EUComply

EU Compliance Audit Report

Sample report with illustrative data (generated January 2026) — your Pro reports show live results for your own domain.

Download this report as PDF

URL: https://shopify.com
Generated: January 15, 2026 – 06:02 UTC
Platform detected: Shopify
Report ID: EUC-2026-0115-0602
Plan: EUComply Pro · Daily monitoring (scan #14 of 30-day history)
71%

Overall EU Compliance Score

Your site passes most automated checks. Two items need attention — see findings below.

Pass — minor issues found

Score Summary

71% Overall score
5/7 Checks passed
2 Issues found
30 Days of history

Detailed Check Results

  • HTTPS TLS 1.3 active, valid certificate (Let's Encrypt), expires Mar 12, 2026
  • HSTS header HTTPS works but Strict-Transport-Security header is missing → Add: Strict-Transport-Security: max-age=31536000; includeSubDomains (improves security score for GDPR Art. 32)
  • Cookie consent Cookie consent banner detected (Shopify's default consent banner — verifies consent logic independently)
  • Forms & privacy link 5 forms detected, privacy policy linked in footer
  • Legal pages Privacy policy and terms of service found via common paths
  • CSP header Content-Security-Policy header not set — risk of XSS and data exfiltration → Implement CSP with default-src 'self' as baseline (NIS2 Art. 21 — basic security measures)
  • DORA resilience HTTPS + valid certificate — meets basic DORA ICT security requirements

Recommended Fixes (priority order)

  1. Add HSTS header — protects against SSL stripping. Add Strict-Transport-Security to your server config or Shopify theme.liquid header.
  2. Add Content-Security-Policy header — limits which scripts can run on your site. Start with a restrictive policy and relax as needed.
  3. Review cookie categories — ensure analytics/tracking cookies are correctly categorized as "optional" in your consent manager.

30-Day Compliance History

Score trend over the last 30 days:


Dec 18                                         Jan 15

Dec 20–22: Score dropped due to expired SSL cert (renewed Dec 23). Daily monitoring caught it the same day — no auditor ever saw the gap.

Attachments

This report includes the following documents (available for download with Pro):

  • Compliance Score Badge — embeddable badge showing your 71% score, click-through to verified record
  • GDPR Data Processing Agreement (Art. 28) — controller → processor DPA with EU hosting clauses
  • NIS2 Vendor Compliance Clause Set — audit-trail, incident-reporting and subcontractor clauses
  • EAA Accessibility Statement — compliant with European Accessibility Act requirements

Get your own automated compliance reports

Daily scans, PDF reports, email alerts, and legal templates — $79/year per site.

See Pro features →