Guides Create account 🇬🇧 🇩🇪

Data protection guide

Privacy signals, explained

The way a website handles cookies, fonts, trackers and legal links tells you a lot about how carefully it treats the people who visit it. This guide walks through the privacy signals our scanner looks at, what each one hints at and how to reduce the risk. Every point is a heuristic risk indicator, not a legal verdict.

Scan my privacy signals Jump to the signals

01 Why they matter

Small signals, real trust

Visitors in the DACH region are especially sensitive to how their data is handled, and so are the people who might flag a site. Our scanner reads a handful of signals a browser can observe from the outside: what a page loads before anyone has agreed to anything, where those resources come from and whether the basic legal links are in place. None of this is a compliance judgement. Each signal is a hint that something may be worth a closer look with your own advisers.

02 The signals

Four privacy risk indicators we check

Cookies before consent Consent

What we check. We load the page as a first-time visitor without accepting anything, then look at whether cookies or similar storage are already set. Strictly necessary cookies are expected; marketing or analytics cookies appearing before any interaction are the signal we flag.

Why it is a risk indicator. Storage set before a visitor has had the chance to agree is a common risk indicator, because many analytics and advertising cookies are meant to wait for consent. This is a heuristic: we cannot see the purpose behind every cookie, so treat a flag as a prompt to review your consent banner rather than proof of a problem.

How to fix it. Load your consent tools only after the visitor accepts. Keep the pre-consent page to strictly necessary storage and defer the rest.

Third-party fonts Fonts

What we check. We check whether the page pulls fonts from an external host, such as Google Fonts, at render time. Loading a font from a third party sends the visitor’s IP address to that host on every page view.

Why it is a risk indicator. Externally hosted fonts are a frequent risk indicator because the visitor’s IP address leaves for a third party before any consent, and in the DACH region this has drawn particular attention. We can only observe the request, not any agreement you may have in place, so this is a heuristic flag rather than a finding.

How to fix it. Self-host your fonts and serve them from your own domain. The visitor’s browser then never contacts an outside host to render text.

Known trackers Trackers

What we check. We compare the third-party resources a page requests against a list of widely recognised tracking and advertising services, and report any that we recognise.

Why it is a risk indicator. Recognised trackers are a risk indicator because they often collect behavioural data and may load before consent. The match is heuristic: our list is not exhaustive, a recognised host is not automatically unlawful, and a legitimate tool you have disclosed may still show up. Use a flag to confirm each service is documented and consent-gated.

How to fix it. Inventory every third-party script, remove what you do not need and route the rest through your consent layer so they load only after agreement.

Missing legal links Legal

What we check. We look for the standard legal links a site is generally expected to carry, such as an imprint and a privacy policy, in places a visitor would reasonably find them.

Why it is a risk indicator. A missing imprint or privacy-policy link is a risk indicator because these pages are how visitors learn who runs the site and how their data is used. Our check is heuristic: it follows common link patterns and wording, so an unusual label or an unlinked page may be missed. A flag means it is worth confirming the links are present and easy to reach.

How to fix it. Link a clearly labelled imprint and privacy policy from a persistent place, such as the footer, on every page of the site.

03 Reading the results

Signals, not certainties

Every privacy signal we surface is a heuristic observed from the outside of your site. A flag means something is worth a closer look, not that anything is wrong; a clean result means we did not observe that particular signal, not that a page is beyond question. Use the findings to prioritise where to point your own data-protection review, and confirm anything material with people who know your setup.

how to read a flag Flag worth a closer look, review with your advisers No flag signal not observed from the outside Every check a heuristic, never a legal verdict

See which privacy signals your site raises

Our free Quickscan reads your live privacy signals alongside security headers, sustainability, accessibility, SEO and performance, then explains every finding in plain language.

Scan your site for free Latest scans
Recent scans Guides Pricing API Data protection Imprint © 2026 Erseni