A claim does not only come from a stock agency
Fines for mishandling personal data arrive faster and hurt more than image claims: an inspector only has to open your site and look for a consent checkbox next to the contact form. We look at the site the same way and back every finding with the article of the law and the size of the fine.
- No install
- First check is free
- Full report by email
- Transfers abroadCounters, Google Fonts, reCAPTCHA, chats and pixels — with the owner and jurisdiction of every service.
- Forms and consentWhether every form has a consent checkbox, whether it is pre-ticked, whether it links to the policy and where the submission goes.
- Documents on the sitePolicy, consent text, cookie notice and the mandatory sections inside the policy.
- Connection securityHTTPS on every page and cookies set before the visitor agrees.
- Rights to imagesPictures from the pages we walk: the filename, the rights holder in the metadata and a stock agency watermark on the shot itself.
What is visible from outside in half a minute
The scanner walks the site the way an inspector would — no install and no admin access.
Walking the pages
Home, policy, consent text, contacts, checkout, sign-in and registration — up to eight pages, including the site’s own subdomains.
Reading the scripts
We download external scripts and Google Tag Manager containers and look for counters, pixels and widgets by their call signatures.
Parsing forms and documents
Consent checkboxes, links to the policy, where the submission goes; mandatory policy sections, the cookie notice, cookies before consent and HTTPS.
Scoring
Every finding gets a risk level, the article of the law and the range of the fine. Part is shown right away, the full report goes to your email.
What cannot be seen from outside
- What appears after a visitor’s actions: pop-up forms, checkout steps, the account area
- Whether the regulator was notified, where the database lives and who is responsible — the plugin asks about that
- Images, fonts and texts — the plugin checks those from inside the site
What a mistake costs and what exactly we check
Four groups of checks. Three run from the outside for free; the fourth the plugin covers with questions that code cannot answer.
Cross-border transfers
We open your pages the way a visitor sees them and catch every outbound connection. Twenty-six services in the dictionary, from Google Fonts and reCAPTCHA to Hotjar and Mailchimp, each with its owner and jurisdiction.
- What exactly the service receives
- A Russian replacement for it
- Where on the site it was found
Forms and consent
We parse every form on the site no matter which plugin built it: is there a consent checkbox, is it pre-ticked, does its label link to the policy, is the newsletter opt-in kept separate.
- Enquiries, comments, checkout
- A checkbox that starts unticked
- Marketing consent as its own tick
Documents on the site
We check that the policy is published rather than left as a draft, that the footer links to it, and that the text carries all ten required sections, from processing purposes to how consent is withdrawn.
- Policy, consent text, cookie notice
- Which sections are missing
- Whether foreign recipients are named
Storage and the regulator
What code cannot answer we ask outright: was the notification filed, where does the database live, is a responsible person appointed, is there a breach procedure. Answering "not sure" never turns into a violation.
- Notification to Roskomnadzor
- Database kept inside Russia
- 24 hours to report a breach
Check your own site
No install, no sign-up. The full report with fixes goes to your email.

