{"resource":"privacy-scan","url":"https://example.com/","detected":{"trackers":[],"consentTooling":[],"https":true},"summary":{"trackersDetected":0,"consentToolDetected":false,"findings":1,"byImpact":{"critical":0,"serious":1,"moderate":0},"runtimeCheckRequired":true},"findings":[{"ruleId":"no-privacy-policy-link","regulation":["GDPR","CCPA/CPRA"],"impact":"serious","count":1,"message":"No link to a privacy policy was found on the page. A clear privacy policy/notice is a baseline transparency requirement under GDPR and CCPA.","howToFix":"Publish a privacy policy and link to it from every page (commonly in the footer).","helpUrl":"https://oag.ca.gov/privacy/ccpa","sample":"no <a> to a privacy policy detected"}],"coverageNote":"Automated static-HTML testing detects only OBSERVABLE signals in the page source — which known third-party tracker scripts are present, whether a consent banner / CMP and a privacy-policy or \"Do Not Sell\" link exist, cookie attributes, and HTTPS. It CANNOT determine whether trackers or cookies actually fire BEFORE the user consents (the behaviour most often fined), nor evaluate the content of your policy or your actual data flows — those require loading the page in a real browser and a legal review. A clean static scan is NOT a determination of GDPR/CCPA/ePrivacy compliance.","disclaimer":"Not legal advice and not a certification of GDPR, CCPA/CPRA or ePrivacy compliance. Automated static testing is partial (see coverageNote); confirming pre-consent tracker behaviour needs a browser-based scan, and compliance needs review by a qualified professional. Do not rely on this scan as proof of compliance.","standards":["GDPR","CCPA/CPRA","ePrivacy"],"scannedAt":"2026-07-31T10:03:08.483Z","acceptableUse":"/policy"}