Skip to content
USE CASE: COMPLIANCE

GDPR Website Audit

Detect exposed personal data on your website before supervisory authorities do. Free scanner that stores no scan data.

Cumulative GDPR Fines Since May 2018

€5.88 Billion

2,245+ enforcement actions across the EU

GDPR violations can result in fines up to €20 million or 4% of global annual turnover, whichever is higher. Exposed personal data on your website is a clear violation of data minimization principles.

A GDPR website audit is a check of what your public pages reveal about identifiable people, measured against the regulation rather than against taste. The GDPR — Regulation (EU) 2016/679 — has applied across the EU since 25 May 2018. Article 5(1)(c) requires data minimisation, and a breach of the basic principles falls in the upper fine band under Article 83(5): up to €20 million or 4% of worldwide annual turnover, whichever is higher. Article 32 requires appropriate technical and organisational security; a breach there falls in the lower band under Article 83(4), up to €10 million or 2%. One scan covers at most 1,000 pages, so plan a large estate as several runs.

Relevant GDPR Articles

Article 5 — Principles of Data Processing

Personal data must be processed lawfully, fairly, and in a transparent manner. Data should be minimized — only collected for specified, explicit, and legitimate purposes.

piisafe.eu helps: Identifies unnecessary personal data exposed on your website that violates data minimization.

Article 25 — Data Protection by Design and Default

Controllers must implement appropriate technical measures to ensure only necessary personal data is processed. This applies to the amount of data collected, extent of processing, period of storage, and accessibility.

piisafe.eu helps: Pre-launch scans demonstrate "privacy by design" — you check before deploying.

Article 32 — Security of Processing

Controllers must implement appropriate security measures including the ability to ensure ongoing confidentiality of processing systems and services.

piisafe.eu helps: Regular scans verify no accidental PII exposure has occurred.

Article 33 — Breach Notification

Data breaches must be reported to supervisory authorities within 72 hours. Exposed PII on a public website may constitute a breach requiring notification.

piisafe.eu helps: Detect exposure before it becomes a reportable breach.

Personal Data We Detect

Every type below is verified against the live detection API. Universal types apply to any language; national identifiers are listed by the country that issues them.

👤 Names (PERSON)
📧 Email Addresses
📱 Phone Numbers
🌍 IBAN (all countries)
💳 Credit Cards
🏦 SWIFT/BIC Codes
🪙 Crypto Wallets
📍 Locations
🏢 Organisations
🌐 IP & MAC Addresses
🇬🇧 UK: NI Number, NHS Number, Passport, Driving Licence
🇺🇸 US: SSN, ITIN, Passport, Driving Licence, Bank Number
🇧🇬 Bulgaria: EGN
🇨🇿 Czechia: Rodné číslo
🇸🇰 Slovakia: Rodné číslo
🇪🇪 Estonia: ID Card
🇱🇻 Latvia: ID Card, Personas kods
🇹🇷 Turkey: Kimlik No, Driving Licence
🇮🇱 Israel: ID Number
🇮🇳 India: Aadhaar, PAN, Passport
🇦🇺 Australia: TFN, ABN, ACN, Medicare, Passport, Driving Licence
🇳🇿 New Zealand: Passport, IRD, NHI, Driving Licence
🇨🇦 Canada: SIN, Passport, Driving Licence
🇸🇬 Singapore: UEN, Passport
🏥 Medical: Record Number, Licence, ICD Code

58 entity types in total, 48 languages, dedicated national identifiers for 14 countries. See the full entity list.

Not currently covered as dedicated types: German Steuer-ID and Personalausweis, French INSEE, Spanish DNI/NIE, Italian Codice Fiscale, Dutch BSN, Austrian and Swiss social security numbers, Polish PESEL. Names, addresses, IBANs, e-mail addresses and phone numbers in those countries are still detected by the universal types above.

Why piisafe.eu for GDPR Audits?

No-Storage Architecture

Scan results exist only in server memory during your session and are never stored — essential for processing personal data responsibly.

German Infrastructure

All processing in Germany (Hetzner, Nuremberg). No US cloud, no third-country transfers. True GDPR Article 44 compliance.

Audit-Ready Reports

Export findings as HTML, JSON, or CSV. Include in your Data Protection Impact Assessments (DPIAs) and audit documentation.

Deterministic Detection

Same input = same output, every time. Exact recognisers for formatted identifiers, an NLP recogniser with fixed settings for names and places - reproducible results that auditors can verify.

GDPR Audit Workflow

  1. Initial Scan: Run piisafe.eu on your website with the GDPR preset. Document all findings in your audit log.
  2. Risk Assessment: Evaluate each finding. High-risk PII (SSNs, health data, financial records) requires immediate remediation.
  3. Remediation: Remove or mask exposed personal data. Update data retention policies. Implement access controls.
  4. Verification Scan: Re-scan after remediation to confirm all issues are resolved. Export Grade A report.
  5. Ongoing Monitoring: Schedule regular scans (monthly or after major releases) to maintain compliance.

Start Your GDPR Audit Now

Free, no registration. Detect exposed personal data in 60 seconds. Export audit-ready reports.

Start Free Scan