GDPR compliance, automated
Complicer runs a 70-rule automated scan of your website, verifies your cookie consent implementation, and generates regulator-ready evidence packages — so your team spends less time on compliance spreadsheets and more time building.
Free plan available. No credit card required.
Ready to check your own exposure?
Honest by design — we never overclaim what an audit can prove.Our methodology
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into force across the European Union and European Economic Area on 25 May 2018. It governs how organisations collect, store, process, and share personal data — any information that can directly or indirectly identify a living individual, from a name or email address to an IP address or cookie identifier. GDPR replaced the 1995 Data Protection Directive and established a single, harmonised framework that applies regardless of where an organisation is based, provided it processes the data of EU residents.
GDPR applies to a much wider set of organisations than many businesses realise. If your website uses analytics cookies, collects email addresses, or displays personalised content to visitors located in the EU, GDPR almost certainly applies to you — even if your company is headquartered in the United States, Australia, or anywhere else outside the EEA. The regulation distinguishes between data controllers (organisations that determine the purposes and means of processing) and data processors (organisations that process data on behalf of a controller), and imposes obligations on both. Most websites act as controllers of their visitors' data and processors of data passed to them by their customers.
The penalties for non-compliance are substantial. Under Article 83 of GDPR, supervisory authorities can impose administrative fines of up to €20 million or 4% of total annual worldwide turnover — whichever is higher — for the most serious infringements, such as processing without a lawful basis or violating the basic principles of data protection. Less serious infringements carry fines of up to €10 million or 2% of turnover. Since 2018, EU data protection authorities have issued more than €4 billion in total fines, with enforcement accelerating every year.
Key GDPR requirements
GDPR contains 99 articles, but most compliance risk concentrates around eight core requirements. Here is what your organisation needs to have in place. If you also deploy AI systems, the EU AI Act layers additional obligations on top.
Lawful basis for processing
Every data processing activity must rest on one of six lawful bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests.
Valid consent mechanisms
Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes and bundled consent do not meet the GDPR standard.
Data subject rights
Individuals hold eight enforceable rights: access, rectification, erasure, restriction, portability, objection, and rights related to automated decisions.
Data Protection Officer
Public authorities and organisations that carry out large-scale systematic monitoring or process special-category data must appoint a DPO.
Data Protection Impact Assessment
A DPIA is mandatory before processing that is likely to result in high risk to individuals, including large-scale profiling or processing biometric data.
Breach notification
Organisations must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to individuals.
International data transfers
Transferring personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or another approved safeguard.
Records of processing activities
Most organisations must maintain written records of all processing activities covering purposes, categories of data, recipients, and retention periods.
How Complicer helps
Manual compliance audits take weeks and cost thousands. Complicer automates the technical layer so your legal and engineering teams can focus on decisions that actually need human judgment.
Automated cookie audit
Our Playwright-powered crawler visits your website the way a real browser does, inventorying every cookie set before and after consent. We classify each cookie by purpose, map it to a vendor, and flag anything that fires before the user has given valid consent.
Consent banner testing
We test your consent management platform against 70 rules drawn directly from GDPR Article 7, Recital 32, and ePrivacy guidelines. Dark patterns, pre-ticked boxes, and buried reject options are all surfaced with evidence-grade screenshots.
Evidence packages
Every audit generates a tamper-evident, SHA-256-checksummed evidence package containing screenshots, HAR files, scan logs, and a structured compliance report. When a Data Protection Authority requests documentation, you are ready in minutes.
Continuous monitoring
GDPR compliance is not a one-time checkbox. Complicer re-scans your website on a schedule you control, alerts you when new compliance issues appear after a deployment, and tracks your compliance score over time so you can demonstrate improvement.
70
compliance rules checked per scan
5 min
average time to first results
72 hrs
GDPR breach notification window covered
Why automated GDPR compliance matters
A typical modern website integrates dozens of third-party scripts — analytics platforms, advertising pixels, support chat widgets, A/B testing tools, and more. Each of these can set cookies, fingerprint browsers, or transmit personal data to servers outside the EEA. Auditing these integrations manually requires capturing network traffic, reading vendor documentation, and cross-referencing consent flows — a process that is both time-consuming and error-prone.
Complicer automates this technical audit layer. Our Playwright-based crawler replicates the experience of a user visiting your site with no consent given, then again after accepting all categories, then again after rejecting all. We record every cookie set, every network request made, and every piece of data transmitted at each stage. This gives you a precise, reproducible map of your actual data flows — not a theoretical inventory based on what vendors claim their scripts do.
The resulting evidence package is designed to satisfy the documentation requirements of Article 5(2) GDPR (the accountability principle) and to support responses to Data Subject Access Requests, DPA investigations, and internal audit processes. Because every scan produces a cryptographically signed, timestamped record, you can demonstrate not just your current compliance posture but your compliance posture at any point in the past — which matters when a regulator is investigating whether you were compliant at the time a complaint was filed.
Run your first GDPR audit for free
Enter your website URL and get a full 70-rule GDPR compliance scan in under five minutes. No credit card. No sales call.
Start free scanFree plan available. Results in under 5 minutes.
Ready to check your own exposure?
Honest by design — we never overclaim what an audit can prove.Our methodology