Most sites are compliant the day they are checked and quietly broken a month later. ComplianceKit rescans yours on a schedule and emails you when your compliance score drops.
Anyone can tell you whether your site is compliant today. ComplianceKit is built to still be checking next month.
Set your site to rescan every week or every month. You do nothing — the scan runs on its own and the result lands in your dashboard.
When a rescan finds your compliance score has dropped, we email you the before-and-after score and a link straight to the scan. That is the whole point of the product.
We load your site in a real browser and record every cookie and tracking script that actually fires — including the ones that only appear after consent.
A customisable consent banner that installs with one line of code, speaks 24 EU languages, and keeps a record of every consent choice your visitors make.
Privacy and cookie policies written from your real scan results, plus an embeddable request form and tracked workflow for access and deletion requests.
Scans, consent records and policy versions are timestamped and kept for your plan's retention window — the dated history a regulator asks for, not one afternoon's snapshot.
Setup takes an afternoon. Step four is the one you never have to think about again.
Enter your URL. We load the site in a real browser and record every cookie and tracker that actually fires.
We draft privacy and cookie policies from your real scan results and your jurisdiction. You review and publish.
Add the consent banner with a single line of code, or install the WordPress plugin. No developer needed.
Pick weekly or monthly rescans. If your compliance score drops, you get an email telling you what changed.
Every paid plan includes scheduled rescans and score-drop alerts — you are paying for the watching, not for one report. Start on the free plan, cancel any time.
Perfect for small websites and blogs
For growing businesses with multiple websites
For large organizations with advanced needs
Everything you need to know before getting started. Still curious? Reach out any time.
A tool that keeps watching your website after you have made it compliant. It scans for cookies and trackers, generates your policies, serves your consent banner and handles subject requests — then rescans on a schedule and tells you when something breaks. It is built for business owners, not lawyers or developers.
That is exactly the problem it solves. Your site does not stay still — you add a marketing pixel, a plugin updates, an agency drops in a chat widget, and cookies appear that your policy never mentioned. ComplianceKit rescans every week or month, compares against your last result and emails you when your compliance score drops. The first scan is the setup; the monitoring is the product.
It can give you an opinion today. It will not be watching your site next Tuesday when a plugin update adds a tracker, it will not serve a consent banner to your visitors, it will not keep a dated record of who consented to what, and it will not be there in eighteen months when someone asks you to prove you were compliant on a particular date. Those are the parts that actually take the work off you.
No. It helps you understand your obligations and generate the standard documents most websites need, but it is not a law firm and does not provide legal advice. For complex situations or formal sign-off, consult a qualified lawyer.
No honest tool can guarantee that — compliance depends on how you actually handle data. What ComplianceKit does is catch the gaps most sites miss (undisclosed cookies, missing policies, no consent banner) and give you accurate documents and a compliant banner, so you are far better protected than doing it alone.
GDPR (EU/EEA), the UK GDPR, POPIA (South Africa), CCPA/CPRA (California), LGPD (Brazil) and other major privacy regimes, with jurisdiction-specific detection built in.
It loads your site in a real browser and records every cookie and tracking script that actually fires — including third-party and post-consent cookies — not just a guess from your page source.
No. Add your website, run a scan, generate your policies, and drop in the consent banner — a single line of code. Setup takes minutes.
Yes — both are available as a lightweight embed you can drop onto any website, and there is a WordPress plugin that deploys them without touching code.
They are generated from your real scan data and tailored to your site, and you review and approve every policy before it goes live — nothing publishes automatically.
Core data is hosted in the EU (database in Ireland, application in the Netherlands), encrypted in transit and at rest, with data processing agreements in place with every service provider we use.
Yes, and we can show our work. We host in the EU, we offer a data processing agreement you can sign online, we publish our sub-processors, and we have formally appointed a representative in Ireland under Article 27 GDPR and Article 27 UK GDPR — with a registered DSA legal representative too. A privacy tool that has not done its own homework should not be trusted with yours.
Yes — plans scale from a single site up to unlimited, so you can manage all your properties from one account.
Yes — the dashboard and generated policies support all 24 official EU languages, plus others.
Yes. Plans are month-to-month with no lock-in, and you can cancel from your dashboard whenever you like.
If the answer is "a while ago", find out now. Free plan, no credit card, no legal expertise required.