/ Public reports

Every site PrivacyLens has scanned.

Browse the public TrustScore database — see how brands stack up.

zithos.gr
42/100

Zithos.gr is a Greek restaurant website with a template-generated Privacy Policy and Cookie Policy (both dated October 25, 2023, which is appropriate for today's date of July 24, 2026). However, critical compliance gaps exist: no Terms of Service document is provided despite the site offering reservations and likely collecting customer data; Facebook Pixel tracking is deployed without a cookie consent banner, which violates ePrivacy Directive requirements; the policies lack GDPR-specific rights disclosures (data portability, right to object, supervisory authority details); and there is no evidence of a Data Processing Agreement for third-party processors. The policies read as generic templates with minimal customization for the restaurant's actual data practices.

cmjornal.pt
58/100

Correio da Manhã demonstrates a moderate commitment to privacy compliance with a comprehensive GDPR-aligned privacy policy and detailed terms of service, both last updated to reflect RGPD requirements. However, the site deploys Google Analytics and Facebook Pixel trackers without a visible cookie consent banner—a likely violation of the ePrivacy Directive. The privacy and terms policies are hosted on a separate subdomain (aminhaconta.xl.pt), which may confuse users. No dedicated cookie policy document exists despite the privacy policy referencing one. Payment processing details are minimal. The site appears to lack proactive measures for cookie consent management, and the absence of clear Data Processing Agreement disclosures for third-party data sharing (PMP, advertisers) raises transparency concerns.

weekofbali.org
18/100

This appears to be a personal travel blog documenting ski trips and surf travel, written in Swedish. The site deploys Google Analytics tracking but lacks any privacy policy, terms of service, cookie policy, or consent banner—creating severe GDPR and ePrivacy Directive violations. No payment processing was detected. The absence of fundamental legal disclosures for a tracking-enabled site represents a critical compliance gap that exposes visitors to unconsented data collection and leaves the site operator vulnerable to regulatory penalties.

bettingtracker.pro
62/100

BettingTracker.Pro demonstrates moderate privacy and compliance practices with comprehensive Privacy Policy and Terms of Service documents updated February 2026. However, the platform deploys Google Analytics and Cloudflare tracking without a cookie consent banner, presents a broken cookie policy link, and requires JavaScript rendering for all legal documents including privacy policy access — creating GDPR Article 12 transparency barriers. The site processes payment data through Stripe/PayPal and handles sensitive betting analytics, yet lacks specific cookie disclosures and consent mechanisms for non-essential trackers. While the privacy framework is substantive, implementation gaps around ePrivacy Directive compliance and document accessibility significantly undermine user rights and regulatory adherence.

bettingtracker.pro
52/100

BettingTracker.pro presents a betting analytics platform with fairly comprehensive Privacy Policy and Terms of Service documents, both dated February 6, 2026. However, the site deploys Google Analytics and Cloudflare Insights tracking without a cookie consent banner, creating a high-severity ePrivacy Directive violation. The absence of a dedicated Cookie Policy despite documented use of tracking technologies is another compliance gap. Critical legal documents require JavaScript to render, hindering accessibility under GDPR Article 12. The platform processes sensitive betting data and payments through third parties (Stripe, PayPal) but lacks explicit Data Processing Agreements or adequacy mechanism disclosures for international transfers. The Terms contain broad liability disclaimers that may not satisfy consumer protection standards in EU jurisdictions. These issues collectively represent moderate-to-high legal risk.

bettingtracker.pro
62/100

BettingTracker.Pro demonstrates a reasonable baseline effort with comprehensive Privacy Policy and Terms of Service documents dated February 2026. However, critical compliance gaps exist: no dedicated Cookie Policy despite deploying Google Analytics and Cloudflare tracking, no cookie consent banner mechanism for non-essential cookies, and all user-facing pages require JavaScript rendering which may hinder GDPR Article 12 accessibility requirements. The platform processes payments through Stripe and PayPal but lacks transparent disclosure of Data Processing Agreements or subprocessor lists. While the policies cover core GDPR rights and data retention schedules, the absence of cookie compliance mechanisms and reliance on JavaScript for policy visibility create moderate regulatory risk.

