Pepsi

pepsi.com

Compare

Geo-redirect detected

https://pepsi.com redirected to https://www.pepsi.nl/.

https://pepsi.com

Scanned Apr 15, 2026 · 32.5s

Your website score is

30/100
Critical

Grade

D30

Banner

No

Regulatory Compliance

Multi-regulation overview — click any regulation for details

Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.

Tag Leak detected 7 user data leaks before consent on pepsi.com.

Security Headers

4/6 present

Strict-Transport-Security

Add HSTS header to enforce HTTPS connections and prevent downgrade attacks

Content-Security-Policy

frame-ancestors 'self'; upgrade-insecure-requests;

X-Frame-Options

SAMEORIGIN

X-Content-Type-Options

nosniff nosniff

Referrer-Policy

Set a Referrer-Policy header to control how much referrer information is shared

Permissions-Policy

interest-cohort=()

Google Consent Mode

V2
100/100
GTM Containers:GTM-M77P92V

Consent Parameters

ParameterDefault
Ad Storagedenied
Ad User Datadenied
Ad Personalizationdenied
Analytics Storagedenied
Functionality Storagenot_set
Personalization Storagenot_set
Security Storagenot_set

Post-Rejection Audit

Reject Button

Found

Post-Rejection Fires

0 vendors

Consent Mode

Not Detected

GTM Load

2234ms pre-consent

Google Tag Manager(GTM-M77P92V)

Loaded 2234ms after page load — before the consent banner was detected. Per a 2022 German court ruling, GTM itself transmits the user's IP to Google pre-consent.

Consent Mode V2: Not Detected

Google Consent Mode was not detected on this site.

No tracking vendors detected firing after rejection

Consent Record Audit

Issues detected

Consent record stored after interaction

GDPR Art. 7(1)

No consent record written — cannot prove consent was given

No CMP consent cookie or localStorage entry was found after the consent interaction. GDPR requires controllers to demonstrate consent was given.

Consent withdrawal mechanism accessible

GDPR Art. 7(3)

No way for users to withdraw consent found on page

No cookie settings link, footer link, or floating consent button was detected. GDPR requires users to withdraw consent as easily as they gave it.

Why this matters

Under GDPR Article 7, controllers must be able to demonstrate that consent was given (Art. 7(1)) and ensure users can withdraw consent at any time, as easily as giving it (Art. 7(3)). Sites with no consent record or no withdrawal mechanism cannot legally rely on consent as a lawful basis.

Tracker categories detected

Security2
Functional1 vendor
Tag Management1 vendor
Critical3
criticalNetwork

No consent banner detected — all cookies and tags fire without user consent

criticalConsent Record

No recognizable consent cookie or storage entry detected after interaction — GDPR Article 7(1) requires controllers to demonstrate consent was given (server-side storage cannot be verified)

criticalConsent Record

No recognizable consent withdrawal mechanism detected — GDPR Article 7(3) requires users can withdraw consent as easily as giving it (cookie settings link or floating button expected)

Warnings7
Google Tag Manager
Google Tag Manager2 findingsID tracked

www.googletagmanager.com

Google Tag Manager
warningNetworkTag ManagementGoogle Tag Manager

Google Tag Manager loads before consent — this is expected and required for GCM v2 to initialise consent defaults before any tags fire

ID: GTM-M77P92VHost: www.googletagmanager.comFired: 2094ms after load
Google Tag Manager
warningGTMTag ManagementGoogle Tag Manager

GTM loaded before consent banner — IP address transmitted to Google pre-consent (container: GTM-M77P92V)

Google Consent Mode
warningConsent ModeGoogle Consent Mode

Consent Mode detected but no consent update call fires on rejection — Consent Mode V2 may not be properly wired to your CMP

vendor logo
warningNetwork

Unknown third-party request to www.pepsi.nl before consent

Host: www.pepsi.nlFired: 619ms after load
vendor logo
warningNetwork

Unknown third-party request to cdn-prod.securiti.ai before consent

Host: cdn-prod.securiti.aiFired: 2282ms after load
vendor logo
warningNetwork

Unknown third-party request to app.securiti.ai before consent

Host: app.securiti.aiFired: 2567ms after load
vendor logo
warningNetwork

Unknown third-party request to www.joy-pepsico.eu before consent

Host: www.joy-pepsico.euFired: 3543ms after load
Info6
Google (Cdn)
infoNetworkGoogle (Cdn)

Google (cdn) loaded before consent

Host: www.youtube-nocookie.comFired: 2042ms after load
infoCookieFunctionalImperva

Imperva cookie "nlbi_3164567" set before consent — Incapsula DDoS Protection and Web Application Firewall: Load balancing cookie. To ensure requests by a client are sent to the same origin server.

Cookie: nlbi_3164567Domain: .pepsi.nlRetention: session
infoCookieFunctional

Imperva/Incapsula visitor ID — necessary for site protection

Cookie: visid_incap_3164567Domain: .pepsi.nl
infoCookieFunctional

Imperva/Incapsula session — necessary for site protection

Cookie: incap_ses_1862_3164567Domain: .pepsi.nl
infoCookieFunctional

Imperva/Incapsula visitor ID — necessary for site protection

Cookie: visid_incap_3165269Domain: .joy-pepsico.eu
infoCookieFunctional

Imperva/Incapsula session — necessary for site protection

Cookie: incap_ses_1689_3165269Domain: .joy-pepsico.eu

Is this your site?

Run a full multi-page scan with monitoring and get detailed remediation steps

Scan pepsi.com

This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com