Skip to content

Compliance

Does my site need a privacy policy

Under the GDPR a privacy notice is mandatory the moment you process any personal data, which includes an email signup or an analytics cookie. It is also a hard requirement for Google Ads, the Apple and Google app stores, and Stripe onboarding, so this blocks distribution as well as creating legal exposure.

What 13x checks

This is rule compliance.privacy-policy in the public registry: Privacy policy is linked. It runs on every audit, against the pages we actually fetched, and its result is derived from the response rather than estimated.

Surface
Compliance
Score weight
18 of the readiness score
Scope
Runs on every audited page
Applies
To every site

Registry version 2026-07-30. Every rule is published, and the audit is deterministic — the same page produces the same finding every time.

The fix

The same text the audit hands you when this check fails on your own site.

Publish a privacy notice and link it from your global footer so it is reachable from every page.

It has to state, at minimum: who the controller is, what data you collect, why, on what legal basis, who you share it with, how long you keep it, and how someone exercises their rights.

13x does not generate legal text. Use a reputable generator such as iubenda, Termly or eRecht24, or a lawyer, then link the result at /privacy. What this check verifies is that the page exists and loads.

Does your site have this problem?

13x checks this and 112 others against your live URL in about 30 seconds. No account, and every finding comes with the fix for your framework.

No signup. Results in 30 seconds.

More compliance checks