getprivacylens.com
88/100

PrivacyLens demonstrates exceptionally strong privacy practices with comprehensive GDPR-compliant policies, transparent data-minimization measures, and minimal tracking. The site uses only strictly necessary cookies, discloses AI sub-processors under zero-retention contracts, provides self-service account deletion, and implements robust security controls including annual penetration testing. However, Google Analytics is detected on the homepage despite the Cookie Policy claiming no tracking cookies are used—a high-severity contradiction that undermines trust. Additionally, the site lacks explicit CCPA-specific disclosures beyond opt-out language, and the AI-generated content disclaimer could be more prominent throughout the user journey.

trysoro.com
72/100

Trysoro.com demonstrates strong foundational privacy practices with a comprehensive GDPR/CCPA-compliant privacy policy and detailed terms of service, both attorney-reviewed and recently updated (May 17, 2026). However, critical compliance gaps exist: the site deploys Google Analytics and Facebook Pixel tracking without a cookie consent banner, violating EU ePrivacy Directive requirements. No dedicated cookie policy is present despite extensive discussion of cookies in the privacy policy. The site processes significant personal data (API credentials, billing information, content) and relies on third-party AI providers, but lacks transparency around the current subprocessor list (available only on request). Payment processor detection found no explicit processor, raising questions about PCI compliance disclosure. Overall, the legal framework is robust but operational compliance—particularly cookie consent mechanism—requires immediate attention.

betai.gr
72/100

BetAI.gr demonstrates good foundational privacy practices with a comprehensive GDPR-compliant privacy policy, clear terms of service, and a detailed cookie policy all dated February 2026. The site uses consent-based marketing cookies (Meta Pixel), privacy-respecting analytics (Plausible), and reputable third-party processors (Stripe, Clerk, Cloudflare). However, critical issues remain: no cookie consent banner is present despite marketing cookies being mentioned, no clear data controller entity or registration number is provided, refund policy lacks specificity, and international data transfer safeguards need more detail. The platform appropriately disclaims gambling services and sets a 21+ age requirement, but the absence of a visible consent mechanism for the Meta Pixel creates potential ePrivacy Directive non-compliance.

airbnb.com
32/100

Airbnb.com presents significant privacy and compliance concerns. While the site references a comprehensive privacy framework with multiple jurisdictional supplements, the actual policy documents are inaccessible—both the Privacy Policy and Terms of Service URLs return only navigation scaffolding without substantive legal text. No Cookie Policy was found despite Facebook Pixel tracking being deployed and a consent banner being present. The homepage requires JavaScript for basic functionality, potentially creating accessibility barriers. These structural issues—broken policy links, missing cookie documentation, and active tracking without visible policy disclosures—create material GDPR Article 12-14 transparency risks and potential ePrivacy Directive violations.

notion.so
72/100

Notion demonstrates strong privacy and compliance infrastructure with comprehensive GDPR measures, SAML SSO, SCIM provisioning, standard contractual clauses, and detailed data governance practices. However, critical accessibility issues undermine compliance: the privacy policy is in Spanish while the English homepage advertises English-language services, creating a language barrier for English-speaking users that may violate GDPR Article 12's clarity requirement. The terms of service link points only to marketplace guidelines rather than master subscription terms, leaving users unable to review core contractual obligations. Cookie policy implementation appears solid with no non-essential trackers detected and no consent banner (appropriate for strictly-necessary cookies only). Payment processing details are absent from public documentation. The site would benefit significantly from proper language-matched policies and complete terms accessibility.

sdna.gr
38/100

This Greek sports news site (sdna.gr) presents significant privacy and compliance risks. While a privacy policy exists, it is written in Greek only, lacks key GDPR disclosures (legal basis, retention periods, DPO contact), and does not clearly identify the data controller. More critically, the site deploys third-party trackers (Google Analytics, Facebook Pixel, Hotjar) without a visible cookie consent banner, violating ePrivacy Directive requirements. Terms of Service and Cookie Policy documents are entirely absent despite homepage links suggesting they exist (broken links), creating material compliance gaps. The homepage and privacy policy both required JavaScript rendering to view, raising GDPR Article 12 accessibility concerns. The opt-out interface on the homepage suggests awareness of CCPA/US privacy laws but does not remedy EU compliance deficiencies.

stripe.com
88/100

Stripe demonstrates strong privacy practices with comprehensive, attorney-drafted policies covering GDPR, CCPA, DPF certification, extensive sub-processor disclosure, and detailed cookie management. The Privacy Center is exceptionally transparent, providing granular explanations of data controller/processor roles, international transfers, and product-specific privacy information. Minor issues include potential over-reliance on legitimate interest for certain marketing activities, dense legal language that may challenge average-user comprehension, and some ambiguity around AI model training scope. Overall, Stripe sets a high bar for financial infrastructure providers.

