A free compliance scan for websites with visitors in the EU.
Enter a URL. EUComply fetches the page the way a browser does and checks nine things regulators, auditors and procurement teams tend to ask about first. No account; the worker keeps only aggregate scan counters and hostname-level statistics, not the full URL or scan results.
Takes about ten seconds. The scan reads the public HTML and HTTP headers of the page you give it — nothing more.
Who it is for
People who run a website
You have customers or readers in Europe and no legal department. You want to know whether the obvious things are in place before a customer, a competitor or a regulator points them out.
Agencies and freelancers
You hand over sites and get the compliance questions afterwards. Run a scan before launch and again after every redesign, and send the client a link to the result instead of a promise.
Developers
You added the consent banner and the headers three deploys ago. The scan tells you whether they are still there. The checks are open source, so you can read exactly what "pass" means.
How the scan works
- You give it a URL
A domain is enough. The scanner normalises it and fetches the front page over HTTPS.
- It reads what a browser would receive
Response headers, TLS details and the served HTML. It does not log in, click, fill forms or crawl other pages.
- It runs nine checks
Each check looks for concrete evidence: a header that is present, a consent script that loads, a privacy link next to a form.
- You get a result you can share
Pass, warning or fix needed for each check, with a suggested fix. The result lives in the link, not in a database.
What it checks
Nine checks, each tied to a specific rule or widely accepted baseline. The scanner reports what it found, not what it thinks of you.
- HTTPS and HSTS
Is the site served over TLS, and does it send Strict-Transport-Security? GDPR Article 32 expects appropriate technical security; HSTS is the cheap part of it.
- Cookie consent
Looks for a known consent platform (Cookiebot, OneTrust, Klaro, Complianz and about a dozen more) in the served HTML. The ePrivacy Directive requires consent before non-essential cookies.
- Tracker and consent markers
Compares Google Analytics, Meta Pixel, TikTok, Hotjar and similar script markers with consent-platform markers in the served HTML. Runtime request order is not observed.
- Google Consent Mode v2
Detects the consent-mode signals Google has required for EU ad personalisation since March 2024. Only relevant if you run Google Ads or Analytics.
- IAB TCF
Detects the Transparency and Consent Framework used by publishers and ad-tech. Informational for most sites.
- Forms and privacy notice
If the page has a form, is there a link to a privacy policy? GDPR Article 13 requires informing people at the point of collection.
- Legal pages
Are a privacy policy, terms, an imprint (mandatory in Germany and Austria) and an accessibility statement linked from the front page?
- Security headers
Content-Security-Policy, X-Content-Type-Options, Referrer-Policy and frame protection. Not a law, but the baseline NIS2 auditors and cyber insurers expect.
- Resilience and mail markers in the page text
Counts static markers in the served page: incident response, business continuity, failover, a status page, and SPF/DKIM/DMARC/MX wording. Two or more markers count as a pass, and the check runs on every site. It reads wording, not controls, so it is not a DORA assessment.
What it cannot tell you
The scan looks at one page, once, from the outside. It cannot see what your consent banner does after someone clicks, what your privacy policy actually says, how you process data on the server, or whether your contracts with processors exist.
A full score means the visible basics are in place. It does not mean you are compliant, and no automated tool can honestly claim that. Use the result as a to-do list and as evidence that you checked, not as a certificate.
Where the rules stand
- GDPR applies
Consent, privacy notices and the right to be informed cover every website with visitors in the EU.
- NIS2 transposition deadline
Essential and important entities in 18 sectors need risk measures and incident reporting; national laws are still arriving.
- DORA applies
Financial entities and their ICT providers must manage ICT risk, test resilience and report incidents.
- European Accessibility Act applies
New e-commerce, banking and ticketing services must be accessible; services that already existed have until 28 June 2030.
- AI Act: most obligations apply
Chatbots and generated content must be labelled; the high-risk rules for regulated products follow in 2027.
- Cyber Resilience Act reporting
Makers of products with digital elements must report actively exploited vulnerabilities; the full obligations apply from 11 December 2027.
The dates are when the EU rules start to apply. National implementation can add earlier or stricter deadlines.
The guide, free as a PDF
EU Website Compliance Guide 2026 is a 24-page handbook for the person who owns the website rather than the lawyer. Each chapter explains one rule, what it asks of a website in practice, and ends with a checklist you can run against your own site.
It covers the same ground as the scanner plus the things a scanner cannot see: what a privacy policy must contain, when an imprint is mandatory, what the Accessibility Act means for a shop, and how NIS2 and DORA reach suppliers.
- Why compliance matters in 2026
- GDPR fundamentals for websites
- Cookie consent: what the law requires
- Privacy policy: the Article 13 checklist
- Imprint and legal notice
- Security headers
- Third-party trackers
- European Accessibility Act
- NIS2 and DORA
- Email: SPF, DKIM, DMARC
- Compliance by platform
- Monthly maintenance checklist
- Tools and resources
- Regulation overview table
Pricing, honestly
The scanner, the guide and the checklists are free and will stay free. Pro costs 79 USD per website per year and unlocks editable HTML document starters plus an HTML report from the latest WordPress scan. Full document templates are sold separately from 29 USD. Hosted daily monitoring is not included.
Questions people ask
Do you store the URLs or results?
No. The scan runs in a Cloudflare Worker, returns the result to your browser and forgets it. The worker keeps a scan counter and hostname-level aggregate statistics, not the full URL or scan results. If you register a site for daily monitoring, that domain and your email are stored for that purpose only.
Is the scan itself GDPR-friendly?
The site sets no cookies and loads no third-party fonts or embeds. Visits are counted with Plausible, a cookieless analytics tool hosted in the EU that stores no personal data. The scanner fetches your public page the way any visitor would.
Does it work for non-WordPress sites?
Yes. It reads HTTP and HTML, so it works on Shopify, Webflow, Squarespace, Wix, Next.js, Drupal, hand-written HTML and anything else that serves a page. It identifies the platform when it can, so the suggested fixes are relevant.
My site passed. Am I compliant?
You have the visible basics in place, which is further than most sites get. Compliance also involves what you do with data, what your documents say and how you handle requests. The guide and the checklists cover that part.
Why were the legal-document generators removed?
Earlier versions of this site offered generators for privacy policies, imprints, terms and refund policies. They produced documents that looked legal without a lawyer behind them. That is not a service I am comfortable offering, so they are gone. The checklists tell you what such documents must contain.
Who makes this
EUComply is built and maintained by Mads Holst Jensen, a developer in Odense, Denmark, who builds and looks after websites for agencies and small businesses. It started as an internal pre-launch check and became a public tool because clients kept asking for it. The scanner's source is on GitHub; if a check is wrong, open an issue.