EUComply

Is your website breaking GDPR? Find out free — in 10 seconds.

The biggest EU privacy fines — Google €325M, SHEIN €150M, Meta €1.2B — all started with the same technical mistakes most websites still make. Paste your URL and get a plain-language compliance score: no sign-up, nothing installed, works on every platform.

Try:

What the check looks at

The scan runs nine technical checks against your live page. The ones that matter most — because they are the exact patterns regulators fine for:

CheckWhy it matters
Trackers before consentAnalytics or ad cookies firing before the visitor clicks is the pattern behind the SHEIN (€150M) and American Express decisions. It is invisible to you — but not to a regulator's test tool.
Google Consent Mode v2Required since March 2024 for EEA ad personalisation. Missing signals silently break Google Ads measurement.
IAB TCF signalsMost large ad platforms read consent through IAB's Transparency & Consent Framework. Missing TCF wiring means "reject" may not reach them.
HTTPS & security headersUnencrypted pages fail the baseline of GDPR Art. 32 and NIS2 expectations — and lose visitor trust.
Privacy policy reachableThe ePrivacy rule requires clear information before consent; an unreachable policy undermines the entire legal basis.
Fair warning: passing today doesn't mean passing tomorrow. Marketing adds scripts, CMP settings drift, tag managers change. Pro ($79/year) re-scans your site daily and alerts you when something breaks.

The three mistakes that cost real companies millions

  1. Cookies fire before the click. Open your own site in an incognito window with dev tools open — if network requests hit analytics or ad domains before you touch the banner, you have pre-consent tracking. This is the single most common finding in enforcement actions against ordinary company sites.
  2. "Reject all" is harder than "Accept all". Equal prominence, equal number of clicks, first banner layer — anything less is a dark pattern under the standard set by CNIL's decisions against Meta and Google.
  3. Rejecting changes nothing. Click "Reject all", reload, and watch whether the same cookies fire again. Misconfigured tag managers make this one of the most common audit findings.

Deeper background: the GDPR cookie fines tracker and the EU cookie consent guide 2026.

Frequently asked questions

Is my website legally required to be GDPR compliant?

If you have visitors from the EU/EEA — even a single one — yes. GDPR and the ePrivacy rules apply based on where your visitors are, not where your company is. A US or Asian webshop shipping to Europe is fully in scope, which is why enforcement has reached companies far outside the EU.

What happens if my site fails a compliance check?

EU data protection authorities can fine up to €20 million or 4% of global revenue under GDPR, plus ePrivacy sanctions. Recent decisions include €325M against Google and €150M against SHEIN for consent failures. Most proceedings against ordinary business sites begin with a single complaint — often from a competitor or a privacy activist running automated checks like this one.

Doesn't my platform handle cookie compliance automatically?

No platform guarantees compliance out of the box. WordPress plugins, Shopify apps and Squarespace banners all require correct configuration — and misconfiguration is itself a common violation. Compliance depends on how your scripts and consent tool are set up, which is exactly why testing the live page matters regardless of platform.

Can I check without installing anything?

Yes. This checker fetches your public page HTML and analyses it server-side. Nothing is installed on your site, and no account is needed. It works identically on WordPress, Shopify, Wix, Squarespace, Webflow, Next.js or hand-coded sites.