sdna.gr
12/100

This website presents severe compliance and transparency risks. The homepage is completely blocked by Cloudflare security, preventing access to any content or legal documents. No privacy policy, terms of service, or cookie policy could be located despite standard discovery attempts. Cloudflare Insights tracking is active without any visible cookie consent mechanism or documentation. The entire site requires JavaScript rendering just to display basic content, creating significant accessibility barriers under GDPR Article 12. Without foundational legal documents and with aggressive blocking mechanisms, users have no way to understand data practices, legal rights, or contractual terms. This configuration is incompatible with GDPR transparency obligations and creates substantial legal exposure.

sdna.gr
15/100

SDNA.gr presents severe privacy and compliance risks. All three core legal documents—Privacy Policy, Terms of Service, and Cookie Policy—return 404 errors despite being linked from the homepage, leaving users with no enforceable legal framework or transparency about data practices. The site deploys multiple tracking technologies (Google Analytics, Facebook Pixel, Hotjar) without a functional cookie consent banner or accessible policy documentation, creating significant GDPR Article 6, 7, 12, and 13 non-compliance exposure. The homepage and all policy pages require JavaScript rendering, creating accessibility barriers. Given the Greek domain and EU user base, these deficiencies represent material regulatory risk.

stripe.com
82/100

Stripe demonstrates strong privacy and compliance practices with comprehensive, detailed policies covering GDPR, CCPA, cookies, and data processing. The site offers transparent information about data collection, use, and international transfers, with clear user rights disclosures and a dedicated Privacy Center. However, several issues prevent a higher score: the Privacy Policy is extremely lengthy (potentially hindering GDPR Article 12 transparency requirements), some policy dates appear outdated relative to the current date (June 2026), and the sheer complexity may overwhelm average users. The Terms of Service lack consumer-friendly plain language summaries, and there's minimal specific disclosure about AI model training using transaction data beyond fraud prevention.

httpbin.org
15/100

httpbin.org is a developer utility service for testing HTTP requests and responses. It completely lacks essential legal documentation: no privacy policy, terms of service, or cookie policy exist. While the service appears minimal with no detected trackers or payment processing, the absence of any legal framework creates significant compliance risk. Any collection or logging of request data (IP addresses, headers, payloads) without disclosure violates GDPR transparency requirements. The site cannot demonstrate lawful basis for data processing, user rights mechanisms, or liability limitations.

httpbin.org
15/100

httpbin.org is a developer utility service for testing HTTP requests and responses. It completely lacks essential legal documents: no privacy policy, no terms of service, and no cookie policy were found. While the site appears to be a technical tool with no detected trackers or payment processors, the absence of any legal framework creates significant GDPR Article 13/14 compliance risks if any personal data (IP addresses, request headers, user-submitted data) is logged or processed. This represents a high-risk configuration for any service handling user data, even in a testing context.

httpbin.org
15/100

httpbin.org is a developer testing utility that presents severe privacy compliance risks. The site has no privacy policy despite collecting and displaying user HTTP headers, IP addresses, and request data. The 'terms of service' link returns JSON diagnostic data rather than legal terms. There is no cookie policy, no GDPR compliance documentation, and no transparency about data handling practices. While the site appears to be a simple HTTP testing tool without commercial intent, the complete absence of user-facing legal documentation and the visible collection of personally identifiable information (IP addresses) creates significant regulatory exposure under GDPR Article 13 and CCPA disclosure requirements.

sdna.gr
15/100

This Greek sports news website presents severe privacy and compliance risks. All three core legal documents—Privacy Policy, Terms of Service, and Cookie Policy—link to broken pages that return 404 errors, meaning the site effectively has no enforceable legal framework. Despite this, the site deploys multiple third-party trackers (Google Analytics, Facebook Pixel, Hotjar) without a functional cookie consent banner, violating ePrivacy Directive and GDPR requirements. The homepage includes opt-out toggles for CCPA/GDPR rights and references Google consent mechanisms, but these cannot substitute for comprehensive, accessible legal policies. The site acknowledges selling personal data and sharing with IAB downstream participants, yet provides no transparent privacy policy to inform users of these practices. Critical legal pages require JavaScript rendering, reducing accessibility for users with disabilities or assistive technologies.

