Cookie / Tracking Notice review
Cookie / tracking notice with ePrivacy + GDPR Art. 7 consent and CCPA / CPRA opt-out (GPC).
Review your document — free → See a sample report- 6 document-specific checks
- + 104 general checks
- Nothing uploaded
- Free forever (MIT)
What it checks
Cookie categories disclosed (strictly necessary / functional / analytics / advertising)
Cookie notice must categorize cookies (strictly necessary, functional / preferences, analytics / performance, targeting / advertising).
Critical · PRV-001
Consent mechanism (opt-in for non-essential)
Cookie notice must disclose the consent mechanism for non-essential cookies (banner / preference center).
Critical · PRV-002
Per-cookie disclosure — name / provider / purpose / duration
Cookie notice should disclose per-cookie details: name, provider, purpose, and retention duration.
Warning · PRV-003
Withdraw consent — instructions
Cookie notice must explain how users can withdraw consent (as easy as giving it — GDPR Art. 7(3)).
Critical · PRV-004
CCPA / CPRA opt-out (Sale / Share / Cross-context behavioral advertising)
Cookie notice for CCPA / CPRA-covered businesses must explain the right to opt out of sale / share / cross-context behavioral advertising (GPC support).
Warning · PRV-005
Third-party recipients / international transfers
Cookie notice must disclose third-party recipients and any international transfers.
Warning · PRV-006
Every run also applies 104 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.
Often reviewed with
How it works
- Open vaulytica.com — no account, nothing to install.
- Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
- Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
More privacy & data protection documents
- Biometric Data Consent (BIPA-style)
- Children's Privacy Notice (COPPA)
- Data Sharing Agreement (Research / Inter-Agency)
- DPA — CCPA Service Provider (CPRA-aligned)
- DPA — Controller to Processor (EU/UK)
- DPA — Multi-State US (CCPA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, DPDPA)
- DPA — Processor to Sub-Processor (EU/UK GDPR)
- Data Protection Impact Assessment (GDPR Art. 35)
- Data-Incident Notification Template
- Privacy Notice (GDPR)
- Privacy Notice (US / CCPA)
- Privacy Policy Linter
- Records of Processing Activities (GDPR Art. 30)
- EU Standard Contractual Clauses — Module 2 (Controller to Processor)
- EU Standard Contractual Clauses — Module 3 (Processor to Processor)
- SMS / Telemarketing Consent Disclosure
- UK International Data Transfer Addendum / IDTA
- Vendor Security Addendum
- Vendor Security Questionnaire (SIG / CAIQ)