
Privacy policy GDPR: policy against site behaviour
At a glance
EU-05HighGDPR Art. 5(1)(a), 13; Art. 83(5)(a) and (b)
Peeky reads the claims in a privacy policy and sets each one beside what the browser did on the same site, such as 'no third-party sharing' next to an ad network that loaded.
Last checked against the source:
The rule
The GDPR does not contain a rule titled “the policy must match the site”. The idea comes from two places: the principle of fair and transparent processing, and the list of things a company has to tell people when it collects their data.
Article 5(1)(a) says personal data shall be “processed lawfully, fairly and in a transparent manner in relation to the data subject”. Article 5(2) adds that the controller “shall be responsible for, and be able to demonstrate compliance with” the principles in paragraph 1.
Article 13(1) says that where personal data are collected from the person, the controller shall, at the time they are obtained, provide among other things “the purposes of the processing for which the personal data are intended as well as the legal basis for the processing”, “the recipients or categories of recipients of the personal data, if any”, and where applicable the fact that the controller intends to transfer the data to a third country. Article 13(2) adds the retention period, the rights of the person and the right to complain.
A privacy policy is how most websites meet Article 13. If it names no advertising vendor and one receives the visitor’s data, the policy is open to being set against Article 13’s recipients line. If it says no data leaves the EU and a request goes to a server elsewhere, the sentence and the request disagree.
The Article 29 Working Party’s transparency guidelines (revised 11 April 2018) say transparency is “intrinsically linked to fairness”. A central point is that “the data subject should be able to determine in advance what the scope and consequences of the processing entails and that they should not be taken by surprise at a later point about the ways in which their personal data has been used” (para. 10). On wording, the information “should be concrete and definitive; it should not be phrased in abstract or ambivalent terms” (para. 12), and qualifiers such as “may”, “might”, “some”, “often” and “possible” should be avoided (para. 13).
Penalties sit in the upper tier. Article 83(5)(a) covers “the basic principles for processing”, pursuant to Article 5, and Article 83(5)(b) covers “the data subjects’ rights pursuant to Articles 12 to 22”, which includes the information duties in Article 13. Both carry a ceiling of EUR 20 million or, for an undertaking, 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. Enforcement has mostly concerned missing or unclear information. A literal contradiction between a stated claim and observed behaviour is the narrowest and clearest form, and this check looks for that.
What PeekWell checks and how
EU-05 asks one question per claim: does something the browser did contradict a specific sentence in the privacy policy? It looks only for contradiction. Gaps in what a policy discloses belong to sibling checks such as EU-04.
The scan fetches the privacy policy the site links to. A language model reads it and writes down discrete, affirmative claims in a fixed form, for example “no advertising cookies”, “no third-party sharing” or “data stays in the EU”. Each claim is then mapped to a test that code runs against evidence from the same visit: the network requests and cookies the browser recorded in a clean context, once with no or rejected consent and once with consent accepted. A claim of “no advertising cookies” becomes a check for advertising-category cookies in that evidence.
Code makes the decision. The model reads the policy and helps write the explanation, but it never decides that a claim is contradicted. A finding appears only where the evidence directly contradicts a specific claim, and the contradicting request or cookie is attached. Severity starts at high.
The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. A claim it cannot test from a browser visit, such as how long data is kept or what happens on a server, is read but not flagged. Sharing that happens server to server is outside what a visit can see. It does not decide what a word like “share” means in a contract. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
The Irish authority’s WhatsApp decision of 20 August 2021 carries a fine of EUR 225 million. The authority examined whether WhatsApp had met its transparency obligations toward users and non-users, including information about processing shared with other Facebook companies, and the decision page lists Articles 5 and 13. After the binding decision of the European Data Protection Board of 28 July 2021, it imposed the fine, a reprimand and an order to bring the processing into line. On 10 February 2026 the Court of Justice held that WhatsApp’s action against that binding decision is admissible and sent it back to the General Court, which had not yet ruled on the merits when the Court issued its press release. The WhatsApp inquiry concerned the information WhatsApp gave, not a policy set against site behaviour. It is listed because it shows how the transparency principle is enforced at scale.
At the other end, the Spanish authority’s decision in procedure PS/00080/2023 shows how a policy can fall short next to the behaviour of a site. The consent banner on a lawyer-referral website referred to partners and their “legitimate interest”. The authority found the policy unclear on purposes and legal basis, found the legitimate interests of third parties explained only by opening the separate policies of each vendor on a long list, and found no mention of transfers outside the EU although some of the listed vendors were outside it. It fined the company EUR 2,000 under Article 13. Separately, the authority recorded that “legitimate interest” was pre-ticked for more than half of about 130 vendors (the decision elsewhere describes a far longer list), so objecting meant clearing them one by one. The authority treated that as an infringement of the fairness principle in Article 5(1)(a) and fined EUR 5,000. The resolution also fined EUR 5,000 under the Spanish e-commerce law. The decision does not state the company’s size.
Three consequences follow for a company. A policy is evidence of what people were told, so each sentence in it can be set against the site. Article 5(2) means the company has to be able to show how the two were matched. And a claim true on the day it was written can stop being true when someone adds a tag, so the match needs rechecking after releases.
Smaller companies and larger companies
The rule has no size threshold. What differs is how a mismatch gets there.