example.com
15/100

This website presents severe compliance and transparency risks. No privacy policy, terms of service, or cookie policy could be located, despite being fundamental requirements under GDPR, CCPA, and consumer protection law. The absence of these legal documents means users have no information about data collection, processing purposes, user rights, dispute resolution, or liability limitations. While no third-party trackers were detected, the complete lack of legal documentation creates substantial regulatory exposure and erodes user trust.

discord.com
72/100

Discord demonstrates above-average privacy practices with a comprehensive privacy policy (effective September 29, 2025), clear legal basis explanations under GDPR, and transparency about data collection. The platform does not sell personal information and relies on subscriptions and sponsored content for revenue. However, several concerns emerge: the Terms of Service link directs to a third-party community server rather than Discord's actual terms, the Cookie Policy link similarly points to an unrelated community server, and the privacy policy shows extensive automated content scanning and monitoring practices that may raise user concerns. The platform deploys Google Analytics tracking but does provide a cookie consent banner. Payment processing is handled by third parties (Stripe, PayPal), which is appropriate, though the policy could better clarify data retention periods for different categories of information.

notion.so
62/100

Notion is a well-established enterprise SaaS platform with comprehensive privacy and security documentation, including GDPR-compliant policies, SAML SSO, SCIM provisioning, and data processing agreements. However, significant issues undermine user trust: the homepage privacy policy link redirects to a Spanish-language help page rather than the formal Privacy Policy, creating accessibility barriers and potential GDPR Article 12 non-compliance. The Terms of Service link points only to Marketplace guidelines, not general terms. The Cookie Notice was last updated September 2023 (nearly 3 years outdated) and no cookie consent banner is present despite documented use of marketing and analytics cookies from Meta, Google, LinkedIn, TikTok, and others—a likely ePrivacy Directive violation. Payment processing details are absent despite enterprise billing. While Notion's back-end compliance appears robust, these front-end policy accessibility and cookie consent gaps create moderate legal risk.

github.com
68/100

GitHub demonstrates moderate privacy practices with comprehensive Terms of Service (effective April 27, 2026) but significant accessibility and transparency gaps. The privacy policy page fails to render actual policy content without JavaScript, instead showing only navigation elements and repository metadata—a critical GDPR Article 12 violation. The cookie policy link returns a 404 error despite being referenced in the footer. While GitHub maintains robust account security requirements and clearly defines AI data usage in their Terms, the inaccessible privacy documentation and broken cookie policy link create substantial compliance risks. The site deploys a cookie consent banner, suggesting non-essential tracking, but without a functional cookie policy users cannot make informed choices. No third-party payment processors or excessive trackers were detected on the homepage.

airbnb.com
42/100

Airbnb.com appears to reference comprehensive privacy and terms documents, including multiple regional supplements and a cookie policy. However, the actual policy content retrieved is incomplete — both the Privacy Policy and Terms of Service URLs returned only navigation scaffolding and header text rather than substantive legal language. This suggests the full policies may require JavaScript execution or deeper navigation, creating potential GDPR Article 12 transparency violations. A Cookie Policy link is referenced in supplemental documents but was not found at the expected URL. Facebook Pixel tracking is present, and while a consent banner was detected, the incomplete policy retrieval prevents verification of lawful basis and data processing disclosures. No payment processor details were visible. The site may have robust policies in place, but accessibility and retrieval issues present meaningful compliance risks until full policy text can be confirmed.

stripe.com
82/100

Stripe demonstrates strong privacy practices with comprehensive, detailed policies covering GDPR, CCPA, DPF certification, and international data transfers. The company provides extensive transparency about data controller/processor roles, sub-processors, AI model training, and cross-border transfers. Cookie consent mechanisms are in place, and the platform's own payment processing is handled internally. However, some issues emerge: the Privacy Policy and related documents are extremely lengthy and complex (potentially violating GDPR Article 12's 'concise' requirement), certain policy links appear to lead to identical or overlapping content creating navigation confusion, and the sheer volume of legal documentation (60+ linked policies) may overwhelm users seeking clear answers. The site also deploys Plausible Analytics without explicit opt-in consent, and while weapon detection measures at events are disclosed, the privacy implications could be explained more clearly for attendees.

