Guides · AuditLume

Visible privacy and consent: an initial review

Separate detectable links and tracker signals from the legal and contextual decisions that require specialist review.

What the scanner observes

The scanner looks for a visible privacy link and known tracker patterns in the initial page. It can flag a tracker when it finds no common consent signal, but it cannot determine the lawful basis, verify every subsequent request or judge whether policy wording fits a particular organisation.

The scanner checks for a visible privacy link, known tracker patterns, a common consent signal and Referrer-Policy. It cannot decide whether consent is valid or inventory every data flow.

AuditLume reads the final public response and initial HTML only; the finding remains a prompt for verification rather than a conclusion about the whole organisation.

A responsible manual review

Automated output is an invitation to investigate, not a verdict. Check representative pages, complete the real user task and include people with different devices or needs. Treat unusual results as context to understand rather than a score to optimise blindly.

How to prioritise

Review the evidence on the exact public page, record the current state, make one controlled change and check again. Keep screenshots or response details when they help colleagues understand the decision.

  1. Make the privacy route easy to find from stable navigation.
  2. Describe purposes, recipients and choices in plain language.
  3. Test the consent interface before and after a decision.
  4. Use browser tools or a specialist review to inspect network activity.

Limits to remember

A positive signal does not certify accessibility, privacy, security, legal compliance or search performance. A missing signal does not by itself prove harm. AuditLume reads public responses and initial HTML; specialist, legal and manual reviews remain separate activities.