Skip to main content

How a European Event Brand Reviewed Website Tracking and Consent Behavior Across 10 Domains

A European event and media organization operating ten interconnected websites needed a clearer technical view of how cookies, pixels, analytics tools, session-replay technologies, and third-party requests behaved across its digital ecosystem.

Auditzo conducted a multi-domain website tracking review covering shared tag-management infrastructure, consent-banner behavior, regional website journeys, and selected third-party technologies. The engagement produced an evidence-backed findings register, a cross-domain technology inventory, developer-focused remediation guidance, and a structured verification workflow.

By Auditzo Updated August 03, 2026

Scope note: This case study has been anonymized. Client-identifying details, screenshots, request values, account identifiers, and other sensitive technical information have been withheld. Auditzo documents technical website behavior and does not provide legal advice, determine legal violations, or certify compliance.

Case Study at a Glance

  • Organization: European event and media brand
  • Digital estate: 10 interconnected public websites
  • Visitor contexts reviewed: France, Germany, and selected United States traffic scenarios
  • Technical focus: Cookies, tracking pixels, analytics, session-replay tools, tag-manager behavior, consent sequencing, and third-party requests
  • Teams involved: Development, marketing operations, privacy, and business stakeholders
  • Auditzo output: Technical evidence, cross-domain findings, remediation priorities, and follow-up verification guidance

The engagement required more than a single automated scan. The organization needed a structured review of multiple domains, representative pages, shared infrastructure, and consent-related website behavior.

Organizations requiring similar multi-page or multi-domain investigation can review Auditzo's Manual Evidence Audit. For a transparent explanation of automated and manual testing boundaries, see the Auditzo audit scope and limitations.

The Multi-Site Website Tracking Challenge

The organization used its websites to support event registrations, digital content, hybrid experiences, sponsor campaigns, attendee engagement, and marketing analytics.

Over time, different internal teams, agencies, campaign managers, and technology vendors had introduced scripts and tags across the ten-domain estate. Several websites shared templates, tag-manager containers, consent-management configurations, and marketing integrations.

The resulting environment included technologies associated with:

  • Web analytics and audience measurement
  • Advertising and conversion tracking
  • Social-media pixels
  • Session replay and behavioral analytics
  • Cross-device or audience-matching services
  • Sponsor and campaign tracking
  • Consent management
  • Tag management
Diagram showing 10 websites connected to shared templates, consent management, tag management, custom scripts, and external tracking technologies.
Shared templates, consent controls, and tag configurations can influence multiple domains across the same digital estate.

These technologies are commonly used across modern digital platforms. Their presence alone does not establish that a website is operating unlawfully.

The technical challenge was whether the organization could reliably answer practical questions such as:

  • Which technologies appeared across each domain?
  • Which third-party requests occurred during initial page load?
  • Did the website behave differently after an Accept or Reject choice?
  • Were consent rules applied consistently across shared templates?
  • Could tag-manager triggers bypass the intended consent workflow?
  • Were regional and device-specific implementations behaving consistently?
  • Which internal team or external vendor owned each technology?

Without a shared technical inventory and repeatable evidence workflow, the organization could not easily distinguish expected website behavior from configurations requiring further development, privacy, or legal review.

Why Multi-Domain Privacy Reviews Are More Complex

A single-domain review can already involve multiple scripts, cookies, browser-storage mechanisms, vendors, and user journeys. Across ten websites, those dependencies multiply.

Shared infrastructure can spread one configuration pattern widely

When several websites use the same theme, container, plugin, component, or consent-management configuration, one implementation decision can affect multiple domains.

This creates efficiency when the shared configuration is correct, but it also means that an outdated trigger, directly embedded script, or sequencing problem can appear across several websites.

Different teams may control different parts of the stack

Developers may control page templates, marketing teams may manage tag containers, agencies may introduce campaign scripts, and privacy teams may oversee consent categories and disclosures.

Without a shared inventory, no individual team may have a complete picture of the website's tracking environment.

