⚠ Sample Report — Fictional data for demonstration only. Run a real audit →
Compliance Audit Report
https://example-business.ie
Risk: MEDIUMSample Report — discoverable.ie
58%
Overall
22
Passed
12
Failed
8
Warnings
2
Skipped
44
Checks
Sample Findings — Privacy Notice (GDPR)
4 passed · 2 failed · 2 warnings | Score: 55%
PASS
Privacy Policy Exists
GDPR-001
A privacy policy page was found at /privacy-policy with sufficient content (1,842 words).
FAIL
Controller Identity Disclosed
GDPR-002
The privacy policy does not clearly identify the data controller's name and registered address as required by GDPR Art. 13(1)(a).
HIGH
💡 Add the full legal name, registered address and company number of the data controller to your privacy policy.
PASS
Lawful Basis Stated
GDPR-003
The privacy policy references a lawful basis for processing personal data.
WARN
DPO Contact Present
GDPR-007
No Data Protection Officer contact details were found. Required if your organisation processes sensitive data at scale.
MEDIUM
💡 If a DPO is required, add their name and email/postal address to the privacy policy.
FAIL
International Transfer Mechanism
GDPR-008
No reference to Standard Contractual Clauses, adequacy decisions, or other transfer mechanisms was found, despite third-party analytics tools being detected.
HIGH
💡 Disclose the legal mechanism used for any transfers of personal data outside the EEA (Art. 46 GDPR).
Sample Findings — Cookie Consent
1 passed · 3 failed · 2 warnings | Score: 28%
PASS
Cookie Banner Present
COOKIE-001
A cookie consent banner was detected on the homepage.
FAIL
Reject / Decline Option Available
COOKIE-003
No clear reject or decline button was detected on the cookie banner. Required by CJEU Planet49 ruling and DPC guidance.
CRITICAL
💡 Add an equally prominent "Reject All" or "Decline" button alongside "Accept All" on your cookie consent banner.
FAIL
No Consent Before Cookies Set
COOKIE-002
Google Analytics scripts appear to load before any consent interaction, indicating pre-consent cookie setting.
CRITICAL
💡 Implement a consent management platform that blocks all analytics/marketing scripts until the user actively accepts them.
Sample Findings — Technical Security
3 passed · 1 failed · 1 warning | Score: 65%
PASS
HTTPS Enforced
TECH-001
The website correctly redirects to HTTPS and the final URL is served over a secure connection.
PASS
HSTS Header Present
TECH-002
Strict-Transport-Security header is set with max-age=31536000.
FAIL
Content Security Policy
TECH-004
No Content-Security-Policy header was found. This increases the risk of cross-site scripting (XSS) attacks.
HIGH
💡 Implement a Content-Security-Policy header. Start with a report-only policy to identify violations before enforcing.
Run Your Own Audit
Get a full 44-check report for your website in under 5 minutes.
This site uses only strictly necessary cookies — session management and payment processing (Stripe). No analytics or advertising cookies are used.
Cookie Policy