The Rulebook
45 checks, one page each
Every check Peeky runs has a page: the rule behind it, what the scan looks at, how regulators have treated it and what to change. Start with the contents.
European Union15 checks
EU-01Non-essential trackers firing before consentePrivacy Directive, GDPREU-02Consent rejection not honoured (cosmetic consent)ePrivacy Directive, GDPREU-03Cookie banner asymmetry (reject harder than accept)ePrivacy Directive, GDPREU-04Observed processors not disclosed in privacy policyGDPREU-05Policy says one thing, the site does anotherGDPREU-06International transfer without disclosed safeguardGDPREU-07No / inaccessible way to exercise data-subject rightsGDPREU-08Missing mandatory Art. 13 disclosuresGDPREU-09Missing / inaccessible privacy policyGDPREU-10Web accessibility barriers (European Accessibility Act)European Accessibility ActEU-11Fake / unverifiable testimonials & reviewsUnfair Commercial Practices Directive, Omnibus DirectiveEU-12Manipulative urgency / scarcity (dark patterns)Unfair Commercial Practices Directive, Omnibus DirectiveEU-13Subscription auto-renewal / hard cancellationConsumer Rights Directive, Unfair Commercial Practices Directive, Omnibus DirectiveEU-14Missing trader identity / imprint (Impressum)e-Commerce Directive, Consumer Rights Directive, Digitale-Dienste-GesetzEU-15Insecure transport or missing security headersGDPR
United Kingdom15 checks
UK-01Non-essential cookies set before consent (PECR reg. 6)PECR, Data (Use and Access) Act 2025UK-02Reject not as easy as accept (banner asymmetry)PECR, UK GDPRUK-03Cookie walls (consent as condition of access)PECR, UK GDPRUK-04Tracking that ignores withdrawn consentPECR, UK GDPRUK-05'Instigator' ad-tech consent gapPECR, Data (Use and Access) Act 2025UK-06Observed processors not disclosed (UK GDPR Art. 13/14)UK GDPRUK-07Privacy notice missing UK GDPR Art. 13/14 contentUK GDPRUK-08No data-protection complaints procedureData (Use and Access) Act 2025UK-09DSAR / rights mechanism absent or brokenUK GDPR, Data (Use and Access) Act 2025UK-10Missing / inaccessible privacy policyUK GDPRUK-11Electronic marketing without the right permissionPECR, Data (Use and Access) Act 2025UK-12Web accessibility barriers (Equality Act 2010)Equality Act 2010UK-13Fake / unverified reviews & testimonialsDMCCA 2024UK-14Manipulative dark patterns (urgency/scarcity/subscription traps)DMCCA 2024UK-15Insecure transport or missing security headersUK GDPR
United States15 checks
US-01Fake / incentivised reviews & testimonialsFTC Reviews Rule, FTC ActUS-02'Do Not Sell/Share' link missing or non-functionalCCPA/CPRAUS-03Global Privacy Control (GPC) signal not honouredCCPA/CPRAUS-04Selling/sharing data undisclosed in privacy policyCCPA/CPRAUS-05Notice at collection missingCCPA/CPRAUS-06Web accessibility barriers (ADA Title III)ADA Title III, Unruh ActUS-07Privacy and security claims the site does not back upFTC ActUS-08Manipulative dark patterns (FTC §5)FTC ActUS-09Subscription auto-renewal / cancellation friction (ROSCA)ROSCA, FTC ActUS-10Children's data collected without clear notice or consentCOPPAUS-11Multi-state privacy opt-out and policy gapsUS state privacy lawsUS-12Health-related pages sending identifiers to ad-techHIPAA, FTC Health Breach Notification RuleUS-13Missing / inadequate privacy policyCalOPPA, FTC ActUS-14Marketing email basics (CAN-SPAM)CAN-SPAMUS-15Unencrypted transport or sensitive paths reachableFTC Act
Nothing matches that. Try one word, like “consent” or “WCAG”.


