Privacy Policy

Last updated: June 2026 · gdprgard.eu

1. Data Controller

GDPRGard.eu is operated as a freelance GDPR consultancy service based in Croatia, EU. For data-related enquiries contact: hello@gdprgard.eu

2. What Data We Collect

3. Legal Basis for Processing (Art. 6 GDPR)

4. Third-Party Recipients

5. Data Retention

6. Your Rights (Art. 15–22 GDPR)

You have the right to: access your data, correct inaccuracies, request deletion, restrict processing, data portability, and object to processing. To exercise any right, email hello@gdprgard.eu. We will respond within 30 days.

7. Complaints

You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP): azop.hr

8. Contact

Data controller contact for privacy matters: hello@gdprgard.eu · gdprgard.eu

EU
GDPRGard.eu — Free GDPR Audit Tool For European Businesses

Is your website
GDPR
compliant?

Find out in 30 seconds. Our AI-powered checker audits your website across 10 critical GDPR requirements — before the regulators do.

Run Free Audit Why this matters
€5.88B
Total GDPR fines since 2018
€20M
Maximum fine per violation
10
Compliance checks, 30 seconds
Free
No signup, no credit card
🇪🇺 EU GDPR Compliant
🔒 SSL Secured
⚖️ Art. 6 GDPR Lawful Basis
🤖 AI-Powered Audit
🚫 No Data Sold
Results in 30 Seconds
🛡️ Art. 28 DPA Signed
Hosted on Netlify
Cookie Consent · Privacy Policy · Data Processing Transparency · Third-Party Trackers · User Rights (Art. 17) · DPO Contact · Consent Basis · SSL Security · Pre-Ticked Boxes · Cookie Categories · Cookie Consent · Privacy Policy · Data Processing Transparency · Third-Party Trackers · User Rights (Art. 17) · DPO Contact · Consent Basis · SSL Security · Pre-Ticked Boxes · Cookie Categories ·
Lawful Basis Declaration — Article 6(1) GDPR

Under Article 6(1) GDPR, every processing activity requires a specific lawful basis. GDPRGard.eu processes personal data under two lawful bases only, applied as follows per activity:

⚠️ No processing on the basis of contractual necessity (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)), vital interests (Art. 6(1)(d)), or public task (Art. 6(1)(e)) is carried out on this website. No special category data (Art. 9) or criminal conviction data (Art. 10) is processed. No automated decision-making or profiling (Art. 22) takes place.
Data Processing Activities — Art. 5(1)(b) & Art. 13 GDPR

Each activity below lists its explicit, specific purpose per Art. 5(1)(b) GDPR — purpose limitation principle.

Consultation request handling
Consent — Art. 6(1)(a)
Specific purpose: To respond to enquiries about GDPR compliance services, assess the data subject's needs, and provide a free initial assessment. Not used for any other purpose, not shared beyond Formspree (processor), no automated decision-making.
Data: Name, email, website URL, message Retention: 90 days via Formspree
AI-powered GDPR audit tool
Legitimate Interest — Art. 6(1)(f)
Specific purpose: To deliver the requested GDPR compliance analysis by passing the submitted URL to Anthropic's API. The URL is the minimum data necessary. No personal data transmitted. LIA conducted: providing a free tool directly requested by the user.
Data: Website URL only (no personal data) Retention: Not stored — real-time only
Consent preference storage
Legitimate Interest — Art. 6(1)(f)
Specific purpose: To remember the user's cookie consent choice and avoid repeated requests. Stored exclusively in the user's own browser localStorage. Necessary to comply with ePrivacy Directive obligation to honour consent choices.
Data: Consent choice + timestamp (browser only) Retention: 365 days, never transmitted
Anonymous usage analytics
Consent — Art. 6(1)(a)
Specific purpose: To understand which pages are most visited and how users discover the site, in order to improve content and experience. No personal profiles created. Strictly opt-in — only loaded after affirmative consent via cookie banner.
Data: Anonymous page views (no IP/identifiers) Retention: 365 days, opt-in only
Third-Party Sub-Processors & Tracker Disclosure (Art. 13(1)(e) & Art. 28 GDPR)
No advertising pixels, tracking scripts, or social media widgets used
This website does NOT use Google Analytics, Facebook Pixel, Google Ads, LinkedIn Insight Tag, TikTok Pixel, Hotjar, Intercom, or any other third-party tracking or advertising technology. No data is shared with ad networks or data brokers. No cross-site tracking occurs.

