Most of a privacy health check, automated
Not long ago, finding out whether your website complied with the GDPR meant hiring people. A lawyer and a technically-minded colleague would spend the better part of a week going through the site by hand. Listing every third party each of the most popular pages loads, every cookie set before anyone clicked accept, every request quietly heading off to a server in the United States. Then they'd prioritise it, write it up, and hand you a report. It was genuinely useful work, but it was also a photograph, taken once, for a five-figure fee.
Most of that week was not legal reasoning. It was discovery, the tedious and repetitive inventory work a machine does faster, cheaper, and without skipping the four-hundredth page out of boredom.
What a GDPR discovery pass really involves
Strip a privacy health check down and the bulk of it is finding and counting things:
- Which third-party domains your pages contact, from analytics and fonts to embedded video, chat and marketing tags.
- Which cookies are set before consent, and what each one is for.
- Which known trackers are present, and which pages use local storage.
- Where visitor data is leaving the EU, usually to a US endpoint.
- The state of your TLS version and security headers.
None of that needs a legal opinion to gather. It needs patience and coverage, on every page rather than just the homepage. Which is precisely what Webperf Audit does, on every page, using our headless-Chromium Webbkoll fetcher. It assembles the same inventory a consultant used to build by hand, and hands you the complete result as data you own outright.
The photograph problem
A one-off health check carries a built-in flaw since it starts ageing the moment it's delivered. The tracker that lands you in trouble usually isn't on the homepage the auditor checked. It's added to a campaign landing page six weeks later, by someone in a hurry, long after the consultant has invoiced and gone. The report can't see it, because the report was a moment and your website is a stream.
Continuous auditing catches that new third party the week it appears, while the person who added it still remembers why. The engagement bought you a single snapshot; the tool keeps the running record. That difference is the whole reason privacy checks belong on a schedule, not in a folder.
The analytics question, specifically
The other thing organisations reach for consultants about is web analytics. Google Analytics has spent years in legal weather. Regulators in Austria, France and Italy each ruled its use unlawful in 2022 over how it sent visitor data to the United States, and Sweden's IMY later fined companies on the same grounds. The footing under those transfers keeps shifting as one framework is struck down and the next is built: Safe Harbour, then Privacy Shield, now the Data Privacy Framework. The question doesn't disappear outside the EU, it changes shape. The UK runs its own adequacy assessment, and under Australia's APP 8 and Canada's accountability principle the sender stays responsible for the data after it leaves. It's genuinely confusing, and it's the sort of thing people book a webinar to make sense of.
But the first practical step is always the same, and it isn't legal. Know what you load. Before you can decide whether a US transfer is lawful, you have to establish that it's happening at all. The audit answers which of our pages set cookies before consent, and which ones phone home to Google, or to any other endpoint outside the EU?
with a per-page list rather than a guess. That diagnosis is what the entire analytics debate rests on, and it's what a tool produces in minutes.
Where the tool stops, on purpose
Two parts of the old engagement stay firmly human, and no tool should claim otherwise.
- The first is judgment. Whether a specific transfer is lawful under today's framework, whether your consent wording is adequate, whether your data-processing agreements genuinely cover you, these are calls for someone who reads law for a living. A scan can prove a tracker fires before consent, but it can't tell you your legal exposure. The conclusions stay yours to draw, or your lawyer's.
- The second is the fix. Migrating off Google Analytics to an EU-hosted, privacy-respecting alternative such as Matomo, gating trackers behind real consent, self-hosting your fonts, none of that happens by observing it. The audit points at the work, but people still do it.
What that leaves you with
So the privacy health check doesn't vanish. It changes shape. The expensive, repeatable majority of it, the discovery, the inventory, the prioritised technical findings, collapses into something that runs every day for the price of a subscription. The scarce human hours stop being spent finding the problem and start being spent where they earn their keep. Like weighing the risk and repairing it. And when you do bring in a lawyer, you can point them at a live, exportable audit instead of a PDF that went stale the month it was written.
This is the same division of labour we keep returning to. The tool does the tireless counting, but people do the thinking. Privacy is simply a case where the counting used to cost a great deal, and the thinking got buried underneath it.
The traditional health check was a good idea trapped in an expensive, one-time format. Most of what made it valuable, a complete and current picture of what your site really does with your visitors' data, is exactly the kind of work software should carry. Keep your people for the parts that need a person. Let the tool do the crawling.
The cookie and third-party audit is included in every plan, and Webperf Audit runs the full privacy check across every page. See the plans, or email hello@webperf.cloud.