The GDPR Kit scans your website, detects your cookies and trackers, and generates four ready-to-use compliance documents: a privacy policy, cookie policy, consent banner code and data processing record — all tailored to what your site actually uses.
The GDPR Kit scans your website URL and detects all cookies and third-party trackers present. It categorises them as essential, functional, analytics or marketing. It then generates all four compliance documents pre-populated with the actual trackers found on your site — not a generic template.
Create two new pages on your website: /privacy-policy and /cookies. Paste the generated content into each page. Add links to both pages in your site footer — they must be accessible from every page.
Paste the consent banner HTML as the first element inside your body tag. Test it on a fresh browser session — you should see the banner before any analytics fires. Check in your browser developer tools (Network tab) that GA4 or your analytics platform does not appear until after you click Accept.
If you use Google Tag Manager, create a Custom Event trigger listening for the consent_accepted event fired by the banner. Move all non-essential tags (analytics, advertising, heatmaps) to fire only on this trigger.
Keep the generated RoPA in your internal documentation. You do not publish this — it is an internal record required under Article 30 that you must produce on request from the ICO.
Run the GDPR Kit and get actionable results in minutes. Pay as you go.
Generate GDPR Kit →