Privacy Policy

Last updated: June 2026 · gdprgard.eu

1. Data Controller

GDPRGard.eu is operated as a freelance GDPR consultancy service based in Croatia, EU. For data-related enquiries contact: privacy@gdprgard.eu

2. What Data We Collect

3. Legal Basis for Processing (Art. 6 GDPR)

4. Third-Party Recipients

5. Data Retention

6. Your Rights (Art. 15–22 GDPR)

You have the right to: access your data, correct inaccuracies, request deletion, restrict processing, data portability, and object to processing. To exercise any right, email privacy@gdprgard.eu. We will respond within 30 days.

7. Complaints

You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP): azop.hr

8. Contact

Data controller contact for privacy matters: privacy@gdprgard.eu · gdprgard.eu

EU
GDPRGard.eu — Free GDPR Audit Tool For European Businesses

Is your website
GDPR
compliant?

Find out in 30 seconds. Our AI-powered checker audits your website across 10 critical GDPR requirements — before the regulators do.

€5.88B
Total GDPR fines since 2018
€20M
Maximum fine per violation
10
Compliance checks, 30 seconds
Free
No signup, no credit card
🇪🇺 EU GDPR Compliant
🔒 SSL Secured
⚖️ Art. 6 GDPR Lawful Basis
🤖 AI-Powered Audit
🚫 No Data Sold
Results in 30 Seconds
🛡️ Art. 28 DPA Signed
Hosted on Netlify
Cookie Consent · Privacy Policy · Data Processing Transparency · Third-Party Trackers · User Rights (Art. 17) · DPO Contact · Consent Basis · SSL Security · Pre-Ticked Boxes · Cookie Categories · Cookie Consent · Privacy Policy · Data Processing Transparency · Third-Party Trackers · User Rights (Art. 17) · DPO Contact · Consent Basis · SSL Security · Pre-Ticked Boxes · Cookie Categories ·
Lawful Basis Declaration — Article 6(1) GDPR

Under Article 6(1) GDPR, every processing activity requires a specific lawful basis. GDPRGard.eu processes personal data under two lawful bases only, applied as follows per activity:

⚠️ No processing on the basis of contractual necessity (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)), vital interests (Art. 6(1)(d)), or public task (Art. 6(1)(e)) is carried out on this website. No special category data (Art. 9) or criminal conviction data (Art. 10) is processed. No automated decision-making or profiling (Art. 22) takes place.
Data Processing Activities — Art. 5(1)(b) & Art. 13 GDPR

Each activity below lists its explicit, specific purpose per Art. 5(1)(b) GDPR — purpose limitation principle.

Consultation request handling
Consent — Art. 6(1)(a)
Specific purpose: To respond to enquiries about GDPR compliance services, assess the data subject's needs, and provide a free initial assessment. Not used for any other purpose, not shared beyond Formspree (processor), no automated decision-making.
Data: Name, email, website URL, message Retention: 90 days via Formspree
AI-powered GDPR audit tool
Legitimate Interest — Art. 6(1)(f)
Specific purpose: To deliver the requested GDPR compliance analysis by passing the submitted URL to Anthropic's API. The URL is the minimum data necessary. No personal data transmitted. LIA conducted: providing a free tool directly requested by the user.
Data: Website URL only (no personal data) Retention: Not stored — real-time only
Consent preference storage
Legitimate Interest — Art. 6(1)(f)
Specific purpose: To remember the user's cookie consent choice and avoid repeated requests. Stored exclusively in the user's own browser localStorage. Necessary to comply with ePrivacy Directive obligation to honour consent choices.
Data: Consent choice + timestamp (browser only) Retention: 365 days, never transmitted
Anonymous usage analytics
Consent — Art. 6(1)(a)
Specific purpose: To understand which pages are most visited and how users discover the site, in order to improve content and experience. No personal profiles created. Strictly opt-in — only loaded after affirmative consent via cookie banner.
Data: Anonymous page views (no IP/identifiers) Retention: 365 days, opt-in only
Third-Party Sub-Processors & Tracker Disclosure (Art. 13(1)(e) & Art. 28 GDPR)
No advertising pixels, tracking scripts, or social media widgets used
This website does NOT use Google Analytics, Facebook Pixel, Google Ads, LinkedIn Insight Tag, TikTok Pixel, Hotjar, Intercom, or any other third-party tracking or advertising technology. No data is shared with ad networks or data brokers. No cross-site tracking occurs.

