Most OneTrust deployments are leaking data, slowing sites and failing audits — despite significant annual spend. Run this 5-point check.
Pillar A – Compliance Audit
5-Point DIY Audit
Score yourself: 1pt per pass
- Open an Incognito tab.
- Before clicking Accept, check DevTools › Application › Cookies.
- Do ‘Performance’ or ‘Targeting’ cookies appear? They shouldn’t.
- Navigate to your login page — a frequent misconfiguration blind spot.
- Are analytics or ad trackers still firing before consent?
- Open DevTools › Network.
- Filter by ‘analytics’ or ‘fbevents’.
- Scripts loading regardless of consent bypass your CMP entirely.
- Accept cookies on desktop.
- Clear cache and revisit on mobile.
- Broken sync = duplicate consent requests.
- Click ‘Manage Preferences’.
- Can a user genuinely reject all non-essential cookies in under 3 clicks? Regulators are watching.
If you scored < 4/5:
You’re likely breaching GDPR Art. 5 & 7 and leaking attributable revenue.
Pillar B – Data Attribution
Industry Opt-In Benchmarks
Low opt-in = broken attribution

The Attribution Gap
48% opt-in = up to 52% of converting users are invisible to your analytics stack. GA4, Meta CAPI & Google Ads all depend on consented signals. Missing them breaks ROAS modelling.
8–15% revenue recovery per 10pt opt-in improvement
Benchmarks based on industry opt-in data across e-commerce and B2C sectors. Optimised figures achievable with UX-led consent strategy.
Pillar C – Site Speed & SEO
Core Web Vitals Impact
A poorly-loaded OneTrust banner isn’t just a UX problem — Google can penalise you for it.

The SEO Link
Google’s Core Web Vitals are a direct ranking signal. Render-blocking CMP scripts that delay LCP beyond 2.5s are penalised in organic search — regardless of your content quality.
It wouldn’t be a bad idea to check these:
- Load OneTrust script with async attribute
- Avoid fixed-position banner pushing content down (use overlay)
- Run PageSpeed Insights before/after CMP enabled
















