,350,000Source: Tractor Supply order
Sep 2025SHEINCNIL, FranceCookies were placed as soon as a visitor arrived, and new advertising cookies were placed after the visitor clicked Refuse all.€150,000,000Source: SHEIN decision
May 2025Todd SnyderCalifornia Privacy Protection AgencyThe consent tool's opt-out did not work for 40 days, and Global Privacy Control was not processed.$345,178Source: Todd Snyder order
Mar 2025American HondaCalifornia Privacy Protection AgencyIts privacy tool made opting out harder than opting in, and asked for more verification than an opt-out needs.$632,500Source: American Honda order
Health
Jul 2023BetterHelpFederal Trade CommissionShared visitors' email addresses and health questionnaire answers with Facebook, Snapchat, and others for advertising, after promising to keep them private.$7,800,000Source: BetterHelp order
Feb 2023GoodRxFederal Trade CommissionShared users' health information with Facebook, Google, and other companies without telling them.$1,500,000Source: GoodRx order
Visits 1 to 4Same page, same minute
Four visits to every page. The difference between them is the finding.
Glassrecord opens each page in a real browser from North America and Europe: before a choice, after Reject all, with Global Privacy Control on, and after Accept all. Results appear as each visit finishes.
/bookmaplestone-dental.com
1Before choosing
MMaplestone DentalServicesOur dentistsInsuranceBook a visit
New patients
Book your first cleaning
Exams, cleanings, and X-rays in one visit. Most insurance accepted.
NameEmailPreferred dateRequest appointment
Your privacyWe use cookies to run this site and, with your permission, to measure visits and show ads.
Reject allAccept all
MetaTikTokGoogle
Meta, TikTok, and Google Analytics load before the visitor answers the banner.
2After Reject all
MMaplestone DentalServicesOur dentistsInsuranceBook a visit
New patients
Book your first cleaning
Exams, cleanings, and X-rays in one visit. Most insurance accepted.
NameEmailPreferred dateRequest appointment
MetaGoogle
Meta still receives requests. Google Analytics still gets the page address. TikTok stops.
3With GPC on
MMaplestone DentalServicesOur dentistsInsuranceBook a visit
New patients
Book your first cleaning
Exams, cleanings, and X-rays in one visit. Most insurance accepted.
NameEmailPreferred dateRequest appointment
Your privacyWe use cookies to run this site and, with your permission, to measure visits and show ads.
Reject allAccept all
GPC sent
MetaTikTokGoogle
The browser sent the signal. Meta, TikTok, and Google Analytics ran anyway.
4After Accept all
MMaplestone DentalServicesOur dentistsInsuranceBook a visit
New patients
Book your first cleaning
Exams, cleanings, and X-rays in one visit. Most insurance accepted.
NameEmailPreferred dateRequest appointment
MetaTikTokGoogleHotjar
Every third party runs, as the visitor agreed.
Fig. 2The four visits to maplestone-dental.com/book, Sep 24, 2026, from 14:02 UTC. Example.
Which third parties ran on each visit to maplestone-dental.com/book
Third party
Before choosingBefore
After Reject allReject
With GPC onGPC
After Accept allAccept
MEMetaAdvertising
Ran without the visitor accepting
Ran without the visitor accepting
Ran without the visitor accepting
Ran after the visitor accepted
TTTikTokAdvertising
Ran without the visitor accepting
Did not run
Ran without the visitor accepting
Ran after the visitor accepted
GAGoogle AnalyticsAnalytics
Page address sent without consent
Page address sent without consent
Page address sent without consent
Ran after the visitor accepted
HJHotjarSession recording
Did not run
Did not run
Did not run
Ran after the visitor accepted
Ran without the visitor acceptingRan after the visitor acceptedDid not run
Google's cookieless pings still carry the page address, so they are a finding on any page: medium before a choice, high after a refusal or on a health page, where the address says what the visitor was reading.
Sep 24 to Sep 26One finding, start to close
Found, fixed, closed.
One finding on the booking page, from the request Meta received to the record that closed it.
Sep 24, 14:02 UTCFound3 of 6 pages
Every finding shows what the browser sent, and who put it there.
The request, the screenshot, the time, the region, the visitor's choice, and the tag, plugin, or snippet that caused it. A finding names the authority that concerns it and never states a legal conclusion.
For the owner
Your booking page sends each visit to Meta after the patient says no.
