Privacy policy checker — what does yours actually say?
Most privacy policies name no legal basis, no retention period and no way to exercise a right. Check yours in thirty seconds, free, no signup.
No signup · No commitment · Result in 30 seconds
A privacy policy is the one legal document a regulator reads first, and the one most sites copied from somewhere else. The copy usually looks complete: it runs for two thousand words, cites the GDPR by article number, and answers none of the questions actually being asked. This checker reads the policy you publish and reports what is missing from it, clause by clause.
What the check looks for
- Whether a legal basis is named for each purpose, not just asserted in general terms
- Whether retention periods are stated, and stated in a way a reader could act on
- Whether the data-subject rights are attributed to the reader’s own personal data — not to cookies, not to the company, not buried in a reserve clause
- Whether the policy names the actual recipients and any transfer outside the EEA
- Whether a contact route exists for exercising those rights, and whether it works
Why templates score badly
A template states the law in the abstract. Your policy has to state what your site does: which data, for which purpose, on which legal basis, kept how long, shared with whom. The difference is invisible to a reader skimming for reassurance and obvious to anyone checking. It is also the difference between a document that survives a complaint and one that adds to it — a policy that describes processing you do not do is a false statement about your own business.
The scoring here is deliberately strict about attribution. Credit is given for a right only when the text grants it to the reader’s own personal data — not to cookies in general, not to the company, and not inside a clause that reserves the right to refuse.
How it works
- Enter your address. The checker loads your site the way a visitor does, finds the policy you publish, and reads it.
- Read what came back: every missing element is named, with the clause that should have carried it.
- Fix it in place: generate a policy pre-filled with what the check already found about your site.
Where this fits
This page answers one question: is the policy you publish any good? Two neighbours answer the others. The cookie checker reports what your site actually sets in a visitor’s browser and what fires before consent. The full compliance scan covers both plus your other legal pages, your company identification and your trackers, and returns a single score out of 100.
Privacy policy checker — FAQ
What does the checker actually read?
The privacy policy published on your site, found the way a visitor would find it. It scores what the text contains — legal basis, retention, recipients, transfers, rights and how to exercise them — rather than whether a page merely exists at a plausible URL.
Why do most privacy policies score badly?
Because they were copied from a template written for a different business. Templates state the law in the abstract instead of naming what this site does: which data, for what purpose, kept how long, shared with whom. That reads as complete and answers none of the questions a regulator asks.
Is a good score the same as being compliant?
No. The check reads the document you publish. Compliance also depends on what your site actually does — the trackers that fire before consent, the data you really collect — which is what the full compliance scan covers.
Is it free, and do I need an account?
Free, no signup, no card, and no personal data collected during the check. The result appears in about thirty seconds.
My policy was written by a lawyer. Is it worth checking?
Yes, and for a specific reason: a policy drafted once tends to stay as drafted while the site changes around it. New analytics, a new payment provider, a new form — each adds a purpose and a recipient the text never mentioned.