booktest.pro
62/100

BookTest.pro presents a moderate privacy risk profile. The site has comprehensive privacy and terms documents updated in 2026, but deploys Google Analytics and Cloudflare tracking without a cookie consent banner, creating potential GDPR/ePrivacy violations. The platform processes educational content including children's data, yet lacks a dedicated cookie policy and clear COPPA compliance mechanisms. Payment processing is mentioned in policies but processors are not clearly identified on-site. The homepage requires JavaScript rendering to display content, raising accessibility concerns under GDPR Article 12. While the privacy policy demonstrates awareness of data protection obligations, the absence of user consent mechanisms before tracking deployment is a significant compliance gap.

booktest.pro
62/100

BookTest.pro demonstrates moderate privacy practices with a comprehensive privacy policy and terms of service, but several compliance gaps create notable risks. The site deploys Google Analytics and Cloudflare tracking without a cookie consent banner, which likely violates ePrivacy Directive requirements. The homepage requires JavaScript rendering to display content, raising GDPR Article 12 accessibility concerns. While the privacy policy addresses AI data processing and children's privacy appropriately, the absence of a dedicated cookie policy and the lack of explicit legal jurisdiction in the terms create uncertainty. Payment processors are mentioned (Stripe, PayPal) but not visibly implemented on the analyzed pages. The 'credits are non-refundable' policy may conflict with consumer protection laws in some jurisdictions.

bettingtracker.pro
52/100

BettingTracker.Pro presents moderate to serious privacy and compliance concerns. While the site provides detailed privacy and terms documents (both dated February 6, 2026, which is valid as of today's date May 27, 2026), critical issues undermine user trust: Google Analytics tracking is active without a cookie consent banner, violating ePrivacy Directive requirements for non-essential cookies in the EU. All pages including legal documents require JavaScript to render, creating GDPR Article 12 accessibility barriers. No dedicated cookie policy exists despite documented cookie use. The privacy policy lacks specifics on data transfer safeguards and AI prediction data handling. Payment processor details are vague (Stripe/PayPal mentioned but not detected on homepage). The tipster marketplace and AI prediction features introduce complex data flows that may not be fully addressed in current policies. These are potential compliance gaps, not definitive violations, but they present meaningful risk for a platform handling sensitive betting data and financial transactions.

bettingtracker.pro
42/100

BettingTracker.pro presents significant privacy and compliance concerns. While privacy policy and terms of service documents exist with reasonable content coverage, critical implementation issues undermine user protection. The site deploys Google Analytics and Cloudflare tracking without a cookie consent banner, violating ePrivacy Directive requirements. All key pages including legal documents require JavaScript rendering, creating accessibility barriers prohibited under GDPR Article 12. The privacy policy is future-dated (February 6, 2026, after today's date of May 25, 2026 appears to be a typo for 2025), and no dedicated cookie policy exists despite active tracking. Payment processor integration with Stripe and PayPal is mentioned but not detected on the homepage. For a platform handling sensitive betting data and financial transactions, these compliance gaps represent substantial legal risk.

bettingtracker.pro
52/100

BettingTracker.pro is a betting analytics platform with a reasonably comprehensive privacy policy and terms of service, both dated February 2026. However, the site deploys Google Analytics and Cloudflare tracking without a cookie consent banner, violating ePrivacy Directive requirements. Critical legal documents require JavaScript to render, creating GDPR Article 12 accessibility barriers. The platform processes payments and tipster earnings through Stripe/PayPal but lacks a dedicated cookie policy despite explicit tracking. The privacy policy shows good data retention schedules and GDPR rights enumeration, but the absence of consent mechanisms for non-essential cookies represents a significant compliance gap. The site is not a gambling operator but facilitates commercial tipster services, raising questions about consumer protection and refund policies.

bettingtracker.pro
12/100

This betting tracker website presents severe privacy and compliance risks. While the homepage displays links to a privacy policy and terms of use, both documents are completely inaccessible—the links are broken and return nothing. Google Analytics is deployed without any cookie consent mechanism or disclosures. There is no cookie policy, no GDPR compliance framework visible, and no transparency about data collection practices. Users cannot make informed decisions about their data because fundamental legal documents are missing or non-functional.

