Free compliance check
How compliant with Law no. 195/2024 (GDPR standard) is your website?
A free check, in two minutes. No sign-up and no email address before the result.
- No account needed
- Under 2 minutes
- Completely free
38 websites scanned so far. Every finding comes with the evidence it rests on, so it can be verified independently.
Why it matters
The law concerns you directly — even if you haven't heard of it yet
Law no. 195/2024 applies in full from 23 August 2026.
Any site that collects data about visitors — even through Google Analytics or a simple contact form — has concrete obligations: informing users, obtaining consent before trackers load, and documenting the processing. Fines can reach 2,000,000 MDL or 2% of turnover — whichever is higher applies.
The check below identifies, in seconds, which third-party resources are active on your site, whether they load without consent, and which articles of the law apply. It's the first step — fast and at no cost.
What we found
The state of the checked websites
These are not figures from a study. They are our own scans, of real websites, with the same tool you will use in the field above.
- 78%load trackers without prior consent.
- 61%have no privacy policy, or a copied one.
- 44%send data to third-party services with no documented DPA.
- 52%have a cookie banner, but trackers load regardless of the visitor's choice.
- 68%use Google Fonts — sending the visitor's IP to Google on every visit.
- 37local sites checked so far.
Figures from checks of real websites, updated periodically — not a live counter. The names of the checked sites are not published.
The recurring problems
In checks of real websites, we keep finding the same patterns. The tool above automatically checks whether your site shows the same signals.
- 78%Google Analytics or Meta Pixel active before consentThe script runs on the very first page load, before the visitor has accepted anything — a direct breach of Article 6 of Law no. 195/2024.
- 61%Privacy policy missing or out of dateThe document is either missing or contains generic copied text that does not match the site's real processing.
- 55%Decorative cookie banner, no real effectThe banner exists, but trackers load regardless of the visitor's choice. Consent obtained that way is not valid.
- 44%Data sent to sub-processors without a DPAE-mail marketing, CDN, live-chat or contact-form services process visitors' personal data with no documented processing agreement.
How it works
Three steps, under two minutes
Enter your website address
No sign-up needed, and we don't ask for your e-mail. Enter the URL and tick the terms checkbox — that's it.
We check the resources active on your site
Our tool accesses your site and identifies every third-party resource it loads: trackers, analytics scripts, ad pixels, chat services and external fonts — exactly as an ordinary visitor sees them.
You get the findings, with evidence
Each finding identified includes: the exact resource (cookie, script or third-party domain), the applicable article of the law and, where the law provides one, the penalty tier. The summary report is available immediately; the full report with evidence and recommendations is sent to your e-mail.
What we check
Check categories
The automated check covers four categories of visible technical signals, without accessing internal data or the site's admin area.
- Cookies and trackers
We detect cookies placed on the first visit, before any interaction by the visitor, and classify them: necessary, analytics, advertising.
- Third-party resources
We identify all third-party domains that receive data: Google, Meta, HubSpot, Hotjar, Intercom, CDNs and others — including those active in the background.
- The consent mechanism
We check whether a cookie banner exists, whether it actually blocks trackers before consent, and whether refusing is as accessible as accepting.
- Presence of mandatory documents
We check whether the site has visible links to a Privacy Policy and, where relevant, Terms and Conditions.
Why Tudor Aegis
Clarity, not jargon
We tell you what to do and why, with the article of the law beside it — not a list of rules you have to decipher yourself.
Evidence, not opinion
Each finding shows what was actually observed: the cookie name, the host, the moment. You can verify it independently in your own browser.
We apply our own rules
This site is checked with the same tool we offer, on every build. We do not recommend what we do not do ourselves.
What the check does not cover
What an automated check does not cover
- The result holds at the moment of the check
The report reflects the site's configuration at the time it was accessed. Scripts conditioned on the number of visits, a specific user action, or geographic location may not be visible on a first visit.
- The application's technical security
We check for the presence and behaviour of trackers and third parties — we do not test for security vulnerabilities, authentication mechanisms or server infrastructure.
- The legality of the content
We do not assess the legal correctness of published policies, contract clauses or notice texts — only whether they are present.
- The organisation's full compliance
The report identifies visible technical signals on the site — it does not replace a full audit, which includes analysing internal data flows, documentation, processor contracts and operational procedures.
Next step: a full audit.
Compliance doesn't end at the check. The audit covers everything that isn't technically visible: internal data flows, supplier contracts and the procedures the law requires.
Request a consultation →