Care & Support

Technical GDPR Website Check

Have your site's cookie banner and tracking checked technically.

We check whether cookies, tracking technologies, and external services are actually blocked before consent, and whether your consent banner works correctly on a technical level. You get a clear report with concrete issues, priorities, and recommendations. On request, we implement the recommended technical improvements directly.

What you get

Independently checked, technically

We don't rely on your cookie plugin's settings — we test what actually happens in the browser.

Clear recommendations

Results ranked by priority — what's critical, what needs action, what's a suggestion.

Fixes included on request

We can fix issues we find directly afterwards, if you want us to.

Cookies before consent, and tracking despite rejection

Many sites show a cookie banner but still load Google Analytics, Meta Pixel, or other services before consent is given. Sometimes tracking even keeps running after a visitor has rejected it.

Services load before consent

Google Analytics, Meta Pixel & co. often start before any consent has actually been given.

Tracking stays active after rejection

Some scripts keep running even though a visitor explicitly declined.

Cookie plugin settings aren't enough

What's configured in the backend doesn't have to match what the browser actually loads and sends.

Request a check and fix

On request, we implement the recommended changes directly for you.

What we check in the GDPR website check

Our technical GDPR check doesn't just look for a cookie banner. We examine whether consent management, website tracking, and external services technically work together correctly.

Cookie banner

We test whether accepting, rejecting, and later changing the choice work technically. We also check whether non-essential services stay blocked before consent.

Tracking

We check website tracking and analyse Google Analytics, Google Tag Manager, Google Ads, Meta Pixel, and other tracking technologies, among others.

External services

We check connections to Google Fonts, Google Maps, YouTube, Vimeo, reCAPTCHA, external CDNs, and marketing tools.

The basics

We check SSL/HTTPS, mixed content, and forms, as well as the technical setup of your privacy policy and imprint.

Check and fix from one source

If we find technical issues, we can fix them right afterwards. That includes, for example:

Configuring consent management

The consent logic gets set up correctly under the hood, not just displayed on the surface.

Blocking tracking before consent

Analytics and marketing scripts only start once consent has actually been given.

Wiring Google Tag Manager correctly

Tags get tied to the real consent state instead of firing indiscriminately.

Loading external content based on consent

Google Maps, YouTube, and similar embeds only appear once the right consent is given.

Cleaning up duplicate or broken tracking codes

Scripts that are loaded multiple times or outdated get removed instead of piling up.

Adjusting forms and third-party services

Technical adjustments to forms and external services are part of this too.

Request a check and fix

On request, we implement the recommended changes directly for you.

How it works

  1. 01

    Send us your URL

    You simply send us your website's URL.

  2. 02

    We check your site

    We examine the cookie banner, tracking, and external connections across different consent states.

  3. 03

    You get the results

    You receive the results in a clear format, ranked by priority.

  4. 04

    We fix the issues

    On request, we implement the necessary technical improvements directly.

A technical check. Not legal advice.

Our GDPR website check focuses on the technical implementation of your site. We check which cookies, tracking technologies, and external services actually get loaded, and whether consent management technically controls them. The check is not legal advice, not a legal review of your privacy texts, and not a GDPR certification. We only establish whether a privacy policy and imprint are present and technically linked in a sensible way.

Clear results and recommendations

After the website privacy check, you'll know:

01

What's working?

You see which consent flows and embedded services are technically controlled correctly.

02

Where are the problems?

We name concrete technical issues on your site.

03

How urgent is a fix?

Results are categorised as critical, needs action, or recommended.

04

What should change?

You get concrete, understandable recommendations for your site.

Frequently asked

What does the GDPR website check cover?

We examine the cookie banner, consent management, cookies, website tracking, external services, and selected technical fundamentals.

Is this a legal GDPR review?

No. We check the technical implementation and don't offer legal advice or GDPR certification.

Is a GDPR check possible for WordPress?

Yes. Our focus is on WordPress sites and WooCommerce stores. We can generally run the technical check on other website systems too.

Can you fix the issues you find directly?

Yes. On request, we fix the technical issues and then re-test the affected consent flows.

Isn't an existing cookie banner enough on its own?

Not necessarily. A cookie banner can be visible and functional while tracking technologies or external services still load before consent. That's why we check your site's actual behaviour in the browser.

What does "tracking despite rejection" mean?

Some tracking scripts keep running even after a visitor has explicitly declined consent — for example because cookies or tags aren't correctly tied to the consent state. That's exactly what we check for, so that rejected services actually stay blocked.

What information do you need for the check?

For a start, your website's URL is usually enough. If protected areas, specific forms, or particular marketing features need checking, we'll agree on the required information or access with you.

How do I get the results?

You get a clear overview of the technical findings. We show what's working, where problems exist, how urgent they are, and what changes we recommend.

Do you also check the privacy policy and imprint?

We check whether a privacy policy and imprint are present, reachable, and technically linked in a sensible way. A legal review of the texts for completeness or accuracy isn't part of the check.

Does a cookie banner need to already exist?

No. We can also check sites that don't have consent management set up yet. In that case, we record the existing cookies, tracking technologies, and external services, and recommend a suitable technical setup.

Get your cookie banner checked

Find out whether cookies, website tracking, and external services are actually controlled the way your consent banner promises.

Back to services overview