For the developer
fbevents.js, added by GTM tag 14, sent GET /tr/ 0.7 s after the click.
For counsel
Observed Sep 24, 2026, 14:02:09 UTC, from North America, after Reject all. The capture, screenshot, and request are kept with the finding.
GlassrecordMaplestone DentalFindingsExample
CriticalExample
Meta still receives requests after the visitor rejects
3 of 6 pages/book, /, /new-patientsNew on Sep 24
The banner offered Reject all. After the click, the page still sent the visit to Meta.
What the browser sent, 0.7 s after Reject all
GET https://www.facebook.com/tr/?id=1184203391&ev=PageView&dl=https%3A%2F%2Fmaplestone-dental.com%2Fbook&rl=&if=false&ts=1727186530118&fbp=fb.1.1727186529.84210391
The page address
The browser ID the pixel set
Who put it there
GTM-W7Q4ZP
Meta Pixel (all pages)
fbevents.js
facebook.com/tr
Where it matters
California Invasion of Privacy Act. Wiretap suits concern pixels that keep sending page visits to an advertiser after a visitor objects.
CCPA. The CPPA has fined sites whose opt-out did not stop sharing.
What closes it
Two scans in a row that visit /book, /, and /new-patients after Reject all and see no request to Meta.
Severity follows what was sent, to whom, and after which choice.
Sep 25, 10:40 UTCFixedPriya Raman
Fixes are grouped by who does the work.
Findings with one cause become one fix, with the steps written out. Each fix says who does it, how long it takes, what it changes in your marketing numbers, and which findings it closes. Send it as a link to a developer or your agency. They need no account.
Tag managerHold a tag, add a consent check
Consent platformHonor GPC, add Reject all
Site codeMove a snippet, mask a form
HostingHeaders, TLS, email records
Vendor consoleTurn off a vendor's feature
Coming soonWhen a fix has to wait, Protection can hold a tag on your pages.
GlassrecordMaplestone DentalFixesExample
1CriticalPRPriya RamanExample
Hold the tags until the visitor accepts
Tag managerAbout 20 minCloses 4 findings
Steps
In Google Tag Manager, open container GTM-W7Q4ZP and go to Tags.
Open Meta Pixel (all pages). Under Consent settings, choose Require additional consent for tag to fire and add ad_storage.
Do the same for TikTok base.
Open Google Analytics 4, choose the same setting, and add analytics_storage.
Submit and publish the container.
Mark fixed. Glassrecord scans the three pages again.
Effect on your numbers
Meta, TikTok, and Google Analytics stop counting visitors who reject or send Global Privacy Control. Visitors who accept are counted as before. Google Analytics can no longer estimate the visitors who refuse.
Closes
CriticalMeta still receives requests after the visitor rejects
HighMeta and TikTok load before consent
HighThe cookie _fbp is set after the visitor rejects
HighGoogle Analytics sends the page address without consent
Send to developerMark fixed, re‑scan
glassrecord.com/fix/8KQ2M4TD
Glassrecord
Hold the tags until the visitor accepts
maplestone-dental.com. Sent by Priya Raman. No account needed.
I made the change, scan again
Sep 26, 09:14 UTCClosedScan 2 of 2
A finding closes when a re‑scan proves it.
In Glassrecord, Mark fixed starts a scan. It does not close anything. A finding seen after Reject all needs two clean scans in a row. Then it goes into a closure record you can forward to a client, an insurer, or counsel.
Sep 24, 14:02Found on /book, /, and /new-patients
Sep 25, 10:40Priya Raman published the Tag Manager change
Sep 25, 10:49Scan 1 after the fix: not seen
Sep 26, 09:14Scan 2: not seen. Closed
GlassrecordMaplestone DentalClosure recordExample
GlassrecordClosure recordcls_8K2QM4TDExample
Meta still receives requests after the visitor rejects
maplestone-dental.com, 3 pages, visited after Reject all from North America
MMaplestone DentalServicesOur dentistsInsuranceContactBook a visit
New patients
Book your first cleaning
Exams, cleanings, and X-rays in one visit. Most insurance accepted.
NameEmailPreferred dateRequest appointment
GET facebook.com/tr/0.7 s after Reject all
Before, Sep 24Meta received the visit
MMaplestone DentalServicesOur dentistsInsuranceContactBook a visit
New patients
Book your first cleaning
Exams, cleanings, and X-rays in one visit. Most insurance accepted.
