GDPR Website Scanner

GDPR Website Scanner

Check your website for GDPR violations, cookie consent failures, AI data processing gaps, and missing privacy policy disclosures. Free scan. No signup required. Results in under 3 minutes.

Covers GDPR · EU AI Act · CCPA · FTC — no signup required

What GDPR Requires from Your Website

GDPR is not just a cookie banner. These are the obligations most websites with EU visitors need to meet.

Lawful basis for data collection

Every piece of personal data your website collects needs a lawful basis under GDPR Article 6: consent, legitimate interests, or contract. For AI systems, this must be documented.

Cookie consent before tracking

Non-essential cookies — analytics, advertising, AI personalization — cannot fire until the user consents. Many websites get this wrong: the cookie loads on page entry, not after consent.

Privacy policy that names your AI tools

GDPR Articles 13 and 14 require you to disclose which third-party processors handle personal data. If you use OpenAI, a CRM, or analytics AI, they must appear in your privacy policy.

International data transfer safeguards

Sending user data to US-based AI APIs (OpenAI, Anthropic, Google AI) is an international transfer under GDPR Chapter V. You need Standard Contractual Clauses in place.

Right to erasure and access

Users must be able to request deletion or access to their data processed by AI systems. Your privacy policy must explain how to submit these requests.

AI-specific transparency under Article 22

If your website uses AI to make decisions that significantly affect users — pricing, content access, approvals — GDPR Article 22 requires you to inform users and offer human review.

What the GDPR Scanner Checks

SiteProof AI scans your website's publicly visible pages and identifies compliance gaps across all major GDPR obligations for AI-using websites.

✓

Cookie consent behavior

Does consent fire before or after non-essential cookies load?

✓

Privacy policy AI disclosure

Does your policy name the AI tools processing user data?

✓

Chatbot AI disclosure

Does your chatbot identify itself as AI per EU AI Act Article 50?

✓

Missing GDPR clauses

Are data retention periods, transfer safeguards, and rights sections present?

✓

Third-party AI data flows

Which external AI APIs receive user data from your site?

✓

Automated decision-making notice

Are users informed when AI influences decisions that affect them?

GDPR and the EU AI Act Apply Together

If your website uses AI tools — chatbots, recommendation engines, analytics, or AI-generated content — both GDPR and the EU AI Act apply simultaneously. The EU AI Act's transparency obligations (Article 50) became enforceable on August 2, 2026. GDPR has been in force since 2018.

Most websites need to satisfy both: GDPR for how they collect and process personal data, and the EU AI Act for how they disclose the use of AI to users. A single scan from SiteProof AI checks both at once and gives you a prioritized list of what to fix.

Frequently Asked Questions

Does my website need a GDPR audit?

If your website collects any personal data from EU users — including IP addresses, cookies, or form submissions — GDPR applies. An audit identifies whether you have the required consent mechanisms, privacy disclosures, and data handling processes in place.

What does the free GDPR website scan check?

The free scan checks publicly visible compliance signals: cookie consent behavior, whether cookies fire before or after consent, privacy policy presence, chatbot AI disclosures, and missing GDPR required sections. Deeper checks (data processing agreements, internal policies) require the full audit report.

Does using a cookie banner mean I'm GDPR compliant?

Not necessarily. Common issues include: consent banners that don't block cookies before acceptance, banners where reject is harder to find than accept, and banners that accept all cookies by default. The CNIL fined Google €150 million for making rejection harder than acceptance.

What are the GDPR fines for non-compliance?

GDPR fines have two tiers: up to €10 million or 2% of global annual turnover for lesser violations, and up to €20 million or 4% of global annual turnover for serious violations. The higher of the two figures applies.

Does GDPR apply to my website if I'm not based in the EU?

Yes, if EU residents can visit your website and you collect their personal data — even just via cookies or analytics — GDPR applies. The regulation is territorial in scope based on where the users are, not where the company is headquartered.

What's the difference between a GDPR audit and an EU AI Act audit?

A GDPR audit focuses on personal data processing — lawful basis, consent, data transfers, and user rights. An EU AI Act audit focuses on AI transparency obligations — chatbot disclosures, AI content labeling, and risk classification. SiteProof AI covers both in one scan.

How long does a GDPR website audit take?

The automated scan takes under 3 minutes and covers all publicly visible pages. A thorough manual review of internal processes, data processing agreements, and documentation typically takes several hours for a small site.

Do I need a Data Protection Officer (DPO)?

Most small and medium websites do not need a DPO. GDPR requires a DPO only for public authorities, organizations that systematically monitor individuals at large scale, or those processing special category data at scale. For most commercial websites, a DPO is optional but good practice.

Check Your Website's GDPR Compliance Now

Free scan. No signup required. Results in under 3 minutes.

Scan Your Site Free →