GDPR compliance coverage
We scan SaaS websites against 9 automated checks across 7 GDPR articles. Each article below maps to the specific website-level signals we test.
Principles relating to processing of personal data
The foundational principles — data minimization, purpose limitation, accuracy, and integrity — that govern all lawful personal-data processing.
Lawfulness of processing
Requires a valid lawful basis (consent, contract, legitimate interest, etc.) before any personal data is processed.
Conditions for consent
Defines what constitutes valid consent — freely given, specific, informed, unambiguous — and that pre-ticked boxes do not count (Planet49 ruling).
Information to be provided where data collected from the data subject
Mandatory disclosures when collecting personal data directly — identity of controller, processing purposes, legal basis, retention period, data subject rights, and cross-border transfer safeguards.
Right to erasure ('right to be forgotten')
Data subjects can request deletion of their personal data. A SaaS without a working deletion path is a compliance defect.
Processor obligations
When a SaaS shares user data with third-party processors (analytics, email, payments), a written Data Processing Agreement is required.
Security of processing
Mandates appropriate technical and organizational measures — encryption, access control, secrets management — proportional to risk.
Run a scan on your site
See all 9 checks evaluated against your actual website in 60 seconds.
Scan free →