Use the tool
Privacy-conscious: this tool runs in your browser where practical, so your working input stays on your device unless the page explicitly says otherwise.
1. What does your website use or collect?
Select everything that applies. These choices determine which safeguards are relevant to the score.
2. What safeguards do you have in place?
Choose Not sure when you have not verified an item. The checker will treat uncertainty as something to review.
Privacy readiness result
Priority actions
Items to verify
Good signals
Triggered review areas
Important: this score is a planning aid based only on your answers. It does not determine which privacy laws apply to your organization and it does not certify compliance. Verify important requirements for your business, audience and jurisdictions.
What this tool does
Use this browser-based privacy readiness checker to review common website data practices such as contact forms, analytics, advertising pixels, email marketing, third-party embeds, privacy notices, cookie controls and user-rights processes. The result is a practical self-assessment, not legal advice or a certification of compliance.
Privacy obligations depend on what a website actually collects, which technologies it uses, where its visitors are located and which laws apply. A simple brochure site can have a very different risk profile from an ecommerce or advertising site. This checker therefore starts with your website activities, then evaluates the safeguards you say are in place. It does not inspect your website automatically and it cannot determine every legal requirement for your business.
Useful for
- Create a quick privacy-readiness snapshot before launching or reviewing a website.
- Identify missing policies, cookie controls, data-rights processes or vendor disclosures that deserve a closer look.
- Compare privacy practices across client websites using the same checklist.
- Prepare a focused list of questions for a privacy professional or compliance service.
How to use it
- Select the activities and data practices that apply to your website.
- Answer the safeguard questions with Yes, No or Not sure.
- Run the check to calculate a readiness score based only on the items triggered by your answers.
- Review the priority actions and verify important requirements against the laws and regions that apply to your organization.
Worked examples
Lead-generation website
InputContact form + analytics + email newsletter
ResultPrivacy notice, analytics/cookie controls, marketing consent/unsubscribe, vendor disclosures and a rights-request process become important review items.
The checker adapts the review to the activities you select instead of applying every question equally.
Simple informational site
InputNo accounts, no ads, no newsletter; only basic hosting
ResultA lower-complexity result with fewer triggered controls, while still recommending verification of hidden data flows and a current privacy notice where appropriate.
Server logs, embedded services or hosting features can still create data flows that are not obvious from the page design.
Common mistakes to avoid
- Copying another website’s privacy policy without checking whether it matches the services, vendors and data flows actually used.
- Installing analytics, advertising pixels or embedded widgets without reviewing what they store or transmit.
- Treating a cookie banner as proof of full privacy compliance; policies, rights handling, vendor management and retention can matter too.
- Assuming a website has no privacy obligations simply because it does not sell products or require user accounts.
Before you use the result
- Confirm the technologies actually loaded on the live website, including analytics, advertising tags, chat widgets, embedded media and form services.
- Check that published policies name or describe the real categories of data, purposes and third parties used by the site.
- Test privacy choices and consent controls in a fresh browser session rather than relying on how the site behaves for an administrator.
- Document who receives privacy requests and how deletion, access, correction or opt-out requests are handled when applicable.
Edge cases and limitations
- Privacy laws vary by jurisdiction, business size, data type, audience and activity; a self-assessment score cannot determine legal applicability.
- Third-party scripts can change their behavior or add new cookies after an update, so a one-time review can become outdated.
- Children’s data, health information, precise location, financial information and other sensitive data can require additional safeguards beyond this general checklist.
- Consent requirements and opt-out mechanisms differ across regions, so a single global banner or policy may not satisfy every situation.
Practical tips
- Start with an inventory of forms, cookies, analytics, ad pixels, embedded services and account features before drafting policy language.
- Keep privacy notices aligned with what the website actually does, and review them when tools or vendors change.
- Use the Not sure option honestly; uncertainty is useful because it identifies something that should be verified rather than guessed.
- Treat the score as a planning aid, not a legal conclusion. For important compliance decisions, use qualified legal or privacy advice for the regions that apply to you.
Frequently asked questions
Does a high score mean my website is legally compliant?
No. The score is a self-assessment based on the answers you provide. It is designed to surface common gaps, not to certify legal compliance.
Does ToolsDiary scan my website or collect my answers?
No. This version is a browser-based questionnaire. Your selections are evaluated locally in the page and are not sent to ToolsDiary by the checker.
Do I need a privacy policy if I only have a contact form?
A contact form can collect personal information such as names, email addresses and message content. Whether a particular notice is legally required depends on the laws and circumstances that apply, but documenting what you collect and why is a sensible review item.
When should I review cookie consent?
Review it when the site uses analytics, advertising, personalization or third-party technologies that store or read information on a visitor’s device. The exact consent or opt-out requirement depends on the applicable jurisdiction and technology.
What should I do with a Not sure result?
Treat it as a verification task. Check your website code, tag manager, plugins, vendor settings and policies, or ask the person responsible for the site before marking the item complete.