Home / Help Center / Use the public compliance scanner

Compliance Scanner

Use the public compliance scanner

Scan any public URL for trackers, consent UI, policy links, and compliance signals—available on all plans including Free.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

May 2026

Reading time

3 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

When to use this

The compliance scanner at /scanner analyzes a public URL without requiring the runtime script. It is ideal for first-touch audits, competitive reviews, and periodic health checks on sites you do not manage. Free, Pro, and Growth plans all include publicScanner access; managed runtime features are separate.

Run a scan before signing up to demonstrate value to stakeholders, or after go live to see whether public view matches your protected configuration. Pro adds public/private scan comparison when you own the site—telemetry in the dashboard contrasts with what anonymous scanners see.

Scans are not legal opinions. They highlight technical signals: third-party scripts, consent banner presence, policy URLs, cookie behavior, and scoring heuristics tuned for GDPR-oriented website compliance.

Scan the URL your customers actually land on—`/blog` paths sometimes omit tags present only on homepage templates. For international sites, run scans per locale path if hreflang routes serve different heads.

Combine scanner output with Records of Processing Activities maintenance: findings tell you what fires on the wire, not whether you have lawful basis documented internally.

Saved reports support security questionnaire workflows—attach scan id and date in responses to vendor risk portals when asked for cookie or tracking evidence.

Step-by-step instructions

  1. Navigate to /scanner from the marketing site or dashboard link.
  2. Enter a full URL including https:// and optional path to scan a specific landing page.
  3. Start the scan and wait for the job to complete—large tag-heavy pages take longer.
  4. Review the compliance score summary and category breakdown at the top of the report.
  5. Expand tracker and script sections to see domains loaded before interaction.
  6. Check consent and policy sections for banner detection and link reachability.
  7. Export or share the report link if your workflow needs a ticket attachment.
  8. For sites you own on Pro, open dashboard scans to compare with runtime diagnostics.
  9. Create remediation tasks: install runtime, fix policies, or adjust banner per failed checks.

Expected result

You receive a structured report with score, findings list, and evidence snippets suitable for prioritization. Repeat scans over time show whether changes helped. Managed site owners use failures to drive setup wizard work; external sites may only be fixable by their operators.

Authenticated users may see scan history in dashboard depending on feature flags; anonymous users still get one-off reports.

Establish a cadence—weekly for high-change marketing sites, monthly for stable brochures—to detect tag sprawl early. Pair each scan review with owner assignment: engineering for blocking, marketing for banner copy, legal for policy updates.

Troubleshooting

Scan timed out or failed

Confirm the URL is publicly reachable without bot challenges. Reduce scope to homepage if deep paths hang on infinite scroll. Retry after outages; extremely large single-page apps may exceed limits—try canonical marketing URL.

Score differs from competitor tools

Each scanner uses different weights. Read individual findings rather than chasing an identical number. See External scanner results help for mapping Cookiebot and similar outputs.

Protected site still scores low publicly

Public scan does not see owner-only runtime signals until tags are on the page. Verify script install and go live, then rescan. Some fixes are visible only after cache clears globally.

FAQ

Can I scan competitors?
You may scan public URLs you are permitted to test under applicable law and your internal policies. GDPRChecker does not grant permission to probe systems you do not own—follow your organization's acceptable use rules.
How many scans can I run?
Fair-use limits may apply per IP or account to prevent abuse. For high-volume monitoring, use dashboard scans on Pro and schedule reviews rather than hammering the public endpoint.
Does scanning store personal data?
Scans analyze the page as an anonymous visitor. See GDPRChecker privacy policy for retention of scan artifacts tied to accounts.

GDPRChecker help articles provide product guidance and do not constitute legal advice. Use them for setup and troubleshooting, and consult qualified counsel for legal interpretation.

Need hands-on verification?

Use the compliance scanner or open your dashboard to finish setup and go live.