example.org
12/100

This website presents severe privacy and compliance risks. There is no privacy policy, terms of service, or cookie policy available anywhere on the site. While no trackers or payment processors were detected, the complete absence of fundamental legal documentation creates substantial regulatory exposure under GDPR, CCPA, and similar privacy frameworks. Users have no information about data collection, processing purposes, legal rights, or how to contact the organization. This configuration may violate multiple jurisdictions' transparency requirements and cannot satisfy basic consumer protection standards.

example.com
12/100

This website presents severe privacy and compliance risks. It completely lacks a privacy policy, terms of service, and cookie policy—fundamental legal documents required under GDPR, CCPA, and most consumer protection frameworks. While no third-party trackers or payment processors were detected, the absence of core legal documentation means users have no information about data collection, retention, user rights, or liability terms. This configuration may violate GDPR Article 13 transparency requirements and creates significant legal exposure for the operator.

example.com
15/100

This website presents severe compliance and transparency risks. No privacy policy, terms of service, or cookie policy could be found despite being fundamental legal requirements for any website collecting data or interacting with users. The absence of these documents creates significant GDPR Article 13/14 violations, potential liability under various consumer protection laws, and leaves users with no understanding of how their data may be processed. Even a minimal documentation website should provide basic legal disclosures. The complete absence of privacy documentation represents a critical compliance gap.

bettingtracker.pro
42/100

BettingTracker.Pro presents significant privacy and compliance concerns. While privacy policy and terms of service documents exist, they contain major red flags: the privacy policy references a different company name ('OddsChamp'), contains a future date (last updated 5/20/2026), and all policy documents require JavaScript to be accessible—violating GDPR's 'easily accessible' requirement. No cookie policy exists despite detected trackers (Google Analytics, Cloudflare), and no cookie consent banner was found, creating potential GDPR violations. The platform handles sensitive betting data, payment information, and processes financial transactions for tipsters, yet lacks transparent cookie practices and has inconsistent branding across legal documents. These issues suggest incomplete compliance preparation and may expose users to privacy risks.

booktest.pro
62/100

BookTest.pro demonstrates moderate privacy practices with a comprehensive privacy policy and terms of service that address key areas like data collection, AI processing, and children's privacy. However, several compliance gaps exist: the site lacks a cookie policy despite using tracking technologies (Google Analytics, Cloudflare), has no cookie consent banner which violates GDPR requirements, and critical policy documents require JavaScript to render making them inaccessible to users with disabilities or JavaScript disabled. The payment disclosure is incomplete as payment processors are mentioned in policies but not clearly visible on the homepage. While the privacy policy covers essential topics, the lack of cookie consent mechanisms and accessibility issues present medium-to-high compliance risks.

notion.so
72/100

Notion demonstrates strong privacy practices with comprehensive GDPR compliance, detailed privacy policies, and transparent data handling. However, several issues affect the overall trust score: the absence of a visible cookie consent banner despite extensive tracking capabilities, policy documents served primarily in Spanish rather than English (creating accessibility concerns), and the lack of clear payment processor information despite offering paid services. The platform appropriately positions itself as a data processor for customer content while maintaining clear boundaries on data ownership. Most concerning is the missing cookie consent mechanism, which may not satisfy EU ePrivacy Directive requirements.

stripe.com
82/100

Stripe demonstrates strong privacy practices overall with comprehensive policies, clear GDPR frameworks, and transparent data processing agreements. The privacy policy is detailed and recently updated (April 2026), distinguishing between different user roles and providing substantial transparency about data handling. However, potential issues exist around the complexity of the privacy framework, lack of accessible cookie settings information in the excerpts provided, and the inherent risks associated with processing vast amounts of financial transaction data. While Stripe appears to implement robust security measures, the scale of data processing ($1.9T in payments) represents significant risk if any breach or compliance gap occurs.

booktest.pro
28/100

BookTest.pro presents significant privacy and compliance concerns. The privacy policy, terms of service, and cookie policy all appear to be placeholder links returning only the homepage content, indicating these critical legal documents may not actually exist. The site deploys Google Analytics and Cloudflare tracking without a cookie consent banner, violating GDPR requirements. All pages require JavaScript to render, making legal documents inaccessible to users with JS disabled, screen readers, and search engines—a direct violation of GDPR Article 12's 'easily accessible' mandate. The service processes educational content including potentially sensitive student data (PDFs, textbooks, progress tracking) without demonstrating proper data protection measures. Given the target audience includes minors (students), the absence of COPPA/child protection disclosures is a critical gap. These issues collectively create substantial legal and privacy risks.

