How privacy compliance monitoring works
A monitoring platform visits your properties the way a real user would, and the way a regulator or a plaintiff’s expert would. It loads pages and app screens under different consent choices, jurisdictions, browsers, and devices, and compares everything that fires with what the law requires and what that user agreed to. Because testing runs continuously, it also catches drift: the new tag added on a Tuesday, or the SDK update that ships with an app release.
Visit like a real user
Pages, app screens, and CTV sessions, across consent states, regions, and devices.
Record every request
Every cookie, tag, pixel, SDK, and network call, including what each one sends.
Compare to law and consent
Each data flow is checked against the jurisdiction’s rules and the user’s choice.
Flag, document, repeat
Violations come with evidence and a fix, and testing runs again tomorrow.
Privacy compliance monitoring vs. consent management
The two are often confused because both deal with consent. They do different jobs, and most enterprises need both.
The control
Consent management platform
Job
Collects and stores each user’s consent choices
What it sees
The banner and the choices recorded
Who runs it
Usually the vendor that serves the banner
Output
A consent record
The audit
Privacy compliance monitoring
Job
Verifies that tags, pixels, and SDKs actually respect those choices
What it sees
Every data flow leaving the page, app, or TV
Who runs it
An independent third party
Output
Audit-ready evidence, plus a prioritized technical to-do list
94.7%
of almost 30,000 websites with cookie consent banners had at least one potential GDPR violation, including cookies the banner assigned to the wrong category. Bollinger, Kubicek, Cotrini, and Basin, USENIX Security 2022. Karel Kubicek is Vault JS’s Lead Privacy & AI Researcher.
A CMP vendor attesting that its own banner works is like a company auditing its own books. Regulators and courts increasingly want to see what systems actually did, not what they were configured to do.
What privacy compliance monitoring catches
Pre-consent firing
Tags and pixels that load before the user has made any consent choice.
Opt-outs that don’t stick
Do Not Sell or Share requests and Global Privacy Control signals that are acknowledged but not honored downstream.
Undisclosed sharing
Personal data, including health and financial information, sent to vendors the privacy policy does not name.
Form fields read before submit
Scripts that read what users type into forms and send it to third parties, often before the user presses submit. A USENIX Security 2026 study found this on 3.18% of 15,000 websites, behavior that maps to CIPA wiretap claims.
Video viewing data
Video titles and viewer identifiers shared with advertising pixels, the pattern behind VPPA suits.
Cookieless tracking
Device fingerprinting and ID syncing that follow users without setting a cookie.
Mobile SDK traffic
SDKs in iOS and Android apps that transmit data before the consent prompt appears.
Cross-device gaps
Opt-outs given on a website that do not carry over to the same user’s connected TV app.
Compromised third-party scripts
The same runtime monitoring catches security threats in third-party code, such as card-skimming JavaScript injected into a checkout page. That is how attackers hit British Airways, and how Vault JS found suspicious code from one martech vendor on nearly 60 websites. See Security Monitoring.
Why it matters now
Enforcement has moved from reading privacy policies to testing what websites and apps actually do.
$1.55M
Healthline Media, July 2025
The California Attorney General alleged the site kept sending identifiers and article titles to advertising partners after consumers opted out.
$2.75M
Disney, February 2026
A stipulated judgment with California over opt-outs that did not carry across devices and services, including no in-app opt-out on its connected TV apps.
Private litigation follows the same logic. Plaintiffs’ firms test sites with the same kinds of tools a monitoring platform uses, then file under statutes such as CIPA and VPPA. Finding the problem first costs far less than reading about it in a complaint.
What to look for in a monitoring platform
Independence
The tester should not be the vendor that serves your banner.
Web, mobile, and CTV
Coverage across websites, iOS and Android apps, and connected TV, not websites alone.
Runtime testing
Real user journeys observed as they happen, not only static scans of code.
Consent states and regions
Every scenario tested: accept, reject, no action, opt-out signals, and each jurisdiction you serve.
Audit-ready evidence
Captured requests, payloads, and consent states you can hand to a regulator or a court.
A technical to-do list
Findings your engineers can act on, prioritized by legal risk.
Frequently Asked Questions
If you can see it, you can fix it.
Vault JS is an independent, third-party privacy compliance monitoring platform for enterprise web, mobile, and CTV properties.