Accessibility Watch

Consent & tracking report for block.xyz

Consent risk grade: F
Based on an automated pre-consent tracking scan on July 21, 2026.

Critical risk. A video player shares this page with pre-consent pixels — the VPPA footprint plaintiffs target — on top of heavy pre-consent tracking.

On a cold page load — before any consent was given — this page sent data to 2 third-party trackers (3 requests). No consent banner was detected at all.

Sending data to advertising and analytics third parties before a visitor consents is what powers the wave of CIPA "wiretapping" demand letters in the U.S. and GDPR / ePrivacy enforcement in the EU — and every item below is fixable.

VPPA exposure (Video Privacy Protection Act). When a marketing pixel fires on a page with video, plaintiffs argue it shares "what video this person watched" with a third party (e.g. Meta) without consent. The VPPA carries statutory damages of ~$2,500 per violation, and this video+pixel combination is the single hottest privacy-litigation pattern right now.

How to fix it: Gate the pixel until consent, embed video via youtube-nocookie.com (or a privacy-mode equivalent), or remove marketing pixels from pages that host video. Any one of these breaks the footprint.

What we found, and how to fix it

Google Analytics 4 sends visitor data to a third-party analytics service before consent.

Google Analytics 4 · Analytics · 2 requests before consent

US: CIPA EU: GDPR/ePrivacy Sends identifiers: tid, cid

Why it matters: Analytics like GA4 set identifiers and report the visit to Google before the visitor agrees — cited under CIPA in the US and treated as non-essential tracking that requires prior consent under GDPR/ePrivacy in the EU.

How to fix it: Gate analytics behind consent. For Google Analytics, use Consent Mode v2 with analytics_storage defaulting to "denied" and flipping to "granted" only after the visitor accepts — you keep the measurement without the pre-consent exposure.

Google Tag Manager sends visitor data to a third-party analytics service before consent.

Google Tag Manager · Analytics · 1 request before consent

US: CIPA EU: GDPR/ePrivacy Sends identifiers: id

Why it matters: Analytics like GA4 set identifiers and report the visit to Google before the visitor agrees — cited under CIPA in the US and treated as non-essential tracking that requires prior consent under GDPR/ePrivacy in the EU.

How to fix it: Gate analytics behind consent. For Google Analytics, use Consent Mode v2 with analytics_storage defaulting to "denied" and flipping to "granted" only after the visitor accepts — you keep the measurement without the pre-consent exposure.

Fix these before a demand letter finds them — free

The free ForensicConsent browser extension finds every tracker that fires before consent on your own pages, flags the VPPA footprint, and gives you the fix recipe for each — at no cost. Run it, gate your trackers, and re-check this page anytime.

Own this site? Gate your trackers behind consent, then re-scan — this report updates automatically, and comes down entirely once you pass.

Or remove this report without fixing →

This is an automated scan of the page’s public behavior on a single cold load; it reports what the page transmitted before any consent, not a legal verdict. Exposure flags show the public legal basis these patterns are cited under — they are informational, not legal advice. See our methodology.

How this report was produced

Automated scan of block.xyz as it publicly behaved on , using the ForensicConsent detection ruleset (2026.06.22). The captured pre-consent requests and these results are sealed with a tamper-evident hash (a590b182d247b459…). We report only what the page publicly transmitted before consent at that time.