Scan a website for the EU compliance basics.
Nine checks on the front page of any site: transport security, consent, trackers, privacy links, legal pages and headers. Free, no account, and the result is not stored anywhere.
Try it on , or .
–
A pass means the scanner found evidence on this page. A warning means it could not tell. Fix needed means something expected is missing. Read the checklists for the parts no scanner can see.
Check this site again every morning
Register and you get an email when a check changes from pass to fail. Free while the monitoring service is in test; your address is used for this and nothing else.
What each check means
- HTTPS and HSTS
- The site must be served over TLS. HSTS tells browsers never to try plain HTTP again. A missing HSTS header is a warning, not a failure.
- Cookie consent
- Looks for a known consent platform in the HTML. If you set no non-essential cookies you do not need one, and you can ignore the warning.
- Trackers before consent
- Analytics and advertising scripts that load without any consent mechanism on the page. Under ePrivacy and GDPR Article 6 these need prior consent.
- Google Consent Mode v2
- Only relevant if you use Google Ads or Analytics with EU visitors. Without it, Google limits your measurement.
- IAB TCF
- Relevant for publishers selling programmatic ads. Everyone else can ignore it.
- Forms and privacy notice
- A form without a privacy link nearby is the easiest GDPR finding there is. Add the link and a short sentence on what you do with the data.
- Legal pages
- Privacy policy and terms for everyone; an imprint if you sell to Germany or Austria; an accessibility statement if the Accessibility Act applies to you.
- Security headers
- CSP, X-Content-Type-Options, Referrer-Policy and X-Frame-Options or frame-ancestors. Cheap to add, and the first thing a security questionnaire asks about.
- Operational resilience
- Checks for DORA-related wording on sites in financial services or their ICT suppliers. Other sites get an informational note only.