TMOD LogoTMOD

Privacy policy checker

Checks your privacy policy exists and contains real GDPR and CCPA substance.

What TMOD checks

  • Locates your privacy policy by URL patterns, internal link text, and an AI classifier that recognises the page in any language.
  • Reads the page and tests it against GDPR vocabulary, legal basis, data subject rights, processors, retention, rather than only confirming a page exists.
  • Tests separately for CCPA concepts, including the right to opt out of sale and the disclosure of categories collected.
  • Checks for general privacy vocabulary as a baseline, so a policy that is neither GDPR- nor CCPA-shaped is still assessed rather than failed outright.

Why it matters

A privacy policy is an explicit AdSense requirement, not a nice-to-have. Serving ads means third-party cookies and data collection you are obliged to disclose, and its absence is one of the more common straightforward rejections.

It is also a legal requirement in most jurisdictions the moment you collect any personal data, and analytics counts. The exposure there is considerably larger than a rejected ad application, with regulators rather than a review queue on the other end.

The reason this check reads the content rather than confirming a URL exists is that almost every site has a page at /privacy, and a large share of them say nothing. A page reading 'we value your privacy and do not share your data' is not a privacy policy in any sense that matters to either a regulator or a reviewer.

How to fix it

01Describe your actual data flows

Name every service that receives visitor data: analytics, ad networks, embedded video, fonts loaded from a CDN, comment systems, hosting. This list is what a policy is for, and it is the part templates cannot fill in for you.

02Cover the required elements

What data is collected, why, on what legal basis, who it is shared with, how long it is kept, and how someone exercises their rights including access and deletion. If EU visitors are in scope, GDPR expects all of them stated.

03Disclose advertising cookies explicitly

AdSense requires you to disclose the use of third-party ad cookies and, where applicable, point to Google's own advertising policies. This is a specific, checkable requirement and a common omission.

04Link it from every page and keep it current

A footer link on every page is the convention and the expectation, alongside the other pages a reviewer looks for. Revisit it whenever you add a service, a policy that has not been touched in three years is unlikely to still describe your site.

What the major regimes actually ask for

GDPR wants a policy someone can act on. What personal data you collect, why, the lawful basis for each purpose, who else receives it, whether it leaves the region, how long you keep it, and how a visitor exercises access, correction, deletion, portability and objection. Plus a real way to contact whoever is responsible. Analytics and advertising both count as processing, which is what brings an ordinary blog into scope.

California's rules approach the same ground from the other side. They centre on categories: what categories of personal information you collect, where they came from, what you do with them, who you disclose them to, and a clear route to opt out of sale or sharing, which for a site running behavioural advertising is not a hypothetical.

Cookies sit under separate rules again, which is why a policy and a consent mechanism are two different obligations rather than one. None of this is legal advice, and the check here is not a legal review: it reads the page for the substance these regimes expect and tells you what is missing. Whether your specific processing is adequately covered is a question for someone who can be professionally wrong about it.

Keeping the policy true after you add a tool

A privacy policy is a snapshot of a system that keeps changing. Every embedded video, hosted font, heatmap trial, chat widget, comment system and ad partner added after the policy was written is a processor the policy does not mention. Nobody removes one, and nobody updates the page, so the document drifts from the site by a service or two a year.

The practical fix is to derive it from something you already have. The list of third-party requests your pages make is the same list the performance audit produces when it asks why the site is slow, and it is the closest thing to ground truth about who receives visitor data. Walking that list once or twice a year and reconciling it with the policy takes an hour.

Then date the review on the page, and delete the services you have dropped rather than leaving them listed in case they come back. Both directions matter: an omission is a gap, and a policy naming processors you do not use tells a reader, a reviewer or a regulator that the document was never about this site in the first place.

Questions

I have a privacy policy but it is flagged. Why?

The check reads the content and looks for the substance a real policy contains, what is collected, the legal basis, third-party processors, retention, and how rights are exercised. A short page asserting that you respect privacy without describing any actual processing will be flagged, and that is the correct result.

Does GDPR apply if I am not in the EU?

It applies based on whose data you process, not where you are. If EU residents visit your site and you collect their data, which analytics does, you are generally in scope. Most site owners find it simpler to write one policy that satisfies the strictest regime they plausibly touch than to attempt geographic segmentation.

Can I use a generated privacy policy?

As a starting point, provided you then edit it to match your site. Generators produce reasonable structure and standard clauses. What they cannot know is which services you actually use, and a policy naming products you do not use while omitting your ad network is a compliance problem rather than a solution.

Is a privacy policy enough on its own?

No. For EU visitors you also need a working consent mechanism that gates tracking before it fires, which is checked separately. A policy describing consent you do not actually collect is arguably worse than no policy, because it documents the gap.

This check runs inside the policy & compliance audit

Checking one thing costs the same as checking everything, the crawl is the expensive part, not the checks.

Open it