Skip to content

A/B testing from Optimizely

Optimizely Web Experimentation and website tracking lawsuits

Optimizely shows different versions of a page to different visitors and records how each group behaves.

Free, about a minute, no signup for your score.

What Suitcast knows about Optimizely Web Experimentation

Medium risk

Type
A/B testing
Vendor
Optimizely

Requests the scanner matches to it

  • cdn.optimizely.com
  • cdn-pci.optimizely.com
  • logx.optimizely.com
  • .optimizely.com

The short answer

Optimizely Web Experimentation is an A/B testing script from Optimizely. Suitcast rates its risk under the California Invasion of Privacy Act, CIPA, as medium, because complaints describe scripts like it recording visitors before they consent. The fix is to load it only after a visitor accepts, or to remove it when it is not used.

Why complaints name it

Complaints describe testing tools like this as assigning visitors an ID and sending their clicks to a third party before consent.

The act allows $5,000 per violation, which is why firms look for scripts that run the moment a page opens.

The fix

How to stop Optimizely Web Experimentation firing before consent

Written for the person who runs the site, with the setting to change.
  1. Ask your developer to start the Optimizely snippet only after the cookie banner records an accept, or to use Optimizely's built-in opt-in setting.

  2. Remove it if you finished testing.

How the scan checks this

  1. Loads your pages like a first visit. A real browser, nothing clicked, nothing accepted.
  2. Checks every request before the banner is answered. A request to cdn.optimizely.com is matched to Optimizely Web Experimentation and recorded with the millisecond it fired.
  3. Clicks reject and watches again. When the banner has a reject button, the scan presses it; if Optimizely Web Experimentation keeps firing, the report says so.

Scanner rules and limits are on the methodology page.

Same type

Other A/B testing scripts the scanner checks

Scripts of the same kind carry the same pattern in complaints, and the same fix.

Questions owners ask

Whether Optimizely Web Experimentation is a problem, how to check your site, and where the counts come from.
Is having Optimizely Web Experimentation on my site illegal?
No. The complaints do not claim the script is illegal; they claim it recorded a visitor before the visitor consented, or kept recording after the visitor declined. Loading Optimizely Web Experimentation only after consent, or removing it when it is not used, is what removes the pattern the complaints describe.
How do I know if Optimizely Web Experimentation fires before consent on my site?
Run the free scan. It loads your pages without clicking anything and checks every request that leaves the browser against its tracker catalog, recording the millisecond each match fired. If Optimizely Web Experimentation appears, it fired before consent. When your banner has a reject button, the scan clicks it and reports whether the script kept firing.
Where do the case counts on this page come from?
From the complaint text of verified California Invasion of Privacy Act filings. When a complaint names this script, the case is linked to it. Complaints that are not yet available in the public record are not counted, so the number is a floor.

Does Optimizely Web Experimentation fire before consent on your site?

The free scan checks every request your pages make before the banner is answered, shows the millisecond Optimizely Web Experimentation fired, and whether it kept firing after reject.

Free, about a minute, no signup for your score.

Suitcast identifies risk indicators. It is not legal advice and does not determine compliance.