GDPR Website Check — Free Privacy Analysis
Check your website for GDPR and ePrivacy risks in under a minute. Every finding is backed by real evidence — no guessing, no blanket statements.
Free · No account required · 1 scan per day and IP address
- Evidence-based findings
- EU hosting (Hetzner)
- 100 % tracking-free itself
Most websites violate the GDPR — without knowing it
A cookie banner alone does not make a website compliant. Trackers often load before consent is given, plugins quietly embed US services, and every website update can introduce new risks. The problem: you cannot tell from the outside — but an authority or a cease-and-desist lawyer can.
up to €20M
or 4% of annual global turnover
That is how high a GDPR fine under Art. 83 GDPR can reach — relevant for small businesses too, once authorities find tracking without consent.
Cease-and-desist warnings
from competitors & associations
Google Fonts, the Meta pixel or analytics without valid consent are a frequent trigger for cease-and-desist warnings. A single non-compliant third-party request can be enough.
Loss of trust
among customers & business partners
Data protection is a buying argument. Those who can prove they work cleanly earn trust — those who stand out often lose it for good.
The good news: In under a minute you will know in black and white where you stand — with real evidence instead of gut feeling. Free and without an account.
Scan for free nowHow the free GDPR scan works
Enter URL
Enter the full URL of your website and click "Scan now for free".
Scan running
Our system checks the cookies, trackers, third-party requests and privacy configurations of your site.
Get report
You instantly receive a complete findings report with a risk assessment and concrete recommendations for action.
What a findings report looks like
Every finding is backed by real evidence and includes concrete recommendations for action.
Sample finding
Finding
The script gtag/js?id=G-XXXXX was loaded before cookie consent was given. This transfers personal data (IP address, usage behaviour) to Google LLC (USA) without a legal basis.
Recommendation
Only load analytics scripts after explicit consent via a GDPR-compliant consent manager (e.g. IAB TCF 2.2). Alternatively, evaluate cookieless analytics tools without a US transfer.
req#42cookie:_gaA complete report contains all findings by severity (Critical → High → Medium → Low) with a risk score.
Checking once isn't enough — stay on the safe side continuously
Data-protection compliance is not a fixed state but an ongoing process. Updates to your CMS and shop system (WordPress, Shopware, Shopify & Co.), plugins and themes change your website constantly and keep pulling in new services such as Google Fonts. Only a regular check with dated reports creates genuine provability and peace of mind — and we handle it automatically for you, without you having to think about it.
Updates change your website — and the risks
Every update to your CMS or shop system — WordPress, Shopware, Shopify & Co. — and every plugin or theme update brings new dependencies: embedded Google Fonts, marketing tags or external scripts can suddenly and unnoticed load new trackers. A one-off check is therefore already out of date tomorrow.
Catch issues early instead of fixing them expensively later
Recurring scans flag a new risk the moment it appears — not only once the cease-and-desist letter lands in your mailbox. You stay in control at all times.
Reports arrive automatically by email
Set it up once and never think about it again: you receive your current report automatically by email — as an easy-to-read summary and as a PDF to file away.
Provable for authorities & partners
Every report is backed by real evidence and dated. That way you document seamlessly that you check your website regularly — a strong argument when it counts.
Your convenience features from the Starter plan
- Weekly or daily schedules — you choose the rhythm
- Automatic report by email after every scan
- PDF export for your data-protection documentation
- Clear dashboard with history and changes
The legal bases the check is built on
We don’t assess by gut feeling, but along the applicable EU and German rules — and we capture the evidence using the official methodology of Europe’s data-protection supervisors.
General Data Protection Regulation (EU) 2016/679
Principles of processing (Art. 5), legal bases (Art. 6), information duties (Art. 13) and the fining framework (Art. 83) — the basis of every data-protection assessment in the EU.
Telecommunications Digital Services Data Protection Act
The German law (formerly TTDSG) requires explicit consent for storing and reading information on end-user devices — that is, for most cookies and trackers.
ePrivacy Directive 2002/58/EC
The EU rule on protecting privacy in electronic communications — the foundation of cookie and consent rules across Europe.
Planet49 (C-673/17) & Schrems II (C-311/20)
Active, informed consent instead of pre-ticked boxes — plus strict requirements for data transfers to third countries such as the USA.
German Data Protection Conference (DSK)
The guidance for telemedia providers spells out how German authorities assess tracking, consent and opt-in in practice.
Website Evidence Collector
Under the hood, the open-source Website Evidence Collector developed by the European Data Protection Supervisor (EDPS) captures the evidence — the same methodology supervisory authorities use for their own audits.
Note: The report is a technical aid and does not replace individual legal advice. It highlights technical GDPR and ePrivacy risks on an evidence basis — the legally binding assessment is made by your data protection officer.
- TÜV + BSI + IHK certified
- 500 compliance mandates
- Liability-insured up to €5 million
- Response in under 24 h
Typical data-protection risks by industry
Every industry has its own pitfalls. The scanner detects them automatically — regardless of what your website was built with.
Medical practices & healthcare
- Appointment-booking widgets with US third-party services
- Health data as a special category (Art. 9 GDPR)
- Google Maps & Fonts without consent
E-commerce & online shops
- Tracking pixels (Meta, Google Ads) before consent
- Cart cookies with excessively long lifetimes
- Payment scripts from third-party servers
Law firms & tax advisors
- Client confidentiality vs. embedded third-party services
- Contact forms without a transport-encryption notice
- Professional-conduct disclosure obligations
Agencies & service providers
- Portfolio embeds (YouTube, Vimeo) load trackers
- Web fonts & CDNs transmit visitor IPs
- Liability toward your own clients for violations
Trades & local businesses
- Website-builder sites with hidden trackers
- Review widgets from third-party platforms
- Outdated or missing privacy policy
SaaS & software providers
- Product analytics (heatmaps, session replay)
- Login cookies without correct classification
- Status & support widgets from US providers
Plans
Start free — and scale when you need to.
1 free scan per day, no registration.
- 1 scan/day per IP
- Full HTML report
- Findings with evidence
Regular checks with reporting for small teams.
- 5 scans/day
- Recurring schedules
- Report by email & PDF export
- Your own dashboard
For agencies and larger client portfolios.
- Unlimited scans (fair use)
- Everything in Starter
- Multi-tenant
- API access
All plans for B2B customers (businesses within the meaning of § 14 BGB). Prices incl. VAT, payment via PayPal.
Frequently asked questions
Contact & initial consultation
Want to discuss a scan result, ask about a plan, or get help with implementation? Write to us — we reply within 24 hours.
DATUREX GmbH
Hermann-Reichelt-Straße 3A01109 Dresden
Germany
- Reply within 24 h
- Initial consultation free & non-binding
- Advice in German