Skip to main content

Tag Scanner: scan and categorize your Tags

tag scanner, scan tags, categorize tags, categorization, cookie categories, necessary, functional, performance, statistics, marketing, unknown tags, cookie banner, consent, GDPR, CCPA, cookie policy update, rescan

Written by AdOpt Support

The Tag Scanner finds the services (Tags) running on your site and lets you categorize them by purpose — the basis for a correct cookie banner. This guide covers the essential path and, after that, why this is one of the most important steps of your banner.

Part 1 — How to scan and categorize

1. How to get there

  1. Log in to your AdOpt account.

  2. Select the (1) Organization and the (2) Disclaimer you want to configure.

  3. Open the (3) Tag scanner step of the Disclaimer.

2. Where the scan reads

The scan reads the URLs registered when you created your Disclaimer. To include new pages, edit the Disclaimer (gear icon → Edit) and add the URLs — they become part of the Scanner's coverage.

📢 Important: register every page with distinct services (that use cookies) so all Tags show up here.

3. Run the scan

Click Scan tags and wait a few moments. If nothing appears, clear your cache (CTRL+SHIFT+R) and disable ad blockers/VPNs that may block third-party Tags.

4. Review the Tags found

The Tags appear in a list. AdOpt suggests an automatic classification for each one, based on market patterns — but the final decision is yours.

5. Categorize each Tag

Classify each Tag according to the service's purpose. AdOpt organizes Tags into purpose categories:

  • Necessary — essential for the site to work, or required by law. Without them, the site (or your business model) doesn't operate. Typically don't require consent.

  • Functional — enable features and preferences: remembering language and preferences, recognizing the logged-in session, chatbots.

  • Performance — keep the site stable and secure: for example, protection against attacks (DDoS) and load balancing.

  • Statistics — measure audience and behavior: where visitors come from, what they do, and how they navigate.

  • Marketing — track for advertising: remarketing, ad pixels, email cadences, and campaign measurement.

📢 Categorization depends on each service's purpose, your company's strategy, and the interpretation of the applicable law. Define the categories together with your legal team/DPO.

6. Don't leave Tags as Unknown

Tags the Scanner doesn't recognize fall into a 6th category: Unknown. They won't appear on your banner until categorized. Review the list and move every Unknown Tag into one of the 5 categories.

7. Save

At the bottom of the list, click Save and publish. Once every Tag is categorized, the Tag scanner step turns green.

Part 2 — Why good categorization matters

Major privacy laws — the GDPR and UK-GDPR in Europe and the UK, the CCPA/CPRA in California, and others — expect consent (or, for US-style laws, opt-out choices) to be specific and purpose-based, with clear information about what each group of services does. Categorizing Tags is what operationalizes that: visitors understand what each group of services is for and can decide on each one. The 5 categories above are how AdOpt structures purpose-based consent — the law doesn't define these names.

Under the GDPR and the ePrivacy rules, non-essential cookies are commonly grouped by purpose — roughly functional/preferences, performance/analytics/statistics, and advertising/marketing — while strictly necessary ones sit apart. AdOpt's categories map onto that logic:

  • Necessary ≈ strictly necessary cookies (basic site functions; typically no consent required).

  • Functional ≈ functionality / preferences cookies.

  • Performance and Statistics ≈ performance / analytics cookies.

  • Marketing ≈ advertising cookies.

A widely shared rule across these laws: non-essential cookies (statistics, marketing and the like) must start off and may only run after the visitor opts in (GDPR) or is given a clear opt-out (US state laws) — which AdOpt handles by default. AdOpt's banner also adapts automatically to the visitor's country and applicable law, so the right model is applied per region.

Part 3 — A maintenance step (not "set and forget")

Each scan is a snapshot of your site — a picture of the moment it ran. If Tags or cookies are added or removed later, that snapshot goes stale, and the banner stops reflecting what the site actually uses. To see the current picture, you need to run a new scan.

That's why the Tag Scanner is one of the most important steps of your banner: it's what keeps you continuously aligned. A common trap: the step can show as complete (it received a configuration) yet still be incomplete on compliance — for example, if Tags were mis-classified or the site changed since the last scan. Configured doesn't mean compliant.

Your Cookie Policy updates along with it

If you use the Cookie Policy generated by AdOpt with the cookie table enabled, every new scan updates that policy automatically — together with the banner's second layer. So when the Scanner finds a new service and you categorize it, both the banner and the Cookie Policy document reflect it with no manual editing. It's one of the platform's biggest strengths: you don't have to rewrite your documentation every time the site changes.

Put maintenance on autopilot

  • Manual: re-run the scan whenever you change the site's services (and review periodically).

  • Automatic (recommended): with the Scheduled Scanner, AdOpt re-scans at the frequency you choose and — with the AdOpt-generated Cookie Policy — keeps both the banner and the document up to date on their own. It's the lightest way to stay aligned without having to remember to scan. (Scanner availability and frequency vary by plan — see goadopt.io/plans.)

Next steps

Did this answer your question?