The following sub-processors are used solely to operate core website functions. Each has a Data Processing Agreement (DPA) in place per Art. 28 GDPR:

Formspree Inc. (formspree.io)
Processes contact form submissions. Receives: name, email, message. US-based — transfers covered by Standard Contractual Clauses (SCCs). DPA: formspree.io/legal/dpa. Data retained max 90 days.
Art. 28 DPA ✓
Anthropic PBC (anthropic.com)
Processes AI audit requests. Receives: website URL only (no personal data). US-based — transfers covered by Standard Contractual Clauses (SCCs). Data is processed in real-time and not retained by Anthropic for training without consent.
Art. 28 DPA ✓
Netlify Inc. (netlify.com)
Hosts and serves this website. Processes: server access logs (IP address, browser type) for security and uptime purposes only. US-based — transfers covered by SCCs. GDPR-compliant hosting with signed DPA. Logs retained 30 days.
Art. 28 DPA ✓
No pre-ticked consent boxes — Art. 7 GDPR & Planet49 ECJ Ruling compliant
No checkbox, toggle, or consent mechanism on this website is pre-selected by default. All consent requires a clear, affirmative act by the user before activation (Art. 7 GDPR, Recital 32, Planet49 C-673/17 ECJ ruling). The contact form below contains no marketing consent checkbox. Cookie consent defaults to rejected — only necessary cookies load before consent is given.
Cookie Categories & Granular Opt-In Controls (ePrivacy Directive & Art. 7 GDPR)

Cookies are categorised below. Each non-essential category requires independent, granular opt-in consent before activation. Users can accept, reject, or customise categories individually via the cookie banner or settings panel (accessible at any time via "Manage preferences" in the banner). No non-essential cookies are set before explicit per-category consent is given.

Category 1 — Strictly Necessary
Always Active — No consent required
Required for the website to function. Cannot be disabled. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). These cookies do not track you across sites.
Cookies used: gdprgard_cookie_consent — stores your consent preferences (localStorage, 365 days, never transmitted to server) · gdprgard_audit_used — rate-limit flag (sessionStorage, session only)
Category 2 — Analytics
Opt-in required — OFF by default
Used to understand how visitors interact with the site (pages viewed, traffic sources). No personal profiles created. No data sold or shared with advertisers. Legal basis: consent (Art. 6(1)(a) GDPR). Only activated after explicit, granular opt-in via cookie banner.
Status: Currently no analytics provider is active. Toggle in cookie settings will activate if/when enabled.
Category 3 — Marketing / Advertising
Not used — No cookies set
This website does not use advertising networks, retargeting pixels, or marketing cookies of any kind. No Facebook Pixel, Google Ads, LinkedIn Insight Tag, or equivalent technology is present. If this changes in future, explicit opt-in consent will be required before any marketing cookie is set.
Cookies used: None.
Category 4 — Functional / Preference
Not used — No cookies set
No functional cookies (language preferences, saved logins, personalisation) are currently used beyond the strictly necessary consent preference storage listed in Category 1.
Cookies used: None.
🔧 Manage your preferences: Click "Manage preferences" in the cookie banner (bottom of page) to independently toggle each non-essential category at any time. Withdrawing consent is as easy as giving it — Art. 7(3) GDPR.
Exercise Your Rights Under GDPR (Art. 15–22) — Dedicated Request Form
📋 Access (Art. 15)
Request a copy of all personal data we hold about you.
✏️ Rectification (Art. 16)
Request correction of inaccurate or incomplete data.
🗑️ Erasure (Art. 17)
Request deletion of your personal data ("right to be forgotten").
⏸️ Restriction (Art. 18)
Request that we limit how we use your data.
📦 Portability (Art. 20)
Request your data in a machine-readable format (CSV/JSON).
🚫 Object (Art. 21)
Object to processing based on legitimate interest.
Submit a Data Rights Request
We respond within 30 days as required by Art. 12 GDPR. All requests are free of charge.
Or email directly: hello@gdprgard.eu · Complaints: AZOP

Non-compliance is an expensive gamble

GDPR enforcement is accelerating across Europe. Real data, real fines — click each topic to see the full picture.

