Privacy Policy Checker
Paste a URL or your policy text. See what your policy is missing in 20 seconds.
- Structured gap report, not a vague pass / fail
- A 0–100 score plus a plain-English verdict — publish, polish, or rewrite
- Each finding cites the specific framework clause it maps to
Most privacy policies on the web were written once and never revisited. Laws change, sub-processors get added, and what was compliant in 2023 may not be in 2026. Our checker reads your policy, compares it against the disclosures that GDPR, CCPA, UK GDPR, PIPEDA, and the Australian Privacy Act actually require today, and shows you what is missing. The whole report appears in under a minute, no card and no account needed.
Grounded in real law, not training-data recall.
Required disclosures
GDPR Articles 13 and 14, CCPA §1798.100 and §1798.135, UK GDPR equivalents, plus the Australian Privacy Principles. We check whether each mandatory item is actually present — not just whether you mention the topic.
Data subject rights
Access, deletion, correction, portability, objection, withdrawal of consent. Whether the rights are named, whether the process to exercise them is described, whether response timeframes are mentioned.
International transfer safeguards
Whether the policy names a specific safeguard mechanism (Standard Contractual Clauses, adequacy decision, derogation under Art. 49) or hides behind vague language.
Cookie and tracking disclosures
ePrivacy Directive consent requirements, CCPA opt-out signals, the cross-context behavioural advertising language CPRA 2026 introduced.
Sub-processor and recipient transparency
Whether third parties are named or described in categories specific enough that a user can identify them, not just "service providers".
Retention statements
Whether retention periods are stated per category, vaguely stated, or absent entirely.
What you'll probably see in the report.
Retention given as "as long as necessary"
Common, real, but rarely enforced for SMBs. We flag it but at low severity.
CCPA "two-method" rule violations
Email-only contact for privacy requests. Technically required to provide two methods; almost no SaaS does. Surfaced as polish, not blocker.
Cookie banner mentioned but no opt-out path
A live banner without a re-open-preferences link is a real GDPR ePrivacy gap.
Effective date over 18 months old
Worth refreshing even if the substance is fine — a stale date signals the policy is no longer maintained.
Ready to see what your policy is missing?
Paste a URL or your policy text. Get a structured gap report plus a 0–100 compliance score in around 20 seconds. Free, no signup, no email.
Questions people ask before running the audit.
Other ways people audit their policies.
Run your audit now.
Free, structured, calibrated for SMBs. Paste your URL or text and get the report in seconds.
