Home / Guides / What Does a GDPR Checker Test?

Website Compliance

What Does a GDPR Checker Test?

A plain-English explanation of what a GDPR checker can test on a website: banners, cookies, trackers, pre-consent requests, policies, evidence, and limitations.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

July 2026

Reading time

5 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

Introduction

A GDPR checker is most useful when it explains exactly what it can and cannot test. The phrase sounds broad, but a browser-based tool can only inspect certain parts of compliance: what the page loads, what the banner does, which cookies and scripts appear, and whether policy and evidence signals line up.

That scope is still valuable. Many website GDPR problems are technical and visible: analytics before consent, a missing reject path, a cookie policy that does not match the live site, or a tag manager that bypasses consent defaults. These are the issues a checker can help teams find quickly.

This guide breaks down the main areas a GDPR checker can test, how to interpret results, and where human review is still required.

3. Cookies, scripts, pixels, and storage

A GDPR checker can collect cookie names and tracker labels, but it should not store cookie values. Cookie values may contain identifiers. A privacy-conscious checker stores metadata such as name, provider, purpose, category, duration, source, confidence, and review status.

Modern websites use more than cookies. Pixels and scripts may send data without a persistent cookie. Local storage and session storage can also hold identifiers. A checker should therefore present an inventory of cookies, scripts, pixels, and storage signals instead of pretending that cookies are the whole story.

  • Cookie names such as _ga or _fbp.
  • Tracker scripts such as Google Analytics, Meta Pixel, or Hotjar.
  • Tag manager signals such as GTM containers.
  • Pre-consent network requests to analytics or marketing endpoints.
  • Runtime-reported cookie names from verified managed sites.

4. Policy links and cookie declarations

A checker can detect whether privacy and cookie policy links are present, but it cannot fully judge legal quality from a link. The better test is consistency: do the technologies detected on the site appear in the cookie declaration and policy text?

If the inventory contains Meta Pixel but the policy never mentions Meta or advertising cookies, the checker can flag a review item. If the policy mentions Google Tag Manager but no GTM signal is detected, the checker can suggest confirming whether the policy is stale or whether GTM appears on another page.

Cookie declarations should be built from reviewed items, not raw scanner output. Unknown scripts should remain in a needs-review section until someone confirms their category and purpose.

What a GDPR checker cannot test

  • Whether your lawful basis is correct for every processing purpose.
  • Whether your processor agreements and subprocessor lists are complete.
  • Whether data subject access and deletion workflows are handled correctly.
  • Whether international transfer safeguards are sufficient.
  • Whether offline, CRM, email, or server-side processing is compliant.
  • Whether a regulator would accept every legal interpretation.

These limitations do not make a checker less useful. They define the boundary. Use the checker for website technical controls, then involve privacy and legal owners for the wider program.

How to read a GDPR checker report

Treat the report as a triage document. Critical issues are usually technical facts that need attention, such as no banner, optional trackers before consent, or no published declaration. Warnings may be review items, such as unknown scripts or policy text that may not match detected vendors.

Do not aim for a cosmetic green badge while ignoring evidence quality. A better goal is a repeatable workflow: detect, review, fix, publish, monitor, and recheck.

  1. Fix confirmed pre-consent tracker requests first.
  2. Make reject and preferences easy to use.
  3. Review unknown cookie and tracker inventory items.
  4. Publish a cookie declaration from reviewed items.
  5. Compare policy text with detected vendors.
  6. Enable scheduled scans to catch future drift.

Report interpretation

A GDPR checker should make uncertainty visible. Unknown scripts, stale policies, and missing metadata are not the same as confirmed failures, but they are exactly the items teams should review.

Try the GDPRChecker workflow

Short disclaimer

GDPRChecker provides technical checks and operational evidence for website privacy controls. It does not provide legal advice or guarantee GDPR compliance.

FAQ

Does a GDPR checker test cookie banners?
Yes. It can detect banner presence, preference controls, and whether optional trackers appear before a visitor gives consent.
Can a GDPR checker detect Google Analytics?
It can detect common Google Analytics scripts, cookies, and network requests. It should also check whether those signals occur before or after consent.
Does a GDPR checker store cookie values?
A privacy-first checker should not store cookie values. It should store cookie names and metadata needed for review and declaration.
Can a GDPR checker review my privacy policy?
It can check for policy presence and consistency signals, but full legal review of policy wording should be done by a qualified reviewer.
Why does a checker show needs-review items?
Some items are detected with limited context. Needs-review items should be classified by a human before being published in a final declaration.

GDPRChecker guides are educational resources and do not constitute legal advice. Use them to understand technical and operational privacy requirements, and consult qualified counsel for legal interpretation.

Check Your Website in Under 60 Seconds

  • No signup required
  • GDPR-focused checks
  • Cookie banner detection
  • Privacy policy verification