Consent, cookies and tracking checked.

The technical layer reviewed end to end: which scripts fire when, which cookies get set, where data flows and how much of it is actually consented to.

Six layers checked, one fix list.

The review runs against the page as actually served, not against what the CMS claims is configured.

  1. Cookie inventory

    A complete inventory of first-party, third-party, persistent and session cookies, categorised by purpose, provider, lifetime and legal basis.

  2. Consent flow

    How consent is requested, stored, withdrawn and respected. Common faults: scripts firing before consent, no withdrawal route, nudged acceptance.

  3. Tracking and analytics

    Analytics, ad pixels, heatmaps and session recording checked for whether they sit cleanly behind consent and whether the data is usable at all.

  4. Third-party services

    Embedded maps, videos, fonts, chat widgets and form services. Every script that phones home from your domain is captured and assessed.

  5. Data flows

    Forms, lead capture, CRM and email integrations. Where data goes, who processes it and what the privacy policy has to disclose.

  6. Legal frame as the benchmark

    The review runs against GDPR Art. 5, 6 and 7, against § 25 TDDDG for access to terminal equipment storage, and against the requirements for third-country transfers.

What the audit delivers.

Two to three weeks, resulting in a report with severity tiers and concrete fixes.

Always included

  • Cookie and third-party inventory as a table
  • Finding list with a severity tier per item
  • A concrete fix recommendation per finding
  • Consent flow as-is against target state
  • Data flow sketch for forms and CRM
  • Briefing document for privacy policy and cookie policy

When needed

  • We implement the fixes
  • A re-check after implementation
  • Referral to a data protection officer or specialist lawyer
  • Review of further domains or language versions

Not included

  • Legal advice
  • Drafting of the legal texts
  • Representation in warning-letter cases
  • A certificate or seal

On its own or paired with the SEO audit.

Many clients combine both, because the same templates are involved.

SEO Audit

€690

one-off, two to three weeks

  • Technical, on-page, content, architecture
  • Prioritised action list
  • Works well alongside the GDPR audit

Strategy Call

€190

60 to 75 minutes, credited later

  • Obvious risks at a glance
  • Written action list
  • Right when you want to start broader

Three signals that it does not fit.

A technical audit does not replace a legal review.

  1. You are looking for legal advice or finished legal texts. We deliver the technical facts your lawyer or data protection officer can work from efficiently.
  2. You need a seal for the website. An audit is a snapshot with a fix list, not a certificate.
  3. You want confirmation rather than change. If scripts fire before consent, that goes into the report.

Common questions about the GDPR audit.

We are outside the EU. Does the GDPR apply to us?

As soon as you address visitors, customers or users in the EU and EEA, the GDPR applies regardless of where you are based. Most non-EU companies with European customers fall within its scope.

Is this legal advice?

No. We audit the technical implementation: cookies, consent flows, third-party scripts, tracking, data flows. We coordinate with your legal advisers on wording but do not replace them.

Will my tracking still work afterwards?

Yes. Properly consented tracking is more reliable than patchy tracking that fires before consent and produces data you cannot legally use anyway.

Do you implement the fixes as well?

On request, yes. Many clients implement themselves, others have the fixes delivered straight away. Both work, and the scope is set after the audit.

What do you find most often?

Externally loaded fonts, analytics firing before consent, map and video embeds loading on page view, consent layers that do not actually block, missing withdrawal routes and legacy scripts nobody can account for any more.

Send us the URL. We come back with a fixed scope.

If you would rather start broader, the strategy call is the right entry point. The obvious risks are covered there as part of the technical lens.

Reply within one working day. 60 to 75 minutes, €190, credited against your project fee.

Please fill in.
Please enter a valid email address.
Please fill in.
Please confirm.

Book a strategy call