Skip to main content
ComplicerAUDIT GRADE
MethodologyUse casesEU AI ActPricingBlogDocsSign inSTART FREE AUDIT
GDPR compliance software

GDPR compliance, automated

Complicer runs a 70-rule automated scan of your website, verifies your cookie consent implementation, and generates regulator-ready evidence packages — so your team spends less time on compliance spreadsheets and more time building.

Scan your website freeView pricing

Free plan available. No credit card required.

Ready to check your own exposure?

Run a free auditWe click Reject on your real banner and show you what happened.

Honest by design — we never overclaim what an audit can prove.Our methodology

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into force across the European Union and European Economic Area on 25 May 2018. It governs how organisations collect, store, process, and share personal data — any information that can directly or indirectly identify a living individual, from a name or email address to an IP address or cookie identifier. GDPR replaced the 1995 Data Protection Directive and established a single, harmonised framework that applies regardless of where an organisation is based, provided it processes the data of EU residents.

GDPR applies to a much wider set of organisations than many businesses realise. If your website uses analytics cookies, collects email addresses, or displays personalised content to visitors located in the EU, GDPR almost certainly applies to you — even if your company is headquartered in the United States, Australia, or anywhere else outside the EEA. The regulation distinguishes between data controllers (organisations that determine the purposes and means of processing) and data processors (organisations that process data on behalf of a controller), and imposes obligations on both. Most websites act as controllers of their visitors' data and processors of data passed to them by their customers.

The penalties for non-compliance are substantial. Under Article 83 of GDPR, supervisory authorities can impose administrative fines of up to €20 million or 4% of total annual worldwide turnover — whichever is higher — for the most serious infringements, such as processing without a lawful basis or violating the basic principles of data protection. Less serious infringements carry fines of up to €10 million or 2% of turnover. Since 2018, EU data protection authorities have issued more than €4 billion in total fines, with enforcement accelerating every year.

Key GDPR requirements

GDPR contains 99 articles, but most compliance risk concentrates around eight core requirements. Here is what your organisation needs to have in place. If you also deploy AI systems, the EU AI Act layers additional obligations on top.

Lawful basis for processing

Every data processing activity must rest on one of six lawful bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests.

Valid consent mechanisms

Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes and bundled consent do not meet the GDPR standard.

Data subject rights

Individuals hold eight enforceable rights: access, rectification, erasure, restriction, portability, objection, and rights related to automated decisions.

Data Protection Officer

Public authorities and organisations that carry out large-scale systematic monitoring or process special-category data must appoint a DPO.

Data Protection Impact Assessment

A DPIA is mandatory before processing that is likely to result in high risk to individuals, including large-scale profiling or processing biometric data.

Breach notification

Organisations must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to individuals.

International data transfers

Transferring personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or another approved safeguard.

Records of processing activities

Most organisations must maintain written records of all processing activities covering purposes, categories of data, recipients, and retention periods.

How Complicer helps

Manual compliance audits take weeks and cost thousands. Complicer automates the technical layer so your legal and engineering teams can focus on decisions that actually need human judgment.

1

Automated cookie audit

Our Playwright-powered crawler visits your website the way a real browser does, inventorying every cookie set before and after consent. We classify each cookie by purpose, map it to a vendor, and flag anything that fires before the user has given valid consent.

2

Consent banner testing

We test your consent management platform against 70 rules drawn directly from GDPR Article 7, Recital 32, and ePrivacy guidelines. Dark patterns, pre-ticked boxes, and buried reject options are all surfaced with evidence-grade screenshots.

3

Evidence packages

Every audit generates a tamper-evident, SHA-256-checksummed evidence package containing screenshots, HAR files, scan logs, and a structured compliance report. When a Data Protection Authority requests documentation, you are ready in minutes.

4

Continuous monitoring

GDPR compliance is not a one-time checkbox. Complicer re-scans your website on a schedule you control, alerts you when new compliance issues appear after a deployment, and tracks your compliance score over time so you can demonstrate improvement.

70

compliance rules checked per scan

5 min

average time to first results

72 hrs

GDPR breach notification window covered

Why automated GDPR compliance matters

A typical modern website integrates dozens of third-party scripts — analytics platforms, advertising pixels, support chat widgets, A/B testing tools, and more. Each of these can set cookies, fingerprint browsers, or transmit personal data to servers outside the EEA. Auditing these integrations manually requires capturing network traffic, reading vendor documentation, and cross-referencing consent flows — a process that is both time-consuming and error-prone.

Complicer automates this technical audit layer. Our Playwright-based crawler replicates the experience of a user visiting your site with no consent given, then again after accepting all categories, then again after rejecting all. We record every cookie set, every network request made, and every piece of data transmitted at each stage. This gives you a precise, reproducible map of your actual data flows — not a theoretical inventory based on what vendors claim their scripts do.

The resulting evidence package is designed to satisfy the documentation requirements of Article 5(2) GDPR (the accountability principle) and to support responses to Data Subject Access Requests, DPA investigations, and internal audit processes. Because every scan produces a cryptographically signed, timestamped record, you can demonstrate not just your current compliance posture but your compliance posture at any point in the past — which matters when a regulator is investigating whether you were compliant at the time a complaint was filed.

Run your first GDPR audit for free

Enter your website URL and get a full 70-rule GDPR compliance scan in under five minutes. No credit card. No sales call.

Start free scan

Free plan available. Results in under 5 minutes.

Ready to check your own exposure?

Run a free auditWe click Reject on your real banner and show you what happened.

Honest by design — we never overclaim what an audit can prove.Our methodology

ComplicerAUDIT GRADE

We test whether Reject actually works on your site — and seal the evidence you can hand to a regulator.

GDPR-ALIGNED · SHA-256 · Ed25519 · EU-W1
PRODUCT
Free scanUse casesMethodologyEU AI ActPricingDocsBlog
COMPANY
ContactSecurityTrust
LEGAL
PrivacyTermsSubprocessorsComplaint
EVIDENCE CHAIN INTACT · SHA-256 · Ed25519 · RFC 3161-READY© 2026 COMPLICER