
Updated
Start with the requests, not the banner
Open a clean browser profile and record the network requests before making any consent choice. Repeat after declining, accepting and withdrawing. List fonts, maps, videos, analytics endpoints and embedded widgets. Identify the operator and purpose of each request. A banner cannot control a script that was already loaded independently elsewhere in the application.
Match the description to the implementation
The Italian Garante distinguishes technical storage from tracking that requires consent. Its guidance also sets conditions for treating certain analytics as technical. Hosting analytics yourself is not, by itself, an exemption. Check the actual configuration with the person responsible for the privacy assessment.

For this website, optional analytics starts after consent. The form stores contact requests in the private administration inbox. These are different processing activities and should be described separately. Document the fields collected, who can access them, the storage location and how a deletion request will be handled. Avoid describing pseudonymous identifiers as anonymous.
Make the controls work
Keep rejection available and the website usable after declining. Provide a persistent way to change the choice. Test a withdrawal during an active visit, not only after reloading. Verify that queued tracking events stop and unnecessary device identifiers are removed. Server-side data already collected needs its own handling process.
Check every release
Recheck the network when adding a chat widget, video embed or booking tool. Review the contact form and the administration access controls. Keep a small record of the tested version, settings and observed requests. Technical checks support a privacy review; they do not replace the legal assessment or the operator’s responsibility for accurate information.