Regional behavior may not be consistent

A consent banner, script, campaign, or website component may behave differently depending on:

  • Visitor region
  • Browser and device
  • Language
  • Campaign source
  • Website experiment or A/B test
  • Logged-in or logged-out status
  • Consent history stored in the browser

Testing one desktop session from one location does not establish how every visitor will experience the website.

Website behavior changes over time

New campaigns, plugins, embeds, sponsor tags, and container updates can modify website behavior after an audit has been completed.

This makes documented ownership, release controls, repeatable testing, and appropriately scoped monitoring especially important for multi-site organizations.

Auditzo explains its evidence-capture and interpretation process in the website audit methodology.

Audit Scope and Technical Review Method

Auditzo structured the engagement around observable website behavior rather than relying only on privacy-policy wording, consent-platform settings, or a list of installed plugins.

The approved review scope included representative public pages and selected visitor journeys across the ten-domain environment.

Comparison of initial, Reject, and Accept consent states across cookies, browser storage, third-party requests, scripts, and screenshot context.
Consent-state testing compares observable website behavior before interaction and after Reject or Accept choices.

The purpose of this comparison is to document observable technical differences between consent journeys. It does not determine whether the implementation satisfies every applicable legal requirement.

1. Initial Page-Load Review

Auditzo reviewed what appeared to load, store, and connect during the initial browser observation window before relying on any consent interaction.

The initial-state review considered:

  • Cookies visible to the browser
  • Browser-storage indicators
  • Third-party request destinations
  • Analytics, advertising, and session technologies
  • Tag-manager activity
  • Consent-management platform initialization
  • Request timing and sequence

An initial-load observation provides a useful technical baseline. It does not, by itself, establish how the website behaves after every possible consent choice or visitor interaction.

Where the website journey and approved scope allowed it, Auditzo compared observable behavior across separate consent states, such as:

  • No-interaction or initial state
  • Reject journey
  • Accept journey

This comparison helped the technical team determine whether the visitor's choice produced the intended changes in cookies, scripts, browser storage, and third-party request activity.

A consent-state comparison documents technical differences. It does not, by itself, determine whether a configuration satisfies every applicable legal requirement.

Organizations focused specifically on ecommerce consent behavior can also review Auditzo's cookie consent audit for ecommerce websites.

3. Network and Request-Level Evidence

Auditzo reviewed browser-network and HAR-based evidence to identify observable third-party connections and understand when selected services appeared during the test journey.

Relevant evidence could include:

  • Request destination and hostname
  • Request timing
  • Page URL and referrer context
  • Observable query-string or payload fields
  • Cookie and identifier references
  • Redirect or synchronization activity
  • Associated vendor or technology category

Screenshots were used to document visible page and consent-banner context. Network records were used separately to document browser request activity.

A screenshot alone was not treated as proof of a particular data transmission. Similarly, an isolated request required review in the context of its timing, purpose, associated technology, consent state, and surrounding website journey.

4. Tag Manager and CMP Sequence Review

The review examined whether the consent-management platform and tag-management setup appeared to operate in the intended order.

Auditzo looked for patterns such as:

  • Tags initialized before the consent tool was ready
  • Triggers that did not reference an appropriate consent state
  • Custom HTML or directly embedded scripts outside the main control flow
  • Duplicate or legacy tags
  • Different implementations across shared templates
  • Mobile or region-specific behavior differing from the primary desktop journey

5. Cross-Domain Comparison

Rather than treating each website as an unrelated scan, Auditzo compared recurring technologies, containers, consent patterns, and implementation differences across the domain group.

This made it easier to distinguish between:

  • A site-specific implementation issue
  • A shared configuration pattern
  • A legacy technology present on selected domains
  • A region-specific variation
  • A campaign or vendor integration requiring ownership review
Six-step Auditzo workflow covering scope definition, initial-state capture, consent-state comparison, evidence correlation, remediation planning, and verification.
Auditzo separates technical observation, evidence correlation, remediation planning, and follow-up verification into defined stages.

