See what loads after a visitor declines

This check reads the HTML of your homepage and immediately shows the first signals about your trackers, cookies and consent tool; the full list follows in the report. The full scan opens your site in a real browser, clicks reject itself, and then measures which requests and cookies still come through anyway.

Verify your signals Signals instead of a number

What the scan recognises by name

Choose a category. You see which services FlowCore recognises and why that category appears in a GDPR report.

Trackers

The scripts that exist to track your visitor. If they are there without consent, that is the heaviest signal in the report.

Without consent, this carries the most weight.
  • Google Analytics
  • Tag Manager
  • Google Ads
  • Meta Pixel
  • Hotjar
  • TikTok Pixel
  • LinkedIn Insight
  • Microsoft Clarity
  • Pinterest Tag
Step 1 of 2

Which website would you like to check for GDPR signals?

Start with your domain. We will then ask for your email address to begin the technical check.

  • No account required
  • Not a legal assessment
  • Signal shown in this card

Verify your signals

Enter your domain and email address. You get no number but a signal, with the first findings below it.

  • A signal instead of a scoreRisk signals, to check manually, or none. A number would read as "compliant", and a technical check cannot say that.
  • The first findings, with what was foundSuch as “No Set-Cookie header in the first HTTP response” or “Privacy policy found and reachable”. The rest follows in the report.
  • And its own limits alongside itThe result itself carries, in the card, what a static reading cannot see, so that an empty result never reads as a clean bill.

The check reads the served HTML of the domain you enter and does not run JavaScript: what only appears after loading or after a click, it does not see. For that, the full scan opens your site in a real browser and clicks reject itself. It remains a technical measurement, not a legal judgement: no scan from the outside can see data processing agreements, retention periods and internal processes.

Explore the full GDPR report

Three levels of evidence separate what is in the page, what only appears after a click and the context that belongs with it.

What is in your pageRead from the code your site sends.
Trackers, and whether there is consent for them

If tracking techniques are present without a recognised consent tool, that is a risk, not a remark. If there is a tool, it stays a check: present is not the same as working.

Embedded services, by name

Video, maps, chat, payment and fonts that your page fetches from someone else when it loads. Eighteen of these are recognised.

Cookies, sorted

Strictly necessary versus the rest, and separately which ones live longer than the consent under which they were set.

Forms and checked boxes

A pre-ticked marketing checkbox is not consent. A form without a reachable privacy policy is one too.

Where your data goes

Google AnalyticsOutside the EU
Meta PixelOutside the EU
YouTubeOutside the EU
Google FontsOutside the EU
MollieIn the EU

5 parties on a single page, 4 of them process outside the EU. That is allowed, but then you need to be able to name and cover that party. The report names them, because a visitor cannot object to someone nobody has told them about.

You never invited them, and yet they are there

A font from Google, a map with the route, a video block on your about page: things someone once pasted in, one by one, because they looked good. They all fetch something from another business, and that business sees your visitor's IP address in the process.

The report lists them and states which ones process outside the EU. Not because that is forbidden, but because you then need to be able to name them in your privacy policy, and that does not work with a list you have never seen.

Most of them you can replace or host yourself. For the rest, it is enough that they are listed in your policy.

What else gets measured on your page

Frequently asked questions about the GDPR scan

What does the GDPR and cookie scan check?

The check reads the static HTML of your homepage and looks for recognised trackers, embedded services, cookies, a consent tool and a reachable link to your privacy policy. The full scan does that across multiple pages and also has a real browser visit your site.

Does the scan run JavaScript?

The regular check does not: it only reads the code your server sends, so what only appears after a click stays out of view. The full scan does. There, a real browser opens your site, looks at what loads before anything is clicked, then clicks reject and looks again.

Why do I not get a percentage or a number?

Because a number on this topic gets read as a judgement. Each point therefore gets a signal: risk, check, fine, or for information. That way a result without risks can never pass for proof of compliance, because it is not.

Is this a legal judgement of GDPR compliance?

No. The scan measures technical signals: what loads, when, to whom, and what is in your privacy policy. Whether your organisation is fine also depends on data processing agreements, retention periods, internal processes and matters that no scan from the outside can see.

Why does my consent tool show "check" and not "fine"?

Because present is not the same as working. The code only shows that there is a banner, not whether it actually blocks the trackers until someone says yes. That exact change is what the browser scan measures in the full report.

Are other pages checked too?

The check looks at your homepage. The full scan also runs through the pages you select yourself and names in the report which ones they were. That is not redundant: a page with a video block or a payment button sets different cookies than your homepage.

Is your question not listed? Ask it directly