6.29 Privacy / Compliance / Data Policy / User Rights / AI-Transparency Suite
150 checks in Schema, Local, Trust, Deep Audit. AI-assisted
Scored in the Deep Audit's AI analysis pass.
GDPR / Ccpa / Cpra / Lgpd — Baseline Compliance
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.01 | Validate GDPR applicability | Defined | Critical | Deterministic + AI |
| 6.29.02 | Validate CCPA/CPRA applicability | Defined | Critical | Deterministic + AI |
| 6.29.03 | Validate LGPD applicability | Defined | Critical | Deterministic + AI |
| 6.29.04 | Validate lawful basis of data processing declared | Present | Critical | Deterministic + AI |
| 6.29.05 | Validate privacy policy includes data categories collected | Complete | Heavy | Deterministic + AI |
| 6.29.06 | Validate privacy policy includes purpose of processing | Complete | Heavy | Deterministic + AI |
| 6.29.07 | Validate privacy policy includes retention periods | Present | Heavy | Deterministic + AI |
| 6.29.08 | Validate privacy policy includes user rights explanation | Present | Heavy | Deterministic + AI |
| 6.29.09 | Validate privacy policy includes data controller identity | Present | Medium | Deterministic + AI |
| 6.29.10 | Validate privacy policy includes contact for privacy requests | Present | Medium | Deterministic + AI |
Cookie Consent Management (Cmp) & Tracking Compliance
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.11 | Validate consent banner appears before non‑essential cookies | Yes | Critical | Deterministic + AI |
| 6.29.12 | Validate cookies blocked prior to consent | Yes | Critical | Deterministic + AI |
| 6.29.13 | Validate CMP supports granular consent (analytics, ads, functional) | Present | Heavy | Deterministic + AI |
| 6.29.14 | Validate user can withdraw consent anytime | Present | Heavy | Deterministic + AI |
| 6.29.15 | Validate cookie categories listed accurately | Accurate | Heavy | Deterministic + AI |
| 6.29.16 | Validate no auto‑accept behavior | Clean | Medium | Deterministic + AI |
| 6.29.17 | Validate "Legitimate Interest" fully declared (if used) | Correct | Medium | Deterministic + AI |
| 6.29.18 | Validate CMP log stores consent versioning | Present | Medium | Deterministic + AI |
| 6.29.19 | Validate CMP works across subdomains | Functional | Medium | Deterministic + AI |
| 6.29.20 | Validate CMP does not block core UX | Smooth | Medium | Deterministic + AI |
User Rights: Access, Delete, Modify, Portability
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.21 | Validate user access request system exists | Present | Critical | Deterministic + AI |
| 6.29.22 | Validate deletion request system exists | Present | Critical | Deterministic + AI |
| 6.29.23 | Validate correction/rectification request workflow | Present | Heavy | Deterministic + AI |
| 6.29.24 | Validate data portability workflow available | Present | Heavy | Deterministic + AI |
| 6.29.25 | Validate response SLA within legal timeframe | Compliant | Heavy | Deterministic + AI |
| 6.29.26 | Validate user identity verification process before fulfilling requests | Present | Medium | Deterministic + AI |
| 6.29.27 | Validate logs kept for rights requests | Present | Medium | Deterministic + AI |
| 6.29.28 | Validate privacy team contact reachable | Reachable | Medium | Deterministic + AI |
| 6.29.29 | Validate automated responses do not leak extra data | Clean | Medium | Deterministic + AI |
| 6.29.30 | Validate requests can be submitted from mobile devices | Functional | Medium | Deterministic + AI |
Data Retention, Storage, Audit Trails & Transparency
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.31 | Validate retention schedule documented | Present | Heavy | Deterministic + AI |
| 6.29.32 | Validate data deletion automated when retention expires | Present | Heavy | Deterministic + AI |
| 6.29.33 | Validate encryption at rest documented | Documented | Heavy | Deterministic + AI |
| 6.29.34 | Validate backups follow same retention schedule | Consistent | Medium | Deterministic + AI |
| 6.29.35 | Validate removal processes include logs & database entries | Complete | Medium | Deterministic + AI |
| 6.29.36 | Validate subprocessors listed publicly | Listed | Medium | Deterministic + AI |
| 6.29.37 | Validate subprocessors align with privacy regulations | Compliant | Medium | Deterministic + AI |
| 6.29.38 | Validate DPA (Data Processing Agreement) available | Present | Medium | Deterministic + AI |