Key Technical Patterns Documented During the Review

The evidence review identified recurring implementation patterns that required technical, operational, privacy, or legal-team attention.

Consent controls were not applied consistently across the full estate

Some reviewed pages and templates did not appear to apply the same consent behavior consistently.

The differences were associated with variations in:

  • Website templates
  • Trigger rules
  • Directly embedded scripts
  • Plugins and integrations
  • Shared tag-management configurations

Some third-party technologies appeared early in the page lifecycle

Selected analytics, advertising, audience, and behavioral technologies appeared during the initial page-load sequence on reviewed pages.

The finding did not automatically classify those requests as legal violations. It gave the organization and its advisers a factual starting point for determining:

  • Why the technology loaded
  • Which team or vendor controlled it
  • Whether the behavior matched the intended consent design
  • Whether disclosures and controls required further review
  • Whether additional regional or consent-state testing was needed

Tag-manager configuration increased the risk of inconsistent behavior

Some tags were controlled through shared containers, while others were introduced through templates, plugins, custom HTML, or campaign-specific integrations.

This made it possible for a website to display a consent banner while selected technologies remained outside the banner's effective technical control.

Legacy and duplicate scripts made ownership unclear

Several technologies required ownership review because the current team could not immediately confirm:

  • Why the technology was present
  • Who originally added it
  • Which business function depended on it
  • Whether it remained operationally necessary
  • Whether the implementation was consistent across domains

Shared website components propagated recurring patterns

Because the websites reused infrastructure and components, similar behavior appeared across more than one domain.

This helped the organization focus on root configuration patterns instead of treating every technical observation as an isolated website problem.

Evidence Delivered to the Client Team

Auditzo organized the engagement so that development, marketing, privacy, business, and legal stakeholders could work from the same technical record.

Diagram showing screenshots, HAR and network evidence, cookie and storage comparisons, technology inventory, findings register, and developer handoff.
Manual Evidence Audit deliverables may combine screenshots, network evidence, state comparisons, findings, and remediation guidance according to the agreed scope.

Executive and Scope Summary

  • Reviewed domains and representative pages
  • Test environment and regional context
  • Browser and observation details
  • Consent states reviewed
  • Known limitations and exclusions

Cross-Domain Technology Inventory

  • Observed technologies and vendor ecosystems
  • Associated domains and request destinations
  • Technology categories
  • Initial timing observations
  • Domains or templates where the technology appeared

Technical Findings Register

  • Observed behavior
  • Affected domain or page group
  • Supporting evidence references
  • Practical technical context
  • Suggested owner team
  • Recommended next review or remediation action

Evidence References

  • Timestamped screenshots where applicable
  • HAR and browser-network observations
  • Cookie and storage tables
  • Request-level examples
  • Consent-state comparison notes
  • Evidence and report traceability information

Developer Remediation Handoff

  • Consent-management sequencing recommendations
  • Tag-manager trigger review
  • Directly embedded script inventory
  • Legacy and duplicate tag cleanup
  • Regional and mobile journey checks
  • Post-change verification steps

Legal and privacy teams needing counsel-directed technical support can review Auditzo's website privacy audit support for law firms.

Organizations needing human-reviewed screenshots, consent-state comparisons, HAR/network analysis, cookie and storage comparisons, and agreed supporting evidence files can review the Manual Evidence Audit service.

Technical Remediation Priorities

The remediation plan focused on reducing implementation uncertainty and making consent behavior easier to control, test, and maintain across multiple domains.

1. Establish one authoritative technology inventory

The organization needed a controlled inventory showing:

  • Each tag, script, pixel, and vendor
  • Its intended business purpose
  • Its internal owner
  • The domains where it was expected to operate
  • Its intended consent category or control path
  • The person or team authorized to modify it

2. Review consent-platform initialization

The consent-management platform needed to initialize early enough for the selected website architecture.

The team also needed to verify that the intended consent state was available before controlled technologies were permitted to run.

