Guide
Scan Location: Why Cookie Banners Differ by Country
The same website can show a full GDPR consent banner to a visitor in Frankfurt, a "Do Not Sell" notice to a visitor in Los Angeles, and nothing to a visitor in Virginia. A cookie scan is only as useful as the location it runs from. This guide explains geo-targeted consent banners and how to scan a site from the US or the EU with CookieInspector.
Cookie banners are often geo-targeted
Most consent management platforms let a website decide who sees the cookie banner based on where the visitor connects from. A common setup shows a full GDPR consent banner to visitors from the European Union and the United Kingdom, a "Do Not Sell or Share" notice to visitors from California, and nothing at all to everyone else.
The website is not doing anything wrong by configuring it that way. But it means there is no single answer to "does this site have a cookie banner?". The answer depends on where you look from.
Platforms with geo rules include Consentmo, CookieYes, Cookiebot, OneTrust, Usercentrics, and most Shopify and WordPress consent apps. The decision is made from the visitor's IP address, so a browser language setting or a VPN-less "simulate EU" flag does not change what the site serves.
What a scan from the wrong location gets wrong
A scanner that connects from the United States sees the site the way a US visitor does. On a geo-targeted site that can mean:
- No banner detected, even though EU visitors get one. The report flags a missing consent banner that does not exist for the audience you care about.
- Different cookies and trackers before consent. Many sites load analytics and marketing tags freely for non-EU visitors and hold them back until consent in the EU. A US scan reports pre-consent tracking the EU visitor never experiences, or the other way around.
- A different score. The same site can be "likely non-compliant" from one location and much closer to compliant from another, and both reports are accurate for their region.
For a GDPR review the question is what the EU visitor sees, so the scan should originate in the EU. For a CCPA review, it should originate in California.
Scan locations in CookieInspector (beta)
CookieInspector can run a scan from three locations:
- US East (Virginia): the default. Every scan runs from here unless you choose otherwise, including all scans on the Free plan.
- Germany (Frankfurt): an EU location, for GDPR and ePrivacy reviews.
- US West (California): for CCPA and CPRA reviews, including "Do Not Sell or Share" notices that only appear to California visitors.
Choosing the location is available on the Pro and Agency plans. The scanner itself is identical in every location: the same browser, the same checks, the same report. Only the network the visit originates from changes, which is exactly what geo-targeting keys on.
The feature is in beta. If a scan from another location looks off, re-run it from US East and compare; the report shows which location each scan ran from.
How to use it
- Open New scan, enter the website, and pick a location under "Scan location". US East is preselected.
- Run the scan. The report header shows "Scanned from" with the location, and your scan history shows the location on every row.
- To compare, run the same site from two locations. A banner that appears in one and not the other is geo-targeting at work, not a scanner error.
Scans from any location count towards your monthly quota in the same way.
When a comparison is worth running
- The report says "no consent banner detected" on a site you know shows one to EU visitors.
- You are preparing a GDPR audit, a DPA response, or evidence for a client in the EU.
- A client's CMP is configured with regional rules and you want to verify each rule actually works.
- Pre-consent tracking findings differ from what your own browser shows from another country.
If both locations give the same result, the site is not geo-targeting its consent behaviour and a single scan is enough going forward.
Related guides
More insightsReady to prove your compliance?
Start with a scan so you can show regulators and stakeholders the evidence you followed cookie compliance checker best practices.
Run a scan from the EU