Skip to content

Privacy policy on a website

Key idea:

The processing policy is the operator's mandatory public document: who the operator is, what data is collected and why, who receives it (including counters and widgets), retention and deletion, the subject's rights. It lives on its own page reachable from every page, and is linked at every data-collection form. Absence or unavailability is an offence under Art. 13.11(3).

Check your site →

Minimum sections

  • Operator name and contacts
  • Processing purposes per data category
  • The data collected (including cookies and counter identifiers!)
  • Legal grounds
  • Third parties receiving data, and their jurisdiction
  • Retention periods and deletion
  • Subject rights and the request procedure
  • Publication date and version

The most common hole: the policy covers forms but is silent about analytics, pixels and chats — precisely the parties receiving data from the first second.

Where to publish and how to link

A dedicated page (usually /privacy or /policy), a footer link on every page, plus the mandatory link at every form next to the consent element. The document opens without registration and stays current: a new counter or CRM is a reason to bump the version.

Checking

The scanner verifies the policy's presence, the link's reachability, and the point-of-collection link at every form — across several pages at once. On RU sites the policy often lives inside the consent document; the scanner recognises that variant too.

Related

Cookies Before ConsentWhat is written without permission
Consent BannerIs there an equal Reject option
PII FormsConsent and policy at the form
Projections152-FZ and GDPR grades

Why teams trust us

A–F
grade + 152-FZ/GDPR
3
browser sessions per page
PDF
integrity-signed report
Free
scan without signup

How it works

1

Enter your site URL

2

The scanner opens pages in a browser

3

Get a grade and a fix list

Why check your site for privacy compliance?

Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.

Real Browser

Three sessions per page: no action, banner accepted, banner rejected.

Trackers and Jurisdiction

Service catalogue: who receives visitor data and in which country.

Policy at Collection Point

The policy link and consent element are checked next to the form, not in the footer.

Signed PDF

Report with an HMAC integrity stamp — hand it to your lawyer or contractor.

Who uses this

Business

preparing for an audit

Lawyers

technical facts for an opinion

Web Studios

client site handover

DevOps

consent regression monitoring

Common Mistakes

Loading analytics before consentA counter in writes cookies before any banner. This is exactly what an audit records.
Banner without a Reject buttonConsent is voluntary only when refusing is as easy as agreeing.
Policy only in the footerThe visitor must see who receives their data at the moment of submission — next to the form itself.
Checking once and forgettingA new widget or tag manager quietly adds trackers. Only a re-check catches the regression.

Best Practices

Delay trackers until consentInitialise analytics from the CMP accept callback, not on page load.
Offer an equal RejectAccept and Reject buttons — same size, same level.
Consent checkbox at every formUnchecked by default, with the processing policy linked right there.
Turn on monitoringA standing watch alerts you when the grade drops — before an auditor notices.

Monitor compliance automatically

Scheduled re-checks with an alert when pre-consent trackers appear on your site.

Sign up free

Learn more

Frequently Asked Questions

Will an internet template do?

As a skeleton — yes, but the data list, purposes and third parties are unique per site. A template with someone else's purposes is worse than nothing: it asserts a falsehood.

Are the policy and the consent one document?

Different ones: the policy describes how the operator handles data; the consent is the subject's expression of will. In practice they are often published side by side.

How often to update?

On every change to the data, purposes or third parties: a new chat widget or counter already qualifies.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.