01
€1.2B fined in 2024 alone
Regulators across Europe issued €1.2 billion in fines — bringing the all-time total to €6.1 billion since 2018.
Annual GDPR Fines (€ billions) — Source: DLA Piper 2025
2018
€72M
2019
€253M
2020
€307M
2021
€972M
2022
€1.0B
2023
€2.9B
2024
€1.2B
🏆 Largest ever fine: €1.2B vs Meta (2023)
📍 Ireland leads: €3.5B total fines issued
📈 363 data breaches reported daily in 2024
⚠️ Top 2024 fine: €310M vs LinkedIn
Source: DLA Piper GDPR Fines Survey 2025 →
02
SMBs are the new target
Regulators increasingly target small businesses — size is not a shield. Spain alone issued 107 fines in a single year, most against SMBs.
Fines by Volume — Top Countries 2024 (Source: GDPR Enforcement Tracker)
Spain
107 fines
Romania
61 fines
Italy
41 fines
Germany
30 fines
Hungary
19 fines
Croatia
~8 fines
⚖️ GDPR applies to ANY company processing EU data
💶 Even small fines hurt SMBs with thin margins
👔 Executives face personal liability (Netherlands precedent)
🏦 Finance & energy sectors now firmly in scope
Source: CMS GDPR Enforcement Tracker Report 2026 →
03
New EU AI Act adds obligations
The EU AI Act adds a new compliance layer on top of GDPR. If your website uses chatbots, analytics, or recommendation tools — you're already in scope.
EU AI Act — Key Deadlines & Penalties
Feb 2025 ✓
Prohibited AI practices banned
AI systems that manipulate users or exploit vulnerabilities are now illegal across the EU.
Aug 2025 ✓
GPAI transparency rules apply
General-purpose AI models (like ChatGPT integrations) must meet new transparency obligations.
Aug 2026 ⚠️ Upcoming
High-risk AI full compliance
AI used in HR, credit, or education must be registered and audited. Fines up to €35M or 7% of global revenue.
🤖 Chatbots on your site = AI Act scope
💰 Fines up to €35M or 7% of global revenue
🔗 GDPR + AI Act must be managed together
📋 SMBs get simplified documentation rules
Source: GDPR Local — EU AI Act Summary →
04
Most websites fail basic checks
The majority of European SMB websites fail at least 3 out of 10 GDPR checks — most gaps are simple to fix but expensive to ignore.
Most Common GDPR Failures on SMB Websites
78%
Missing proper cookie consent
65%
No legal basis stated for data processing
58%
Third-party trackers fire before consent
45%
No DPO or data contact listed
✅ Most issues fixable in under a week
🔍 2026 EDPB focus: transparency obligations
📬 443 breach notifications/day in EU (2025)
🛠️ Cookie banners are the #1 fix needed
Source: GDPR Enforcement Tracker + EDPB 2026 →

Audit your website
right now

No signup. No credit card. Just your URL and 30 seconds.

gdprgard.eu/checker
Enter your website URL
Initialising...
GDPR Compliance Audit
Found compliance gaps?
I fix GDPR issues for European SMBs — fast, affordable, no legal jargon.
Book a free 20-min consultation to discuss your results.
Book Free Consultation
🔒
You've used your free audit
You've already run a free audit in this session. To protect fair access for all users, each visitor gets one free check.

Want your full compliance report and a fix plan? Book a free consultation — I'll audit your site manually and send you the full PDF report.
Book Free Consultation →

What the audit covers

Every check maps to a specific GDPR article or requirement under EU law.