| 6.29.39 | Validate cross‑border data transfers disclosed | Disclosed | Medium | Deterministic + AI |
| 6.29.40 | Validate transfer mechanisms (SCC, BCR) compliant | Valid | Medium | Deterministic + AI |
AI Transparency, Model Disclosure & Legal Signals
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.41 | Validate AI usage declared (if AI is used) | Declared | Heavy | Deterministic + AI |
| 6.29.42 | Validate model types disclosed (if applicable) | Present | Heavy | Deterministic + AI |
| 6.29.43 | Validate user data not used for model training unless opt‑in | Compliant | Heavy | Deterministic + AI |
| 6.29.44 | Validate training data transparency provided (if relevant) | Present | Heavy | Deterministic + AI |
| 6.29.45 | Validate AI‑generated content labeled clearly | Present | Medium | Deterministic + AI |
| 6.29.46 | Validate AI disclaimers present | Present | Medium | Deterministic + AI |
| 6.29.47 | Validate privacy policy includes AI processing clauses | Present | Medium | Deterministic + AI |
| 6.29.48 | Validate privacy‑AI alignment matches system behavior | Aligned | Medium | Deterministic + AI |
| 6.29.49 | Validate no unannounced AI decision‑making | Clean | Medium | Deterministic + AI |
| 6.29.50 | Compute partial Privacy score for Chunk 1 | Complete | Medium | Deterministic + AI |
Compliance Signals in HTML, Headers & AI-Crawlable Data
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.51 | Validate privacy policy linked in footer | Present | Heavy | Deterministic + AI |
| 6.29.52 | Validate cookie policy linked in footer | Present | Heavy | Deterministic + AI |
| 6.29.53 | Validate terms of service linked in footer | Present | Heavy | Deterministic + AI |
| 6.29.54 | Validate privacy policy accessible in <head> via meta tags | Present | Medium | Deterministic + AI |
| 6.29.55 | Validate data processing disclosures present in microdata or JSON-LD | Present | Medium | Deterministic + AI |
| 6.29.56 | Validate data controller information in schema.org | Present | Medium | Deterministic + AI |
| 6.29.57 | Validate AI-processing disclosure in schema (if used) | Present | Medium | Deterministic + AI |
| 6.29.58 | Validate “Do Not Sell My Data” link visible (CCPA/CPRA websites) | Present | Medium | Deterministic + AI |
| 6.29.59 | Validate GPC (Global Privacy Control) signals respected | Functional | Medium | Deterministic + AI |
| 6.29.60 | Validate legal pages indexable if legally allowed | Correct | Medium | Deterministic + AI |
Data Sharing & Adtech Compliance
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.61 | Validate third-party trackers declared | Complete | Heavy | Deterministic + AI |
| 6.29.62 | Validate marketing tools configured for “consent mode” | Correct | Heavy | Deterministic + AI |
| 6.29.63 | Validate analytics respects consent state | Functional | Heavy | Deterministic + AI |
| 6.29.64 | Validate advertising cookies blocked until consent | Clean | Medium | Deterministic + AI |
| 6.29.65 | Validate email marketing tools comply with region rules | Compliant | Medium | Deterministic + AI |
| 6.29.66 | Validate no dark patterns used to force consent | Clean | Medium | Deterministic + AI |
| 6.29.67 | Validate consent logs stored securely | Present | Medium | Deterministic + AI |
| 6.29.68 | Validate no undocumented trackers present | Clean | Medium | Deterministic + AI |
| 6.29.69 | Validate fingerprinting techniques not used without consent | Clean | Medium | Deterministic + AI |
| 6.29.70 | Validate cookies expire according to legal standards | Correct | Medium | Deterministic + AI |
Minor Protection, Sensitive Data & Sector-Specific Compliance
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.71 | Validate COPPA applicability | Defined | Critical | Deterministic + AI |
| 6.29.72 | Validate age gating present if required | Present | Critical | Deterministic + AI |
| 6.29.73 | Validate sensitive health data (if applicable) follows HIPAA principles | Safe | Heavy | Deterministic + AI |
| 6.29.74 | Validate PCI-DSS applicability for card handling | Defined | Heavy | Deterministic + AI |
| 6.29.75 | Validate financial businesses follow FINRA/GLBA transparency | Present | Heavy | Deterministic + AI |
| 6.29.76 | Validate medical businesses include required disclaimers | Present | Medium | Deterministic + AI |
| 6.29.77 | Validate legal businesses include attorney-client disclaimers | Present | Medium | Deterministic + AI |
