GDPR check
A privacy policy describes what your site does. The check shows what it actually does.
European rules prescribe what that policy must contain and require tracking to wait for consent, and they provide for penalties in the more serious cases. That is why the gap between what is written and what happens is not a formality.
How it works
I open your site with a real browser and click nothing.
A static check — one that only reads the source code — gets this wrong, because consent banners are injected by script these days, so such a check never sees them and then claims there is none. So I load your site with a real browser, as an ordinary visitor, wait, and read which cookies were set before anyone clicked anything. The findings carry their names, not an estimate.
Tracking cookies before consent
If they are set before the visitor chooses anything, the findings name them individually. Two cases are recorded separately: no consent banner at all, and a banner that exists while tracking does not wait for its click.
Whether a privacy policy exists
I look for it in the usual places and in the footer. If there is none, that is a finding in itself — European rules require you to tell visitors in advance what data you collect, why, and where it goes.
A form with no link to the policy
A contact form or newsletter signup that asks for personal data with no link to the privacy policy anywhere near it.
A contradiction between what is said and done
The most serious finding: the policy explicitly states that visitors are not tracked, yet tracking cookies are set anyway. That is no longer a gap in the text but a departure from your own promise.
The limits of this check
What the check does not claim.
It does not say you are compliant
The check is external and looks at a limited number of points. “No findings” is not confirmation of compliance — the most that can honestly be said is that on the points checked there is no obvious discrepancy.
It does not say you are breaking the law
I record an observation and a discrepancy, not a verdict. There are strictly necessary cookies, legitimate interests and contractual bases an external check cannot see. This is not legal advice and does not replace a lawyer — but with it you know what to ask.
Google Tag Manager alone is not reported
With Consent Mode the container legitimately loads while tags do not fire until consent — which is exactly what compliant companies do. The conclusion comes from actual cookies, not from the presence of a script.
I do not see every single cookie
I catch the ones a real browser sets in the first few seconds without a single click. I change nothing and remove nothing — I only read.