GetGDPRScan
Sign in
GDPR Website Scanner

Check your website for GDPR risks in 30 seconds

Run a quick automated scan for tracking, privacy policy coverage, cookie consent, and form data exposure.

Sample report

See exactly what you get

Click any image to zoom in

GDPR compliance for a website usually comes down to a handful of technical and content issues: tracking scripts that fire before consent, a cookie banner that doesn't actually block anything, a missing or incomplete privacy policy, and forms that collect personal data without disclosure. Our scanner checks your site's publicly visible pages against these common risk areas, so you can see exactly what's wrong and how to fix it — no legal background required.

How it works

1

We load your live page

We fetch your homepage and analyse it — no login or installation needed.

2

30+ GDPR checks run

We check cookie consent, trackers, forms, privacy policy, and technical security against GDPR requirements.

3

Score + action plan

Each finding is graded by severity and comes with a specific fix instruction and legal reference.

What we check

Cookie & Consent

  • Cookie consent banner
  • Reject / refuse option present
  • Trackers blocked before consent
  • Cookie policy: purpose & retention periods disclosed

Tracking & Analytics

  • Google Analytics / GA4
  • Google Ads (Conversion Tracking)
  • Meta (Facebook) Pixel
  • Other tracking scripts & pixels
  • Third-party font providers
  • Third-party iframes & embeds
  • Google Tag Manager (GTM)

Data Collection

  • Forms collecting personal data
  • Form submission method security
  • Google reCAPTCHA
  • Data minimisation & purpose limitation (Art. 5)

Technical Security

  • HTTPS / Secure Connection
  • SSL certificate validity
  • HTTP Security Headers (HSTS, X-Frame-Options…)
  • Advanced security headers (CSP, Permissions-Policy)
  • Cookie security flags (Secure, HttpOnly, SameSite)
  • Mixed HTTP/HTTPS content

Privacy Policy

  • Privacy policy exists and is accessible
  • Third-party services disclosed (reCAPTCHA, analytics, fonts…)
  • Data controller identity and contact details disclosed
  • Processing purposes and legal basis stated (Art. 6 GDPR)
  • Data recipients identified
  • Data retention periods stated
  • Data subject rights covered (Art. 15–21 GDPR)
  • Right to withdraw consent mentioned
  • Right to lodge a complaint with a supervisory authority
  • Implied consent language
  • International data transfers and safeguards disclosed

GDPR — not legal advice

This scan checks your website's publicly visible cookie consent, tracking, and data-handling setup against common GDPR requirements (Art. 6, 7, 13). It's an automated technical check, not a legal compliance audit — always confirm significant findings with a qualified advisor.

What does a GDPR website scan check?

GetGDPRScan analyses your site's publicly visible pages the same way a regulator or a visitor's browser would. It looks at what actually loads and runs, not just what your cookie banner claims to do.

  • Whether tracking scripts (Google Analytics, Meta Pixel, and others) load before the user consents
  • Whether a cookie banner is present and whether it has a working reject option
  • Whether a privacy policy is present, linked, and reachable
  • Whether forms that collect personal data disclose how it's used and include a consent mechanism
  • Basic technical signals like HTTPS enforcement that relate to data protection

Is a cookie banner required under GDPR?

If a website uses non-essential cookies or tracking — analytics, advertising pixels, embedded videos with third-party cookies — GDPR and the ePrivacy Directive generally require the user's consent before those activate, not just a notice that they exist.

  • A banner that only offers 'Accept' with no equivalent way to reject isn't valid consent under most EU guidance
  • Consent must come before tracking scripts run, not after — many sites get this wrong by loading Google Analytics on page load regardless of the banner
  • Essential cookies (session, security, load balancing) don't require consent, only disclosure
  • Requirements and enforcement vary somewhat by EU member state, but the core principle — prior, freely given, specific consent — is consistent

Does a GDPR scan guarantee compliance?

No automated tool can guarantee full GDPR compliance — that depends on your specific data processing, contracts with vendors, internal retention policies, and more, which aren't visible from the outside.

  • A scan is an automated first line of defence: it catches the most common, visible risks before a complaint or audit does
  • It cannot see your database, internal processes, or data processing agreements
  • Findings are a starting point for fixing what's detectable from a public scan, not a legal certificate
  • For anything high-stakes, pairing scan results with legal advice specific to your business is the safer approach

Frequently asked questions

Related compliance tools