The following sub-processors are used solely to operate core website functions. Each has a Data Processing Agreement (DPA) in place per Art. 28 GDPR:

Formspree Inc. (formspree.io)
Processes contact form submissions. Receives: name, email, message. US-based — transfers covered by Standard Contractual Clauses (SCCs). DPA: formspree.io/legal/dpa. Data retained max 90 days.
Art. 28 DPA ✓
Anthropic PBC (anthropic.com)
Processes AI audit requests. Receives: website URL only (no personal data). US-based — transfers covered by Standard Contractual Clauses (SCCs). Data is processed in real-time and not retained by Anthropic for training without consent.
Art. 28 DPA ✓
Netlify Inc. (netlify.com)
Hosts and serves this website. Processes: server access logs (IP address, browser type) for security and uptime purposes only. US-based — transfers covered by SCCs. GDPR-compliant hosting with signed DPA. Logs retained 30 days.
Art. 28 DPA ✓
No pre-ticked consent boxes — Art. 7 GDPR & Planet49 ECJ Ruling compliant
No checkbox, toggle, or consent mechanism on this website is pre-selected by default. All consent requires a clear, affirmative act by the user before activation (Art. 7 GDPR, Recital 32, Planet49 C-673/17 ECJ ruling). The contact form below contains no marketing consent checkbox. Cookie consent defaults to rejected — only necessary cookies load before consent is given.
Cookie Categories & Granular Opt-In Controls (ePrivacy Directive & Art. 7 GDPR)

Cookies are categorised below. Each non-essential category requires independent, granular opt-in consent before activation. Users can accept, reject, or customise categories individually via the cookie banner or settings panel (accessible at any time via "Manage preferences" in the banner). No non-essential cookies are set before explicit per-category consent is given.

Category 1 — Strictly Necessary
Always Active — No consent required
Required for the website to function. Cannot be disabled. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). These cookies do not track you across sites.
Cookies used: gdprgard_cookie_consent — stores your consent preferences (localStorage, 365 days, never transmitted to server) · gdprgard_audit_used — rate-limit flag (sessionStorage, session only)
Category 2 — Analytics
Opt-in required — OFF by default
Used to understand how visitors interact with the site (pages viewed, traffic sources). No personal profiles created. No data sold or shared with advertisers. Legal basis: consent (Art. 6(1)(a) GDPR). Only activated after explicit, granular opt-in via cookie banner.
Status: Currently no analytics provider is active. Toggle in cookie settings will activate if/when enabled.
Category 3 — Marketing / Advertising
Opt-in required — OFF by default
Google AdSense is used to show and measure ads. No Facebook Pixel, Google Ads (conversion tracking), LinkedIn Insight Tag, or retargeting pixel is present — AdSense is the only advertising technology on this site. The AdSense script does not load until you explicitly allow the Marketing category in the cookie banner (Art. 6(1)(a) GDPR, your consent).
Cookies used: IDE, __gads, __gpi, test_cookie, NID (Google Ireland Ltd / Google LLC) — only if enabled.
Category 4 — Functional / Preference
Not used — No cookies set
No functional cookies (language preferences, saved logins, personalisation) are currently used beyond the strictly necessary consent preference storage listed in Category 1.
Cookies used: None.
🔧 Manage your preferences: Click the 🍪 cookie icon in the bottom corner of any page to reopen the consent banner and change your Marketing choice at any time. Withdrawing consent is as easy as giving it — Art. 7(3) GDPR.
Exercise Your Rights Under GDPR (Art. 15–22) — Dedicated Request Form
📋 Access (Art. 15)
Request a copy of all personal data we hold about you.
✏️ Rectification (Art. 16)
Request correction of inaccurate or incomplete data.
🗑️ Erasure (Art. 17)
Request deletion of your personal data ("right to be forgotten").
⏸️ Restriction (Art. 18)
Request that we limit how we use your data.
📦 Portability (Art. 20)
Request your data in a machine-readable format (CSV/JSON).
🚫 Object (Art. 21)
Object to processing based on legitimate interest.
Submit a Data Rights Request
We respond within 30 days as required by Art. 12 GDPR. All requests are free of charge.
Or email directly: hello@gdprgard.eu · Complaints: AZOP

