Running Compliance Scans
Test how your live site handles consent: choose jurisdictions and checks, run a Compliance Scan once or on a schedule, and turn failed checks into tasks.
Overview
A Compliance Scan loads your live site the way a visitor would and tests how it actually behaves: whether trackers fire before consent, whether rejecting really stops them, whether the site honors Global Privacy Control, and more. Choose the jurisdictions you care about, and each scan loads your site from that region, so it sees the consent experience a visitor there would see.
Compliance Scans are available on paid plans. If you don't see Compliance Scan in the Actions catalog, contact us to turn it on for your organization.
Setting Up a Compliance Scan
- Go to Actions → Browse Catalog and choose Compliance Scan.
- Choose the domain or subdomain to scan.
- Choose one or more jurisdictions.
- Choose which checks to run. Checks a jurisdiction requires are turned on for you.
- Run the scan once, or set it to run on a schedule.
Jurisdictions
- California (CCPA/CPRA)
- European Union / UK (GDPR)
- United States (General)
- Canada (PIPEDA)
- Brazil (LGPD)
- India (DPDPA)
Checks follow the jurisdiction. Under opt-in regimes like GDPR, tracking before consent is a failure. Under opt-out laws like CCPA/CPRA, it's advisory.
Checks
- Pre-consent tracking: checks whether non-essential trackers fire before the visitor gives consent.
- Global Privacy Control: sends a GPC signal and checks that the site treats it as an opt-out, as several state laws require.
- Choice symmetry: checks that rejecting is as easy as accepting, with no dark-pattern imbalance in the banner.
- Reject efficacy: after the visitor rejects, checks that non-essential trackers actually stop firing.
- Privacy policy freshness: finds the linked privacy policy and checks that it was updated in the last 12 months.
- Data-subject request intake: scans the policy for a way to exercise data rights, such as a form, an email address, or an account page.
- Consent-state mismatch: checks that observed tracking matches the consent the visitor actually granted.
- Do Not Sell or Share (CCPA): checks for a working Do Not Sell or Share opt-out, as CCPA/CPRA requires.
- Third-party tracking (CIPA): checks whether third-party pixels or session replay send data before consent.
Reading Results
Each run appears in the Activity list under Actions. Expand a run to see:
- An overall Risk level of Low, Medium, or High, based on the problems found.
- Each check's result: Pass, Fail, or Inconclusive when there isn't enough evidence to call it. A check can also show Not applicable for the jurisdiction, or Disabled if you turned it off for this scan.
- For each check, what was checked, what was found, and how to fix it.
Turning Failures Into Tasks
On any failed check, click Create task to open a task for the fix, so it stays on your team's list until it's resolved.
Cost
Each scan uses 2,500 Actions plus up to 50 Data Credits for each jurisdiction it covers. If the scan can't load your site at all, it isn't charged. See Actions and Data Credits.