GDPR Website Scanner
GDPR Website Scanner
Check your website for GDPR violations, cookie consent failures, AI data processing gaps, and missing privacy policy disclosures. Free scan. No signup required. Results in under 3 minutes.
Covers GDPR · EU AI Act · CCPA · FTC — no signup required
What GDPR Requires from Your Website
GDPR is not just a cookie banner. These are the obligations most websites with EU visitors need to meet.
Lawful basis for data collection
Every piece of personal data your website collects needs a lawful basis under GDPR Article 6: consent, legitimate interests, or contract. For AI systems, this must be documented.
Cookie consent before tracking
Non-essential cookies — analytics, advertising, AI personalization — cannot fire until the user consents. Many websites get this wrong: the cookie loads on page entry, not after consent.
Privacy policy that names your AI tools
GDPR Articles 13 and 14 require you to disclose which third-party processors handle personal data. If you use OpenAI, a CRM, or analytics AI, they must appear in your privacy policy.
International data transfer safeguards
Sending user data to US-based AI APIs (OpenAI, Anthropic, Google AI) is an international transfer under GDPR Chapter V. You need Standard Contractual Clauses in place.
Right to erasure and access
Users must be able to request deletion or access to their data processed by AI systems. Your privacy policy must explain how to submit these requests.
AI-specific transparency under Article 22
If your website uses AI to make decisions that significantly affect users — pricing, content access, approvals — GDPR Article 22 requires you to inform users and offer human review.
What the GDPR Scanner Checks
SiteProof AI scans your website's publicly visible pages and identifies compliance gaps across all major GDPR obligations for AI-using websites.
Cookie consent behavior
Does consent fire before or after non-essential cookies load?
Privacy policy AI disclosure
Does your policy name the AI tools processing user data?
Chatbot AI disclosure
Does your chatbot identify itself as AI per EU AI Act Article 50?
Missing GDPR clauses
Are data retention periods, transfer safeguards, and rights sections present?
Third-party AI data flows
Which external AI APIs receive user data from your site?
Automated decision-making notice
Are users informed when AI influences decisions that affect them?
GDPR and the EU AI Act Apply Together
If your website uses AI tools — chatbots, recommendation engines, analytics, or AI-generated content — both GDPR and the EU AI Act apply simultaneously. The EU AI Act's transparency obligations (Article 50) became enforceable on August 2, 2026. GDPR has been in force since 2018.
Most websites need to satisfy both: GDPR for how they collect and process personal data, and the EU AI Act for how they disclose the use of AI to users. A single scan from SiteProof AI checks both at once and gives you a prioritized list of what to fix.
Frequently Asked Questions
Does my website need a GDPR audit?
If your website collects any personal data from EU users — including IP addresses, cookies, or form submissions — GDPR applies. An audit identifies whether you have the required consent mechanisms, privacy disclosures, and data handling processes in place.
What does the free GDPR website scan check?
The free scan checks publicly visible compliance signals: cookie consent behavior, whether cookies fire before or after consent, privacy policy presence, chatbot AI disclosures, and missing GDPR required sections. Deeper checks (data processing agreements, internal policies) require the full audit report.
Does using a cookie banner mean I'm GDPR compliant?
Not necessarily. Common issues include: consent banners that don't block cookies before acceptance, banners where reject is harder to find than accept, and banners that accept all cookies by default. The CNIL fined Google €150 million for making rejection harder than acceptance.
What are the GDPR fines for non-compliance?
GDPR fines have two tiers: up to €10 million or 2% of global annual turnover for lesser violations, and up to €20 million or 4% of global annual turnover for serious violations. The higher of the two figures applies.
Does GDPR apply to my website if I'm not based in the EU?
Yes, if EU residents can visit your website and you collect their personal data — even just via cookies or analytics — GDPR applies. The regulation is territorial in scope based on where the users are, not where the company is headquartered.
What's the difference between a GDPR audit and an EU AI Act audit?
A GDPR audit focuses on personal data processing — lawful basis, consent, data transfers, and user rights. An EU AI Act audit focuses on AI transparency obligations — chatbot disclosures, AI content labeling, and risk classification. SiteProof AI covers both in one scan.
How long does a GDPR website audit take?
The automated scan takes under 3 minutes and covers all publicly visible pages. A thorough manual review of internal processes, data processing agreements, and documentation typically takes several hours for a small site.
Do I need a Data Protection Officer (DPO)?
Most small and medium websites do not need a DPO. GDPR requires a DPO only for public authorities, organizations that systematically monitor individuals at large scale, or those processing special category data at scale. For most commercial websites, a DPO is optional but good practice.
Check Your Website's GDPR Compliance Now
Free scan. No signup required. Results in under 3 minutes.
Scan Your Site Free →