Personal data

What to review on a data-collecting site

Start with a map of forms, purposes, recipients, storage, and access—not with a banner.

Visible on the site

What the technical review can observe.

  • Forms, fields, document links, and separate consent actions.
  • Cookies, scripts, iframes, fonts, and external network destinations.
  • HTTPS, public endpoints, and part of the WordPress configuration.

Outside the scan

Where manual review is required.

  • Legal grounds and necessity of each data category.
  • Internal documents, staff, backups, and every processor agreement.
  • Completeness of regulatory notification and the ISPDn threat model.

Next step

Keep evidence separate from decisions.

Build a data-flow map, assign an owner to each decision, and separate technical changes, documents, and questions for legal review.

Tell us what the site needs.

A goal, the current difficulty, and an optional website address are enough. Do not send passwords, keys, or private exports.