Privacy compliance monitoring, defined

What is privacy compliance monitoring?

Privacy compliance monitoring is the continuous, independent testing of what your websites, mobile apps, and connected TV apps actually do with personal data, compared against what privacy law and each user’s consent allow. A consent management platform is the control. Monitoring is the audit that shows whether the control worked.

How privacy compliance monitoring works

A monitoring platform visits your properties the way a real user would, and the way a regulator or a plaintiff’s expert would. It loads pages and app screens under different consent choices, jurisdictions, browsers, and devices, and compares everything that fires with what the law requires and what that user agreed to. Because testing runs continuously, it also catches drift: the new tag added on a Tuesday, or the SDK update that ships with an app release.

1

Visit like a real user

Pages, app screens, and CTV sessions, across consent states, regions, and devices.

2

Record every request

Every cookie, tag, pixel, SDK, and network call, including what each one sends.

3

Compare to law and consent

Each data flow is checked against the jurisdiction’s rules and the user’s choice.

4

Flag, document, repeat

Violations come with evidence and a fix, and testing runs again tomorrow.

Privacy compliance monitoring vs. consent management

The two are often confused because both deal with consent. They do different jobs, and most enterprises need both.

The control

Consent management platform

Job

Collects and stores each user’s consent choices

What it sees

The banner and the choices recorded

Who runs it

Usually the vendor that serves the banner

Output

A consent record

The audit

Privacy compliance monitoring

Job

Verifies that tags, pixels, and SDKs actually respect those choices

What it sees

Every data flow leaving the page, app, or TV

Who runs it

An independent third party

Output

Audit-ready evidence, plus a prioritized technical to-do list

94.7%

of almost 30,000 websites with cookie consent banners had at least one potential GDPR violation, including cookies the banner assigned to the wrong category. Bollinger, Kubicek, Cotrini, and Basin, USENIX Security 2022. Karel Kubicek is Vault JS’s Lead Privacy & AI Researcher.

A CMP vendor attesting that its own banner works is like a company auditing its own books. Regulators and courts increasingly want to see what systems actually did, not what they were configured to do.

What privacy compliance monitoring catches

The failures continuous testing surfaces most often

Pre-consent firing

Tags and pixels that load before the user has made any consent choice.

Opt-outs that don’t stick

Do Not Sell or Share requests and Global Privacy Control signals that are acknowledged but not honored downstream.

Undisclosed sharing

Personal data, including health and financial information, sent to vendors the privacy policy does not name.

Form fields read before submit

Scripts that read what users type into forms and send it to third parties, often before the user presses submit. A USENIX Security 2026 study found this on 3.18% of 15,000 websites, behavior that maps to CIPA wiretap claims.

Video viewing data

Video titles and viewer identifiers shared with advertising pixels, the pattern behind VPPA suits.

Cookieless tracking

Device fingerprinting and ID syncing that follow users without setting a cookie.

Mobile SDK traffic

SDKs in iOS and Android apps that transmit data before the consent prompt appears.

Cross-device gaps

Opt-outs given on a website that do not carry over to the same user’s connected TV app.

Compromised third-party scripts

The same runtime monitoring catches security threats in third-party code, such as card-skimming JavaScript injected into a checkout page. That is how attackers hit British Airways, and how Vault JS found suspicious code from one martech vendor on nearly 60 websites. See Security Monitoring.

Why it matters now

Enforcement has moved from reading privacy policies to testing what websites and apps actually do.

$1.55M

Healthline Media, July 2025

The California Attorney General alleged the site kept sending identifiers and article titles to advertising partners after consumers opted out.

$2.75M

Disney, February 2026

A stipulated judgment with California over opt-outs that did not carry across devices and services, including no in-app opt-out on its connected TV apps.

Private litigation follows the same logic. Plaintiffs’ firms test sites with the same kinds of tools a monitoring platform uses, then file under statutes such as CIPA and VPPA. Finding the problem first costs far less than reading about it in a complaint.

What to look for in a monitoring platform

Privacy counsel, marketing operations, and security and GRC teams use monitoring to get evidence rather than assurances. When you evaluate a platform, look for:

Independence

The tester should not be the vendor that serves your banner.

Web, mobile, and CTV

Coverage across websites, iOS and Android apps, and connected TV, not websites alone.

Runtime testing

Real user journeys observed as they happen, not only static scans of code.

Consent states and regions

Every scenario tested: accept, reject, no action, opt-out signals, and each jurisdiction you serve.

Audit-ready evidence

Captured requests, payloads, and consent states you can hand to a regulator or a court.

A technical to-do list

Findings your engineers can act on, prioritized by legal risk.

Frequently Asked Questions

No law uses the term, but California now comes close. Since January 1, 2026, CCPA regulations require risk assessments before selling or sharing personal information, which covers most advertising tracking. Businesses that meet the regulations’ risk thresholds must also complete annual independent cybersecurity audits, with the first certifications due April 1, 2028 for companies with more than $100 million in revenue. And under the CCPA, GDPR, and other laws, opt-outs and consent choices have to actually work, which regulators now test directly. Continuous monitoring produces the evidence those assessments, audits, and investigations ask for.

Partly. Many CMPs now scan their own banner and the cookies it finds. That is useful, but it is the vendor checking its own control, and those scans routinely miss trackers. They often stop at the login screen, so tracking on account pages, checkout, and patient portals goes unseen. They miss trackers loaded inside iframes, such as embedded video players, chat widgets, and ads. They see little of the tracking that sets no cookie at all, like fingerprinting and server-to-server ID syncing. And most cover websites only. Independent monitoring tests every data flow across web, mobile, and CTV, including logged-in journeys and embedded content, under multiple consent states, and documents the result.

Yes. Analytics, session replay, chat, and advertising scripts can read form fields as users type and send that input to third parties, sometimes before the user ever presses submit. A USENIX Security 2026 study found this on 3.18% of 15,000 websites. Plaintiffs treat it as interception under California’s wiretap law, CIPA. CMP scanners list cookies and do not watch what scripts do with form input. Monitoring does. Read our CIPA analysis.

A cookie scanner lists the cookies a page sets. Monitoring watches everything that leaves the page or app, including requests that set no cookie at all, form input sent to third parties, and trackers inside iframes, and checks each one against the user’s consent and the law. Cookie lists are also often wrong: in a study of almost 30,000 websites with consent banners, 94.7% had at least one potential GDPR violation, including cookies assigned to the wrong category.

Continuously, or at least whenever the tag stack, a CMP setting, or an app release changes. Most consent failures are introduced by routine changes, such as a new tag or an SDK update, not by the original setup.

If you can see it, you can fix it.

Vault JS is an independent, third-party privacy compliance monitoring platform for enterprise web, mobile, and CTV properties.