Most of a privacy health check, automated

Not long ago, finding out whether your website complied with the GDPR meant hiring people. A lawyer and a technically-minded colleague would spend the better part of a week going through the site by hand. Listing every third party each of the most popular pages loads, every cookie set before anyone clicked accept, every request quietly heading off to a server in the United States. Then they'd prioritise it, write it up, and hand you a report. It was genuinely useful work, but it was also a photograph, taken once, for a five-figure fee.

Most of that week was not legal reasoning. It was discovery, the tedious and repetitive inventory work a machine does faster, cheaper, and without skipping the four-hundredth page out of boredom.

What a GDPR discovery pass really involves

Strip a privacy health check down and the bulk of it is finding and counting things:

None of that needs a legal opinion to gather. It needs patience and coverage, on every page rather than just the homepage. Which is precisely what Webperf Audit does, on every page, using our headless-Chromium Webbkoll fetcher. It assembles the same inventory a consultant used to build by hand, and hands you the complete result as data you own outright.

The photograph problem

A one-off health check carries a built-in flaw since it starts ageing the moment it's delivered. The tracker that lands you in trouble usually isn't on the homepage the auditor checked. It's added to a campaign landing page six weeks later, by someone in a hurry, long after the consultant has invoiced and gone. The report can't see it, because the report was a moment and your website is a stream.

Continuous auditing catches that new third party the week it appears, while the person who added it still remembers why. The engagement bought you a single snapshot; the tool keeps the running record. That difference is the whole reason privacy checks belong on a schedule, not in a folder.

The analytics question, specifically

The other thing organisations reach for consultants about is web analytics. Google Analytics has spent years in legal weather. Regulators in Austria, France and Italy each ruled its use unlawful in 2022 over how it sent visitor data to the United States, and Sweden's IMY later fined companies on the same grounds. The footing under those transfers keeps shifting as one framework is struck down and the next is built: Safe Harbour, then Privacy Shield, now the Data Privacy Framework. The question doesn't disappear outside the EU, it changes shape. The UK runs its own adequacy assessment, and under Australia's APP 8 and Canada's accountability principle the sender stays responsible for the data after it leaves. It's genuinely confusing, and it's the sort of thing people book a webinar to make sense of.

But the first practical step is always the same, and it isn't legal. Know what you load. Before you can decide whether a US transfer is lawful, you have to establish that it's happening at all. The audit answers which of our pages set cookies before consent, and which ones phone home to Google, or to any other endpoint outside the EU? with a per-page list rather than a guess. That diagnosis is what the entire analytics debate rests on, and it's what a tool produces in minutes.

Where the tool stops, on purpose

Two parts of the old engagement stay firmly human, and no tool should claim otherwise.

What that leaves you with

So the privacy health check doesn't vanish. It changes shape. The expensive, repeatable majority of it, the discovery, the inventory, the prioritised technical findings, collapses into something that runs every day for the price of a subscription. The scarce human hours stop being spent finding the problem and start being spent where they earn their keep. Like weighing the risk and repairing it. And when you do bring in a lawyer, you can point them at a live, exportable audit instead of a PDF that went stale the month it was written.

This is the same division of labour we keep returning to. The tool does the tireless counting, but people do the thinking. Privacy is simply a case where the counting used to cost a great deal, and the thinking got buried underneath it.

The traditional health check was a good idea trapped in an expensive, one-time format. Most of what made it valuable, a complete and current picture of what your site really does with your visitors' data, is exactly the kind of work software should carry. Keep your people for the parts that need a person. Let the tool do the crawling.


The cookie and third-party audit is included in every plan, and Webperf Audit runs the full privacy check across every page. See the plans, or email hello@webperf.cloud.