Methodology
The review no longer relies on HTML source alone. We combine a static external check, a real-browser deep scan and evidence about server-side areas that cannot be observed from outside.
Three review layers
Important: The score measures data minimisation within the documented review scope. It is not a GDPR certification or a general security rating.
100 points across five areas
1. Quick check – statically observable from outside
| Criterion | Weight | Scoring | Maximum score after failure |
|---|---|---|---|
| Third-party connections | 7 | pass / not_applicable = 100%; fail / unknown = 0% | – |
| Tracking | 12 | pass / not_applicable = 100%; fail / unknown = 0% | 50/100 |
| Cookies | 5 | pass / not_applicable = 100%; fail / unknown = 0% | – |
| Browser storage | 5 | pass / not_applicable = 100%; fail / unknown = 0% | – |
| Fingerprinting | 14 | pass / not_applicable = 100%; fail / unknown = 0% | 35/100 |
The external check fetches the site over HTTPS and evaluates statically visible cookies, embedded third-party resources, known tracking indicators, browser-storage indicators and fingerprinting indicators. It cannot prove what is stored internally on a server.
3. Server-side and operator-dependent criteria
| Criterion | Weight | Factors | Cap when IP data is stored |
|---|---|---|---|
| Access logs | 15 | no storage of visitor IP / identifiers = 100% present without visitor IP / identifiers = 85% stores visitor IP / identifiers = 0% unknown / not checked = 0% | 60/100 |
| Error logs | 8 | no storage of visitor IP / identifiers = 100% present without visitor IP / identifiers = 90% stores visitor IP / identifiers = 0% unknown / not checked = 0% | – |
| Application logs | 10 | no storage of visitor IP / identifiers = 100% present without visitor IP / identifiers = 85% stores visitor IP / identifiers = 0% unknown / not checked = 0% | 65/100 |
| Reverse proxy / CDN | 10 | not present = 100% present without visitor IP / identifiers = 90% processes visitor IP but does not forward it to origin = 60% processes visitor IP and forwards it to origin = 30% stores/processes visitor IP / identifiers = 0% unknown / not checked = 0% | 55/100 |
| Forms | 7 | no storage of visitor IP / identifiers = 100% present without visitor IP / identifiers = 90% stores visitor IP / identifiers = 0% unknown / not checked = 0% | – |
| Security / anti-spam systems | 7 | no storage of visitor IP / identifiers = 100% present without visitor IP / identifiers = 85% stores visitor IP / identifiers = 0% unknown / not checked = 0% | – |
Calculation
Each criterion has a fixed weight. Its points equal weight × factor. The result is normalised to 100. Severe findings can additionally cap the maximum score. Unknown answers earn no quality points and reduce review coverage.
Score levels
| 90–100 | 5/5 · very high data minimisation |
|---|---|
| 75–89 | 4/5 · high data minimisation |
| 55–74 | 3/5 · moderate data minimisation |
| 35–54 | 2/5 · limited data minimisation |
| 15–34 | 1/5 · low data minimisation |
| 0–14 | 0/5 |
History and methodology versioning
For published sites, the score, coverage, category results, methodology version and review time are stored as history snapshots. Older values therefore remain attributable to the methodology used at the time.
2. Deep scan – actual browser behaviour
The deep scan is the second and much deeper review layer. It loads up to 12 internal pages in headless Chromium. This shows not only what the source code declares, but what actually happens after JavaScript executes. A tracker loaded dynamically can therefore become visible even if it was absent from the original HTML.
- runtime requests and third-party hosts,
- cookies after JavaScript execution,
- LocalStorage, SessionStorage and IndexedDB,
- service workers and external iframes,
- Fetch, XHR, sendBeacon and WebSockets,
- runtime use of selected fingerprinting-relevant APIs,
- forms and external form targets.
The deep scan remains deliberately passive: it does not submit forms, create accounts, confirm purchases or follow action/logout/delete/download links or internal URLs with query strings. Deep-scan findings currently provide additional review evidence and do not yet change the public score automatically.
Re-checks
Published websites are periodically checked again from the outside. The public record shows the latest check and the next scheduled check. Changes to private server-side settings still require operator evidence or manual review.
Limitations
- A static external check is not a complete browser/JavaScript audit.
- Internal server logs cannot reliably be ruled out externally.
- Provider or infrastructure processing may occur independently of the website operator.
- A high score only describes the published scope and point in time.
Methodology v1.0.0 · Updated 30 September 2026