Frequently asked questions about the GDPR scan
What does the GDPR and cookie scan check?
The check reads the static HTML of your homepage and looks for recognised trackers, embedded services, cookies, a consent tool and a reachable link to your privacy policy. The full scan does that across multiple pages and also has a real browser visit your site.
Does the scan run JavaScript?
The regular check does not: it only reads the code your server sends, so what only appears after a click stays out of view. The full scan does. There, a real browser opens your site, looks at what loads before anything is clicked, then clicks reject and looks again.
Why do I not get a percentage or a number?
Because a number on this topic gets read as a judgement. Each point therefore gets a signal: risk, check, fine, or for information. That way a result without risks can never pass for proof of compliance, because it is not.
Is this a legal judgement of GDPR compliance?
No. The scan measures technical signals: what loads, when, to whom, and what is in your privacy policy. Whether your organisation is fine also depends on data processing agreements, retention periods, internal processes and matters that no scan from the outside can see.
Why does my consent tool show "check" and not "fine"?
Because present is not the same as working. The code only shows that there is a banner, not whether it actually blocks the trackers until someone says yes. That exact change is what the browser scan measures in the full report.
Are other pages checked too?
The check looks at your homepage. The full scan also runs through the pages you select yourself and names in the report which ones they were. That is not redundant: a page with a video block or a payment button sets different cookies than your homepage.
Is your question not listed? Ask it directly