DATUREX

GDPR Website Check — Free Privacy Analysis

Check your website for GDPR and ePrivacy risks in under a minute. Every finding is backed by real evidence — no guessing, no blanket statements.

Report language

Report language

Free · No account required · 1 scan per day and IP address

  • Evidence-based findings
  • EU hosting (Hetzner)
  • 100 % tracking-free itself

Most websites violate the GDPR — without knowing it

A cookie banner alone does not make a website compliant. Trackers often load before consent is given, plugins quietly embed US services, and every website update can introduce new risks. The problem: you cannot tell from the outside — but an authority or a cease-and-desist lawyer can.

up to €20M

or 4% of annual global turnover

That is how high a GDPR fine under Art. 83 GDPR can reach — relevant for small businesses too, once authorities find tracking without consent.

Cease-and-desist warnings

from competitors & associations

Google Fonts, the Meta pixel or analytics without valid consent are a frequent trigger for cease-and-desist warnings. A single non-compliant third-party request can be enough.

Loss of trust

among customers & business partners

Data protection is a buying argument. Those who can prove they work cleanly earn trust — those who stand out often lose it for good.

The good news: In under a minute you will know in black and white where you stand — with real evidence instead of gut feeling. Free and without an account.

Scan for free now

How the free GDPR scan works

1

Enter URL

Enter the full URL of your website and click "Scan now for free".

2

Scan running

Our system checks the cookies, trackers, third-party requests and privacy configurations of your site.

3

Get report

You instantly receive a complete findings report with a risk assessment and concrete recommendations for action.

What a findings report looks like

Every finding is backed by real evidence and includes concrete recommendations for action.

Sample finding

Google Analytics loaded without consent
Critical

Finding

The script gtag/js?id=G-XXXXX was loaded before cookie consent was given. This transfers personal data (IP address, usage behaviour) to Google LLC (USA) without a legal basis.

Recommendation

Only load analytics scripts after explicit consent via a GDPR-compliant consent manager (e.g. IAB TCF 2.2). Alternatively, evaluate cookieless analytics tools without a US transfer.

Evidence:req#42cookie:_ga

A complete report contains all findings by severity (Critical → High → Medium → Low) with a risk score.

Checking once isn't enough — stay on the safe side continuously

Data-protection compliance is not a fixed state but an ongoing process. Updates to your CMS and shop system (WordPress, Shopware, Shopify & Co.), plugins and themes change your website constantly and keep pulling in new services such as Google Fonts. Only a regular check with dated reports creates genuine provability and peace of mind — and we handle it automatically for you, without you having to think about it.

Updates change your website — and the risks

Every update to your CMS or shop system — WordPress, Shopware, Shopify & Co. — and every plugin or theme update brings new dependencies: embedded Google Fonts, marketing tags or external scripts can suddenly and unnoticed load new trackers. A one-off check is therefore already out of date tomorrow.

Catch issues early instead of fixing them expensively later

Recurring scans flag a new risk the moment it appears — not only once the cease-and-desist letter lands in your mailbox. You stay in control at all times.

Reports arrive automatically by email

Set it up once and never think about it again: you receive your current report automatically by email — as an easy-to-read summary and as a PDF to file away.

Provable for authorities & partners

Every report is backed by real evidence and dated. That way you document seamlessly that you check your website regularly — a strong argument when it counts.

Your convenience features from the Starter plan

  • Weekly or daily schedules — you choose the rhythm
  • Automatic report by email after every scan
  • PDF export for your data-protection documentation
  • Clear dashboard with history and changes
View plans & convenience features

The legal bases the check is built on

We don’t assess by gut feeling, but along the applicable EU and German rules — and we capture the evidence using the official methodology of Europe’s data-protection supervisors.

GDPR

General Data Protection Regulation (EU) 2016/679

Principles of processing (Art. 5), legal bases (Art. 6), information duties (Art. 13) and the fining framework (Art. 83) — the basis of every data-protection assessment in the EU.

§ 25 TDDDG

Telecommunications Digital Services Data Protection Act

The German law (formerly TTDSG) requires explicit consent for storing and reading information on end-user devices — that is, for most cookies and trackers.

ePrivacy

ePrivacy Directive 2002/58/EC

The EU rule on protecting privacy in electronic communications — the foundation of cookie and consent rules across Europe.

CJEU case law

Planet49 (C-673/17) & Schrems II (C-311/20)

Active, informed consent instead of pre-ticked boxes — plus strict requirements for data transfers to third countries such as the USA.

DSK guidance

German Data Protection Conference (DSK)

The guidance for telemedia providers spells out how German authorities assess tracking, consent and opt-in in practice.

EU/EDPS methodology

Website Evidence Collector

Under the hood, the open-source Website Evidence Collector developed by the European Data Protection Supervisor (EDPS) captures the evidence — the same methodology supervisory authorities use for their own audits.

Note: The report is a technical aid and does not replace individual legal advice. It highlights technical GDPR and ePrivacy risks on an evidence basis — the legally binding assessment is made by your data protection officer.

  • TÜV + BSI + IHK certified
  • 500 compliance mandates
  • Liability-insured up to €5 million
  • Response in under 24 h

Typical data-protection risks by industry

Every industry has its own pitfalls. The scanner detects them automatically — regardless of what your website was built with.

Medical practices & healthcare

  • Appointment-booking widgets with US third-party services
  • Health data as a special category (Art. 9 GDPR)
  • Google Maps & Fonts without consent

E-commerce & online shops

  • Tracking pixels (Meta, Google Ads) before consent
  • Cart cookies with excessively long lifetimes
  • Payment scripts from third-party servers

Law firms & tax advisors

  • Client confidentiality vs. embedded third-party services
  • Contact forms without a transport-encryption notice
  • Professional-conduct disclosure obligations

Agencies & service providers

  • Portfolio embeds (YouTube, Vimeo) load trackers
  • Web fonts & CDNs transmit visitor IPs
  • Liability toward your own clients for violations

Trades & local businesses

  • Website-builder sites with hidden trackers
  • Review widgets from third-party platforms
  • Outdated or missing privacy policy

SaaS & software providers

  • Product analytics (heatmaps, session replay)
  • Login cookies without correct classification
  • Status & support widgets from US providers

Plans

Start free — and scale when you need to.

Free
€0/day

1 free scan per day, no registration.

  • 1 scan/day per IP
  • Full HTML report
  • Findings with evidence
Scan now
Recommended
Starter
€49.00/month

Regular checks with reporting for small teams.

  • 5 scans/day
  • Recurring schedules
  • Report by email & PDF export
  • Your own dashboard
Sign up now
Pro
€149.00/month

For agencies and larger client portfolios.

  • Unlimited scans (fair use)
  • Everything in Starter
  • Multi-tenant
  • API access
Sign up now

All plans for B2B customers (businesses within the meaning of § 14 BGB). Prices incl. VAT, payment via PayPal.

Frequently asked questions

Contact & initial consultation

Want to discuss a scan result, ask about a plan, or get help with implementation? Write to us — we reply within 24 hours.

DATUREX GmbH

Hermann-Reichelt-Straße 3A
01109 Dresden
Germany
  • Reply within 24 h
  • Initial consultation free & non-binding
  • Advice in German

Your details are used solely to process your inquiry. Privacy Policy