Practical GDPR-Scan example

Alice runs a website. Bob helps her correct technical issues.

Alice runs a small business website. She wants to understand which privacy-related technical signals are visible to an external visitor. Bob, the developer, needs clear evidence to decide what to inspect and correct first.

Alice shows a website on a laptop while Bob inspects cookies and external connections with a magnifying glass.
Alice shows a website on a laptop while Bob inspects cookies and external connections with a magnifying glass.

Practical example

Alice’s website before the review

Alice’s website has changed over time. Plugins, analytics, embedded videos and new contact forms have been added.

Alice does not want to rely on vague impressions. She uses GDPR-Scan to collect observable technical indicators and gives the result to Bob, who can turn it into an action plan.

Practical example

How the review works

  1. Alice defines the scope

    She identifies the domain and relevant pages. A non-intrusive external scan is not a penetration test.

  2. GDPR-Scan observes the website

    The tool collects externally visible indicators such as TLS, headers, cookies, scripts, frames, DNS, MX and legal pages.

  3. Results become evidence

    Findings are organized as JSON and Markdown with indicators, severity and repeatable data.

  4. Bob sets priorities

    Bob separates confirmed issues, items needing investigation and matters requiring legal or organizational assessment.

  5. Corrections are applied

    Plugins, cookies, external services, headers or configurations are changed within the agreed scope.

  6. A second scan compares the site

    The new result technically verifies which indicators changed and which still need attention.

Results

What Alice and Bob receive

  • A clear inventory of observable technical elements.
  • Repeatable evidence connected to remediation work.
  • A priority order for the developer’s work.
  • A later comparison that verifies agreed changes.

Stated limitations

Limits of a technical audit

  • GDPR-Scan does not certify GDPR compliance.
  • It does not replace a DPO, lawyer, records of processing, DPIA or legal analysis.
  • An external scan cannot automatically see internal processes, contracts, legal bases or data stored in company systems.
  • The score covers observable technical indicators and must be interpreted in context.

FAQ

Frequently asked questions about GDPR-Scan

Does GDPR-Scan say whether a website is legally compliant?

No. It identifies observable technical indicators and produces evidence, while compliance also requires legal and organizational assessment.

Does the scan modify the website?

No. The standard review is external and non-intrusive. Corrections are performed separately by the owner or an authorized developer.

Can an agency use it for several clients?

Yes. It can make technical reviews repeatable across several websites when scope, authorization and report limitations are clearly defined.

Would you like to review your website with a repeatable method?

Explore GDPR-Scan or ask Ilion for a technical audit with evidence, priorities and a later verification of agreed corrections.

Explore GDPR-Scan