The GDPR for website owners
A beginner's guide to what the GDPR asks of a website.
See what loads before consent.
The scanner opens one page the way a new visitor would and checks six areas: the consent banner, cookies and trackers set before any choice, HTTPS, the privacy policy and Google Consent Mode.
It reports what it finds on that page. It is not a legal assessment.
Starting the scan
You can stay on this page. The results appear here when the scan finishes.
This is taking longer than usual. The scan is still running.
Some websites block automated scanners with a firewall or bot protection.
What it checks
Each area is a fact about the page you enter. The results say what was found and what to fix.
Finds the banner and checks for an accept button, a reject button beside it, a settings link and pre-ticked boxes.
Lists every cookie set before the visitor clicks anything, and separates common essential cookies from the rest.
Looks for requests to more than 40 known analytics and advertising services, such as Google Analytics and Meta Pixel.
Checks that the page loads over HTTPS and sends the HSTS, Content-Security-Policy, X-Content-Type-Options and Referrer-Policy headers.
Finds the privacy policy and looks for 10 topics a GDPR privacy policy commonly covers, such as the data controller and data subject rights.
When the page loads Google tags, checks for Consent Mode defaults that deny storage and for update commands.
How it works
The scanner never answers the banner, so everything it records happened before a visitor made a choice.
A checklist
The points the scanner looks for, and where each one comes from.
Most EU data protection authorities treat a banner layer with an accept button but no reject option as an infringement, according to the EDPB cookie banner taskforce report of January 2023.
Cookies that are not strictly necessary wait for the visitor's consent (Article 5(3) of the ePrivacy Directive).
Google Analytics, Meta Pixel and similar scripts run only after the visitor accepts their category.
Article 7(3) GDPR requires it, so visitors need a way back to their choice, such as a cookie settings button.
Articles 13 and 14 GDPR list what people must be told, including who the controller is and what rights they have.
Since March 2024, Google asks for it before its audience features use data from visitors in the EEA.
Read the EDPB cookie banner taskforce report (opens in a new tab) for the practices regulators have looked at.
Learn more
Plain explanations of the checks, and the other free tools for a closer look.
A beginner's guide to what the GDPR asks of a website.
The problems scans find most often, and how to fix them.
How to tell which cookies need consent.
Why the reject button matters, and what it should do.
List every cookie across up to 10 pages of a website.
See every third-party script a page loads before the visitor chooses.
Kukie.io shows a banner with Accept all and Reject all side by side, holds back known trackers until visitors agree and records every choice.
Kukie.io provides tools to collect and record consent. It is not legal advice, and using it does not by itself make a website compliant with any law.