| 6.29.78 | Validate education websites include FERPA compliance signals | Present | Medium | Deterministic + AI |
| 6.29.79 | Validate insurance websites include policyholder rights | Present | Medium | Deterministic + AI |
| 6.29.80 | Validate minors’ data not collected without consent | Clean | Medium | Deterministic + AI |
Cross-Domain Privacy Consistency Checks
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.81 | Validate privacy policy identical across all subdomains | Consistent | Heavy | Deterministic + AI |
| 6.29.82 | Validate cookie consent consistent across all subdomains | Consistent | Heavy | Deterministic + AI |
| 6.29.83 | Validate data sharing disclosures identical across locales | Aligned | Medium | Deterministic + AI |
| 6.29.84 | Validate localized privacy pages not contradictory | Clean | Medium | Deterministic + AI |
| 6.29.85 | Validate global privacy coverage matches region targeting | Accurate | Medium | Deterministic + AI |
| 6.29.86 | Validate site language versions include full privacy translations | Complete | Medium | Deterministic + AI |
| 6.29.87 | Validate cookie categories do not differ across languages | Consistent | Medium | Deterministic + AI |
| 6.29.88 | Validate privacy contact routes work in all locales | Functional | Medium | Deterministic + AI |
| 6.29.89 | Validate no region receives hidden tracking not disclosed in their policy | Clean | Medium | Deterministic + AI |
| 6.29.90 | Validate data residency disclosures per region | Disclosed | Medium | Deterministic + AI |
Final Mid-Section Privacy / Compliance Tests
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.91 | Validate risk assessment for data handling documented | Present | Heavy | Deterministic + AI |
| 6.29.92 | Validate privacy officer or responsible entity assigned | Present | Heavy | Deterministic + AI |
| 6.29.93 | Validate incident response procedure for privacy breaches | Present | Heavy | Deterministic + AI |
| 6.29.94 | Validate communication plan for user data breaches | Present | Medium | Deterministic + AI |
| 6.29.95 | Validate DPIA (Data Protection Impact Assessment) performed if required | Complete | Medium | Deterministic + AI |
| 6.29.96 | Validate vendor risk assessments completed annually | Present | Medium | Deterministic + AI |
| 6.29.97 | Validate subprocessors monitored continuously | Present | Medium | Deterministic + AI |
| 6.29.98 | Validate no contradictions between privacy documentation & tracking behavior | Clean | Medium | Deterministic + AI |
| 6.29.99 | Validate privacy disclosures are AI-readable & machine‑interpretable | Clear | Medium | Deterministic + AI |
| 6.29.100 | Compute mid-section Privacy score | >= 80% | Critical | Deterministic + AI |
Privacy Engineering, Data Safety, Technical Controls
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.101 | Validate PII stored only when necessary | Minimal | Heavy | Deterministic + AI |
| 6.29.102 | Validate data minimization enforced at system level | Enforced | Heavy | Deterministic + AI |
| 6.29.103 | Validate anonymization or pseudonymization for analytics | Present | Heavy | Deterministic + AI |
| 6.29.104 | Validate personal data encrypted at rest (AES256+) | Encrypted | Heavy | Deterministic + AI |
| 6.29.105 | Validate personal data encrypted in transit (TLS 1.2+) | Encrypted | Heavy | Deterministic + AI |
| 6.29.106 | Validate logs do not contain PII | Clean | Heavy | Deterministic + AI |
| 6.29.107 | Validate access controls for sensitive data (RBAC/ABAC) | Present | Heavy | Deterministic + AI |
| 6.29.108 | Validate IP addresses anonymized where required | Anonymized | Medium | Deterministic + AI |
| 6.29.109 | Validate session cookies flagged (HttpOnly, Secure, SameSite) | Correct | Medium | Deterministic + AI |
| 6.29.110 | Validate session expiration reasonable | Compliant | Medium | Deterministic + AI |
User Experience Alignment with Privacy
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.111 | Validate privacy links visible across UX | Visible | Medium | Deterministic + AI |
| 6.29.112 | Validate no misleading privacy wording | Clean | Medium | Deterministic + AI |
| 6.29.113 | Validate UX does not push users into data sharing | Clean | Medium | Deterministic + AI |
| 6.29.114 | Validate consent banner accessible from all pages | Present | Medium | Deterministic + AI |
