Test your website for GDPR compliance
Enter your domain to start a free scan and open an account - no integration required.
Overview
The General Data Protection Regulation (GDPR) is a comprehensive data protection law in the European Union that governs the processing of personal data. It applies to all organizations that handle the personal data of EU citizens, regardless of where the organization is based.
Penalties
€10,000–€20,000,000 or 2–4% of global annual turnover
What Complyy checks
15 automated tests — 10 passive, 5 active
Passive (instant scan)
Privacy policy exists and is accessible
Art. 12 requires a privacy notice that is easily accessible, in clear language, and reachable from every page. Absence of a privacy policy is a per-se Art. 13/14 violation.
Privacy policy contains all required GDPR elements
Art. 13/14 enumerate required disclosures: controller identity, purposes, legal basis, recipients, retention, transfers, rights, complaint mechanism. Missing any element is a documented finding in most EU DPA decisions.
Granular cookie opt-in/opt-out per category
Art. 7(2) and ePrivacy require consent to be specific per purpose: analytics, marketing and personalisation must each be opt-in-able and opt-out-able independently. A single global toggle is non-compliant.
Cookie consent banner present and functional
No tracking before consent is given
Loading analytics or marketing trackers before the user consents is one of the most-fined GDPR violations (e.g. CNIL's €150M Google decision). Art. 6 + ePrivacy require prior, freely-given, informed consent before any non-essential cookie or tracker fires.
Cookie consent banner present with accessible reject option
A banner is the visible proof that consent is being collected. EDPB guidelines require an equally prominent "Reject" option alongside "Accept" - missing or buried reject is a top regulator finding.
Reject button dismisses banner and stops tracking
Many sites show a banner but the "Reject" button still allows tracking, which the EDPB treats as no consent at all. Rejecting must actually stop non-essential cookies and trackers from firing.
DPO or privacy contact details listed
Art. 37-39 require many controllers to designate a DPO and Art. 13 requires their contact to be published. Listing only a generic "info@" address fails this requirement.
Data breach notification process documented
Art. 33-34 require a documented breach-notification process: 72-hour notice to the DPA and prompt notice to data subjects when high-risk. Absence is a structural compliance failure regulators check post-incident.
Cookie consent banner free of dark patterns
Pre-ticked boxes, hidden reject, colour-tricks and "legitimate interest" toggles default-on are explicitly prohibited under EDPB 03/2022 dark-pattern guidance. Consent obtained this way is invalid and the site is treated as if no consent existed.
Active (synthetic identity tests)
Right to erasure honored within 30 days (Art. 17)(waits up to 30d for response)
Art. 17 grants the right to be forgotten and Art. 12(3) sets the response window at 30 days (extendable to 90 with notice). Failure to honour deletion is the most-litigated GDPR right.
DPO or privacy contact responds to inquiry within 72 hours(waits up to 3d for response)
Art. 12(3) requires the controller to respond to data-subject communications without undue delay; EDPB practice treats 72 hours as the reasonable upper bound for initial acknowledgment. Silent or auto-bounced DPO contacts indicate the role is nominal only.
Right to access / data copy provided within 30 days (Art. 15)(waits up to 30d for response)
Art. 15 entitles individuals to a copy of their personal data within 30 days. Non-response or partial response triggers DPA complaints and is one of the most common enforcement actions.
Marketing opt-out honored within 30 days(waits up to 30d for response)
Art. 21 grants the right to object to direct marketing at any time, and the controller must stop processing immediately. 30 days is the practical limit DPAs apply before opening a complaint.
Data portability in machine-readable format (Art. 20)(waits up to 30d for response)
Art. 20 requires data provided by the user to be exportable in a structured, commonly-used, machine-readable format (CSV, JSON). PDF screenshots do not satisfy portability.
Learn More About General Data Protection Regulation
What is GDPR?
The General Data Protection Regulation (GDPR) is a regulation enacted by the European Union to enhance the protection of personal data and privacy for individuals within the EU. It aims to give individuals greater control over their personal data and to simplify the regulatory environment for international business.
Who Does It Apply To?
GDPR applies to any organization that processes the personal data of EU residents, regardless of the organization's location. This includes businesses, non-profits, and public authorities.
Key Requirements
Consent: Organizations must obtain clear and affirmative consent from individuals before processing their personal data.
Data Protection Officers: Certain organizations are required to appoint a Data Protection Officer (DPO) to oversee compliance.
Data Subject Rights: Individuals have rights such as access to their data, the right to rectify inaccuracies, and the right to erasure.
Data Breach Notification: Organizations must notify authorities and affected individuals of data breaches within 72 hours.
Penalties
Non-compliance with GDPR can result in hefty fines of up to $22 million or 4% of the annual global turnover, whichever is higher. This emphasizes the importance of adherence to the regulation.
Compliance Tips
Conduct a Data Audit: Identify what personal data you collect, how it is used, and where it is stored.
Update Privacy Policies: Ensure your privacy policies are transparent and easily accessible to users.
Implement Data Protection Measures: Invest in security measures to protect personal data from breaches.
Train Employees: Regularly train staff on data protection principles and practices.
Recently Scanned Websites
Live compliance reports from Complyy's public directory.
The Platform
How Complyy enforces GDPR compliance
Complyy continuously tests your site against General Data Protection Regulation using synthetic identities that behave exactly like regulators — and your customers.
Discover
We visit your website as a real user — finding your privacy policy, cookie banner, opt-out links, and contact details.
Scan & Test
Passive checks run instantly. Active agents sign up, submit deletion requests, and wait for responses — just like regulators do.
Score & Evidence
Every finding is timestamped, SHA-256 hashed, and RFC 3161 certified. Your compliance report is audit-ready from day one.
Why Complyy
The only platform that tests compliance the way regulators do
Real synthetic identities
We register actual accounts — adult and minor — on your platform. No theoretical checks. Real interactions, real evidence.
Active + passive tests
Most tools only check your privacy policy text. Complyy also submits DSAR requests, verifies deletion, and waits for real responses.
Court-admissible artifacts
Every screenshot, response, and timestamp is cryptographically sealed. Built for regulators, DPAs, and legal teams — not just developers.
3
Regulations monitored
18
Compliance tests
∞
Agentic identities
3 min
Avg. first evidence artifact
Is your company GDPR-compliant?
Get a free compliance scan in minutes. No credit card. No setup. Complyy visits your site, runs every test, and delivers a full evidence report.