The only audit scanner that tracks the EU regulatory clock
GDPR + Schrems II (in force since 2020), EAA accessibility (in force since 28 June 2025), AI Act §50 (in force 2 August 2026), plus CCPA and WCAG 2.1 AA — all in one scan. Built and operated by a Danish company subject to the same regulatory clock.
No credit card required · Free first scan · Not legal advice — we surface what auditors check first.
Four EU regulatory layers, one scan
Every check maps to a specific regulation, cites the article, and includes the fine or enforcement risk.
Privacy, cookie consent & US transfers
- ✓Tracking scripts loading before consent
- ✓Missing or inadequate cookie consent banner
- ✓AI analysis: does your privacy policy cover GDPR rights?
- ✓Undisclosed tracking services in the policy
- ✓Schrems II: US subprocessors detected (GA, Stripe, OpenAI) without SCC disclosure
- ✓Missing DPO / controller contact + data retention
Required legal documents
- ✓Missing Terms of Service page
- ✓Missing Cookie Policy (distinct from privacy policy)
- ✓Missing imprint / legal notice (EU/DE requirement)
- ✓No CCPA "Do Not Sell My Personal Information" link
- ✓No visible contact email (GDPR Art. 13 requirement)
- ✓Privacy policy link reachability
EU Accessibility Act + WCAG 2.1
- ✓Accessibility statement published (EAA Article 13)
- ✓Viewport meta blocking pinch-zoom (WCAG 1.4.4)
- ✓Images missing alt text across site
- ✓Form inputs without visible labels
- ✓Buttons with no accessible name
- ✓Inline SVGs without title or aria-label
AI-content disclosure (Aug 2026)
- ✓AI-generated content lacks visible disclosure
- ✓Missing structured-data markup for AI content
- ✓AI-assistant leak phrases ("as an AI language model")
- ✓AI-translated content without disclosure
- ✓Heuristic content analysis flags likely-AI pages
- ✓Cross-check with sitewide AI-content policy
We read your policy — not just its URL
Most compliance checkers verify a privacy policy exists. Seoxpert sends it to AI and checks whether the content actually covers what your site does.
Privacy policy quality analysis
We find your actual privacy policy, read it, and check whether it mentions the specific tracking services you run — not just whether a policy page exists.
Gap detection vs. your actual setup
We cross-reference what your policy says against what's actually loading on your site. A policy that doesn't mention Google Analytics when you're running it is a GDPR violation.
Plain-English explanations
Every compliance finding includes a concrete fix, the specific regulation it relates to, and the fine range — no legal jargon.
Scan your site for compliance gaps now
Free scan — GDPR, CCPA, legal pages, accessibility, and 14 other categories checked in one pass.