Methodology

The review no longer relies on HTML source alone. We combine a static external check, a real-browser deep scan and evidence about server-side areas that cannot be observed from outside.

Goal: to get as close as practical to the website’s actual behaviour without submitting forms, creating accounts or performing invasive tests. Current methodology: v1.0.0.

Three review layers

1. Quick checkExamines HTML, headers, cookies, external resources and statically visible tracking/storage indicators.
2. Deep scanRuns Chromium and observes real requests, cookies, storage, service workers, iframes and selected browser APIs.
3. Server reviewAssesses logs, proxy/CDN, forms and security systems using operator information and evidence.

Important: The score measures data minimisation within the documented review scope. It is not a GDPR certification or a general security rating.

100 points across five areas

Browser & tracking43 points
Server & application logs33 points
Proxy / CDN10 points
Forms7 points
Security / anti-spam7 points

1. Quick check – statically observable from outside

CriterionWeightScoringMaximum score after failure
Third-party connections7pass / not_applicable = 100%; fail / unknown = 0%–
Tracking12pass / not_applicable = 100%; fail / unknown = 0%50/100
Cookies5pass / not_applicable = 100%; fail / unknown = 0%–
Browser storage5pass / not_applicable = 100%; fail / unknown = 0%–
Fingerprinting14pass / not_applicable = 100%; fail / unknown = 0%35/100

The external check fetches the site over HTTPS and evaluates statically visible cookies, embedded third-party resources, known tracking indicators, browser-storage indicators and fingerprinting indicators. It cannot prove what is stored internally on a server.

3. Server-side and operator-dependent criteria

CriterionWeightFactorsCap when IP data is stored
Access logs15no storage of visitor IP / identifiers = 100%
present without visitor IP / identifiers = 85%
stores visitor IP / identifiers = 0%
unknown / not checked = 0%
60/100
Error logs8no storage of visitor IP / identifiers = 100%
present without visitor IP / identifiers = 90%
stores visitor IP / identifiers = 0%
unknown / not checked = 0%
–
Application logs10no storage of visitor IP / identifiers = 100%
present without visitor IP / identifiers = 85%
stores visitor IP / identifiers = 0%
unknown / not checked = 0%
65/100
Reverse proxy / CDN10not present = 100%
present without visitor IP / identifiers = 90%
processes visitor IP but does not forward it to origin = 60%
processes visitor IP and forwards it to origin = 30%
stores/processes visitor IP / identifiers = 0%
unknown / not checked = 0%
55/100
Forms7no storage of visitor IP / identifiers = 100%
present without visitor IP / identifiers = 90%
stores visitor IP / identifiers = 0%
unknown / not checked = 0%
–
Security / anti-spam systems7no storage of visitor IP / identifiers = 100%
present without visitor IP / identifiers = 85%
stores visitor IP / identifiers = 0%
unknown / not checked = 0%
–

Calculation

Each criterion has a fixed weight. Its points equal weight × factor. The result is normalised to 100. Severe findings can additionally cap the maximum score. Unknown answers earn no quality points and reduce review coverage.

Score levels

90–1005/5 · very high data minimisation
75–894/5 · high data minimisation
55–743/5 · moderate data minimisation
35–542/5 · limited data minimisation
15–341/5 · low data minimisation
0–140/5

History and methodology versioning

For published sites, the score, coverage, category results, methodology version and review time are stored as history snapshots. Older values therefore remain attributable to the methodology used at the time.

2. Deep scan – actual browser behaviour

The deep scan is the second and much deeper review layer. It loads up to 12 internal pages in headless Chromium. This shows not only what the source code declares, but what actually happens after JavaScript executes. A tracker loaded dynamically can therefore become visible even if it was absent from the original HTML.

  • runtime requests and third-party hosts,
  • cookies after JavaScript execution,
  • LocalStorage, SessionStorage and IndexedDB,
  • service workers and external iframes,
  • Fetch, XHR, sendBeacon and WebSockets,
  • runtime use of selected fingerprinting-relevant APIs,
  • forms and external form targets.

The deep scan remains deliberately passive: it does not submit forms, create accounts, confirm purchases or follow action/logout/delete/download links or internal URLs with query strings. Deep-scan findings currently provide additional review evidence and do not yet change the public score automatically.

Re-checks

Published websites are periodically checked again from the outside. The public record shows the latest check and the next scheduled check. Changes to private server-side settings still require operator evidence or manual review.

Limitations

  • A static external check is not a complete browser/JavaScript audit.
  • Internal server logs cannot reliably be ruled out externally.
  • Provider or infrastructure processing may occur independently of the website operator.
  • A high score only describes the published scope and point in time.

Methodology v1.0.0 · Updated 30 September 2026