Cross-browser · PECR Reg 61 critical in Chrome, 12 in Firefox — the banner gates Chrome only. A single-browser audit would call this site compliant. It is not.
PDF reportRaw JSONPer-finding remediation
Anonymised composite · Ghost Carbon Report dataset · Jun 2026Scope: point-in-time · homepage unless whole-site selected · UK / US viewsSWDM v4 · NESO live · CC-BY
§ What the evidence contains
01 / Detection
Cross-browser parallel
Chrome + Firefox + Safari at the same moment. M&S: 1 critical in Chrome, 12 in Firefox.
In plain English: Most scanners only check Chrome. Sites often serve different code to Firefox or Safari, Firefox blocks some trackers by default, so the site quietly loads alternatives. We scan all three at once and compare. The gap between them is usually where compliance failures hide.
02 / Network
Regional residential IPs
UK and US. Not a datacenter. See what your real visitors see.
In plain English: Most scanners run from Amazon, Google, or Azure cloud servers, which websites can detect and serve a cleaner version of themselves to. We scan from real home internet connections. So you see exactly what a visitor in Newcastle or New York actually sees, not the polite version sites show to crawlers.
03 / Legal categorisation
PECR taxonomy A/B/C
Cookie (Cat A), cookieless device storage (Cat B), server-side (Cat C). First UK scanner to separate them.
In plain English: Most scanners lump every tracker together. But PECR Regulation 6 covers storing or accessing information on a user’s device — not just cookies. We detect cookies, window.* globals (window.uetq, _hsq, dataLayer), localStorage, IndexedDB, and Service Workers, then split findings into Category A (cookies, standard CMP fix), Category B (cookieless device storage or transport — most CMPs miss this), and Category C (server-side or grey area, needs manual review). Your DPO sees three distinct exposure lines with three different remediation paths.
04 / Defensibility
Case law per finding
Planet49, PECR Reg 6, UK GDPR Art 5(1)(a), CCPA. Cited inline per finding.
In plain English: Every finding we surface is tagged with the law it breaches and the court case that proved it. Planet49 was the 2019 EU Court of Justice ruling that made pre-checked cookie consent boxes illegal. PECR Reg 6 is the UK rule requiring consent before placing trackers. So your DPO doesn't have to translate the report, it already speaks legal language.
05 / Environmental
Carbon waste measured
SWDM v4 × live UK grid intensity (NESO, real-time). CO₂e per visit and annualised.
In plain English: Every tracker that fires before consent transfers data, uses electricity, and emits CO₂. We measure how much, using the Sustainable Web Design Model v4 (the industry-standard methodology) and live UK grid carbon intensity from NESO (the national grid operator), in real time. Most sites we scan emit 50-500 tonnes CO₂e per year from tracking nobody agreed to.
06 / Jurisdiction
Multi-region regulatory
UK · EU · US · Canada · Brazil. Regulations mapped per finding.
In plain English: UK GDPR isn't the only law your site needs to comply with. California needs CCPA. Quebec needs Law 25. Brazil needs LGPD. We map every finding to every regulation it breaches, so you can see exactly where you're exposed, jurisdiction by jurisdiction.