Digital Compliance
What the Tracker Categories Actually Mean
Which Ones Need Consent, and Which Ones Never Did
Run any tracker scan and you get a list of categories back. Analytics, advertising, profiling, platform, necessary. The report assumes you already know which of those matter.
Most of them do not. Roughly half of what a scan finds on a typical site is the site working correctly, and calling that a problem is how scanner reports lose the reader's trust in the first paragraph.
A cookie is not a tracking cookie. The thing that makes a cookie a privacy question is whether it carries a persistent identifier that follows one particular person. Your shopping cart does not. Google Analytics does.
The categories, and which need consent
| Category | Needs notice and an opt out? | What it is |
|---|---|---|
| Strictly necessary | No | Your site does not work without it. Session cookies, cart contents, load balancing, the security token on a login form. |
| Platform | No | The hosting platform delivering the site. Shopify, Squarespace, Wix, WordPress infrastructure. |
| Security | No | Bot filtering, spam protection, fraud checks. |
| Consent | No | The cookie banner itself. It has to run in order to ask the question. |
| Tag manager | No, on its own | A container that loads other tags. Google Tag Manager is the common one. It sets no tracking cookie itself. |
| Analytics | Yes, with notice and an opt out | Measures visits and behaviour using a persistent identifier that follows one visitor across sessions. |
| Advertising | Yes, and this is the strictest | Shares visit data with an ad network for targeting, usually building a profile that follows the person across other sites. |
| Profiling and session recording | Yes, and be careful | Records what an individual actually did. Heatmaps, session replay, scroll and click paths. |
| Email marketing | Yes | Identifies a visitor for marketing follow up, often tying an anonymous visit to a known contact. |
| Social | Yes | A pixel from a social platform, creating a cross site identifier that follows the person off your domain. |
| Chat and support | Depends | A support widget. Some are simple message boxes, some profile visitors and track them across pages. |
| Unclassified | Unknown until reviewed | Something we detected that does not match a known signature. |
Needs notice and an opt out is not the same as needs an opt in banner. Canada permits opt out consent for non sensitive tracking, provided the notice comes at or before collection and the opt out actually works.
What to do about each
| Category | How it is handled |
|---|---|
| Strictly necessary | Nothing to do. These are not a finding and labelling them as one damages your credibility. |
| Platform | Nothing to do, though check what the platform switches on by default. Several bundle their own analytics. |
| Security | Nothing to do. Genuinely necessary to keep the site working. |
| Consent | Nothing to do, but confirm it actually works. A banner that does not gate anything is worse than none. |
| Tag manager | The container is fine. What it injects is the point, and each of those gets assessed on its own. A clean tag manager row never means a clean site. |
| Analytics | The identifier is what makes this personal information. Cookieless analytics that sets no identifier sits outside this entirely. |
| Advertising | The hardest category to defend as within a visitor's reasonable expectations, because the data leaves your site. Must be named in your policy. |
| Profiling and session recording | Session replay can capture form input, which risks pulling in sensitive categories. Where it does, opt out consent is off the table and you need express consent. |
| Email marketing | Also brings Canada's Anti Spam Legislation, which governs what you send rather than what you collect into scope for whatever you send afterwards. |
| Social | The disclosure to a third party is the substance of the finding, not the pixel itself. |
| Chat and support | Read the vendor documentation. Treat as non essential if it profiles. |
| Unclassified | Never reported as a finding without a manual check. An unknown is a question, not a failure. |
The two that trip people up
Tag managers. A tag manager is a container. It loads other things. On a report it looks harmless, because on its own it is, but it is often the delivery mechanism for everything else on the page. If your tag manager row is clean and your analytics row is not, the tag manager is how the analytics got there.
Strictly necessary. This is the category people over claim. A session cookie that keeps someone logged in is necessary. An analytics cookie is not necessary just because your marketing team relies on it. The test is whether the site functions without it, not whether you would miss the data.
If a report tells you PHPSESSID is a tracking risk, the report is wrong, and you should wonder what else in it is wrong. Being fair about the harmless categories is what makes the serious findings believable.
So what actually matters
Five categories are the ones to look at: analytics, advertising, profiling and session recording, email marketing and social. Everything else is either the site running or a question to review by hand.
But they do not all sit at the same level, and this is the distinction the rest of this article has been building toward. For most of them, notice at or before collection and an opt out that actually works is what Canada asks for. Two situations need express, opt in consent instead. Session recording that captures what a person types is one, because it pulls in whatever they typed, including things they never meant to share. Profiling that follows a person in a way they would not reasonably expect, which is usually cross site advertising, is the other. In those cases an opt out is not enough and the tracking has to wait until someone agrees.
If you are in Quebec, the line moves again. Law 25 requires that technology which profiles, locates or identifies a person is off by default, so the express consent case is broader there than it is under Personal Information Protection and Electronic Documents Act, Canada's federal privacy law alone.
If you want to know which of these are on your site and whether they fire before anyone agrees to anything, that is what the audit tests.
Want to know where your own site stands? See what the audit covers, or reach out and we'll get the ball rolling.
Reach outJUMP BACK
All What's Part of It ArticlesDiscover more content by us