GDPR & ePrivacy website scanner

GDPR website scanner

Check a public website for cookies and tracking before consent, available consent controls, and privacy policy signals. CertScore.ai turns browser observations into evidence for GDPR and ePrivacy review; it cannot certify compliance.

By CertScore.ai · Updated

CertScore.ai scans public website behavior for review signals. Findings are automated observations backed by retained evidence, not legal advice, certification, or compliance determinations.

What the scan reviews

Pre-consent tracking
Third-party cookies before consent
Consent UX and Accept/Reject behavior
Policy/runtime disclosure gaps
Session replay and fingerprinting-related signals

Scan a public website

Loading scan form…

From a scan to a reviewable decision

  1. Check the context. Open the report and confirm the target, scan date, region, and coverage. A blocked or incomplete observation is a limitation, not evidence of an absent control.
  2. Inspect the observation. Follow a finding to its retained request, cookie, storage, or policy evidence. Keep pre-consent activity separate from activity after an Accept or Reject click.
  3. Verify the interpretation. A visible Reject button, a completed click, and confirmed refusal are different facts. A cookie remaining in storage does not by itself prove active tracking.
  4. Assign and retest. Give the responsible team the affected vendor, page, consent state, and evidence. After a configuration change, compare a new scan under the same conditions.

Use the sample report to explore the report format; it describes its own retained scan, not your website.

What this scan cannot establish

Public-page observation does not cover private account flows, every page, every region, or all future behavior. Bot defenses and unavailable controls can limit coverage. Accept and Reject observations are separate eligible sessions; an unverified decision stays unverified. A clean observation is not a compliance certificate.

What to give your implementation team

Share the report's target and date, the affected vendor or storage identity, the consent state, and the retained evidence reference. Ask the team to inspect the relevant tag trigger, consent category, or embedded service, then compare a fresh scan after the change.

Direct answer

A GDPR website compliance scanner reviews observable public website behavior that may be relevant to privacy and consent review. CertScore.ai focuses on evidence-backed risk signals, not legal conclusions.

What CertScore.ai checks

CertScore.ai checks request timing, cookies and storage, consent-state evidence, vendor behavior, session replay indicators, fingerprinting-related activity, and whether public disclosures appear aligned with observed behavior.

What follows a confirmed choice

Consent review often stops at the banner. Where an eligible control can be actioned safely, CertScore observes a first-layer choice and separately reports whether its registration was confirmed and whether non-essential activity changes afterward—evidence for GDPR/ePrivacy review, not a determination of compliance or violation.

How teams use it

Privacy, legal, marketing operations, and engineering teams can use CertScore.ai to triage live-site drift after tag-manager edits, CMP changes, launches, and vendor updates.

Review posture

CertScore.ai findings should be reviewed with retained evidence and internal policy context. A finding is a review signal; it is not proof of a GDPR violation or proof that a site is compliant.

Frequently asked questions

Can CertScore.ai tell me if a website is GDPR compliant?

No. CertScore.ai provides automated public-web observations for human and agentic review. It does not provide legal advice, certification, proof of non-compliance, or a GDPR compliance determination.

What does a GDPR website scanner look for?

It can look for consent timing, cookies, storage, tracking requests, vendor domains, session replay indicators, fingerprinting-related signals, privacy disclosures, and whether runtime behavior appears aligned with consent and policy surfaces.

Does CertScore.ai scan behind logins?

This page describes public-web scanning. Authenticated areas, paywalls, bot protections, and blocked routes can limit coverage unless a separate approved workflow is configured.

Key takeaways

CertScore.ai is a public website scanning platform that surfaces GDPR-relevant consent, cookie, tracking, policy, and disclosure review signals.

CertScore.ai findings are automated observations backed by retained evidence. They are not legal advice, certification, or compliance determinations.