3. Review and standardize tag-manager triggers

Tags were reviewed for:

  • Page-load triggers
  • Consent dependencies
  • Custom firing conditions
  • Trigger exceptions
  • Differences between domains
  • Legacy configurations

4. Identify scripts outside the primary control path

Directly embedded scripts, plugins, templates, sponsor integrations, and custom HTML required separate review because they might not follow the same controls as centrally managed tags.

5. Remove or disable obsolete integrations

Legacy and duplicate technologies became candidates for removal where the business team could no longer identify a current operational purpose.

6. Validate regional and mobile behavior

Representative journeys were required for relevant regional contexts and device types rather than assuming that one desktop test represented every visitor experience.

7. Add repeatable post-change verification

After implementation changes, selected pages and consent states could be reviewed again to determine whether the expected technical behavior had changed.

Auditzo can support this stage through website tracking remediation support, including consent configuration review, tag-manager cleanup, developer guidance, and selected post-fix verification.

What Changed for the Organization

The most valuable outcome was not a legal-compliance score. It was a clearer and more maintainable technical view of a complex multi-domain tracking environment.

The engagement gave the organization:

  • A consolidated inventory of observed website technologies
  • A clearer view of shared and site-specific implementation patterns
  • Evidence showing how selected pages behaved during reviewed journeys
  • A structured way to assign findings to development, marketing, privacy, or vendor teams
  • A remediation plan focused on consent sequencing, triggers, legacy scripts, and governance
  • A repeatable method for reviewing selected changes after implementation

Follow-up review was designed to verify selected technical changes within the agreed pages, states, regions, and observation periods.

It was not presented as proof that every possible visitor journey, browser, device, campaign, A/B test, or future website version would behave identically.

Why a One-Time Audit Is Not Always Enough for Multi-Site Organizations

Event and media websites can change frequently.

A new campaign, sponsor pixel, plugin update, container publication, agency change, or website release can introduce new behavior after an audit has been completed.

For organizations with multiple active domains, useful governance may include:

  • Named owners for every tracking technology
  • Approval controls for new tags and embeds
  • Documented consent-category mapping
  • Pre-production checks for significant releases
  • Periodic automated change detection
  • Targeted manual reviews after material implementation changes
  • Clear escalation to privacy or legal advisers where required

Auditzo's Website Privacy Monitoring provides recurring visibility into changes in cookies, trackers, third-party requests, and observable consent-related behavior.

Monitoring is a technical visibility service. It does not guarantee legal compliance, absence of litigation risk, or identical behavior across every future visitor session.

This engagement documented technical website behavior. It did not determine whether the organization had violated GDPR, French cookie requirements, the CCPA/CPRA, CIPA, or any other law.

GDPR and ePrivacy-oriented review

For EU and French visitor contexts, many non-essential cookies and trackers may require appropriate information, consent, and refusal controls unless a relevant exemption applies.

The exact legal treatment depends on the technology, purpose, data flow, jurisdiction, visitor journey, and surrounding circumstances.

California privacy review

Technical evidence may help advisers assess website tracking, disclosures, opt-out mechanisms, consent behavior, and potential sale or sharing questions.

Auditzo documents the observable technical behavior but does not decide whether the activity constitutes a sale, sharing, legal violation, or other regulated event.

CIPA-oriented technical review

For CIPA-oriented matters, Auditzo can document observable third-party scripts, network requests, routing information, cookies, pixels, session tools, and consent behavior.

Qualified counsel must determine whether those technical facts have legal relevance under California law.

Evidence and admissibility

Auditzo can provide structured technical records, timestamps, screenshots, network observations, hashes, and evidence references where included in the agreed scope.

Auditzo does not guarantee that any report, screenshot, HAR file, log, or other artifact will be admissible in a particular legal proceeding. Admissibility and evidentiary use depend on applicable law, authentication, procedure, context, and decisions made by counsel and the relevant court or authority.

Review the Auditzo audit scope and limitations before relying on an automated or manual report.

