https://gsk.com
Scanned Apr 15, 2026 · 38.6s
Your website score is
Grade
BannerConsent Banner
Yes
Regulatory Compliance
Multi-regulation overview — click any regulation for details
Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.
Tag Leak detected 8 user data leaks before consent on gsk.com, including Tealium (Tracker Tracker), Tealium (Analytics Tracker), GA4 and 1 more.
Security Headers
6/6 presentStrict-Transport-Security
max-age=31536000;
Content-Security-Policy
default-src 'self' 'unsafe-eval' 'unsafe-inline' * data:; font-src 'self' fonts.gstatic.com fonts.googleapis.com data:; style-src 'self' 'unsafe-inline' fonts.googleapis.com *.site.com ; img-src 'self' *.googletagmanager.com *.bing.com *.clarity.ms img.youtube.com ssl.google-analytics.com www.facebook.com bat.bing.com cm.everesttech.net *.presage.io maps.googleapis.com maps.gstatic.com *.doubleclick.net *.fls.doubleclick.net *.t.co t.co *.twitter.com *.google.com data:; frame-ancestors 'self'; frame-src 'self' *; connect-src 'self' *.gsk.com *.clarity.ms *.bing.com *.hotjar.com www.google.com akamai.tiqcdn.com glaxosmithklinebeech.tt.omtrdc.net gsk.com *.spotify.com spotify.com *.bing.net bing.net *.google-analytics.com google-analytics.com *.adsrvr.org adsrvr.org *.demdex.net demdex.net *.googleapis.com googleapis.com talkify.net *.talkify.net linkedin.com *.linkedin.com *.hotjar.io hotjar.io wss://*.hotjar.com *.salesforce-scrt.com *.site.com *.doubleclick.net *.fls.doubleclick.net *.tealiumiq.com;
X-Frame-Options
sameorigin
X-Content-Type-Options
nosniff
Referrer-Policy
origin
Permissions-Policy
autoplay=*
Google Consent Mode
V2Consent Parameters
Issues (5)
ad_storage defaults to "granted" — should default to "denied" for GDPR compliance
ad_user_data defaults to "granted" — should default to "denied" for GDPR compliance
ad_personalization defaults to "granted" — should default to "denied" for GDPR compliance
analytics_storage defaults to "granted" — should default to "denied" for GDPR compliance
No GTM container detected — consent mode works best with Google Tag Manager
Post-Rejection Audit
Reject Button
Missing
Post-Rejection Fires
0 vendors
Consent Mode
Not Detected
GTM Load
Not detected
Consent Mode V2: Not Detected
Google Consent Mode was not detected on this site.
Consent Record Audit
Issues detectedConsent record stored after interaction
GDPR Art. 7(1)No consent record written — cannot prove consent was given
No CMP consent cookie or localStorage entry was found after the consent interaction. GDPR requires controllers to demonstrate consent was given.
Consent withdrawal mechanism accessible
GDPR Art. 7(3)No way for users to withdraw consent found on page
No cookie settings link, footer link, or floating consent button was detected. GDPR requires users to withdraw consent as easily as they gave it.
Why this matters
Under GDPR Article 7, controllers must be able to demonstrate that consent was given (Art. 7(1)) and ensure users can withdraw consent at any time, as easily as giving it (Art. 7(3)). Sites with no consent record or no withdrawal mechanism cannot legally rely on consent as a lawful basis.
Tracker categories detected
Critical7
Tealium (tracker) loaded before consent
Tealium (analytics) loaded before consent

GA4 (Google) loaded before consent: Google Analytics gtag.js library

Adobe Analytics cookie "s_fid" set before consent — Alternative cookie with unique user ID / timestamp when the s_vi cookie can not be set for technical reasons
No "reject all" option found — users cannot refuse non-essential cookies (ICO guidance requires this)
No recognizable consent cookie or storage entry detected after interaction — GDPR Article 7(1) requires controllers to demonstrate consent was given (server-side storage cannot be verified)
No recognizable consent withdrawal mechanism detected — GDPR Article 7(3) requires users can withdraw consent as easily as giving it (cookie settings link or floating button expected)
Warnings4
Unknown was clicked but no consent storage was written — tags may continue firing as if consent was never given
localStorage key "animations-enabled" written before consent
localStorage key "theme" written before consent
sessionStorage key "codeLoaded" written before consent
Compliant32
HotJar (Hotjar) loaded correctly after consent
Microsoft Clarity3 findingsID trackedwww.clarity.ms, scripts.clarity.ms, _clck

www.clarity.ms, scripts.clarity.ms, _clck

Microsoft Clarity (Microsoft) loaded correctly after consent

Microsoft Clarity (Microsoft) loaded correctly after consent

Microsoft Clarity cookie "_clck" set correctly after consent

GA4 (Google) loaded correctly after consent
Twitter/X Pixel (X (Twitter)) loaded correctly after consent
LinkedIn Insight Tag (LinkedIn) loaded correctly after consent

Meta Pixel (Meta) loaded correctly after consent

Microsoft Ads (Microsoft) loaded correctly after consent
Google Ads2 findingsgoogleads.g.doubleclick.net, _gcl_ls

googleads.g.doubleclick.net, _gcl_ls

Google Ads (Google) loaded correctly after consent

Google Ads (Google) wrote "_gcl_ls" to localStorage correctly after consent

Adobe Analytics cookie "AMCV_ADFE41C3536A3F7E0A490D45%40AdobeOrg" set correctly after consent
X5 findingsmuc_ads, guest_id_marketing, guest_id_ads, personalization_id, guest_id
muc_ads, guest_id_marketing, guest_id_ads, personalization_id, guest_id
X cookie "muc_ads" set correctly after consent
X cookie "guest_id_marketing" set correctly after consent
X cookie "guest_id_ads" set correctly after consent
X cookie "personalization_id" set correctly after consent
X cookie "guest_id" set correctly after consent
openx.net cookie "i" set correctly after consent
Media.net2 findingsvisitor-id, data-rk
visitor-id, data-rk
Media.net cookie "visitor-id" set correctly after consent
Media.net cookie "data-rk" set correctly after consent
Rapleaf2 findingsrlas3, pxrc
rlas3, pxrc
Rapleaf cookie "rlas3" set correctly after consent
Rapleaf cookie "pxrc" set correctly after consent
Casale Media3 findingsCMID, CMPS, CMPRO
CMID, CMPS, CMPRO
Casale Media cookie "CMID" set correctly after consent
Casale Media cookie "CMPS" set correctly after consent
Casale Media cookie "CMPRO" set correctly after consent
Adobe Advertising2 findingseverest_g_v2, ev_sync_dd

everest_g_v2, ev_sync_dd

Adobe Advertising cookie "everest_g_v2" set correctly after consent

Adobe Advertising cookie "ev_sync_dd" set correctly after consent
HAproxy cookie "SERVERID" set correctly after consent
Adobe Audience Manager4 findingsdemdex, dpm, AMCVS_ADFE41C3536A3F7E0A490D45%40AdobeOrg, dextp

demdex, dpm, AMCVS_ADFE41C3536A3F7E0A490D45%40AdobeOrg, dextp

Adobe Audience Manager cookie "demdex" set correctly after consent

Adobe Audience Manager cookie "dpm" set correctly after consent

Adobe Audience Manager cookie "AMCVS_ADFE41C3536A3F7E0A490D45%40AdobeOrg" set correctly after consent

Adobe Audience Manager cookie "dextp" set correctly after consent
Is this your site?
Run a full multi-page scan with monitoring and get detailed remediation steps
Scan gsk.com →This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com