Cookiebot is installed.
Does it block?
Cookiebot only holds back what it knows as a script of a category. Whatever is hard-coded in the theme or comes through the tag manager loads anyway, before consent or after “Reject”.
The most common causes
The banner shows, the choice is saved, and data still goes out. It is almost always the integration, not the banner.
| What | EU reference |
|---|---|
| Script without a category If a tracker sits in the theme as a normal script tag, the browser runs it right away. Cookiebot only holds it back once the tag has type="text/plain" and data-cookieconsent="statistics" or "marketing". | Art. 5(3) Directive 2002/58/EC |
| Tag in Google Tag Manager A tag without “Require additional consent” (Advanced settings) fires whatever was chosen in the banner. | Art. 5(3) Directive 2002/58/EC |
| The same service added twice A plugin adds the pixel, the theme adds it again. Cookiebot blocks one, the other loads. After “Reject” this is the first thing that shows. | Art. 5(3) Directive 2002/58/EC |
| Videos, maps, fonts Cookiebot only holds back YouTube and Google Maps if the iframe has data-cookieblock-src instead of src and a category. Google Fonts are easiest to self-host. | Art. 5(3) Directive 2002/58/EC |
What a scan shows
It opens your page without consenting, notes every service, then clicks Reject and measures again. For every service that still loads, the report gives the matching script tag for Cookiebot. Free as well: check your email sender.
As of 10 October 2026. We name the reference so you can read it yourself; this is not legal advice.