Skip to main content

How we measure

CompliantHQ's scanner visits every site from a real browser and measures three regulatory areas: cookies and tracking set before consent, accessibility according to WCAG 2.2 AA, and policy & terms documents against GDPR. Here's how it works.

Cookies and tracking

We open every site in a headless Chrome and log every cookie set and every network request that goes out — before the user has clicked any consent banner. Everything logged before consent is checked against GDPR Art. 6 and the ePrivacy Directive Art. 5(3). A cookie or tracker that is not strictly necessary and lacks consent counts as an issue.

Accessibility (WCAG 2.2 AA)

We run Deque Systems' open-source tool axe-core against every page. It's the same engine that Lighthouse and several commercial scanners use. We only report violations of severity "moderate", "serious" and "critical" — minor violations are not included. On free overview scans we stop, for cost reasons, after 10 distinct rule types per site, which is marked with "X+" in the report.

Policy & terms

We fetch the site's policy and terms pages — privacy policy, cookie policy and purchase/usage terms — and have an AI model review the text against GDPR and Swedish law: is there a legal basis and clear purposes, can recipients unsubscribe from mailings, is the policy readable, and does it cover the data actually collected. Since this is an AI-assessed indication, not a deterministic check, we report it as a state rather than an exact issue count.

How often

We re-measure the sites in a study regularly. The result on the report page is always from the latest measurement — the date is shown in the page header. Site owners can request a new measurement after they have claimed their site.

What we don't measure

We do not make legal assessments. That a site has 0 issues in our measurement does not mean it is "100% compliant" — it means it passed our automated checks on the day we measured. Manual aspects (wording in consent banners and processes behind the site) are out of scope.

Questions or objections

We forward the tools' output — we are not judges. If you consider a measurement incorrect we want to know, so we can adjust. Email hello@complianthq.ai.

How we measure — CompliantHQ's method