The biggest EU privacy fines — Google €325M, SHEIN €150M, Meta €1.2B — all started with the same technical mistakes most websites still make. Paste your URL and get a plain-language compliance score: no sign-up, nothing installed, works on every platform.
The scan runs nine technical checks against your live page. The ones that matter most — because they are the exact patterns regulators fine for:
| Check | Why it matters |
|---|---|
| Trackers before consent | Analytics or ad cookies firing before the visitor clicks is the pattern behind the SHEIN (€150M) and American Express decisions. It is invisible to you — but not to a regulator's test tool. |
| Google Consent Mode v2 | Required since March 2024 for EEA ad personalisation. Missing signals silently break Google Ads measurement. |
| IAB TCF signals | Most large ad platforms read consent through IAB's Transparency & Consent Framework. Missing TCF wiring means "reject" may not reach them. |
| HTTPS & security headers | Unencrypted pages fail the baseline of GDPR Art. 32 and NIS2 expectations — and lose visitor trust. |
| Privacy policy reachable | The ePrivacy rule requires clear information before consent; an unreachable policy undermines the entire legal basis. |
Deeper background: the GDPR cookie fines tracker and the EU cookie consent guide 2026.
If you have visitors from the EU/EEA — even a single one — yes. GDPR and the ePrivacy rules apply based on where your visitors are, not where your company is. A US or Asian webshop shipping to Europe is fully in scope, which is why enforcement has reached companies far outside the EU.
EU data protection authorities can fine up to €20 million or 4% of global revenue under GDPR, plus ePrivacy sanctions. Recent decisions include €325M against Google and €150M against SHEIN for consent failures. Most proceedings against ordinary business sites begin with a single complaint — often from a competitor or a privacy activist running automated checks like this one.
No platform guarantees compliance out of the box. WordPress plugins, Shopify apps and Squarespace banners all require correct configuration — and misconfiguration is itself a common violation. Compliance depends on how your scripts and consent tool are set up, which is exactly why testing the live page matters regardless of platform.
Yes. This checker fetches your public page HTML and analyses it server-side. Nothing is installed on your site, and no account is needed. It works identically on WordPress, Shopify, Wix, Squarespace, Webflow, Next.js or hand-coded sites.