EUComply

How the EUComply scanner works — step by step.

Enter any URL — EUComply checks 9 compliance factors in about 10 seconds. No sign-up, no installation, no plugin. Here's exactly what happens, what we check, and what each result means for your site.

Try it now → See Pro features

What the scanner does

EUComply acts like a browser with a checklist. It requests your site's public URL, reads the HTTP response and page HTML, and compares what it finds against 9 compliance checkpoints drawn from EU regulations.

1

Enter a URL

You paste any public website URL — yoursite.com, shopify.com/store, or any page. The only requirement is a public URL that responds to HTTP requests. No admin access, no plugin, no API key.

2

Fetch the site (like a browser would)

EUComply's server sends an HTTP request to your URL with a standard browser User-Agent. It follows redirects (so example.com → www.example.com is handled automatically). The response headers and HTML body are captured for analysis. This works identically regardless of what CMS or platform your site runs on — WordPress, Shopify, Webflow, Wix, static HTML.

3

Run 9 compliance checks

Every check is a pass/fail (or warning) test based on what the page exposes. None require interpreting the full site — each check runs in under a second.

SSL / HTTPS + HSTS: Is the site served over HTTPS with Strict-Transport-Security? (GDPR Art. 32 — security of processing)
Cookie consent: Does the page load a known consent platform (Cookiebot, OneTrust, CookieYes, etc.)? (ePrivacy Directive — prior consent for non-essential cookies)
Google Consent Mode v2: Does the page include gtag/dataLayer signals for consent-based ad personalization? (Required since March 2024 for EU ad conversion tracking)
Form + privacy link: If the page has forms, is a privacy policy link visible nearby? (GDPR Art. 13 — transparency at data collection)
Legal pages: Does the homepage link to a privacy policy, imprint/impressum, accessibility statement, and terms? (GDPR, eCommerce Directive, EAA)
Security headers: Are CSP, X-Content-Type-Options, Referrer-Policy, and X-Frame-Options set? (NIS2 Art. 21 — supply-chain security baseline)
DORA / resilience: Do the page contents mention operational resilience, incident reporting, or ICT risk management? (DORA — EU 2022/2554 for financial & ICT entities)
Trackers without consent: Does the page load GA4, Meta Pixel, TikTok, Hotjar, or other trackers before a consent signal? (Most common EU fine trigger for SMB sites)
Platform fingerprint: What CMS or platform runs the site? (Informational — helps interpret other results)
4

Get a scored report in seconds

Results appear as a scored report with clear pass/fail/warning badges. Each check includes a plain-language explanation of what was found and, on failures, a specific suggested fix. No jargon, no legal-ese — just what to do next.

See it in action

Enter any URL below — or click one of the examples to see a live report.

Try:

How it's different from other scanners

Works on every platform

Most compliance tools only work with WordPress (plugin-based) or scan a single page. EUComply checks any public URL — WordPress, Shopify, Webflow, Next.js, Squarespace, static HTML.

No sign-up for scanning

Free tier requires zero registration. Enter a URL, get a report. No "sign up to see results" gate, no limits. Pro only when you need daily monitoring, PDF reports, and templates.

Multiple regulations in one scan

One scan checks GDPR (privacy, security, consent), NIS2 (headers, supply chain), DORA (resilience disclosures), and EAA (accessibility statement). One report instead of four separate tools.

Frequently asked questions

Does it work on password-protected or internal sites?

No. The scanner only reaches public URLs. Admin areas, login pages, and staging environments are not accessible — these require a different approach (and are not covered by the GDPR right-to-know obligations anyway).

Is a passing score enough for full compliance?

No. EUComply checks technical signals that a compliance-aware person expects to find on a public-facing site. Full compliance also requires data mapping, processing records, consent logs, data-breach procedures, and appropriate contracts. Think of it as a smoke detector — it catches obvious issues before they become expensive.

How do I prove compliance to an auditor or client?

The free scan is a one-time snapshot. Pro runs daily scans, keeps a 30-day score history, produces auditor-ready PDF reports, and gives you a live compliance badge that visitors can verify. It's the documentation layer that turns a scan into defensible evidence.

What does the compliance badge look like?

Pro subscribers embed a JavaScript badge in their site footer. It shows the current compliance score with a small "Verified by EUComply" link. Clicking it opens the public scan record — so a visitor, client, or regulator can verify your score independently.

Need more than a one-time scan?

Pro adds daily automated monitoring, PDF reports, compliance badge, email alerts, and $216+ worth of document templates. All for $79/year.

See Pro features → Try the free scanner first