NameEmailPreferred dateRequest appointment
No request to Meta2 scans in a row
After, Sep 26No request to Meta after Reject all
Sep 24, 14:02Found on /book, /, and /new-patients
Sep 25, 10:40Priya Raman published the Tag Manager change
Sep 25, 10:49Scan 1 after the fix: not seen
Sep 26, 09:14Scan 2: not seen. Closed
Gone on re-scan2026-09-26 09:14 UTC
SHA-256 3f9a…c21e. Anyone holding the record can check it at glassrecord.com/verify. The page shows the code, the domain, the date, and the fingerprint, nothing else.
Weekly scans of maplestone-dental.com from Jul 20 to Oct 5: 12 scans, 4 with changes, 2 with a critical finding.
Tags change every week. Glassrecord keeps checking.
A marketer adds a pixel, a plugin updates, a vendor turns on a feature. Glassrecord scans your pages every week, compares each scan with the last, and tells you what is new.
A scan every weekEvery page you add, from each region your visitors come from.
What changed, by emailA new third party, a new tag, a page worth adding, or a finding that came back.
A finding that returns reopensWith the scan that saw it and the tag or file behind it.
Your logo and name on reports, PDFs, and client updates. Fix links stay on glassrecord.com.
Billing moves, access stays
When a client wants to pay for its own sites, move the billing to them. You keep access and the history.
Scan a prospect first
Run a free scan on a prospect's site before the first call. One free scan per domain every 30 days, whoever runs it. The report shows Glassrecord's name.
Same visits6 other findings
The same visits check security, email, and accessibility.
One report instead of four, with the same evidence and the same fixes.
HighEmail
maplestone-dental.com has no DMARC record
MediumHeaders
The site does not tell browsers to always use HTTPS
MediumTLS
TLS 1.0 or 1.1 is still enabled
HighAccessibility
4 images have no text alternative
MediumAutomated chat
The chat widget does not say it is automated
LowNotices
No page scanned links to a cookie policy, with 14 cookies set
6 questionsSecurity and data
What buyers ask first
Security, data processing, and where scans run: Security. Anything else: Contact.
Our banner vendor already scans our site.
Its scanner lists the cookies and tags it finds. Glassrecord records what each choice changed, names the tag that ignored it, and closes a finding only when a re-scan stops seeing it. Glassrecord sells no banner and no tag manager, so it is not grading its own work.
Our agency handles the website.
Send them the fix link: the steps, the evidence, and a button that starts the re-scan. They need no account.
Is this legal advice? Which laws, including HIPAA?
No. A finding says what the browser observed and which authority concerns it, never that a site violates or complies with a law. It cites the laws that cover both your markets and the region the scan ran from:
EuropeGDPR, the ePrivacy Directive, and UK GDPR
North AmericaThe CCPA and other state privacy laws, Washington's My Health My Data Act, the California Invasion of Privacy Act, COPPA, PIPEDA, and Quebec's Law 25
HIPAA can be cited too, but a 2024 ruling vacated the HHS guidance on public pages (American Hospital Association v. Becerra), so a finding on a public booking page cites state law, as the example does.
What does a scan see, and what does it miss?
It visits from outside, the way a visitor arrives, so nothing is installed on Shopify, WordPress, Webflow, or a custom site. A finding comes only from a request, cookie, or page the browser recorded. Analytics that keeps nothing on the device, such as Cloudflare Web Analytics, is shown but is not a consent finding. Google's cookieless pings still carry the page address, so they are a finding on any page: medium before a choice, high after a refusal or on a health page, where the address says what the visitor was reading. A scan does not see pages behind a sign-in, pages you have not added, or changes between scans.
Will scans or fixes change our marketing data?
Each scan visits a page four times, from each region you scan. On a site that sends data before consent, every visit can reach your analytics and ad tools, so our crawler page lists the scanner's addresses and user agent and how to exclude them where your tools allow. Each fix says what it changes in your numbers: holding a tag until the visitor accepts stops counting visitors who refuse.
What do you keep from my site?
Requests, screenshots, and the names of cookies and storage keys, never their values. A free scan's report is deleted after 30 days. On a paid plan, captures are kept 90 days after the last report or finding that uses them, and evidence a closure record cites is kept as long as the record.
Scan one page free.
The first results arrive while the other visits run.