Non-compliance is an expensive gamble

GDPR enforcement is accelerating across Europe. Real data, real fines — click each topic to see the full picture.

01
€1.2B fined in 2024 alone
Regulators across Europe issued €1.2 billion in fines — bringing the all-time total to €6.1 billion since 2018.
Annual GDPR Fines (€ billions) — Source: DLA Piper 2025
2018
€72M
2019
€253M
2020
€307M
2021
€972M
2022
€1.0B
2023
€2.9B
2024
€1.2B
🏆 Largest ever fine: €1.2B vs Meta (2023)
📍 Ireland leads: €3.5B total fines issued
📈 363 data breaches reported daily in 2024
⚠️ Top 2024 fine: €310M vs LinkedIn
Source: DLA Piper GDPR Fines Survey 2025 →
02
SMBs are the new target
Regulators increasingly target small businesses — size is not a shield. Spain alone issued 107 fines in a single year, most against SMBs.
Fines by Volume — Top Countries 2024 (Source: GDPR Enforcement Tracker)
Spain
107 fines
Romania
61 fines
Italy
41 fines
Germany
30 fines
Hungary
19 fines
Croatia
~8 fines
⚖️ GDPR applies to ANY company processing EU data
💶 Even small fines hurt SMBs with thin margins
👔 Executives face personal liability (Netherlands precedent)
🏦 Finance & energy sectors now firmly in scope
Source: CMS GDPR Enforcement Tracker Report 2026 →
03
New EU AI Act adds obligations
The EU AI Act adds a new compliance layer on top of GDPR. If your website uses chatbots, analytics, or recommendation tools — you're already in scope.
EU AI Act — Key Deadlines & Penalties
Feb 2025 ✓
Prohibited AI practices banned
AI systems that manipulate users or exploit vulnerabilities are now illegal across the EU.
Aug 2025 ✓
GPAI transparency rules apply
General-purpose AI models (like ChatGPT integrations) must meet new transparency obligations.
Aug 2026 ⚠️ Upcoming
High-risk AI full compliance
AI used in HR, credit, or education must be registered and audited. Fines up to €35M or 7% of global revenue.
🤖 Chatbots on your site = AI Act scope
💰 Fines up to €35M or 7% of global revenue
🔗 GDPR + AI Act must be managed together
📋 SMBs get simplified documentation rules
Source: GDPR Local — EU AI Act Summary →
04
Most websites fail basic checks
The majority of European SMB websites fail at least 3 out of 10 GDPR checks — most gaps are simple to fix but expensive to ignore.
Most Common GDPR Failures on SMB Websites
78%
Missing proper cookie consent
65%
No legal basis stated for data processing
58%
Third-party trackers fire before consent
45%
No DPO or data contact listed
✅ Most issues fixable in under a week
🔍 2026 EDPB focus: transparency obligations
📬 443 breach notifications/day in EU (2025)
🛠️ Cookie banners are the #1 fix needed
Source: GDPR Enforcement Tracker + EDPB 2026 →

Audit your website
right now

No signup. No credit card. Just your URL and 30 seconds.

gdprgard.eu/checker
Enter your website URL
Initialising...
GDPR Compliance Audit
Found compliance gaps?
I fix GDPR issues for European SMBs — fast, affordable, no legal jargon.
Book a free 20-min consultation to discuss your results.
Book Free Consultation
🔒
You've used your free audit
You've already run a free audit in this session. To protect fair access for all users, each visitor gets one free check.