🍪
Cookie Consent Banner
Checks for a compliant consent banner with clear accept/reject options. Required under GDPR Art. 6 and ePrivacy Directive.
📄
Privacy Policy Page
Verifies you have an accessible, up-to-date privacy policy disclosing how data is collected and used (Art. 13/14).
👁
Data Processing Transparency
Checks that your policy clearly explains what data is collected, why, and how long it's retained (Art. 5).
🔍
Third-Party Tracker Disclosure
Identifies whether analytics, ads, or social media trackers are disclosed and consented to before activation.
👤
User Rights (Access, Deletion)
Checks that users can exercise their rights: access their data, request deletion, and data portability (Art. 15–20).
📬
DPO / Data Contact
Verifies a contact email or Data Protection Officer is listed for privacy-related requests (Art. 37–39).
⚖️
Legal Basis for Processing
Checks that a lawful basis (consent, legitimate interest, etc.) is stated for each type of data processing (Art. 6).
🔒
SSL / Secure Connection
Confirms your site uses HTTPS to protect data in transit. Required for any site handling personal data (Art. 32).
☑️
No Pre-Ticked Consent Boxes
Validates that consent is freely given and not pre-selected by default. Pre-ticked boxes are explicitly illegal under GDPR.
🗂️
Cookie Categories
Checks that cookies are categorised (necessary vs. analytics vs. marketing) with granular opt-in per category.
💳 No Hidden Fees
📋 Flat Rate Pricing
30-Day Post-Implementation Support
🇭🇷 Based in Croatia, EU
🔄 30-Day Follow-Up Check

Fix your compliance.
Flat fees, no surprises.

All services include a detailed report, implementation, and a 30-day follow-up check.

These are one-time and monthly fees for hands-on expert service. Prefer to use the AI tools yourself instead? They're free to try →

Starter
199
One-time audit + report
  • Full 10-point GDPR audit
  • Detailed written report
  • Prioritised fix list
  • 30-min consultation call
  • DIY guidance included
Get Started
Retainer
299
per month
  • Monthly compliance monitoring
  • Law change alerts (EU AI Act etc.)
  • Ongoing fix implementation
  • Priority support
  • Quarterly audit reports
Get Started

GDPR explained,
simply.

Plain-language guides for European business owners — no legal degree required.

GDPR Basics
What is GDPR and does it apply to your small business?
GDPR applies to every business that processes data of EU residents — regardless of size or location. Here's what that means in practice, and the 5 things you need to do first.
June 2026
5 min read →
Cookie Compliance
The 5 most common cookie banner mistakes — and how to fix them
78% of European SMB websites have illegal cookie banners. Most violations are simple to fix. We break down the Planet49 ECJ ruling and what it means for your website today.
June 2026
4 min read →
EU AI Act
The AI Act delay doesn't cover your chatbot
The AI Act's high-risk rules were delayed to December 2027 — but Article 50's chatbot and AI-content transparency rules were not. Here's what still applies from August 2, 2026.
July 2026
8 min read →
AI Governance
Why every SaaS company needs a DPIA before launching AI features
AI features change how a SaaS product collects, interprets and acts on personal data. A Data Protection Impact Assessment catches overcollection, permission leaks and output risk while they're still cheap to fix.
July 2026
7 min read →
Small Business Guide
Is my small business required to comply with GDPR?
"We're too small for GDPR" is one of the most common — and costly — misconceptions among European SMBs. Here's who actually needs to comply, and what it requires.
June 2026
11 min read →
Common Mistakes
The 10 biggest GDPR mistakes small businesses make
From over-collecting data to skipping a privacy policy entirely — the 10 most common (and costly) GDPR mistakes we see European SMBs make, and the practical steps to fix each one.
July 2026
9 min read →
More guides coming soon · Subscribe for updates →

Let's fix your
compliance together.

Tell me about your website and I'll come back with a free initial assessment within 24 hours.

✓ Message received!
I'll get back to you within 24 hours with a free initial assessment.