| 6.29.115 | Validate cookie settings modifiable via persistent element | Present | Medium | Deterministic + AI |
| 6.29.116 | Validate privacy disclosures readable at 8th‑grade level | Readable | Medium | Deterministic + AI |
| 6.29.117 | Validate dark modes do not hide compliance elements | Consistent | Medium | Deterministic + AI |
| 6.29.118 | Validate mobile designs maintain compliance visibility | Consistent | Medium | Deterministic + AI |
| 6.29.119 | Validate forms show required data usage clarifications | Present | Medium | Deterministic + AI |
| 6.29.120 | Validate Captchas or anti-spam tools not collecting unnecessary PII | Compliant | Medium | Deterministic + AI |
AI-Transparency, Automated Decision-Making & Model Governance
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.121 | Validate automated decision-making disclosed (if used) | Present | Heavy | Deterministic + AI |
| 6.29.122 | Validate human oversight exists for automated systems | Present | Heavy | Deterministic + AI |
| 6.29.123 | Validate user opt-out for automated decisions | Present | Heavy | Deterministic + AI |
| 6.29.124 | Validate model documentation available internally | Present | Heavy | Deterministic + AI |
| 6.29.125 | Validate AI system risk assessed annually | Assessed | Heavy | Deterministic + AI |
| 6.29.126 | Validate explainability statements provided | Present | Medium | Deterministic + AI |
| 6.29.127 | Validate AI inference data not stored unnecessarily | Minimal | Medium | Deterministic + AI |
| 6.29.128 | Validate inference logs protected from leaks | Protected | Medium | Deterministic + AI |
| 6.29.129 | Validate no usage of shadow AI tools or unapproved models | Clean | Medium | Deterministic + AI |
| 6.29.130 | Validate all models documented in privacy policy (if applicable) | Present | Medium | Deterministic + AI |
Organizational, Legal, Documentation & Ongoing Privacy Ops
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.131 | Validate privacy training provided to employees | Present | Heavy | Deterministic + AI |
| 6.29.132 | Validate annual privacy reviews | Completed | Heavy | Deterministic + AI |
| 6.29.133 | Validate vendor onboarding includes privacy checks | Present | Heavy | Deterministic + AI |
| 6.29.134 | Validate no outdated vendors with privacy risks | Clean | Heavy | Deterministic + AI |
| 6.29.135 | Validate internal privacy documentation updated | Updated | Medium | Deterministic + AI |
| 6.29.136 | Validate privacy escalations path defined | Present | Medium | Deterministic + AI |
| 6.29.137 | Validate secure channels used for privacy communications | Secure | Medium | Deterministic + AI |
| 6.29.138 | Validate data breach SOP updated | Updated | Medium | Deterministic + AI |
| 6.29.139 | Validate privacy responsibilities clearly assigned | Assigned | Medium | Deterministic + AI |
| 6.29.140 | Validate compliance with retention across all storage layers | Consistent | Medium | Deterministic + AI |
Final Compliance & Privacy Scoring
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.29.141 | Validate privacy signals consistent across website, apps & APIs | Consistent | Heavy | Deterministic + AI |
| 6.29.142 | Validate all data rights functional & user-friendly | Functional | Heavy | Deterministic + AI |
| 6.29.143 | Validate AI transparency unambiguous & aligned with policy | Aligned | Heavy | Deterministic + AI |
| 6.29.144 | Validate compliance signals meet international standards | Compliant | Medium | Deterministic + AI |
| 6.29.145 | Validate no discrepancies between docs & technical behavior | Clean | Medium | Deterministic + AI |
| 6.29.146 | Validate cross-domain privacy coverage unified | Unified | Medium | Deterministic + AI |
| 6.29.147 | Validate user trust signals measurable | Present | Medium | Deterministic + AI |
| 6.29.148 | Validate accessibility of legal docs | Accessible | Medium | Deterministic + AI |
| 6.29.149 | Validate AI readability of compliance metadata | Clear | Medium | Deterministic + AI |
| 6.29.150 | Compute full Privacy / Compliance composite score | >= 90% | Critical | Deterministic + AI |
← 6.28 Security / Infrastructure Integrity / Anti-Abuse / Bot Protection / Stability Suite6.30 Accessibility / WCAG / ADA / Inclusive UX Suite →
Run these checks on your site
A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.
See plans
Machine-readable: catalog totals and the
full catalog as JSON (IDs, section, weight, status).