One Tuesday, a pixel fires early.
Harbourline Dental is our fictional Manchester clinic: dental sub-sector, England sub-jurisdiction, 29 attached requirements. Follow one real-world-shaped breach from the moment their website changes to the moment the fix is proven. Every step below is how the Radar actually reasons.
The clinic's marketing agency installs a new booking widget on /book-appointment. Helpful feature. But bundled inside it: a Meta Pixel that loads on page open. The Radar's scheduled pass sees the page's fingerprint change and queues a forensic re-capture.
A clean browser session, no cookies, no prior consent, loads the page from a UK vantage. It records every network request before the consent banner is touched:
The dark panel is the only dark thing on this page, and that is deliberate: it is the machine's view. Screenshot, raw bytes, headers and consent state are all vaulted with the hash.
Harbourline's combination (healthcare · dental · UK · England) already carries 29 attached requirements. The pre-consent tracker test belongs to PECR. The gates re-check before anything is alleged:
"A person shall not store or gain access to information stored, in the terminal equipment of a subscriber or user unless… the subscriber or user has given his or her consent."
An independent pass re-reads the artefact byte for byte: hash matches, test definition correct, catalogue release current, coverage sufficient, PECR row fresh. Only now does a finding exist, and it is tiered:
Evidence collected on 26 August 2026 from a UK vantage shows a Meta Pixel request transmitting visitor data from /book-appointment before any consent was given, which is inconsistent with PECR regulation 6. On a healthcare booking page, the same artefact also raises a separate indicator for special-category data risk under UK GDPR Article 9, flagged at T3 for counsel.
Note the discipline: the deterministic part is stated as measured fact. The interpretive part (health-data inference) stays an indicator, because that conclusion belongs to a lawyer, not a scanner.
The clinic's agreed channel is Slack. The message carries the finding, the evidence link, the provision, and a fix with an owner and a deadline:
The developer flips the widget to consent-gated loading. A fresh cold session confirms: no pixel request before opt-in, tracking only after an affirmative Accept, and nothing after Reject. The finding closes as remediated, and the whole story, breach artefact, notification, fix, confirmation artefact, sits in the Evidence Vault.
If the ICO, a competitor or a claimant ever asks about that Tuesday, Harbourline's answer is not a shrug. It is a dated, hashed record showing the issue was found, fixed and verified in two days.
Harbourline Dental is fictional; the timeline, artefacts and Slack message are illustrative sample data. PECR regulation 6 text quoted from the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended. Nothing here is legal advice.