Want your full compliance report and a fix plan? Book a free consultation — I'll audit your site manually and send you the full PDF report.
Book Free Consultation →

What the audit covers

Every check maps to a specific GDPR article or requirement under EU law.

🍪
Cookie Consent Banner
Checks for a compliant consent banner with clear accept/reject options. Required under GDPR Art. 6 and ePrivacy Directive.
📄
Privacy Policy Page
Verifies you have an accessible, up-to-date privacy policy disclosing how data is collected and used (Art. 13/14).
👁
Data Processing Transparency
Checks that your policy clearly explains what data is collected, why, and how long it's retained (Art. 5).
🔍
Third-Party Tracker Disclosure
Identifies whether analytics, ads, or social media trackers are disclosed and consented to before activation.
👤
User Rights (Access, Deletion)
Checks that users can exercise their rights: access their data, request deletion, and data portability (Art. 15–20).
📬
DPO / Data Contact
Verifies a contact email or Data Protection Officer is listed for privacy-related requests (Art. 37–39).
⚖️
Legal Basis for Processing
Checks that a lawful basis (consent, legitimate interest, etc.) is stated for each type of data processing (Art. 6).
🔒
SSL / Secure Connection
Confirms your site uses HTTPS to protect data in transit. Required for any site handling personal data (Art. 32).
☑️
No Pre-Ticked Consent Boxes
Validates that consent is freely given and not pre-selected by default. Pre-ticked boxes are explicitly illegal under GDPR.
🗂️
Cookie Categories
Checks that cookies are categorised (necessary vs. analytics vs. marketing) with granular opt-in per category.
💳 No Hidden Fees
📋 Flat Rate Pricing
30-Day Post-Implementation Support
🇭🇷 Based in Croatia, EU
🔄 30-Day Follow-Up Check

Fix your compliance.
Flat fees, no surprises.

All services include a detailed report, implementation, and a 30-day follow-up check.

These are one-time and monthly fees for hands-on expert service. Prefer to use the AI tools yourself instead? They're free to try →

Starter
199
One-time audit + report
  • Full 10-point GDPR audit
  • Detailed written report
  • Prioritised fix list
  • 30-min consultation call
  • DIY guidance included
Get Started
Retainer
299
per month
  • Monthly compliance monitoring
  • Law change alerts (EU AI Act etc.)
  • Ongoing fix implementation
  • Priority support
  • Quarterly audit reports
Get Started
Paid guides · €39

Not ready for a retainer? Start with the Field Kit.

Seven short guides for solo founders and small teams — DSARs, AI vendor vetting, the Digital Omnibus, the myths that cost businesses real money, and the compliance stack a European solopreneur actually needs. 97 pages of checklists, templates and decision trees. One payment, instant download, no consultant.

See the Compliance Field Kit →

GDPR explained,
simply.

Plain-language guides for European business owners — no legal degree required.

