Free GDPR (DSGVO) & AI-Act Compliance Check
  • Manual review by developers
  • Report in 24 hours
  • No obligation

German lawyers scan
your website in minutes.
We check it in 24 hours — free.

Since a Munich court ruling in 2022, tens of thousands of website owners have received an Abmahnung — a formal German cease-and-desist letter with a fee demand — over Google Fonts, missing cookie banners, and embedded maps. If your website serves customers in Germany or Austria, this applies to you, wherever your business is based. We tell you in 24 hours whether your site is exposed.

Check my website before a lawyer does
  • Cookie banners and consent requirements
  • Google Fonts, Google Maps, YouTube embeds
  • Impressum (legal notice) and privacy policy
  • SSL encryption and tracking scripts
  • New: AI disclosure duty (EU AI Act, from 2 August 2026)

No sales call  ·  No hidden costs  ·  Independent technical assessment

Get my free audit report

Free · 24h report · No commitment

We complete a limited number of manual audits each week. Current turnaround: within 24 hours. Technical review by developers — not legal advice.


Why it matters

The enforcement wave is already running.
Most targets didn't know they were at risk.

Specialized law firms use automated scanners — they cannot see how large your business is, only whether your website has violations. Waiting costs more than fixing it now.

€5,000

An Abmahnung costs more than the lawyer's bill

Legal fees for a single cease-and-desist letter typically run from several hundred to over €2,000. Worse: it comes with a binding declaration to cease — every repeat violation after that can trigger a contractual penalty of €5,000 or more. Fixing the issue beforehand costs a fraction.

2022

Google Fonts is a documented liability

The Munich Regional Court ruled in January 2022 (case 3 O 17493/20): dynamically loading Google Fonts transfers IP addresses without consent — a GDPR violation. Most websites still do this. Most owners don't know.

No. 1

A cookie banner isn't enough

The most common failure in current enforcement waves: the banner is there, but scripts load before consent anyway — or the equally prominent "Reject" option is missing. DSGVO and TDDDG (formerly TTDSG) require both. Existence is not compliance.


The process

How the free audit works

  1. Submit your URL

    Via the form above — takes less than a minute.

  2. Manual review

    No automated scanners. We read your source code and test your consent flow — the same way a cease-and-desist lawyer does, and more thoroughly.

  3. Report by email

    Within 24 hours. Plain language, clear prioritization, concrete next steps.

  4. If you want fixes, not just findings

    We show you exactly what it costs to implement them. Fixed price, no guessing, no pressure.


Manual vs. automated

What an automated scanner misses

If you've already run an automated scan and it came back clean, you may have a false sense of security.

Automated scanner
Manual audit by Be Alpha
Checks for cookie banner existence
Checks if it actually blocks scripts before consent is given — most banners don't
Flags Google Fonts if detected
Checks every external resource loaded on every page, including lazy-loaded and conditional scripts
Takes 30 seconds
Takes 24 hours — thorough, not just fast
Cannot test the consent flow
Tests accept, reject, and dismiss scenarios manually — the same path a lawyer's tool follows
Does not verify Impressum content
Verifies all required fields under § 5 DDG, Germany's Digital Services Act (formerly TMG) — a missing field is a violation, not a technicality

Scope

13 points that determine your legal exposure

Each item we check has a direct legal consequence. Here is what we look at and why it matters.

What we check
Why it matters
Cookie banner configuration
Missing "Reject" button = legally actionable under Germany's TDDDG (formerly TTDSG). This alone is the most common cause of cease-and-desist letters.
Tracking scripts before consent
Scripts must not fire until consent is given. Pre-consent tracking = Art. 6 GDPR violation, regardless of your banner.
Google Fonts loading source
External loading = IP transfer without consent. Munich District Court ruled this illegal in 2022. Most websites still do it.
Google Maps, YouTube, Vimeo embeds
Direct embed without a consent gate = data transfer on page load. Requires a click-to-load wrapper.
Legal notice (Impressum) completeness
Missing required fields = § 5 DDG violation. No lawyer needed to file — anyone can report it.
Privacy policy accuracy
Must match your actual tools and processors. Generic templates do not protect you — they expose you.
Contact form privacy notice
Missing notice = Art. 13 GDPR violation. The form is legally unusable without it.
SSL certificate
No SSL = "Not secure" warning in Chrome + Google ranking penalty + data integrity risk.
Security headers
Missing headers = open to clickjacking and injection. Required for technical GDPR compliance under Art. 32.
External fonts and scripts
Every external resource is a potential data transfer. Each must be audited individually.
Images and content rights
Unlicensed images = copyright claim. Common, expensive, and entirely separate from GDPR risk.
New: AI chatbots and AI content (EU AI Act Art. 50)
From 2 August 2026, chatbots must be labelled as AI and AI-generated content must be disclosed — regardless of company size. We check whether your website is affected.
Newsletter double opt-in
No confirmed opt-in = invalid consent. Every marketing email sent to an unconfirmed address = violation.

Rather check it yourself first?

The 12-point GDPR checklist as a PDF

Not ready to request the audit? Check the most important points yourself — with our compact checklist, including concrete action steps. Delivered instantly by email, free.

