ePrivacy & Cookie Compliance Checks

ComplyGuard performs 11 checks related to the ePrivacy Directive and cookie regulations. These checks cover encryption, cookie consent, cookie policy content, and security headers.

Rule-Based Checks

CheckWhat We Look ForReference
HTTPS EncryptionVerifies the website is served over HTTPS with a valid SSL/TLS certificateePrivacy Directive Art. 4
Cookie Policy PageChecks for a dedicated cookie policy page or sectionePrivacy Directive Art. 5(3)
Cookie Reject ButtonVerifies that users can reject non-essential cookies as easily as accepting themEDPB Guidelines

AI-Powered Checks PRO

CheckWhat We Look ForReference
Cookie CategoriesChecks if cookies are categorized (e.g., necessary, functional, analytics, marketing)ePrivacy Directive Art. 5(3)
Cookie PurposesVerifies that the purpose of each cookie or cookie category is explainedePrivacy Directive Art. 5(3)
Cookie DurationChecks if cookie lifetimes/expiration periods are specifiedEDPB Guidelines
Third-Party CookiesVerifies that third-party cookies are disclosed with the identity of the third partyePrivacy Directive Art. 5(3)
User Control InstructionsChecks for clear instructions on how users can manage or delete cookiesePrivacy Directive Art. 5(3)

Security Headers

HeaderWhat We CheckWhy It Matters
X-Frame-OptionsChecks for DENY or SAMEORIGIN valuePrevents clickjacking attacks
Strict-Transport-Security (HSTS)Verifies HSTS header is presentForces HTTPS connections
Content-Security-Policy (CSP)Checks for a CSP headerPrevents XSS and injection attacks
X-Content-Type-OptionsChecks for nosniff valuePrevents MIME type sniffing
Security headers are checked on all plans as part of the ePrivacy scanning. AI cookie policy analysis requires a Pro or Enterprise plan.