In a small company the policy often comes from a generator or a template, written once, with a sentence such as “we do not share your data with third parties”. Later someone adds a chat widget, an advertising pixel or an embedded video, and the page is never touched. Nobody owns the job of comparing the two. A complaint from a visitor is often how it comes to light, as in Spain, where the authority acted after a complaint.
In a larger company legal writes the policy, many teams and agencies change the site, and a tag manager can add vendors without a release. The policy describes the group in general terms while individual sites and apps do different things. In the WhatsApp matter the information gap concerned processing across a group of companies and applied to users and non-users alike.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
WhatsApp Ireland Ltd
The Irish authority investigated whether WhatsApp gave users and non-users clear information about its processing of personal data, including processing shared with other Facebook companies. The inquiry examined whether WhatsApp had met its transparency obligations, and the decision page lists Articles 5 and 13. After the binding decision of the European Data Protection Board of 28 July 2021, the authority imposed a fine, a reprimand and an order to bring its processing into line. WhatsApp's challenge to that binding decision is before the General Court.
Read the Data Protection Commission (Ireland) publication about WhatsApp Ireland Ltd
Smaller companies
No decision against a smaller company could be confirmed at a regulator's own page where a policy contradicted what the site did. The Spanish decision against Chatwith.io Worldwide, S.L. is described in the text, but the decision does not state the company's size, so it is not listed as a smaller-company case.
How to fix it
Write the policy from what the site does, and recheck it when the site changes. Steps 1 and 2 use the same browser evidence as EU-01, which tests for trackers that load before consent.
- List what the site does. Open the site in a private window with the browser’s network tab open. Write down every third-party domain and cookie, then do it again after accepting the banner.
- Mark each item with a purpose and a recipient. For every vendor on the list, write down what it is for, what it receives and where it is based. Remove any you cannot explain.
- Pick out the claims in the policy. Find every sentence that starts with “we do not”, “we never” or “your data stays”. Test each one against the list from step 1. Reword or delete a sentence the list contradicts, or remove the vendor.
- Name recipients and transfers. Make the policy list the categories of recipients or the vendors by name, say what each gets, and state whether data goes outside the EU and on what footing. Replace “may”, “some” and “from time to time” with what actually happens.
- Tie the policy to releases. Add the policy to the checklist for adding a tag, a plugin or a vendor, so a new request means a new line in the policy before it goes live.
- Re-scan. Run a scan again after the policy and tags change. The finding should disappear once no claim in the policy is contradicted by the visit.
Whether a rewritten policy satisfies a given authority is for your legal adviser. Peeky reports only what it sees.
Questions
What does GDPR Article 5 say about transparency?
Article 5(1)(a) says personal data must be processed lawfully, fairly and in a transparent manner. Article 5(2) adds that the company must be able to show it did. A privacy policy that says one thing while the site does another sits under both words, fairly and transparent.
What must a privacy policy say under GDPR Article 13?
Article 13 lists what a company tells people when it collects their data: who it is, why it uses the data and on what basis, who receives it, and whether it is sent outside the EU. It also asks for how long the data is kept and what rights people have. The text is quoted in the rule.
Can a privacy policy be accurate and still say too little?
Yes. Transparency asks for the information Article 13 lists, in plain words, and not only for statements that happen to be true. In the Spanish decision on Chatwith.io the policy was faulted for unclear purposes and for saying nothing about transfers outside the EU.
What do regulators expect a GDPR privacy policy to look like?
Specific, plain and definite. The Article 29 Working Party's transparency guidelines say information should be concrete and not phrased in abstract or ambivalent terms, and that words like may, might and some should be avoided. If a company uses them, it should be able to show why it had to.
How does Peeky compare a privacy policy with the site?
Peeky reads the policy, writes down its clear claims, and checks each one that a browser can test against the requests and cookies from a clean visit. It flags only a claim the evidence directly contradicts, and attaches the request. How a scan works has the full path.
Filed with
The rule
GDPR (Regulation (EU) 2016/679), Arts. 5(1)(a), 5(2), 12 and 13
Read the rule (GDPR (Regulation (EU) 2016/679), Arts. 5(1)(a), 5(2), 12 and 13)Sources
- Regulation (EU) 2016/679 (GDPR), Art. 5, Principles relating to processing of personal data (legislation.gov.uk, text as adopted)
- Regulation (EU) 2016/679 (GDPR), Art. 13, Information to be provided where personal data are collected from the data subject (legislation.gov.uk, text as adopted)
- Regulation (EU) 2016/679 (GDPR), Art. 83 as adopted by the EU, General conditions for imposing administrative fines (legislation.gov.uk copy)
- Article 29 Working Party, Guidelines on transparency under Regulation 2016/679 (WP260 rev.01, revised and adopted 11 April 2018)
- Data Protection Commission (Ireland), Decision concerning WhatsApp Ireland Ltd (20 August 2021)
- Data Protection Commission (Ireland), Data Protection Commission announces decision in WhatsApp inquiry (2 September 2021)
- Court of Justice of the European Union, press release 11/26, Case C-97/23 P WhatsApp Ireland v European Data Protection Board (10 February 2026)
- AEPD (Spain), resolution in procedure PS/00080/2023 (Chatwith.io Worldwide, S.L.)
Last checked against the source:
For information only. Not legal advice.