One email, nothing else. No newsletter, no spam. Details in our Privacy Policy.

Preview of the GDPR checklist PDF

Why Be Alpha?

No tool. No scanner. Two developers who read your code the way a cease-and-desist lawyer does.

We are developers, not lawyers — we build GDPR-compliant websites every day. We know how a German cease-and-desist lawyer reads your source code, because we read it the same way. Our report is a technical analysis, not legal advice.

Manual review

No automated scanner. We read your source code, check network requests, and test the full consent flow — including what happens when a user clicks "Reject" or closes the banner without deciding.

DACH legal focus

We audit against the rules that German-market websites are actually enforced on: the GDPR, Germany's TDDDG, the EU AI Act, and the Munich Google Fonts ruling — following the current pattern of enforcement waves.

One-stop fix

After the report, you don't need to pass the problem to other vendors. We identify, explain, and fix GDPR issues — fixed price, no surprises, no follow-up sales calls.


The People Behind the Audit

Two developers, not a call center.

No account manager, no outsourced reviewer. One of us personally reads your site and writes your report.

Altin Mullaidrizi, Co-Founder at Be Alpha

Altin Mullaidrizi

Full-Stack Developer & Co-Founder

7+ years building production websites for DACH, Swiss, and US clients — GDPR compliance and page speed built in from the start, not bolted on after.

Blin K., Co-Founder at Be Alpha

Blin K.

Full-Stack Developer & Co-Founder

7+ years fixing compliance and performance issues on live sites across German, Swiss, and US markets — this is the same review we run on our own work.


FAQ

What others ask — and what we answer directly

I already have a cookie banner — isn't that enough?
No. A cookie banner is not automatically GDPR-compliant. The typical failures: a missing "Reject" button, tracking scripts loading before consent, pre-ticked checkboxes. Existence is not the same as compliance — that is exactly what we check manually.
We're a small business. Would a cease-and-desist lawyer really target us?
Yes. Enforcement firms use automated scans — they cannot see how large your business is, only whether your website has violations. Small businesses and solo operators receive the same letters as large companies. The fine amount may vary, but the legal fees do not.
What happens if you find problems? Do I have to buy something?
No. The report is yours — implement fixes yourself, hire another developer, or ask us. If you want our help, you'll receive a transparent fixed-price quote. No pressure, no follow-up calls.
Is the audit really free?
Yes — no strings attached, no hidden contract, no subscription trap. If you want to fix things yourself after receiving the report: great. If you'd like our help, you'll get a transparent fixed-price quote.
Which types of website are eligible?
Any website targeting a German-speaking audience: WordPress, Shopify, TYPO3, Jimdo, Wix, or a custom-built site — the platform doesn't matter. DSGVO requirements apply regardless.
We're not based in Germany — does this apply to us?
Yes, if you market to customers in the EU: the GDPR follows your customers, not your registered address (Art. 3(2) GDPR). Swiss businesses additionally fall under the revised Swiss data protection act (revDSG, in force since September 2023), which has similar requirements. Our check covers both.
What does it cost if I want you to fix it?
Our full GDPR fix (audit, cookie banner setup, font and embed adjustments, updated privacy policy) starts at €399 as a one-time fee. Larger or more complex sites are quoted individually — always as a fixed price upfront.
How did you get my email address?
If we reached out cold: we used your publicly available contact details (legal notice or website) under Art. 6(1)(f) GDPR for legitimate business interest. You can object or request deletion at any time.
What is the new AI disclosure duty starting August 2026?
Article 50 of the EU AI Act applies from 2 August 2026: if you run a chatbot, it must be identifiable as AI. If you publish AI-generated text or images, that must be disclosed. The duty applies regardless of company size. Our check includes whether your website is affected — and what specifically to do about it.
Why doesn't your own website show a cookie banner?
Because it sets no cookies. No tracking, no external services, all fonts self-hosted — a banner would be pure decoration. That is exactly how we audit your website too: what actually loads is what counts, not what is displayed. You are welcome to verify this in our source code at any time.
What happens to my data?
We use your information solely to process your request. No newsletters, no sharing with third parties. Details in our Privacy Policy.

Get started

Get your free GDPR audit report

In your inbox within 24 hours. No sales calls, no commitment.

  • Manual review by developers — not an automated scanner
  • Report with concrete fixes, not just a list of errors
  • Free and no obligation — even if you implement it yourself
  • Full fix available from €399 as a fixed price

Finding issues doesn't mean you've done something wrong. Most websites have at least one. The report tells you what to fix — the implementation is easier than the legal risk.

Get my free audit report

Free · 24h report · No commitment

We complete a limited number of manual audits each week. Current turnaround: within 24 hours. Technical review by developers — not legal advice.

Check your website before a lawyer does.

Get my free audit report

Or email us directly: hello@bealpha-digital.com

Before you go

Take the GDPR checklist with you

The 12 points cease-and-desist firms check first — as a free PDF with concrete steps to check yourself. We'll send it to you instantly by email.

You'll receive the checklist once by email. No newsletter, no spam. More in our Privacy Policy.