What a privacy policy check can prove
A notice can say "we use cookies" and still skip who receives the data.
A privacy policy check reads the notice the scan found. It marks eight topics present or missing. It does not tell you the notice is lawful. The page can pass a phrase test and still be a bad notice for a person who has to rely on it.
Eight topics, not a full notice
The ICO's guide for small organisations lists what a short notice should cover. Explain why you hold the information. Name the lawful basis, who you share it with, and how long you keep it. Article 6 lists six lawful bases. This check does not score all six. It asks whether the text states a basis or a purpose at all.
The eight topics are lawful basis or purposes, access and erasure, data portability, and a privacy contact or DPO. The rest are cookie or tracking disclosure, a do-not-sell or opt-out path, a 12-month lookback, and sharing or sub-processors.
Substance can override a phrase
A phrase list runs first. When a judgment step is available, it can accept a synonym the list missed. It can also reject a phrase that does not cover the topic. Either way, the result is still a reading of text, not a legal opinion.
The California lookback is the narrow case. The California Attorney General's CCPA page describes a right to know about personal information from the prior 12 months. A notice that never mentions that window can fail the pillar even when the rest of the page is long.
If the scan cannot find a policy link, there is no text to judge. A footer that says Privacy, or a /privacy URL that responds, is the usual find. A file behind a login is out of reach.
The notice is not the request log
The cookie topic looks for words such as cookie, pixel, or beacon in the policy. Pre-consent tracking is what the browser stored before anyone clicked Accept. A privacy policy check can pass that sentence while tags already ran. The notice and the network log answer different questions.
CNIL fined Google €325 million in September 2025 for cookie and advertising-consent failures (CNIL decision, 3 September 2025). That order is about what the tags did. A sentence in the policy is not that evidence.
That gap is do cookie banners stop pre-consent tracking. The request log is the cookie consent scanner. Header names are the other small slice: what security headers a scan can see. Both sit on the same score, at 10% each. Cookies are the larger share.
Questions
- What does a privacy policy check look for?
- Eight topics on the policy page: purpose or lawful basis, access and erasure, portability, a contact, cookies, a do-not-sell path, a 12-month lookback, and who data is shared with.
- Can a privacy policy check replace a lawyer?
- No. It marks topics present or missing on the text it could fetch. It does not say the notice is lawful, and it does not see tags that fired before Accept.
Want evidence on a live URL? Run a free accessibility check.