● The most thorough GDPR compliance checker on the market
Ask an AI about this site
See how the major AI systems describe this site — and whether they cite it as a source.
Free-to-try rollout — no account needed
Free to try right now — no account:
More audits are being opened up to try free — this keeps growing.

GDPR Audit and Markdown Generator. Two tools, one URL.

Paste a URL and get two things instantly: a full GDPR compliance read — cookie consent, privacy policy, third-party scripts and data processor disclosures — plus a clean, spec-compliant Markdown export of the page, ready for llms.txt or AI ingestion.

100 free points for new accounts · PAYG from £4.99 or subscribe from £14.99/mo · Credits never expire

20+
GDPR signals checked per run
PECR
cookie consent rules verified
Free
GDPR compliance check
£4.99
pay-as-you-go — or subscribe from £14.99/mo
Why it matters

Compliance risk and unreadable content cost you in different ways

A non-compliant cookie banner loads tracking scripts before consent — that is an ICO enforcement risk. And a page AI agents can't cleanly parse is a page they can't cite. The GDPR Audit finds what exposes you legally; the Markdown Generator finds what's keeping AI from reading you properly.

🍪

GDPR Audit finds what exposes you

Most sites load tracking scripts before consent is given. The GDPR Audit detects every third-party script, checks your consent banner fires first, and flags a missing or incomplete privacy policy before it becomes an ICO problem.

📝

Markdown Generator makes you AI-readable

Converts any page into clean, spec-compliant Markdown — strips navigation and styling, keeps the real content, ready for llms.txt or direct AI ingestion. Tested and working across WordPress, Shopify, Wix, Squarespace, Webflow and more.

🎯

Two problems, one URL, one run

GDPR compliance risks are ranked by ICO enforcement risk. Markdown output is scored on completeness and structure. No spreadsheets, no cross-referencing — a clean result for each, from the same page fetch.

You stay in control

Flagged as a warning? Reprioritise it to Critical.

The GDPR Audit automatically ranks every issue by likely compliance risk. But you're not locked into its call. Know that a specific script firing before consent is your biggest exposure right now? Bump it above everything else and the fix list reorders around it.

Flagged as low-priority but it's actually a real ICO risk for your business? Reclassify it as Critical. The audit rebuilds your prioritised fix list from your real page data, always accurate to your site.

Issue priority
Auto-detectedWarning
↓ you reprioritise toCritical ✓
Rebuilt withimpact score · fix order
Resultprioritised fix list ✓
Free GDPR audit

Find every compliance gap and export clean Markdown — free

The GDPR Audit reads your live page the way a data protection officer would. The Markdown Generator reads it the way an AI agent would. Both run from the same URL, free, no account required.

  • Detects third-party scripts firing before consent
  • Checks your privacy policy is present and complete
  • Converts headings, text and structured data to Markdown
  • Tells you exactly what to add or fix, ranked by risk
Cookie consent bannerpresent ✓
Analytics script timingloads before consent
Privacy policyfound ✓
Meta Pixelfires before consent
Markdown exportgenerated ✓
Contact informationpresent ✓
Cookie consent · PECR

Consent has to be genuine, not just present

A cookie banner existing isn't the same as being compliant. Under GDPR and the UK PECR, consent must be freely given, specific, informed and unambiguous — no pre-ticked boxes, no reject option buried three clicks deep. The GDPR Audit checks not just whether a banner exists, but whether it actually works the way the law requires.

  • Checked directly against your live page's actual behaviour
  • Verified against current GDPR and PECR requirements
  • Highlights every script that fires before consent
  • Covers reject options, not just accept buttons
Consent check
# Consent mechanism
> Banner present, reject option buried ⚠
# Script timing
> 2 scripts fire before consent ⚠
# What we check
Real behaviour of your page,
not just banner presence.
Checked against
✓ GDPR requirements ✓ UK PECR ✓ ICO guidance ✓ Consent timing ✓ Script detection
Markdown · llms.txt spec

A real conversion, not a text dump

Stripping HTML tags isn't enough to make a page AI-readable. The Markdown Generator reads the page the way a browser renders it, keeps every real heading at its correct level, pulls in content that only exists in JavaScript-injected lists or schema.org JSON-LD, and discards navigation, scripts and styling that add nothing for an AI system to read.

