GetGDPRScan
Sign in

GDPR Website Scanner

Check your website for GDPR risks in 30 seconds

Run a quick automated scan for tracking, privacy policy coverage, cookie consent, and form data exposure.

Tracking scriptsCookie consentPrivacy policiesFormsThird-party services

Analyzes websites in 13 European languages

🇬🇧 🇩🇪 🇫🇷 🇮🇹 🇪🇸 🇳🇱 🇸🇮 🇩🇰 🇸🇪 🇫🇮 🇳🇴 🇭🇷 🇷🇸

Sample report

See exactly what you get

Click any image to zoom in

Want full results?

🔓 Unlock full report

Most websites have hidden GDPR issues — often without knowing it.

No signup required Results in 30 seconds

This is what we’ll find on your site

Sample data
55 scripts · 2 trackers1 formCookie banner: YESPrivacy policy: YES

Cookie & Consent

1 issue

Cookie consent banner

Cookie consent banner detected on this page.

Reject / refuse option present

No reject button found in the consent banner.

Why this matters

EDPB Guidelines 05/2020 state that withdrawing or refusing consent must be as easy as giving it. A banner with only an Accept button is unlawful and has been the basis for fines by the French CNIL and Dutch AP.

Trackers blocked before consent

Available in Full Report

Cookie policy: purpose & retention periods disclosed

Available in Full Report

Tracking & Analytics

2 issues

Google Analytics / GA4

Google Analytics detected and loading without confirmed consent.

Why this matters

Google Analytics transfers user data (including IP addresses) to Google servers. Under GDPR this requires prior explicit consent — the Austrian and French DPAs have both issued decisions against GA without consent.

Google Ads (Conversion Tracking)

Google Ads conversion tracking not detected.

Meta (Facebook) Pixel

Meta / Facebook Pixel not detected.

!

Other tracking scripts & pixels

1 additional tracker detected

+ more pixels

🔒 Available in Full Report

Third-party font providers

Available in Full Report

Third-party iframes & embeds

Available in Full Report

Google Tag Manager (GTM)

Available in Full Report

Data Collection

Forms collecting personal data

No forms collecting personal data detected on this page.

Form submission method security

Forms use secure submission methods (POST).

Google reCAPTCHA

Available in Full Report

Data minimisation & purpose limitation (Art. 5)

Available in Full Report

Technical Security

1 issue

HTTPS / Secure Connection

HTTPS enabled — data in transit is encrypted.

SSL certificate validity

SSL certificate is valid and trusted.

HTTP Security Headers (HSTS, X-Frame-Options…)

Missing: X-Frame-Options.

Why this matters

GDPR Art. 5(1)(f) requires appropriate technical measures. Missing headers expose visitors to clickjacking and referrer-based data leakage.

!

Advanced security headers (CSP, Permissions-Policy)

Content-Security-Policy, Permissions-Policy not set — recommended but optional.

Cookie security flags (Secure, HttpOnly, SameSite)

Available in Full Report

Mixed HTTP/HTTPS content

Available in Full Report

Privacy Policy

Privacy policy exists and is accessible

A publicly accessible privacy policy was found.

Third-party services disclosed (reCAPTCHA, analytics, fonts…)

Available in Full Report

Data controller identity and contact details disclosed

Available in Full Report

Processing purposes and legal basis stated (Art. 6 GDPR)

Available in Full Report

Data recipients identified

Available in Full Report

More checks available in the full report.

Also check