Who This Type of Audit Is Best For

A multi-domain website tracking review may be useful for:

  • Event and media organizations operating multiple websites
  • Enterprise groups with shared templates or tag containers
  • Marketing teams managing multiple agencies or campaign vendors
  • Privacy teams that need evidence beyond a policy review
  • Development teams troubleshooting consent and tag behavior
  • Legal teams reviewing website tracking or consent questions
  • Organizations preparing a remediation or monitoring programme
  • Ecommerce groups operating multiple regional storefronts
  • Agencies managing tracking infrastructure for multiple client sites

Teams that first need a broad automated view can compare the available options on Auditzo's website privacy audit plan comparison.

Frequently Asked Questions

What is a multi-site website tracking audit?

It is a technical review of cookies, trackers, scripts, browser storage, third-party requests, consent behavior, and shared infrastructure across more than one website.

It helps identify domain-specific observations as well as recurring implementation patterns affecting several websites.

Did Auditzo certify these websites as GDPR, CCPA, or CIPA compliant?

No. Auditzo does not certify legal compliance.

The engagement documented observed technical behavior and provided evidence and remediation-oriented findings for the client's development, privacy, business, and legal review teams.

Does the presence of a tracker automatically mean a website is violating the law?

No. A tracker, cookie, analytics tool, session-replay technology, or third-party request should not automatically be treated as unlawful.

Its legal treatment depends on its purpose, configuration, data processing, disclosures, visitor choices, jurisdiction, and other relevant facts.

Why is consent-state testing important?

A website may display a consent banner without consistently changing the underlying behavior of cookies, scripts, browser storage, and third-party requests.

Comparing no-interaction, Reject, and Accept journeys can help document whether a visitor's choice produces the intended technical result.

Can an automated scan replace this type of manual review?

No. An automated report can provide a useful initial view of cookies, trackers, third-party requests, and technical signals.

A manual review is more appropriate when multiple pages, consent journeys, regional behavior, human validation, screenshots, request-level analysis, or deeper evidence documentation is required.

Does every Manual Evidence Audit include the same evidence files?

No. Manual Evidence Audits are scoped according to the websites, pages, consent states, regions, technical questions, and agreed deliverables.

Depending on the scope, they may include screenshots, HAR and network evidence, cookie and storage comparisons, consent-state observations, evidence indexes, and other supporting files.

Can Auditzo help implement the recommended changes?

Yes. Technical remediation can be scoped separately.

Depending on the website stack and access available, Auditzo can support consent-configuration review, tag-manager cleanup, script controls, developer handoff, and selected post-change verification.

Can Auditzo work directly with a law firm or privacy counsel?

Yes. Auditzo can work within a counsel-directed technical scope and provide evidence-focused observations for legal and client review.

Auditzo does not replace legal counsel and does not determine legal liability, privilege, admissibility, or compliance.

What Auditzo Delivered

  • Multi-domain website tracking and consent-behavior review
  • Cross-domain technology and third-party request inventory
  • Initial-state and applicable consent-state observations
  • Network, cookie, storage, and screenshot evidence references
  • Technical findings organized by affected domain and owner team
  • Developer-focused remediation priorities
  • Follow-up verification workflow
  • Clear legal, technical, and scope limitations

The exact deliverables for future projects depend on the agreed audit type and scope.

Automated reports provide an initial technical view and do not include human verification, consent-button interaction, or downloadable raw evidence files.

Manual Evidence Audits can include deeper human-reviewed testing and agreed supporting evidence according to the engagement scope.

Need Clearer Evidence Across Multiple Websites?

Start with an automated scan when you need an initial view of cookies, trackers, and third-party activity.

Choose a human-reviewed Manual Evidence Audit when you need deeper consent-state testing, multiple domains, request-level observations, screenshots, human validation, or structured evidence for privacy and legal review.

Run an initial website audit or discuss a scoped Manual Evidence Audit.

Law firms and privacy counsel can review Auditzo's technical evidence support for law firms.

Auditzo provides technical observations, evidence-focused documentation, remediation support, and monitoring. Auditzo does not provide legal advice, certify compliance, confirm legal violations, or guarantee future website behavior.

Share: