Irish & EU Compliance

Know Where Your Website
Stands on Compliance

A documented, automated audit across GDPR, NIS2, cookie consent, data retention, third-party processors, and the European Accessibility Act — delivered as a signed PDF within minutes.

GDPR Art. 13/14 NIS2 Directive ePrivacy / PECR EAA in force Jun 2025 WCAG 2.1 AA DPC guidance
View a sample report
Run a Compliance Audit €39
  • 44 checks across 9 compliance categories
  • PDF report with findings & remediation steps
  • Delivered to your inbox within 5 minutes

Secure payment via Stripe. No subscription.

Regulations covered GDPR (EU) 2016/679 NIS2 Directive 2022/2555 ePrivacy Directive 2002/58/EC EAA Directive 2019/882 WCAG 2.1 AA DPC Guidance 2024

discoverable.ie is an automated compliance audit service for Irish and EU businesses. Submit your website URL and receive a 44-check PDF report covering GDPR, NIS2, cookie consent and the European Accessibility Act — with a scored compliance grade and prioritised remediation steps — in under five minutes.

From submission to report in under 5 minutes

The audit runs automatically against your live website. No installation, no code access, no agent required.

1

Submit your URL & pay

Enter your website address and email. Pay €39 securely via Stripe. Your report is tied to one URL per payment.

2

44 checks run automatically

Our engine fetches your homepage, privacy policy, cookie policy, and accessibility statement. Each of the 44 checks is run and scored against the relevant regulation.

3

PDF report delivered

A signed PDF report is emailed to you. It includes category scores, a risk level, individual check findings, and a prioritised remediation checklist.

44 checks, 9 compliance categories

Every check maps to a specific article, recital, or guidance document. The report cites the relevant legal basis for each finding.

GDPR — Privacy Notice

8 checks

Controller identity, lawful basis, data subject rights, retention policy, DPO details, international transfers and adequacy mechanisms.

GDPR Art. 13, 14, 37, 46 · DPC guidance

Cookie Consent

6 checks

Banner presence, consent before cookies are set, reject / decline option, cookie categories, withdrawal mechanism, and consent management platform detection.

ePrivacy Dir. Art. 5(3) · CJEU Planet49 · DPC

Subject Access Rights

4 checks

SAR contact method, 30-day response commitment, right to erasure (Art. 17), and right to data portability (Art. 20).

GDPR Art. 15, 17, 20

Breach Response

4 checks

Breach notification process, 72-hour DPC reporting obligation, security contact email, and reference to the Irish Data Protection Commission.

GDPR Art. 33, 34

NIS2 Indicators

5 checks

Security policy page, vulnerability disclosure (security.txt), HTTPS enforcement, security response headers, and security contact availability.

NIS2 Dir. 2022/2555 Art. 21

Data Retention

4 checks

Retention schedule disclosure, specific retention periods, data deletion or anonymisation process, and statutory hold provisions.

GDPR Art. 5(1)(e), 13(2)(a)

Third-Party Processors

4 checks

Sub-processor list, transfer mechanisms (SCCs / adequacy), analytics and tracking tool disclosure, and data processing agreement references.

GDPR Art. 28, 46 · Schrems II

Technical Security

5 checks

HTTPS enforcement, HSTS header, X-Frame-Options, Content-Security-Policy, and Referrer-Policy. Based on HTTP response headers.

NIS2 Art. 21 · OWASP

Accessibility (EAA)

4 checks

Accessibility statement, HTML lang attribute, image alt text coverage, and keyboard navigation / ARIA landmark indicators.

EAA Dir. 2019/882 · WCAG 2.1 AA · In force June 2025

Why compliance matters now

Irish and EU regulators are actively enforcing. A documented baseline is the first step in any compliance programme.

⚖️

DPC Enforcement Activity

The Data Protection Commission issued 24 binding decisions in 2023–24, with fines reaching €1.2 billion across EU supervisory authorities. SMEs are not exempt from enforcement.

EAA In Force from June 2025

The European Accessibility Act applies to digital products and services from 28 June 2025. Websites failing basic accessibility requirements risk complaints and enforcement by the National Disability Authority.

🔒

NIS2 Extends to More Sectors

NIS2 significantly expands the scope of cyber-security obligations to include medium-sized enterprises across more sectors. Non-compliance can result in fines of up to €10 million or 2% of turnover.

Simple, one-off pricing

No subscription. No account required. Pay per report. Suitable for one-off due diligence, client audits, or annual compliance reviews.

Compliance Audit Report

Single URL · 44 checks · PDF delivery

39+ VAT
per report
  • 44 checks mapped to GDPR, NIS2, ePrivacy, EAA and WCAG 2.1
  • Category scores with risk level (low / medium / high)
  • Individual finding detail with regulatory reference
  • Prioritised remediation checklist
  • Downloadable PDF report, valid download link for 30 days
  • Delivered to your email within 5 minutes
  • Secure payment via Stripe — card not stored
Run My Audit Now →

Need to audit multiple sites? Contact us for volume pricing.

Who uses discoverable.ie

Data Protection Officers

Verify a client or employer website against GDPR requirements. Use the report as a documented baseline before a formal audit.

Legal & Compliance Teams

Identify surface-level compliance gaps quickly. Use findings to brief management or prioritise remediation workstreams.

IT Security Consultants

Supplement technical assessments with regulatory compliance findings. Covers NIS2 and security header requirements.

Solicitors & Law Firms

Check your own firm's digital presence before a DPC inspection or client inquiry. Demonstrates due diligence.

SME Business Owners

Understand your compliance exposure without engaging a consultant for an initial assessment. Act on the remediation checklist directly.

ISO 27001 Auditors

Use the technical and NIS2 checks as part of external evidence gathering for ISMS scope and control verification.

Frequently asked questions

Is this a legal audit?
No. This is an automated scan of your publicly accessible website. It is not a substitute for advice from a solicitor or qualified data protection practitioner. The report provides a documented baseline — not a legal opinion.
What does the engine actually scan?
It fetches your homepage, privacy policy, cookie policy, accessibility statement, and security.txt. It checks HTTP response headers and analyses page content for required disclosures. It does not access source code, databases, or internal systems.
How quickly will I receive the report?
Most reports are delivered within 2–5 minutes of payment confirmation. Complex or slow-loading sites may take up to 10 minutes.
Can I audit a client's website?
Yes. You only need to provide the public URL and a delivery email. You should ensure you have client permission where required by your professional obligations.
What if the audit fails or the report is not delivered?
Contact [email protected] with your job reference and we will investigate. If the scan failed due to an error on our side, we will re-run or refund.
Does the report show the actual legal risk?
The report shows indicators based on what is publicly visible. It assigns a risk level (low, medium, high) based on the severity of findings. Only a qualified practitioner can assess actual legal risk in context.
Is my data stored?
The URL, email, and report are stored for 12 months and then deleted. We do not sell or share your data. See our Privacy Policy for full details.
Can I get a bulk discount for multiple audits?
Yes — email [email protected] with your requirements. We offer discounted rates for law firms, compliance consultancies, and DPOs auditing multiple clients.

Get your compliance report today

44 checks. PDF delivery. €39 + VAT. No subscription required.

Run an Audit →

Or view a sample report first