Technical GDPR Audit
€450
one-off, two to three weeks
- Cookies, consent, tracking, third parties
- Finding list with severity tiers
- Briefing for the legal texts
The technical layer reviewed end to end: which scripts fire when, which cookies get set, where data flows and how much of it is actually consented to.
The review runs against the page as actually served, not against what the CMS claims is configured.
A complete inventory of first-party, third-party, persistent and session cookies, categorised by purpose, provider, lifetime and legal basis.
How consent is requested, stored, withdrawn and respected. Common faults: scripts firing before consent, no withdrawal route, nudged acceptance.
Analytics, ad pixels, heatmaps and session recording checked for whether they sit cleanly behind consent and whether the data is usable at all.
Embedded maps, videos, fonts, chat widgets and form services. Every script that phones home from your domain is captured and assessed.
Forms, lead capture, CRM and email integrations. Where data goes, who processes it and what the privacy policy has to disclose.
The review runs against GDPR Art. 5, 6 and 7, against § 25 TDDDG for access to terminal equipment storage, and against the requirements for third-country transfers.
Two to three weeks, resulting in a report with severity tiers and concrete fixes.
Many clients combine both, because the same templates are involved.
€450
one-off, two to three weeks
€690
one-off, two to three weeks
€190
60 to 75 minutes, credited later
A technical audit does not replace a legal review.
As soon as you address visitors, customers or users in the EU and EEA, the GDPR applies regardless of where you are based. Most non-EU companies with European customers fall within its scope.
No. We audit the technical implementation: cookies, consent flows, third-party scripts, tracking, data flows. We coordinate with your legal advisers on wording but do not replace them.
Yes. Properly consented tracking is more reliable than patchy tracking that fires before consent and produces data you cannot legally use anyway.
On request, yes. Many clients implement themselves, others have the fixes delivered straight away. Both work, and the scope is set after the audit.
Externally loaded fonts, analytics firing before consent, map and video embeds loading on page view, consent layers that do not actually block, missing withdrawal routes and legacy scripts nobody can account for any more.
If you would rather start broader, the strategy call is the right entry point. The obvious risks are covered there as part of the technical lens.
Reply within one working day. 60 to 75 minutes, €190, credited against your project fee.