What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To audit third-party trackers, inspect what your site requests and stores in a clean browser session, then repeat the same journey before consent, after rejection, after acceptance, and after withdrawal. Chrome DevTools can reveal cookies and network activity, but a trace is evidence of what happened in that test—not a complete legal verdict or a view of every visitor’s experience.

What a tracker audit should cover

A cookie list is only one part of the picture. Include cross-site requests, embedded scripts and resources, pixels, and other technologies that store information on or access information from a visitor’s device. Under UK guidance, PECR may apply regardless of whether the mechanism is a conventional cookie; the ICO’s finalized storage and access technologies guidance was updated on 29 April 2026.

“Third-party” is about context as well as ownership. Google explains that a cookie used in a cross-site context—such as an iframe or subresource request—can be treated as a third-party cookie even when its domain belongs to the site owner but differs from the top-level page. A tracker audit should therefore follow requests and embedded resources, not just search for unfamiliar cookie names.

Prepare a clean, repeatable test

Choose pages and journeys

List the page types and interactions that matter on your site. Include landing pages, forms, logged-in areas, embedded video or maps, checkout, and pages where marketing tags run. Test both initial page loads and relevant interactions; a resource may only load after a click, form submission, or other event.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Control the test conditions

Use a fresh browser profile or clear relevant site storage before each run so an earlier consent choice does not silently affect the result. Record the browser and version, date, page, locale or region, and consent state. If behavior may vary by visitor location, repeat the test from relevant locations: one browser session does not show what every visitor receives.

Inspect requests and cookies in Chrome

  1. Open DevTools and the Network panel. Load the page and watch requests as you interact with it. Record request hosts and relevant scripts, images, pixels, and cookie information attached to requests.
  2. Inspect stored cookies. In DevTools, open Application > Storage > Cookies and review cookies associated with the site and embedded resources.
  3. Check third-party-cookie behavior. Use the Privacy and security panel to review third-party-cookie information and, where useful, temporarily limit third-party cookies while DevTools is open. This can help reveal dependencies; it is not a substitute for testing the site under its ordinary conditions.
  4. Investigate deeper browser events if needed. Google documents recording a Chrome NetLog at chrome://net-export and examining events such as COOKIE_STORE and URL_REQUEST in the Network Log Viewer.

Google’s cookie audit guidance and cookie developer-tools documentation describe these inspection options. PSAT, the Privacy Sandbox Analysis Tool, is an optional Chrome extension that adds cookie-analysis support to DevTools. Use it as an aid to investigation, not as proof of compliance.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Compare behavior across consent states

Repeat the same page journey in each state below, using a clean session or resetting the relevant preference between runs. Save the requests and storage state you observe in each one.

  • No choice yet: Check whether optional scripts, pixels, or cookies appear before a visitor makes a choice.
  • Reject optional categories: Check whether rejection actually suppresses the relevant activity.
  • Accept: Record what loads or is stored after acceptance.
  • Withdraw or revise the choice: Change the preference and check what happens on subsequent page loads and interactions.

Do not rely on cookies alone: a request can transmit data without setting one. Compare network activity as well as stored values. For UK pages, the ICO’s cookies and similar technologies overview says non-essential cookies should not be set on the homepage before consent, and that valid consent requires a clear positive action; merely continuing to use a site is not enough.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Turn observations into an inventory

Keep an evidence-backed record that another person can use to investigate or verify each finding. A useful inventory includes:

  • Observed host or provider and the request, resource, cookie, or other storage mechanism.
  • Page, interaction, browser and version, test date, locale or region, and consent state.
  • Whether it appeared before or after a choice, and what changed after rejection or withdrawal.
  • Its apparent function, the site owner responsible for follow-up, and the open question to resolve.

Compare the inventory with your cookie notice and privacy information. If a trace does not establish what a service does, ask the provider to confirm its purpose and configuration. Google recommends checking with third-party service providers about cross-site cookies and whether a library upgrade or configuration change is needed. Do not infer that a cookie is strictly necessary, or that a vendor is compliant, from its name alone.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Interpret findings without overclaiming

Browser tools show technical behavior in the tested session. They do not identify every server-side transfer, establish who controls every data use, or decide whether a deployment is lawful. Legal scope and exceptions depend on the jurisdiction, technology, and purpose.

For UK sites, PECR and UK GDPR are related but distinct questions. The ICO says PECR can apply to any method of storing information on or accessing information from a user’s device. Its overview describes requirements to tell people what technologies are present and why, and to obtain consent where required. It also describes exceptions for transmission of a communication and technologies strictly necessary to provide a service requested by the user; something helpful or convenient is not necessarily strictly necessary. Where device data is personal data, UK GDPR obligations also apply, and the lawful basis for subsequent processing is a separate consideration from PECR consent. Consult the ICO’s detailed guidance for the specific circumstances, rather than treating a browser result as a legal classification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not extend UK rules automatically to visitors elsewhere. The applicable requirements can differ by visitor location, service, technology, and purpose. For France, CNIL’s analytics guidance indicates that consent generally applies to analytics cookies but refers to a specific exception; the exact conditions are not established here, so check the current official guidance before relying on an exception.

Prioritize fixes and repeat the audit

Investigate unexpected activity before consent first, then work through unexplained providers, stale tags, missing disclosures, and activity that continues after rejection or withdrawal. Assign an owner to each issue, adjust the tag or consent configuration, and rerun the same scenarios so you can compare the result with the original observation. Repeat after changes to tags, the CMS, the consent banner, or vendors, as well as at a sensible periodic interval.

For larger sites, recurring privacy-audit services may help maintain coverage as pages and vendors change. Compare any tool by whether it observes runtime behavior or only scans source or configuration, what it covers, whether it can test consent and withdrawal, how reproducibly it handles pages and regions, what evidence it exports, and whether it makes legal claims that its technical data cannot support.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.