Skip to content

Privacy compliance scan

See what a site loads before the visitor agrees to anything: cookies, trackers, forms collecting personal data, and whether a policy is linked.

TL;DR:

The scanner opens your site in a real browser and records which cookies and trackers are written before the visitor gives consent. It checks the consent banner and whether an equal Reject option exists, forms collecting personal data, the privacy-policy link next to those forms, and third-party services with their jurisdiction. The result is an A–F grade with 152-FZ and GDPR projections and concrete per-page fixes.

A scan takes a few minutes: each page is opened in a real browser three times — without consent, accepting, and rejecting the banner.

Last 7 days: 24 scans · average score 74 of 100

Save & track URLs you check Free account · 24/7 checks · alerts via Telegram, email, Slack — sign up to monitor any URL you test here.
Free Sign Up

RKN operator-registry check

Have you notified Roskomnadzor about processing personal data? Enter a tax ID (INN) — we check the public operator registry.

Cookies Before ConsentWhat is written without permission
Consent BannerIs there an equal Reject option
PII FormsConsent and policy at the form
Projections152-FZ and GDPR grades

Why teams trust us

A–F
grade + 152-FZ/GDPR
3
browser sessions per page
PDF
integrity-signed report
Free
scan without signup

How it works

1

Enter your site URL

2

The scanner opens pages in a browser

3

Get a grade and a fix list

Why check your site for privacy compliance?

Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.

Real Browser

Three sessions per page: no action, banner accepted, banner rejected.

Trackers and Jurisdiction

Service catalogue: who receives visitor data and in which country.

Policy at Collection Point

The policy link and consent element are checked next to the form, not in the footer.

Signed PDF

Report with an HMAC integrity stamp — hand it to your lawyer or contractor.

Who uses this

Business

preparing for an audit

Lawyers

technical facts for an opinion

Web Studios

client site handover

DevOps

consent regression monitoring

Common Mistakes

Loading analytics before consentA counter in writes cookies before any banner. This is exactly what an audit records.
Banner without a Reject buttonConsent is voluntary only when refusing is as easy as agreeing.
Policy only in the footerThe visitor must see who receives their data at the moment of submission — next to the form itself.
Checking once and forgettingA new widget or tag manager quietly adds trackers. Only a re-check catches the regression.

Best Practices

Delay trackers until consentInitialise analytics from the CMP accept callback, not on page load.
Offer an equal RejectAccept and Reject buttons — same size, same level.
Consent checkbox at every formUnchecked by default, with the processing policy linked right there.
Turn on monitoringA standing watch alerts you when the grade drops — before an auditor notices.

Monitor compliance automatically

Scheduled re-checks with an alert when pre-consent trackers appear on your site.

Sign up free

Exactly what the scanner checks

23 rules · registry v3 · this catalogue is rendered from the same rule registry that computes the grade — the page cannot promise a check the engine does not run.

Three browser sessions: data leaking to trackers before consent, orderly flows after accepting, near silence after rejecting

Forms & consent

  • PII form without consent element up to ₽300k
  • Form submits over plain HTTP
  • No privacy-policy link near form up to ₽60k

Consent banner

  • Trackers present, no consent banner up to ₽300k
  • Tracking cookies set before consent up to ₽300k
  • Consent banner lacks reject option up to ₽300k

Policies & documents

  • No privacy policy found up to ₽60k
  • Privacy policy link unreachable up to ₽60k
  • No cookie policy / section up to ₽60k
  • Privacy policy missing mandatory sections up to ₽60k

Cookies

  • Tracking cookies not declared up to ₽60k
  • Cookies missing Secure/HttpOnly
  • Cookie lifetime over 12 months

Third-party services

  • Foreign trackers on RU-jurisdiction site up to ₽300k
  • Unclassified third-party requests

Transfer & localisation

  • Cross-border transfer not disclosed up to ₽300k
  • Identifiers in localStorage before consent up to ₽300k
  • Hosting outside Russia up to ₽6M

Transport security

  • Site served without HTTPS
  • Mixed content on HTTPS page
  • HSTS header missing

Technical hygiene

  • Basic security headers missing
  • Software version disclosure

Every page is opened in a real browser three times — no action, banner accepted, banner rejected. No other RU checker interacts with the banner at all.

What the scanner checks

The scanner opens pages in a real browser and records cookies and network requests made before the visitor touches the consent banner. It also looks at forms collecting personal data, whether a privacy policy is linked next to them, third-party services and their jurisdiction, and transport security. The result is a list of technical observations with the pages they were seen on — not a legal opinion.

Frequently Asked Questions

How do I check my website for privacy compliance?

Enter your site URL — the scanner opens pages in a real browser and records which cookies and trackers are written before the visitor consents, whether a consent banner with an equal Reject option is shown, whether forms collect personal data without a consent checkbox, and whether a privacy-policy link sits next to the form. The result is an A–F grade, 152-FZ and GDPR projections, and a concrete fix list per page.

Why do cookies written before consent matter?

Analytics counters, ad pixels and chat widgets usually initialise the moment the page loads — before the visitor touches the banner. From an audit standpoint that is processing personal data without consent: visitor identifiers have already been shared with third parties. The scanner measures exactly this gap: how many cookies appear before consent versus after accepting the banner.

The site has a consent banner — why is the grade still low?

A banner alone does not solve the problem: if trackers load before the button is pressed, consent is granted after the fact. Common causes of a low grade are a counter in the head that initialises on load, a banner without an equal Reject button, and data-collection forms without a consent checkbox. The fix usually comes down to starting analytics from the banner's accept callback and adding consent elements to forms.

How many pages does the scanner check?

Without signup the scan covers 3 pages: the home page and the pages most likely to collect personal data (contacts, cart, forms). Paid plans raise the depth to 100 pages and add an integrity-signed PDF report and standing monitoring with alerts when the grade drops. The crawl priority is the same: home first, then pages with forms, then policy documents.

How is this different from the quick /152-fz check?

The /152-fz page is a quick aggregator: RKN registry, cookie inventory and tracker detection for a single page, with no saved result. The /compliance scanner goes deeper: a real browser with three sessions (no action, accept, reject), a multi-page crawl, form and policy analysis, grade history and monitoring. Start with the quick check — then run the full scan when you need the complete picture.

Is the scan result a legal opinion?

No. It is an automated technical self-assessment: the scanner records observable facts — cookies, third-party requests, banner behaviour, form structure — and shows what an audit would flag. Results indicate apparent readiness, not legal status. For a binding conclusion, consult qualified privacy counsel.