all listings checked today 18:15 UTC 1146 live 1 in the graveyard how the check works →
TrueTier
Free · 30+ checks · about a minute

GDPR website checker

Find out what your website does before a visitor clicks "accept": which trackers load, which cookies are set, which outside domains receive their IP address — and whether the privacy policy, cookie banner and company details are where the law expects them.

About a minute. No signup for the summary.

What this check looks at

Cookies set before consentCookies your server sets on a first visit, before the visitor has clicked anything — together with trackers before consent, the most frequently fined mistake on EU sites.
Third-party trackersGoogle Analytics and Tag Manager, Google Ads, Meta Pixel, LinkedIn Insight, TikTok Pixel, Hotjar, Microsoft Clarity, Mixpanel, HubSpot and about twenty more, found in the page.
External domainsEvery outside domain the page contacts — each one receives your visitor's IP address.
Cookie consentWhether there is a consent banner when there are trackers to consent to.
Forms collecting personal dataForms that ask for an email or a name, and whether a privacy notice is linked next to them.
Privacy policyLinked from the page, where a visitor can find it.
Operator identificationCompany name, registration or VAT number, address — the "Impressum" German and Austrian law require, and the details the EU e-commerce rules ask for.
Terms and conditionsLinked, as consumer law expects from anyone who sells online.
ContactA way to reach you that is not only a form.

Plus the rest of the 30+ checks — every scan runs all of them.

Why it matters

Under the GDPR and the ePrivacy rules, analytics and advertising may run only after consent. The most common violation is not a missing banner — it is a banner that is there while Google Analytics or the Meta Pixel already loaded behind it. That is exactly what data protection authorities fine.

We open your page the way a first-time visitor does, click nothing, and list what happened.

What it does not do

It is an automated check, not legal advice: it cannot read your contracts with processors or judge whether your privacy policy is correct — only that the risky things are or are not happening.

Questions

How do you know what loads before consent?

We load the page as a first-time visitor who has accepted nothing, and record the tracking scripts in it, the cookies the server sets and every outside domain the page contacts.

Does a cookie banner make my site GDPR compliant?

Only if nothing that needs consent runs before the visitor agrees. A banner shown while Google Analytics already loaded is the typical finding.

Is this legal advice?

No. It is an automated technical check that shows what happens on your page. For the wording of your policy, talk to a lawyer.

Which trackers do you recognise?

Google Analytics and Tag Manager, Google Ads, Meta (Facebook) Pixel, LinkedIn Insight, TikTok Pixel, Hotjar, Microsoft Clarity, Mixpanel, Amplitude, Segment, HubSpot and other common analytics and advertising scripts — about thirty in all.

Other checks