  • Checked directly against the page's real, rendered structure
  • Every H1–H6 heading preserved at its correct level
  • Content in JSON-LD schema and JS-injected lists included
  • Navigation, scripts and styling stripped, not just tags removed
Conversion check
# Heading structure
> 10 H2, 30 H3 — all preserved ✓
# Schema data
> Slogan, keywords, HowTo steps found ✓
# What we check
Real page structure,
not just stripped HTML.
Tested and working on
✓ WordPress ✓ Shopify ✓ Wix ✓ Squarespace ✓ Webflow
Full GDPR coverage

Not just cookies — the whole compliance picture

The GDPR Audit covers every layer of compliance that matters to the ICO and to visitor trust: consent, privacy, data processors and technical implementation.

🍪

Cookie consent

Banner presence, consent mechanism implementation, whether non-essential scripts fire before consent, and whether a genuine reject option is available without buried settings.

🔏

Privacy policy

Presence and accessibility from every page, required disclosures (data collected, purpose, retention, sharing, rights), and whether it covers every third-party processor in use.

📋

Data processors & scripts

Every third-party script detected and identified — analytics, pixels, chat, maps — with a check on whether each is declared in the privacy policy and whether it fires before or after consent.

20+ compliance checks

One tool, every compliance signal that matters

The GDPR Audit covers every factor that determines real compliance risk — from consent mechanics to policy content to technical implementation.

Consent mechanics

Banner presence · genuine reject option · pre-ticked box detection · consent granularity by script category

Script timing

Analytics, advertising and chat scripts checked for whether they fire before or after consent is given

Privacy policy content

Presence and linkage from every page · required disclosures · retention periods · third-party sharing statements

Data processor declarations

Every detected third-party processor cross-checked against what's actually disclosed in the privacy policy

Contact & trust signals

Contact information presence · data controller identification · rights request process visibility

Technical implementation

Cookie categorisation · consent management platform detection · script-blocking verification before consent

How the conversion works

One tool, every content signal that matters

The Markdown Generator covers every layer that determines whether a page's real content is actually captured — from heading structure to schema data to platform quirks.

Heading structure

Every H1–H6 walked in document order and preserved at its correct level, including headings nested inside spans or other inline tags

Schema data

Organization slogan, expertise, keywords and HowTo steps pulled directly from a page's own JSON-LD, not just the visible text

JS-injected content

Lists and data that only exist in JavaScript arrays at runtime — not static HTML — detected and included where present

Metrics & callouts

Stat blocks and key numbers pulled from their real page markup, not left out because they sit outside normal paragraph tags

Platform compatibility

Tested against real WordPress, Shopify, Wix, Squarespace, Webflow, Drupal, Ghost, BigCommerce and HubSpot pages, not just a single template

Filename & scoring

Output filename derived from the real page path, with a completeness score based on content length, heading presence and structure

How it works

URL in, fix list out — in minutes

Paste your URL

The tool fetches your live page, scans every third-party script, and checks your consent banner's real behaviour.

Run the GDPR Audit

Get a full compliance report covering consent, privacy policy, data processors and script timing.

Fix by priority

Work through Critical issues first — each explained in plain English with the exact fix, ranked by compliance risk.

Want the full detail? See how it works →
PAYG from £4.99
pay-as-you-go · no commitment · credits never expire
or subscribe from £14.99/mo
for regular users · cancel anytime
See all pricing
FAQ

Frequently asked questions

Straight answers about what the GDPR Audit and Markdown Generator check, what they cost, and how to use what they find.

What does the Markdown Generator do?

It converts any public page into clean, spec-compliant Markdown — stripping navigation, scripts and styling while keeping the real content, headings and structured data. The output follows the llms.txt v2 specification, ready to save as a page's .md companion file or feed directly to an AI system.

Is the Markdown Generator free?

Yes. A free scan is available with no account required. Logged-in users get it included on Silver plans and above, or pay-as-you-go from £0.99 otherwise.

What content management systems does the Markdown Generator work with?

It's been tested and confirmed working on WordPress, Shopify, Wix, Squarespace, Webflow, Drupal, Ghost, BigCommerce and HubSpot CMS. It works with any publicly accessible URL — no plugin or integration required.

How much does the Markdown Generator cost?

Pay-as-you-go from £0.99 per page, or included free on Silver subscription plans and above. New accounts get free trial points, and credits never expire.

What is the most common reason a Markdown export comes out incomplete?

Content that only exists inside JavaScript-rendered elements or a page's schema.org JSON-LD — not the static HTML — is the most common gap, since a simple scraper never sees it. The Markdown Generator reads both the rendered content and structured data so nothing real is left out.

Can I generate a Markdown export of a competitor's page?

Yes — the Markdown Generator works with any publicly accessible URL. Use it to see exactly how AI-readable a competitor's page is compared to your own.

Do I need an llms.txt file if I already have a sitemap?

