Skip to main content

GDPR·General Data Protection Regulation

EUUKCH

Test your website for GDPR compliance

Enter your domain to start a free scan and open an account - no integration required.

Overview

The General Data Protection Regulation (GDPR) is a comprehensive data protection law in the European Union that governs the processing of personal data. It applies to all organizations that handle the personal data of EU citizens, regardless of where the organization is based.

Penalties

€10,000–€20,000,000 or 2–4% of global annual turnover

What Complyy checks

15 automated tests 10 passive, 5 active

Passive (instant scan)

critical

Privacy policy exists and is accessible

Art. 12 requires a privacy notice that is easily accessible, in clear language, and reachable from every page. Absence of a privacy policy is a per-se Art. 13/14 violation.

high

Privacy policy contains all required GDPR elements

Art. 13/14 enumerate required disclosures: controller identity, purposes, legal basis, recipients, retention, transfers, rights, complaint mechanism. Missing any element is a documented finding in most EU DPA decisions.

high

Granular cookie opt-in/opt-out per category

Art. 7(2) and ePrivacy require consent to be specific per purpose: analytics, marketing and personalisation must each be opt-in-able and opt-out-able independently. A single global toggle is non-compliant.

high

Cookie consent banner present and functional

high

No tracking before consent is given

Loading analytics or marketing trackers before the user consents is one of the most-fined GDPR violations (e.g. CNIL's €150M Google decision). Art. 6 + ePrivacy require prior, freely-given, informed consent before any non-essential cookie or tracker fires.

high

Cookie consent banner present with accessible reject option

A banner is the visible proof that consent is being collected. EDPB guidelines require an equally prominent "Reject" option alongside "Accept" - missing or buried reject is a top regulator finding.

high

Reject button dismisses banner and stops tracking

Many sites show a banner but the "Reject" button still allows tracking, which the EDPB treats as no consent at all. Rejecting must actually stop non-essential cookies and trackers from firing.

medium

DPO or privacy contact details listed

Art. 37-39 require many controllers to designate a DPO and Art. 13 requires their contact to be published. Listing only a generic "info@" address fails this requirement.

medium

Data breach notification process documented

Art. 33-34 require a documented breach-notification process: 72-hour notice to the DPA and prompt notice to data subjects when high-risk. Absence is a structural compliance failure regulators check post-incident.

medium

Cookie consent banner free of dark patterns

Pre-ticked boxes, hidden reject, colour-tricks and "legitimate interest" toggles default-on are explicitly prohibited under EDPB 03/2022 dark-pattern guidance. Consent obtained this way is invalid and the site is treated as if no consent existed.

Active (synthetic identity tests)

critical

Right to erasure honored within 30 days (Art. 17)(waits up to 30d for response)

Art. 17 grants the right to be forgotten and Art. 12(3) sets the response window at 30 days (extendable to 90 with notice). Failure to honour deletion is the most-litigated GDPR right.

critical

DPO or privacy contact responds to inquiry within 72 hours(waits up to 3d for response)

Art. 12(3) requires the controller to respond to data-subject communications without undue delay; EDPB practice treats 72 hours as the reasonable upper bound for initial acknowledgment. Silent or auto-bounced DPO contacts indicate the role is nominal only.

critical

Right to access / data copy provided within 30 days (Art. 15)(waits up to 30d for response)

Art. 15 entitles individuals to a copy of their personal data within 30 days. Non-response or partial response triggers DPA complaints and is one of the most common enforcement actions.

high

Marketing opt-out honored within 30 days(waits up to 30d for response)

Art. 21 grants the right to object to direct marketing at any time, and the controller must stop processing immediately. 30 days is the practical limit DPAs apply before opening a complaint.

high

Data portability in machine-readable format (Art. 20)(waits up to 30d for response)

Art. 20 requires data provided by the user to be exportable in a structured, commonly-used, machine-readable format (CSV, JSON). PDF screenshots do not satisfy portability.

Learn More About General Data Protection Regulation

What is GDPR?

The General Data Protection Regulation (GDPR) is a regulation enacted by the European Union to enhance the protection of personal data and privacy for individuals within the EU. It aims to give individuals greater control over their personal data and to simplify the regulatory environment for international business.

Who Does It Apply To?

GDPR applies to any organization that processes the personal data of EU residents, regardless of the organization's location. This includes businesses, non-profits, and public authorities.

Key Requirements

  • Consent: Organizations must obtain clear and affirmative consent from individuals before processing their personal data.

  • Data Protection Officers: Certain organizations are required to appoint a Data Protection Officer (DPO) to oversee compliance.

  • Data Subject Rights: Individuals have rights such as access to their data, the right to rectify inaccuracies, and the right to erasure.

  • Data Breach Notification: Organizations must notify authorities and affected individuals of data breaches within 72 hours.

Penalties

Non-compliance with GDPR can result in hefty fines of up to $22 million or 4% of the annual global turnover, whichever is higher. This emphasizes the importance of adherence to the regulation.

Compliance Tips

  • Conduct a Data Audit: Identify what personal data you collect, how it is used, and where it is stored.

  • Update Privacy Policies: Ensure your privacy policies are transparent and easily accessible to users.

  • Implement Data Protection Measures: Invest in security measures to protect personal data from breaches.

  • Train Employees: Regularly train staff on data protection principles and practices.

Recently Scanned Websites

Live compliance reports from Complyy's public directory.

Browse the full directory →

The Platform

How Complyy enforces GDPR compliance

Complyy continuously tests your site against General Data Protection Regulation using synthetic identities that behave exactly like regulators — and your customers.

01

Discover

We visit your website as a real user — finding your privacy policy, cookie banner, opt-out links, and contact details.

02

Scan & Test

Passive checks run instantly. Active agents sign up, submit deletion requests, and wait for responses — just like regulators do.

03

Score & Evidence

Every finding is timestamped, SHA-256 hashed, and RFC 3161 certified. Your compliance report is audit-ready from day one.

Why Complyy

The only platform that tests compliance the way regulators do

Real synthetic identities

We register actual accounts — adult and minor — on your platform. No theoretical checks. Real interactions, real evidence.

Active + passive tests

Most tools only check your privacy policy text. Complyy also submits DSAR requests, verifies deletion, and waits for real responses.

Court-admissible artifacts

Every screenshot, response, and timestamp is cryptographically sealed. Built for regulators, DPAs, and legal teams — not just developers.

3

Regulations monitored

18

Compliance tests

Agentic identities

3 min

Avg. first evidence artifact

Is your company GDPR-compliant?

Get a free compliance scan in minutes. No credit card. No setup. Complyy visits your site, runs every test, and delivers a full evidence report.