Guides Create account 🇬🇧 🇩🇪
  • Guides
  • Create account
  • Sign in
  • 🇬🇧 🇩🇪
  • Data protection guide

    Test your website for cookies and trackers

    The way a website handles cookies, fonts, trackers and legal links tells you a lot about how carefully it treats the people who visit it. This guide walks through the privacy signals our scanner looks at, what each one hints at and how to reduce the risk. Every point is a heuristic risk indicator, not a legal verdict.

    Scan website

    Submitted scans are publicly listed on the recent scans page. By scanning, you accept our Terms and Conditions.

    Jump to the signals

    01 Why they matter

    Small signals, real trust

    Visitors in the DACH region are especially sensitive to how their data is handled, and so are the people who might flag a site. Our scanner reads a handful of signals a browser can observe from the outside: what a page loads before anyone has agreed to anything, where those resources come from and whether the basic legal links are in place. None of this is a compliance judgement. Each signal is a hint that something may be worth a closer look with your own advisers.

    02 The signals

    Four privacy risk indicators we check

    Cookies before consent Consent

    What we check. We load the page as a first-time visitor without accepting anything, then look at whether cookies or similar storage are already set. Strictly necessary cookies are expected; marketing or analytics cookies appearing before any interaction are the signal we flag.

    Why it is a risk indicator. Storage set before a visitor has had the chance to agree is a common risk indicator, because many analytics and advertising cookies are meant to wait for consent. This is a heuristic: we cannot see the purpose behind every cookie, so treat a flag as a prompt to review your consent banner rather than proof of a problem.

    How to fix it. Load your consent tools only after the visitor accepts. Keep the pre-consent page to strictly necessary storage and defer the rest.

    Third-party fonts Fonts

    What we check. We check whether the page pulls fonts from an external host, such as Google Fonts, at render time. Loading a font from a third party sends the visitor’s IP address to that host on every page view.

    Why it is a risk indicator. Externally hosted fonts are a frequent risk indicator because the visitor’s IP address leaves for a third party before any consent, and in the DACH region this has drawn particular attention. We can only observe the request, not any agreement you may have in place, so this is a heuristic flag rather than a finding.

    How to fix it. Self-host your fonts and serve them from your own domain. The visitor’s browser then never contacts an outside host to render text.

    Known trackers Trackers

    What we check. We compare the third-party resources a page requests against a list of widely recognised tracking and advertising services, and report any that we recognise.

    Why it is a risk indicator. Recognised trackers are a risk indicator because they often collect behavioural data and may load before consent. The match is heuristic: our list is not exhaustive, a recognised host is not automatically unlawful, and a legitimate tool you have disclosed may still show up. Use a flag to confirm each service is documented and consent-gated.

    How to fix it. Inventory every third-party script, remove what you do not need and route the rest through your consent layer so they load only after agreement.

    Missing legal links Legal

    What we check. We look for the standard legal links a site is generally expected to carry, such as an imprint and a privacy policy, in places a visitor would reasonably find them.

    Why it is a risk indicator. A missing imprint or privacy-policy link is a risk indicator because these pages are how visitors learn who runs the site and how their data is used. Our check is heuristic: it follows common link patterns and wording, so an unusual label or an unlinked page may be missed. A flag means it is worth confirming the links are present and easy to reach.

    How to fix it. Link a clearly labelled imprint and privacy policy from a persistent place, such as the footer, on every page of the site.

    03 Reading the results

    Signals, not certainties

    Every privacy signal we surface is a heuristic observed from the outside of your site. A flag means something is worth a closer look, not that anything is wrong; a clean result means we did not observe that particular signal, not that a page is beyond question. Use the findings to prioritise where to point your own data-protection review, and confirm anything material with people who know your setup.

    how to read a flag Flag worth a closer look, review with your advisers No flag signal not observed from the outside Every check a heuristic, never a legal verdict

    04 Questions

    Frequently asked questions about the privacy signals

    Does a flag in the data protection check mean my site is breaking the law?

    No. Every privacy signal we report is a heuristic observed from the outside, and we can see neither the purpose behind a cookie nor the agreements you may have in place. A flag means the point is worth reviewing with your own data protection advisers; it is never a legal verdict.

    Which cookies may a website set before the visitor has agreed to anything?

    Storage that is strictly necessary to deliver the page, such as a session or a load balancer cookie, is expected before any interaction. Analytics and advertising cookies are the ones we flag when they appear first, because they are normally meant to wait for consent.

    Are third-party fonts such as Google Fonts forbidden?

    They are not forbidden, but they send the visitor IP address to an outside host on every page view, which is why we flag them. Serving the font files from your own domain removes that request entirely and is usually a small change to your stylesheet.

    Why does the scan report a service that I use deliberately and have disclosed?

    Our tracker list matches well-known hosts and cannot tell a documented tool from an undocumented one. A recognised service is not automatically a problem: use the flag to confirm that it is named in your privacy policy and that it loads only after consent.

    What can the data protection check not see?

    Some limits come with any view from the outside. If a site answers our scanner with a block page, for example an HTTP 403 from a bot protection, we do not score it and mark the scan as blocked instead; if that block page already loads services from the USA, we name them. A consent banner that does not come from a known consent platform and only appears late can be missed, and a paid alternative to consent such as an ad-free subscription is only recognised inside the banner or directly next to it. None of this replaces a legal assessment of your site.

    Keep reading

    Every guide stands on its own, and together they cover what our scanner looks at. Pick the one closest to your next question.

    Is your website affected? BFSG check Accessibility statement BFSG for online shops BFSG for medical practices BFSG for hotels BFSG for tradespeople HTTP security headers Content Security Policy HSTS Cookie security Clickjacking and X-Frame-Options Referrer-Policy Permissions-Policy SPF, DMARC and DNSSEC security.txt Monitoring security headers Detecting CSP changes Security headers in nginx Security headers in Apache Security headers in WordPress Security headers in IIS Security headers in TYPO3 Security headers in Shopware 6 Security headers in Plesk All guides

    See which privacy signals your site raises

    Our free Quickscan reads your live privacy signals alongside security headers, sustainability, accessibility, SEO and performance, then explains every finding in plain language.

    Scan your site for free Latest scans
    Recent scans Guides Local leagues Pricing Methodology For hosters API Data protection Imprint Accessibility Terms Cancel contracts here © 2026 Erseni