Is your website GDPR compliant?

Enter your URL. We scan your site for analytics trackers and cookie consent banners, then tell you whether you legally need consent β€” and what to do about it.

Works on any public website. No login required.

What this checks β€” and what it doesn't

GDPR covers everything you do with personal data. This tool checks the part that trips up most websites and that you can verify from the outside: tracking scripts and cookie consent. It fetches your homepage, looks for known analytics and consent-platform scripts, and tells you whether that combination needs consent. It does not review your privacy policy, contact forms, email lists, data-processing agreements or server logs β€” and it isn't legal advice.

What GDPR actually requires from a website

Two rules do most of the work. The ePrivacy Directive says you need consent before storing or reading anything on a visitor's device β€” cookies, localStorage, device fingerprints β€” unless it's strictly necessary to deliver the service the visitor asked for. Analytics is never "strictly necessary". The GDPR then says that if you process personal data (and an IP address or a persistent visitor ID counts), you need a lawful basis, and for analytics that basis is normally consent.

When consent is required it has to be opt-in β€” freely given, specific, informed and unambiguous. In practice that means: nothing fires before the visitor agrees, refusing is as easy as accepting, and pre-ticked boxes or "by continuing you accept" banners don't count.

The shortcut most sites miss: if you never store anything on the device and never process personal data, there is nothing to consent to. That's why cookie-free analytics removes the banner requirement instead of managing it.

Which analytics tools need a cookie banner?

ToolCookiesConsent banner
Google Analytics 4YesRequired
Universal Analytics (legacy)YesRequired
Matomo (default config)YesRequired (cookie-free mode available)
Plausible, Fathom, Umami, GoatCounter, Pirsch, Simple AnalyticsNoNot required
LoglyNoNot required

Configuration changes this: any tool can be made non-compliant by bolting identifiers onto it, and Matomo can be made compliant by disabling cookies. The table reflects each tool's default setup.

Common questions

How do I check if my website is GDPR compliant?

Start from the outside in. Run the scan above to see which trackers your site loads and whether a consent platform is present β€” that covers the most common failure. Then check the parts a scanner can't see: whether your privacy policy names the tools you actually use, whether forms explain what happens to the data, and whether you have processing agreements with your vendors.

What does this checker detect?

Google Analytics 4, Universal Analytics, Plausible, Fathom, GoatCounter, Umami, Simple Analytics, Pirsch, Matomo β€” and common cookie consent platforms (Cookiebot, OneTrust, Complianz, Borlabs, Iubenda, and others). It fetches your homepage HTML and looks for known script patterns.

When do you legally need a cookie banner?

Whenever you store or read something on the visitor's device that isn't strictly necessary, or process personal data without another lawful basis. Google Analytics does both β€” it sets cookies and handles identifiers β€” so it needs consent. Cookie-free, anonymised analytics doesn't store anything on the device or process personal data, so there is nothing to ask consent for.

The check says I have Google Analytics but no banner β€” what should I do?

Two options. Add a compliant consent platform (Cookiebot, Complianz or similar) and make sure GA genuinely doesn't fire before consent β€” a banner that appears while the tracker already ran doesn't fix anything. Or switch to cookie-free analytics, which removes the requirement instead of managing it, and also removes the consent dropoff that makes consented analytics undercount. How analytics without a cookie banner works β†’

Does a cookie banner make my analytics data wrong?

It makes it incomplete. Every visitor who declines or ignores the banner is invisible to your analytics, so your traffic is undercounted by however many people say no β€” often a large share in the EU. Cookie-free analytics measures everyone because it never needed to ask. Why Google Analytics underreports β†’

Can this checker miss things?

Yes β€” it only scans the homepage HTML at the time of the check. Analytics loaded lazily after user interaction, scripts injected by tag managers that render asynchronously, or analytics present only on inner pages may not be detected. It's a quick scan, not a full audit.

Is this legal advice?

No. It's a technical scan plus a plain-English summary of how GDPR and ePrivacy usually apply to website analytics. Rules are enforced by national regulators and interpretations differ between member states β€” for a binding answer about your situation, talk to a qualified advisor.

Going deeper: the full guide to GDPR-compliant analytics Β· running analytics without a cookie banner Β· Logly compared with Google Analytics 4