GDPR Basics
What is GDPR and does it apply to your small business?
GDPR applies to every business that processes data of EU residents — regardless of size or location. Here's what that means in practice, and the 5 things you need to do first.
June 2026
5 min read →
Cookie Compliance
The 5 most common cookie banner mistakes — and how to fix them
78% of European SMB websites have illegal cookie banners. Most violations are simple to fix. We break down the Planet49 ECJ ruling and what it means for your website today.
June 2026
4 min read →
EU AI Act
The AI Act delay doesn't cover your chatbot
The AI Act's high-risk rules were delayed to December 2027 — but Article 50's chatbot and AI-content transparency rules were not. Here's what still applies from August 2, 2026.
July 2026
8 min read →
AI Governance
Why every SaaS company needs a DPIA before launching AI features
AI features change how a SaaS product collects, interprets and acts on personal data. A Data Protection Impact Assessment catches overcollection, permission leaks and output risk while they're still cheap to fix.
July 2026
7 min read →
AI & Business Strategy
AI news and insights: what's actually driving AI-driven business growth
AI spending will hit $2.59 trillion in 2026 — but only 5% of companies say their data is ready for it. What the latest numbers mean for your business.
July 2026
9 min read →
EU AI Act & GDPR
The high-risk deadline moved to December 2027. The GDPR overlap didn't move at all.
The AI Omnibus bought Annex III systems 16 extra months. It bought nothing for GDPR, the penalty tiers, or the two new prohibitions landing in December 2026. Where the two laws still collide.
August 2026
8 min read →
GDPR Enforcement & Reform
GDPR in 2026: record fines, a reform in motion, and what to do now
GDPR fines have passed €7.1 billion and the EU's Digital Omnibus is rewriting cookie consent, breach notification, and DPIA rules. Here's what's actually changed, and what's still just a proposal.
August 2026
9 min read →
Digital Omnibus & GDPR Reform
Inside the EU's Digital Omnibus: what's actually changing for GDPR, and what just stalled
The Digital Omnibus would raise the RoPA exemption to 750 employees, add a one-click cookie reject button, and clarify AI legitimate interest. Only one of those three survived June's Council talks.
August 2026
9 min read →
EU-US Data Transfers
Is “Schrems III” coming? A Supreme Court ruling shakes the Data Privacy Framework
A June 2026 ruling stripped FTC commissioners of removal protections — a pillar the EU cited 259 times to justify the EU-US Data Privacy Framework. Here's what's actually at risk.
August 2026
7 min read →
Small Business Guide
Is my small business required to comply with GDPR?
"We're too small for GDPR" is one of the most common — and costly — misconceptions among European SMBs. Here's who actually needs to comply, and what it requires.
June 2026
11 min read →
Common Mistakes
The 10 biggest GDPR mistakes small businesses make
From over-collecting data to skipping a privacy policy entirely — the 10 most common (and costly) GDPR mistakes we see European SMBs make, and the practical steps to fix each one.
July 2026
9 min read →
AI & GDPR Enforcement
Forget the AI Act — GDPR is already fining companies for AI mistakes
Three recent cases — Clearview AI (€30.5M), a German fintech (€492K), and Replika (€5M) — show regulators using GDPR, not the AI Act, to punish exactly the kind of AI mistakes any business could make.
August 2026
7 min read →
AI Training Data & GDPR
The "It Was Public" Excuse Is Over: GDPR Now Formally Covers AI Training Data
The EDPB's new guidelines end the assumption that scraped public data is fair game for AI training — with no grace period for datasets collected years ago.
August 2026
8 min read →
AI & GDPR Compliance
AI Is 2026's Biggest GDPR Compliance Risk
Legitimate interest assessments, mandatory DPIAs for biometric AI, and Ireland's Grok inquiry show why AI has become GDPR's single largest source of risk in 2026.
August 2026
9 min read →
Industry Benchmark
GDPR Compliance Benchmark 2026: Readiness Scores by Industry
A composite GDPR readiness score for six industries, built from Verizon's 2026 breach data and CMS's 2026 GDPR fine tracker — full methodology and sources.
August 2026
10 min read →
AI Tools & GDPR
Your AI chatbot isn't anonymising anything
The EDPB says AI models are rarely anonymous — so the chatbot, CRM assistant and note-taker you already run need a DPIA, a legal basis and a disclosure of their own.
August 2026
9 min read
GDPR Reform & Enforcement
GDPR in 2026: why “simplification” doesn't mean you can relax
The AI Act delay is law, but the GDPR cookie, breach and AI changes are still only proposals — and enforcement keeps rising. What to fix now and what to wait on.
September 2026
8 min read
Data Security & GDPR Tools
How a VPN Strengthens GDPR Compliance in 2026
IP protection, Article 32 encryption, and secure remote access — a practical guide to where a VPN fits into your GDPR compliance stack.
August 2026
6 min read →
Data Security & GDPR Tools
Is a VPN Mandatory Under the GDPR?
The GDPR never names a VPN as required — Article 32 asks for risk-based security instead. What that actually means for EU businesses.
August 2026
7 min read →
More guides coming soon · Subscribe for updates →

Let's fix your
compliance together.

Tell me about your website and I'll come back with a free initial assessment within 24 hours.

✓ Message received!
I'll get back to you within 24 hours with a free initial assessment.