GDPR Website Scanner
Check your website for GDPR risks in 30 seconds
Run a quick automated scan for tracking, privacy policy coverage, cookie consent, and form data exposure.
Analyzes websites in 13 European languages
🇬🇧 🇩🇪 🇫🇷 🇮🇹 🇪🇸 🇳🇱 🇸🇮 🇩🇰 🇸🇪 🇫🇮 🇳🇴 🇭🇷 🇷🇸
Sample report
See exactly what you get
Click any image to zoom in
Want full results?
Most websites have hidden GDPR issues — often without knowing it.
This is what we’ll find on your site
Sample dataCookie & Consent
1 issueCookie consent banner
Cookie consent banner detected on this page.
Reject / refuse option present
No reject button found in the consent banner.
Why this matters
EDPB Guidelines 05/2020 state that withdrawing or refusing consent must be as easy as giving it. A banner with only an Accept button is unlawful and has been the basis for fines by the French CNIL and Dutch AP.
Trackers blocked before consent
Available in Full Report
Cookie policy: purpose & retention periods disclosed
Available in Full Report
Tracking & Analytics
2 issuesGoogle Analytics / GA4
Google Analytics detected and loading without confirmed consent.
Why this matters
Google Analytics transfers user data (including IP addresses) to Google servers. Under GDPR this requires prior explicit consent — the Austrian and French DPAs have both issued decisions against GA without consent.
Google Ads (Conversion Tracking)
Google Ads conversion tracking not detected.
Meta (Facebook) Pixel
Meta / Facebook Pixel not detected.
Other tracking scripts & pixels
1 additional tracker detected
🔒 Available in Full Report
Third-party font providers
Available in Full Report
Third-party iframes & embeds
Available in Full Report
Google Tag Manager (GTM)
Available in Full Report
Data Collection
Forms collecting personal data
No forms collecting personal data detected on this page.
Form submission method security
Forms use secure submission methods (POST).
Google reCAPTCHA
Available in Full Report
Data minimisation & purpose limitation (Art. 5)
Available in Full Report
Technical Security
1 issueHTTPS / Secure Connection
HTTPS enabled — data in transit is encrypted.
SSL certificate validity
SSL certificate is valid and trusted.
HTTP Security Headers (HSTS, X-Frame-Options…)
Missing: X-Frame-Options.
Why this matters
GDPR Art. 5(1)(f) requires appropriate technical measures. Missing headers expose visitors to clickjacking and referrer-based data leakage.
Advanced security headers (CSP, Permissions-Policy)
Content-Security-Policy, Permissions-Policy not set — recommended but optional.
Cookie security flags (Secure, HttpOnly, SameSite)
Available in Full Report
Mixed HTTP/HTTPS content
Available in Full Report
Privacy Policy
Privacy policy exists and is accessible
A publicly accessible privacy policy was found.
Third-party services disclosed (reCAPTCHA, analytics, fonts…)
Available in Full Report
Data controller identity and contact details disclosed
Available in Full Report
Processing purposes and legal basis stated (Art. 6 GDPR)
Available in Full Report
Data recipients identified
Available in Full Report
More checks available in the full report.