Yes, they serve different purposes. A sitemap lists every URL for search engine crawlers. An llms.txt file, built from Markdown exports, gives AI systems a curated, plain-text summary of your key pages — something a sitemap doesn't provide.

How often should I regenerate a page's Markdown export?

Whenever the page's content changes significantly — the same discipline as re-running any audit. A stale Markdown export can mislead an AI system about what your page currently says.

What counts as AI-ready content?

Content that's readable without a browser rendering JavaScript: real headings, real paragraphs, real lists, and structured data that matches what's visible on the page. The Markdown Generator produces exactly that from any live URL.

Can poor AI-readability affect whether I'm cited by ChatGPT or Perplexity?

Yes. AI answer engines are more likely to cite pages they can parse confidently. A page buried in navigation and scripts, with no clean Markdown or llms.txt equivalent, is harder for an AI system to extract and trust as a source.

What is the difference between a Markdown export and an llms.txt file?

A Markdown export is the clean, converted version of a single page. An llms.txt file is a short, curated index at your site root that points AI systems to your most important pages — often linking to their Markdown versions. You typically need both.

What does the GDPR Audit check?

It checks your page for GDPR compliance signals: whether a cookie consent banner is present and correctly implemented, whether your privacy policy exists and is linked, which third-party scripts are loading and whether they could trigger before consent, and whether your data processor declarations are in order. Every issue is scored and explained with a specific fix.

Is the GDPR Audit free?

Yes. A free scan is available with no account required. Premium plans unlock higher daily audit limits, full data processor reports and priority support.

How much does it cost?

Pay-as-you-go from £4.99, or a subscription from £14.99 a month. New accounts get 100 free points, and credits never expire.

What is the most common GDPR failure on websites?

The most common failure is loading third-party scripts — analytics, advertising pixels, chat widgets — before the visitor has given consent. Under GDPR, tracking scripts must not fire until the user has actively accepted. A cookie banner that loads after the scripts have already run is non-compliant. The GDPR Audit detects third-party scripts and checks whether your consent mechanism fires before them.

Can I audit a competitor's GDPR compliance?

Yes — the tool works with any publicly accessible URL. Auditing a competitor shows whether their compliance gaps give you a trust advantage, or whether they've closed gaps you still have open.

Do I need a privacy policy if I use Google Analytics?

Yes. Any website that processes personal data — including via Google Analytics, Meta Pixel or similar — is required under GDPR to have a privacy policy that discloses what data is collected, how it is used, who it is shared with and for how long it is retained. The GDPR Audit checks whether your privacy policy is present, linked from every page, and contains the required disclosures.

How often should I run a GDPR audit?

Run a GDPR audit after any change to your tech stack — adding a new plugin, analytics tool or chat widget can introduce a compliance gap you didn't have before. Score History logs every run so you can track improvements and catch regressions early.

What counts as a data processor under GDPR?

A data processor is any third party that handles personal data on your behalf — your analytics provider, email marketing platform, chat widget or payment processor all typically count. GDPR requires you to identify and disclose these in your privacy policy, and to have appropriate agreements in place with each one. The GDPR Audit detects the scripts and flags any that aren't declared.

Does the GDPR Audit work with any website platform?

Yes — it works with any publicly accessible URL regardless of platform, including WordPress, Shopify, Webflow, Wix, Squarespace and custom-built sites. No plugin or integration is required.

What is a cookie consent banner and is it required under GDPR?

A cookie consent banner is a notice that informs visitors about the cookies your site sets and asks for their consent before setting non-essential ones. Under GDPR and the UK PECR, consent must be freely given, specific, informed and unambiguous. Pre-ticked boxes or banners that do not offer a genuine reject option are non-compliant. The GDPR Audit checks for a consent banner and flags common implementation failures.

Can a GDPR compliance failure affect my SEO?

Directly, no — Google does not use GDPR compliance as a ranking signal. Indirectly, yes: a non-compliant consent implementation can block your analytics, distort your traffic data and make it harder to make good decisions. A trust signal failure — no privacy policy, no contact information — also weakens E-E-A-T, which does affect rankings. The GDPR Audit flags all of these.

What is the difference between a GDPR audit and a cookie audit?

A cookie audit specifically checks which cookies your site sets, when, and whether consent was collected before setting them. A GDPR audit is broader: it covers cookie consent but also your privacy policy content, data processor disclosures, third-party script loading order, and contact information requirements. The GDPR Audit on aiwebpageseo.com covers all of these in a single run.

Guide

GDPR compliance for websites: what the audit checks and why it matters

GDPR compliance is not a one-time checkbox — it is an ongoing obligation that touches every third-party script, every form and every cookie your site sets. The most common failure is not a missing privacy policy but a correctly worded one that is contradicted by the site's own technical implementation: scripts loading before consent is given, data processors named in the policy that are not actually in use, and consent banners that offer no genuine reject option. The GDPR Audit checks the technical reality, not just the documents.