spotmusic.gr
28/100

SpotMusic.gr presents significant privacy and compliance risks. The privacy policy, terms of service, and cookie policy pages appear to contain only JavaScript requirement messages rather than actual legal documentation, which is a critical red flag. With no functioning privacy policy or terms accessible, no cookie consent banner despite claiming to have a cookie policy, and unclear data handling practices for a music streaming platform, this site may fail to meet basic GDPR, CCPA, and ePrivacy Directive requirements. Users should exercise extreme caution when using this service.

github.com
78/100

GitHub demonstrates strong baseline privacy and compliance practices with comprehensive policies, transparent cookie disclosures, and proper consent mechanisms. However, several areas present potential risks: the privacy policy excerpt provided appears incomplete for full assessment, there's uncertainty around AI training data usage given GitHub Copilot's prominence, limited visibility into third-party data sharing practices for enterprise features, and potential GDPR concerns regarding data retention periods and subject access request processes that aren't clearly detailed in the available content. While GitHub is a reputable platform, users should review complete policy documents and understand how their code and activity data may be processed.

example.com
25/100

This website presents severe compliance and transparency risks. There is no privacy policy, terms of service, or cookie policy present, which creates potential legal liability under GDPR, CCPA, and other privacy regulations. While no trackers or payment processors were detected, the complete absence of foundational legal documentation means users have no information about data handling practices, liability limitations, or their rights. This configuration may violate mandatory disclosure requirements in multiple jurisdictions and exposes both the site operator and users to significant legal and privacy risks.

example.com
15/100

This website presents severe compliance and transparency risks. It completely lacks fundamental legal documents including a privacy policy, terms of service, and cookie policy. There is no cookie consent mechanism, making it potentially non-compliant with GDPR, CCPA, and other privacy regulations. While no trackers or payment processors were detected, the absence of basic legal documentation means users have no information about data handling practices, liability limitations, or their rights. Any commercial use of this domain would likely violate multiple privacy laws.

example.com
25/100

This website presents severe compliance and transparency risks. It completely lacks fundamental legal documents including a privacy policy, terms of service, and cookie policy. There is no cookie consent mechanism in place. While no trackers or payment processors were detected (which slightly mitigates risk), the absence of any privacy documentation means users have no information about data handling practices. Any organization operating this site for actual business purposes would face significant GDPR, CCPA, and general legal exposure. The site appears to be a documentation example domain, but if used operationally, it would require immediate implementation of comprehensive legal policies.

example.com
15/100

This website presents severe compliance and transparency risks. No privacy policy, terms of service, or cookie policy could be identified, which may violate GDPR, CCPA, and other privacy regulations. The absence of fundamental legal documentation means users have no information about data collection, usage rights, liability limitations, or dispute resolution. While no trackers were detected on the homepage, the complete lack of transparency documents creates significant legal exposure for both the site operator and potential liability concerns for users.

example.com
15/100

This website presents severe compliance and transparency risks. It completely lacks fundamental legal documentation including a privacy policy, terms of service, and cookie policy. There is no cookie consent mechanism despite potential regulatory requirements under GDPR and CCPA. While no trackers or payment processors were detected in this scan, the absence of any privacy infrastructure means users have no information about data practices, legal protections, or recourse mechanisms. Any organization operating this domain for actual business purposes would face significant regulatory exposure.

example.com
15/100

This website presents severe privacy and compliance risks. It completely lacks fundamental legal documentation including a privacy policy, terms of service, and cookie policy. There is no cookie consent mechanism in place. While no trackers or payment processors were detected in this scan, the absence of any legal framework means users have no transparency about data practices, rights, or protections. Any organization operating this site may face significant GDPR, CCPA, and other regulatory violations if collecting any user data.

PrivacyLens

AI-powered website trust intelligence. See your hidden privacy & compliance risks before they become expensive.

Product
Resources
Legal

PrivacyLens is not a law firm and does not provide legal advice. All reports, scores, recommendations, and generated documents are AI-generated assessments based on publicly available information and automated analysis. Results may be incomplete, inaccurate, or may not reflect your organization's full compliance posture. Use of PrivacyLens does not create an attorney–client relationship. For legal advice or compliance determinations, consult a qualified attorney.

© 2026 PrivacyLens — a product of WebNet KDR. All rights reserved.
Built for the AI-trust era