No sign-up, no installation, no trial. Paste your domain and get a plain-language report on the technical checks regulators actually run: cookie consent, pre-consent trackers, Google Consent Mode v2 and security headers. Works on WordPress, Shopify, Wix, Squarespace, Webflow, Next.js — or hand-written HTML.
The scan runs nine automated checks against your live page over plain HTTP/HTML. The ones that map directly to enforcement:
| Check | GDPR / ePrivacy link |
|---|---|
| Cookies set before consent | ePrivacy Directive: prior consent required for non-essential cookies. This is the single most common finding in EU enforcement against ordinary business sites. |
| Google Consent Mode v2 | Required since March 2024 for EEA ad personalisation. Missing signals silently restrict Google Ads measurement. |
| IAB TCF signals | The framework most large ad platforms use to receive consent. Missing wiring means a visitor's "Reject" may never reach them. |
| HTTPS & security headers | GDPR Art. 32 requires appropriate technical security measures; missing headers are also an OWASP baseline failure. |
| Privacy policy reachable from homepage | GDPR Art. 13: information must be provided before data collection. An unreachable policy undermines the whole legal basis. |
| Forms with privacy notice links | Every data-collecting form needs a visible link to your privacy policy. |
Most free GDPR checkers test one thing — whether you have a cookie banner. That misses what regulators actually fine for. This scanner looks at how your site behaves:
Deeper background: the EU cookie consent guide 2026, the GDPR cookie fines tracker, and our scanner comparison.
Yes. Scanning any URL is free, unlimited, and requires no account or credit card. The paid product, Pro ($79/year), adds daily re-scans, email alerts and auditor-ready PDF documentation — you only need it if you must prove compliance over time.
Yes — that is the point. The scanner analyses HTTP responses and HTML markup, so it works identically on Shopify, Wix, Squarespace, Webflow, Next.js, Drupal, Joomla, static HTML and custom stacks. No plugin, app or server access needed.
No. Each scan runs in memory and returns its result immediately. No URLs, IPs or scan data are logged or stored.
No. The scanner identifies technical patterns — missing consent signals, trackers without gating, absent security headers. These are strong indicators of compliance risk, but only a qualified lawyer can give legal advice about your specific situation.
Start with the failing checks in the report: each one names the concrete pattern found. For consent issues, review your CMP configuration so scripts only load after consent, and connect Google Consent Mode v2. Re-scan after each fix — it takes ten seconds.