Step 1 — Intake: define what you're auditing and why
Start every engagement by pinning down three facts: which domains the client actually operates (marketing site, landing pages, subdomains, regional variants), which jurisdictions those sites face (California traffic means CIPA and CCPA/CPRA; EU traffic adds GDPR and ePrivacy), and what prompted the audit — a demand letter, a deal's diligence checklist, or preventive housekeeping.
The answers set the scope. A firm responding to a CIPA demand letter needs evidence of what the cited page did on specific dates and fast remediation. A preventive audit covers the full domain list and ends in a monitoring schedule. Write the scope into the engagement letter — it also frames the report you'll deliver at the end.
One scope question worth raising at intake even though it isn't a cookie question: EU-facing consumer sites have been subject to the European Accessibility Act since 28 June 2025, implemented in Germany as the BFSG. Competitors and associations have been sending accessibility Abmahnungen — but standing is not automatic, since § 8 UWG limits who may send one, and counsel report that many lack a genuine competitive relationship or any specific allegation. If the client is already paying for a compliance review, scoping both at once costs little; the BFSG compliance guide covers the German specifics.