Record the visitor's choice.
Retain the consent state and category preferences that were active for the delivered browser experience.
GDPR • CONSENT AND RUNTIME ACCOUNTABILITY
Connect a visitor's consent state with the third-party resources, browser access, and destinations observed during the session—so privacy teams can investigate whether the delivered experience matches the intended choice.

FROM PRIVACY CHOICE TO DELIVERED EXPERIENCE
A consent record describes what a visitor selected. Runtime evidence shows what the website and its third parties subsequently did. Bringing those two views together gives privacy, legal, and engineering teams a practical way to review discrepancies without treating browser telemetry as a complete legal assessment.
Retain the consent state and category preferences that were active for the delivered browser experience.
Identify the third parties, downstream resources, browser capabilities, and destinations active after that choice.
Investigate unexpected activation, narrow unnecessary access where appropriate, and use the current decision and technical context in the organization's privacy workflow.
CONSENT STATE IN OPERATION
A consent interface is only the beginning of the workflow. Retain the selected categories, apply consent-based activation rules to mapped resources, and send consent signals to supported services.
Preserve the categories selected by the visitor and the consent state associated with the delivered experience.
Apply category-based activation rules to mapped resources. Configured services using consent signals may load while receiving the visitor's consent state.
Communicate the resulting state to configured downstream systems without treating signal delivery as proof of legal compliance.
RECIPIENT AND DESTINATION VISIBILITY
An analytics, advertising, support, or personalization tag can introduce additional code and communicate with downstream destinations. Runtime mapping reveals those observed relationships as the visitor experiences them, helping teams validate recipient and transfer documentation.
THE PRIVACY QUESTIONS RUNTIME EVIDENCE CAN INFORM
Browser observations are most useful when they answer a defined privacy question. They can support selected GDPR activities while the controller or processor remains responsible for the underlying legal determination and complete governance record.
Compare storage, page-content, device, and network access with the documented purpose, then investigate behavior that appears unnecessary or unexpected.
Use consent-aware activation rules and reviewed browser boundaries as technical measures within a broader privacy-by-design and default program.
Use observed providers, dependencies, and destinations as supporting input when validating recipients, transfers, and safeguards documented elsewhere.
Use session context, findings, the current decision, and latest disposition to support ongoing review of browser-side security measures.
PURPOSE-LIMITED BROWSER ACCESS
A provider may be approved for one purpose without needing unrestricted access to storage, page content, device features, or arbitrary destinations. Translate the reviewed purpose into narrower technical boundaries and explicit exceptions.
Require newly discovered browser resources to be reviewed before they are trusted in an enforcement workflow.
Restrict supported outbound requests by approved domain patterns or regions where appropriate.
Review and control supported access to storage, DOM content, network APIs, device features, and other browser capabilities.
PRIVACY DISCREPANCY REVIEW
An unexpected resource, destination, or capability creates a concrete discrepancy for privacy, security, and engineering teams to review with session context intact.
Connect a finding to its provider, resource, observed behavior, destinations, capabilities, and affected sessions.
Keep the current decision, latest disposition, and technical context considered during review available with the finding.
Route enabled event notifications through supported email and collaboration integrations used by your response teams.
PRIVACY ACCOUNTABILITY RECORD
Keep consent context, observed third-party activity, policy state, findings, and reviewer decisions connected so privacy teams can explain what was expected, what occurred, and how a discrepancy was handled.
Keep first-seen, last-seen, dependency, behavior, current status, and available provider incident context for observed browser resources.
Keep the current policy state and targeted decisions used to govern supported browser and network access.
Share browser-side findings and governance records with privacy, security, legal, and audit stakeholders.
ADDITIONAL SUPPORTING EVIDENCE
Runtime records can contribute partial technical evidence to adjacent GDPR activities. They are inputs to the wider privacy program, not complete coverage of the underlying obligation.
Provider inventory, dependencies, current policy decisions, vendor assessments, and available incident context can support controller accountability and processor or sub-processor review.
Issues, affected sessions, observed destinations, timestamps, and the latest disposition can inform an organization's assessment of a suspected personal-data incident.
Observed browser capabilities, third-party relationships, and data destinations can provide technical input to a DPIA led and completed through the organization's broader privacy process.
Go deeper into the controls, evidence, and related use cases behind this workflow.
Compare captured visitor choices with observed browser behavior.
Review supported browser access and outbound destinations before applying scoped controls.
See how browser observations and control records support assessment preparation.
See how browser discovery, investigation, policy control, and supporting evidence work together.
GDPR BROWSER GOVERNANCE FAQ
Answers about consent state, runtime visibility, browser-side controls, and the limits of technical evidence within a wider GDPR program.
It focuses on the technical layer: consent state, third-party resources, provider relationships, destinations, supported browser capabilities, policy enforcement, and investigation records.
Browser-side support:These capabilities support accountability and evidence for selected GDPR principles and obligations at the browser layer.
Browser observations and controls may be relevant to work involving Articles 5, 24, 25, 28, 30, 32, 33, and 35, depending on the organization's processing, scope, and implementation.
Browser-side support:The page separates stronger browser-side alignment from partial supporting evidence and avoids presenting either as complete article coverage.
Runtime activity reveals scripts, supported browser access, and network destinations for comparison with processing and legal-basis records.
Browser-side support:The evidence helps privacy and security teams compare observed behavior with their data mapping, purpose, legal-basis, and transparency records.
Yes. Third-party scripts can load additional resources and communicate with further destinations at runtime.
Browser-side support:Provider, resource, and load-flow views reveal observed dependencies beyond the original tag.
No. Observed activity provides evidence for permission review; it does not automatically create or apply a production policy.
Browser-side support:Reviewers deliberately configure global, provider, or resource-level network and browser permissions.
A technical anomaly or issue supplies browser-side facts for the organization's breach assessment.
Browser-side support:The browser-side facts, affected-session context, alert record, and latest disposition can inform the organization's legal and operational assessment.
No. A complete record requires organizational details, purposes, categories of data and data subjects, recipients, transfers, retention, and safeguards beyond browser telemetry.
Browser-side support:Observed providers, destinations, dependencies, and technical controls can support validation of the browser-side portion of records maintained elsewhere.
Consent management records a visitor's choices, applies category-based activation rules to mapped resources, and sends consent signals to supported services. Unmapped resources are not blocked by category rules, and configured signal-based services may load while receiving the consent state. Browser-side observation provides a separate view of the activity that actually occurred.
Browser-side support:Comparing expected consent state with observed runtime behavior helps teams identify and investigate discrepancies alongside their lawful-basis and wider GDPR records.
Connect consent state with observed third-party activity, investigate discrepancies, and preserve a technical record for privacy, legal, security, and engineering review.