Skip to content
One finding, end to end · how it gets proved SAMPLE DATA · FICTIONAL BUSINESS

One Tuesday, a pixel fires early.

Harbourline Dental is our fictional Manchester clinic: dental sub-sector, England sub-jurisdiction, 29 attached requirements. Follow one real-world-shaped breach from the moment their website changes to the moment the fix is proven. Every step below is how the Radar actually reasons.

CLAUSE · CAPTURE · HASH · OWNER
09:14 · CHANGE DETECTED

The clinic's marketing agency installs a new booking widget on /book-appointment. Helpful feature. But bundled inside it: a Meta Pixel that loads on page open. The Radar's scheduled pass sees the page's fingerprint change and queues a forensic re-capture.

09:21 · FORENSIC CAPTURE, COLD SESSION

A clean browser session, no cookies, no prior consent, loads the page from a UK vantage. It records every network request before the consent banner is touched:

GET harbourline-dental.example/book-appointment ... 200
GET fonts.example/... ... 200
POST facebook.com/tr?id=88412...&ev=PageView ← BEFORE CONSENT
consent_state: none · cookie_jar: empty at t0 · _fbp set at t+1.2s
artefact 8f3c19e2a7… captured 09:21:14Z · geo GB · hash stored

The dark panel is the only dark thing on this page, and that is deliberate: it is the machine's view. Screenshot, raw bytes, headers and consent state are all vaulted with the hash.

09:22 · WHICH LAW? THE GATES RUN

Harbourline's combination (healthcare · dental · UK · England) already carries 29 attached requirements. The pre-consent tracker test belongs to PECR. The gates re-check before anything is alleged:

✓ GATE 1 UK connected: establishment + targeting evidence
✓ GATE 2 England matched
✓ GATE 3 PECR is universal for UK site operators
✓ GATE 4 activity present: tracking technology in use
✓ GATE 5 no inverse requirement blocks
✓ GATE 6 nexus held: UK visitors, UK vantage evidence
PECR · PRIVACY AND ELECTRONIC COMMUNICATIONS REGULATIONS 2003 · REG. 6

"A person shall not store or gain access to information stored, in the terminal equipment of a subscriber or user unless… the subscriber or user has given his or her consent."

Enforced by the ICO · penalties rising to UK GDPR levels (£17.5m / 4%) as DUAA 2025 phases in
09:26 · VERIFICATION, THEN ADJUDICATION

An independent pass re-reads the artefact byte for byte: hash matches, test definition correct, catalogue release current, coverage sufficient, PECR row fresh. Only now does a finding exist, and it is tiered:

T1 · MEASURED BREACH SEVERITY HIGH · EFFORT LOW · PRIORITY 1

Evidence collected on 26 August 2026 from a UK vantage shows a Meta Pixel request transmitting visitor data from /book-appointment before any consent was given, which is inconsistent with PECR regulation 6. On a healthcare booking page, the same artefact also raises a separate indicator for special-category data risk under UK GDPR Article 9, flagged at T3 for counsel.

Note the discipline: the deterministic part is stated as measured fact. The interpretive part (health-data inference) stays an indicator, because that conclusion belongs to a lawyer, not a scanner.

09:31 · NOTIFY + COORDINATE

The clinic's agreed channel is Slack. The message carries the finding, the evidence link, the provision, and a fix with an owner and a deadline:

Compliance Radar → #harbourline-compliance · 09:31
T1 finding on /book-appointment: Meta Pixel firing before consent (PECR reg. 6). Evidence: artefact 8f3c19e2 (screenshot + network log). Fix: load the pixel only after opt-in via your consent platform; your booking-widget vendor documents this in Settings → Consent Mode. Owner: web developer. Suggested deadline: 48h. Reply here and we re-scan on your word.
THURSDAY 11:04 · RE-SCAN + VAULT

The developer flips the widget to consent-gated loading. A fresh cold session confirms: no pixel request before opt-in, tracking only after an affirmative Accept, and nothing after Reject. The finding closes as remediated, and the whole story, breach artefact, notification, fix, confirmation artefact, sits in the Evidence Vault.

finding HL-0042 · PECR reg. 6 · status: REMEDIATED
opened 26 Aug 09:26 · closed 28 Aug 11:04 · artefacts 2 · hashes verified
audit trail: exportable, timestamped, regulator-ready

If the ICO, a competitor or a claimant ever asks about that Tuesday, Harbourline's answer is not a shrug. It is a dated, hashed record showing the issue was found, fixed and verified in two days.

See the full dashboard this feeds Run this method on my site

Harbourline Dental is fictional; the timeline, artefacts and Slack message are illustrative sample data. PECR regulation 6 text quoted from the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended. Nothing here is legal advice.