What GDPR actually requires from a website

Under GDPR and the UK PECR, any website processing personal data must: obtain freely given, specific, informed and unambiguous consent before setting non-essential cookies or firing tracking scripts; maintain a privacy policy that discloses what data is collected, for what purpose, how long it is retained and who it is shared with; and ensure that consent can be withdrawn as easily as it was given. Pre-ticked boxes, dark patterns that make rejection harder than acceptance, and banners that load after the tracking scripts have already fired are all non-compliant regardless of how the banner is worded.

Why script loading order matters

The most common technical failure is loading analytics and advertising scripts in the page head, before the consent banner has loaded and before any user interaction. The sequence matters: the script executes, data is sent to a third party, and only then the banner appears asking for consent that has already been bypassed. The GDPR Audit detects every third-party script on the page, identifies the provider, and checks whether it fires before or after a consent signal is present.

The indirect SEO impact

GDPR compliance is not a direct Google ranking signal. It has indirect effects that matter. A consent implementation that blocks analytics before acceptance means your data is incomplete and you are making decisions on a distorted picture of your traffic. A missing privacy policy or absent contact information weakens E-E-A-T trust signals, which do affect rankings. And a data breach or ICO enforcement action is a reputational event that affects far more than your search visibility.

A practical GDPR compliance checklist

  • Check that your consent banner loads before any non-essential scripts fire — not after.
  • Ensure a genuine reject option is available without burying it in settings.
  • Verify your privacy policy covers every third-party processor your site actually uses.
  • Link your privacy policy from every page, including the footer.
  • Run a GDPR audit after every tech stack change — a new plugin can introduce a gap.

Compliance is not expensive to achieve — most of the common failures are configuration errors, not fundamental architecture problems. The GDPR Audit finds them, explains them in plain English, and tells you exactly what to fix.

Guide

Markdown and llms.txt: why your compliance page needs to be AI-readable too

A compliant page and an AI-readable page solve two unrelated problems, and increasingly you need both. GDPR compliance protects you from enforcement action. Markdown readiness determines whether ChatGPT, Perplexity and Google AI can actually parse your page cleanly enough to cite it. Neither one substitutes for the other, and a page can pass one while quietly failing the other.

Why AI agents struggle with normal HTML

A web page is built for a browser, not a language model. Navigation menus, cookie banners, ad scripts and styling all sit in the same HTML as your actual content, and an AI system has to work to separate the signal from the noise. The Markdown Generator does that separation for you — stripping scripts and layout chrome, keeping headings, paragraphs, lists and structured data, in the order they actually appear on the page.

What the llms.txt specification actually asks for

The llms.txt v2 proposal calls for a clean, plain-text Markdown companion to a page — typically saved alongside it as page.md — so an AI agent gets a small, precise version of the content instead of parsing the full rendered HTML. It is explicitly not about dumping everything on the page; it is about giving an agent exactly the real content, nothing else. That is the standard the Markdown Generator's output is built against.

Where compliance and Markdown readiness overlap

They meet in one place: your privacy policy and cookie disclosures are themselves content an AI agent might try to read and summarise on a user's behalf. A privacy policy trapped inside a script-heavy cookie consent widget, or split across tabs that only render after a click, is invisible to both a compliance auditor skimming quickly and an AI agent parsing the static page. Clean Markdown output makes your compliance documentation legible to both audiences at once.

What a good Markdown export actually preserves

A correct conversion keeps every heading at its real level, every list as a real list, and pulls in content that only exists in a page's schema.org JSON-LD or in dynamically-loaded lists — not just the static text a simple scraper would catch. It should work regardless of the platform the page is built on, from a hand-coded site to WordPress, Shopify or Webflow, without needing a plugin or integration.

A practical AI-readability checklist

  • Generate a Markdown export of your key pages and check every real heading survived the conversion.
  • Confirm your privacy policy and cookie disclosures are static, readable text — not locked behind a script-only widget.
  • Check whether any content only exists in JSON-LD schema, and whether that's the version you want an AI agent to read.
  • Re-generate after any significant content change, the same way you'd re-run a compliance check.

Being compliant and being AI-readable are separate jobs, and doing one well says nothing about the other. The GDPR Audit checks whether your page is legally sound. The Markdown Generator checks whether it's actually usable by the systems increasingly standing between you and your next visitor.

Comments & Questions

Ask a question about the platform or leave feedback. Comments are reviewed before appearing.

Loading comments…