Visible on the site
What the technical review can observe.
- Forms, fields, document links, and separate consent actions.
- Cookies, scripts, iframes, fonts, and external network destinations.
- HTTPS, public endpoints, and part of the WordPress configuration.
Outside the scan
Where manual review is required.
- Legal grounds and necessity of each data category.
- Internal documents, staff, backups, and every processor agreement.
- Completeness of regulatory notification and the ISPDn threat model.
Next step
Keep evidence separate from decisions.
Build a data-flow map, assign an owner to each decision, and separate technical changes, documents, and questions for legal review.
Sources
Review forms against primary sources.
Tell us what the site needs.
A goal, the current difficulty, and an optional website address are enough. Do not send passwords, keys, or private exports.