Skip to content
PeekWellThe Rulebook
Join now

The Rulebook

45 checks, one page each

Every check Peeky runs has a page: the rule behind it, what the scan looks at, how regulators have treated it and what to change. Start with the contents.

European Union15 checks

  1. EU-01Non-essential trackers firing before consentePrivacy Directive, GDPR
  2. EU-02Consent rejection not honoured (cosmetic consent)ePrivacy Directive, GDPR
  3. EU-03Cookie banner asymmetry (reject harder than accept)ePrivacy Directive, GDPR
  4. EU-04Observed processors not disclosed in privacy policyGDPR
  5. EU-05Policy says one thing, the site does anotherGDPR
  6. EU-06International transfer without disclosed safeguardGDPR
  7. EU-07No / inaccessible way to exercise data-subject rightsGDPR
  8. EU-08Missing mandatory Art. 13 disclosuresGDPR
  9. EU-09Missing / inaccessible privacy policyGDPR
  10. EU-10Web accessibility barriers (European Accessibility Act)European Accessibility Act
  11. EU-11Fake / unverifiable testimonials & reviewsUnfair Commercial Practices Directive, Omnibus Directive
  12. EU-12Manipulative urgency / scarcity (dark patterns)Unfair Commercial Practices Directive, Omnibus Directive
  13. EU-13Subscription auto-renewal / hard cancellationConsumer Rights Directive, Unfair Commercial Practices Directive, Omnibus Directive
  14. EU-14Missing trader identity / imprint (Impressum)e-Commerce Directive, Consumer Rights Directive, Digitale-Dienste-Gesetz
  15. EU-15Insecure transport or missing security headersGDPR

United Kingdom15 checks

  1. UK-01Non-essential cookies set before consent (PECR reg. 6)PECR, Data (Use and Access) Act 2025
  2. UK-02Reject not as easy as accept (banner asymmetry)PECR, UK GDPR
  3. UK-03Cookie walls (consent as condition of access)PECR, UK GDPR
  4. UK-04Tracking that ignores withdrawn consentPECR, UK GDPR
  5. UK-05'Instigator' ad-tech consent gapPECR, Data (Use and Access) Act 2025
  6. UK-06Observed processors not disclosed (UK GDPR Art. 13/14)UK GDPR
  7. UK-07Privacy notice missing UK GDPR Art. 13/14 contentUK GDPR
  8. UK-08No data-protection complaints procedureData (Use and Access) Act 2025
  9. UK-09DSAR / rights mechanism absent or brokenUK GDPR, Data (Use and Access) Act 2025
  10. UK-10Missing / inaccessible privacy policyUK GDPR
  11. UK-11Electronic marketing without the right permissionPECR, Data (Use and Access) Act 2025
  12. UK-12Web accessibility barriers (Equality Act 2010)Equality Act 2010
  13. UK-13Fake / unverified reviews & testimonialsDMCCA 2024
  14. UK-14Manipulative dark patterns (urgency/scarcity/subscription traps)DMCCA 2024
  15. UK-15Insecure transport or missing security headersUK GDPR

United States15 checks

  1. US-01Fake / incentivised reviews & testimonialsFTC Reviews Rule, FTC Act
  2. US-02'Do Not Sell/Share' link missing or non-functionalCCPA/CPRA
  3. US-03Global Privacy Control (GPC) signal not honouredCCPA/CPRA
  4. US-04Selling/sharing data undisclosed in privacy policyCCPA/CPRA
  5. US-05Notice at collection missingCCPA/CPRA
  6. US-06Web accessibility barriers (ADA Title III)ADA Title III, Unruh Act
  7. US-07Privacy and security claims the site does not back upFTC Act
  8. US-08Manipulative dark patterns (FTC §5)FTC Act
  9. US-09Subscription auto-renewal / cancellation friction (ROSCA)ROSCA, FTC Act
  10. US-10Children's data collected without clear notice or consentCOPPA
  11. US-11Multi-state privacy opt-out and policy gapsUS state privacy laws
  12. US-12Health-related pages sending identifiers to ad-techHIPAA, FTC Health Breach Notification Rule
  13. US-13Missing / inadequate privacy policyCalOPPA, FTC Act
  14. US-14Marketing email basics (CAN-SPAM)CAN-SPAM
  15. US-15Unencrypted transport or sensitive paths reachableFTC Act