Most privacy gaps are internal. A register that was never finished, a process that lives in someone's head, a contract that was signed and never re-read. You can carry those quietly for a long time, because nobody outside the organisation can see them. Cookies and trackers are the opposite kind of gap. Your website loads them the moment a visitor arrives, and anyone with developer tools open, a regulator, a competitor, a journalist, a curious data subject, can watch in real time which advertising and analytics vendors you are handing visitor data to. There is no privilege and no confidentiality. The evidence is served to the public with every page load.
And here is the uncomfortable part: inside most organisations nobody holds the full list. Marketing knows about the campaign pixels it added. IT knows about the tag manager. An agency added something two years ago that nobody documented. The result is a website that behaves in ways its own controller cannot fully describe. The distance between what your site actually does and what visitors were told is a live compliance issue, and the most visible one you have.
What the law requires
Cookies and trackers that identify or profile visitors involve processing personal data, which brings them within Law 124/2024. It helps to keep two obligations apart, because sites routinely satisfy one and fail the other.
Transparency is about disclosure. Visitors must be told clearly what is being placed on their device, by whom, for what purpose and, where relevant, where that data travels. This is the same transparency duty that runs through the whole law: people are entitled to understand what is happening to their data, in plain terms, before they decide anything. A cookie policy buried three clicks deep, written in vendor jargon, or listing categories that no longer match reality, does not discharge it.
Consent is about permission, and it is a higher bar. Art. 8 of Law 124/2024, the Albanian equivalent of GDPR Art. 7, sets the conditions consent has to meet: freely given, specific, informed and unambiguous. For non-essential cookies, advertising, cross-site tracking, remarketing and many analytics configurations, that consent needs to be obtained before those cookies load. Telling someone what you are about to do is transparency. Waiting for them to say yes before you do it is consent. A banner that announces tracking after the tracking has already fired is neither: it describes a decision the visitor never got to make.
Two further points are worth knowing. Albania's Instruction No. 04/2025 on direct marketing applies consent standards aligned with the GDPR, addresses profiling and sets heightened protection for children. Much of what non-essential trackers do, building audience segments, following users across sites, feeding advertising platforms, is exactly that profiling and marketing activity. And if your site has visitors in the EU, the ePrivacy rules apply to storing or reading anything on their device, on top of the GDPR standard for the consent itself.
Essential and non-essential cookies
The line that determines your obligations runs between essential and non-essential cookies, so it is worth drawing carefully.
Essential, or strictly necessary, cookies are the ones the service the visitor asked for cannot function without. Keeping a basket populated, holding a login session, remembering a language selection, distributing traffic across servers and certain security functions all qualify. Because the visitor asked for the service and these cookies merely deliver it, they generally do not require prior consent, though transparency still applies and they should still be described.
Non-essential cookies serve the site operator's purposes rather than the visitor's immediate request. Advertising and retargeting pixels, cross-site tracking, social widgets that phone home, embedded media that profiles viewers, and analytics that go beyond basic measurement all fall here. These are the ones that need consent before they load.
The mistake to avoid is letting the label do the work. Calling a cookie necessary in your banner does not make it necessary. A marketing tag mislabelled as essential is still a non-essential tracker firing without consent, which is precisely why an independent look at the site matters more than settings someone configured once and has trusted ever since.
What a working consent banner looks like
"We have a cookie banner" is one of the most common and most misleading reassurances in this area. The banner is not the compliance; the behaviour behind it is. A banner that does the job has three properties.
Prior blocking. Non-essential cookies and trackers must not fire until the visitor has actively agreed. This is the property most banners fail. The overlay appears, but the scripts behind it have already loaded and already sent data. If tracking runs before the click, the banner is decoration.
A genuine reject. Refusing must be as easy as accepting. A prominent "Accept all" paired with a hidden, greyed-out or multi-step reject does not produce freely given consent, because it engineers the answer. Accept and reject belong side by side, at the same prominence, with rejecting costing the visitor nothing.
Granular categories. Consent should be specific. Visitors should be able to accept analytics while refusing advertising, rather than facing one all-or-nothing switch. Pre-ticked boxes do not count, since silence and inactivity are not agreement, so every non-essential category starts switched off. And the choice has to stick: once someone rejects, the site must not quietly re-ask on the next page or load the trackers anyway.
Why it is easy to drift
Almost nobody ends up non-compliant on purpose. Sites drift, because the tracking surface grows one small, reasonable-looking change at a time while the paperwork stays frozen at the day it was written.
Consider how it happens. Marketing launches a campaign and the ad platform's instructions say to paste in a conversion pixel, so a new tracker, and the vendor behind it, joins the site without anyone touching the cookie policy. Someone embeds a product video to make a page feel richer, and that embed quietly sets its own cookies and profiles whoever scrolls past, whether or not they press play. The analytics tool pushes an upgrade that turns on cross-device identity or advertising features by default, and overnight a measurement tool becomes a marketing tool. A new chat widget, a heatmap trial, an A/B testing script. Each is small, each is defensible in isolation, and none of them updates the running total.
That is tracker creep: the site collects and shares more than the privacy notice admits and more than the banner asks for, not out of bad faith, but because responsibility for the whole surface is diffuse and nobody owns the sum. The notice describes the site as it was at launch. The live site is the accumulated total of every change since, and the gap between them widens on its own until something forces it into view.
How PrivaxisOS handles this
The web scanning module closes that gap by looking at what the site is actually doing rather than what anyone believes it does. It scans your domains and reports every cookie set, categorised by purpose, so essential and non-essential are separated on the basis of behaviour rather than the label someone typed into the banner. It reports the third-party trackers present and the vendors quietly receiving visitor information, including the ones nobody inside the organisation can account for. And it produces a risk score per domain, so a portfolio of sites can be triaged rather than audited one painful page at a time.
The value is the reconciliation. The scan gives you the list of what the site actually sets; you compare it against what your cookie policy describes and what your banner categorises, and the difference is your work queue. Cookies your policy never mentioned, vendors nobody authorised, categories that no longer match behaviour. For every tracker nobody can explain, you either establish a lawful basis and document it, or remove it.
Re-scan on a schedule, because a site that was clean in March drifts by June the moment the next pixel goes in. The scan is a monitoring control rather than a one-off cleanup. This is your most public-facing compliance surface, and someone will eventually look. Far better that it is you, on your own schedule, than an inspector or a reporter with the developer console open.
A short readiness check
Do you know every cookie and tracker your website sets, not the list from launch but the list from today? Does your banner block non-essential trackers until the visitor actively agrees, with a reject as easy to use as accept? Are your categories granular, and do they stay respected across pages? Does your privacy notice describe the site as it actually behaves? And when did you last check rather than assume? If the honest answer is "we set the banner up once", your most visible compliance surface has been running unattended ever since, in full view of anyone who cares to look.