Compliance · Accessibility · Regulation Radar

Your site's regulatory exposure.
Article by article, evidence-based reporting.

Evidalux is the regulatory compliance platform for the web.

No card Self-hosted SaaS Data in 🇳🇱 NL — GDPR
34
Compliance plugins
5
Jurisdictions (EU · UK · US · CA · TR)
34
UI languages (audit reports in EN)
6
Alert channels (Slack/Discord/Teams/Telegram/Email/Webhook)
10k
Pages per site crawl (MinHash near-dup)

Compliance

34 plugins audit one site against the laws below and return an article-by-article matrix. Every finding carries a confidence label, the method behind it and its limitations — we never issue a bare "compliant" stamp.

🇪🇺 European Union — 13

  • GDPR — Reg (EU) 2016/679
  • ePrivacy — Dir 2002/58/EC
  • Digital Services Act — Reg (EU) 2022/2065
  • AI Act — Reg (EU) 2024/1689
  • European Accessibility Act — Dir (EU) 2019/882
  • e-Commerce Directive — Dir 2000/31/EC
  • Consumer Rights Directive — Dir 2011/83/EU
  • Omnibus Directive — Dir (EU) 2019/2161
  • Empowering Consumers (green claims) — Dir (EU) 2024/825
  • Price Indication Directive — Dir 98/6/EC
  • Geo-blocking — Reg (EU) 2018/302
  • Political Advertising — Reg (EU) 2024/900
  • ODR — Reg (EU) 524/2013 (repealed; stale links flagged)

🇬🇧 United Kingdom — 4

  • UK GDPR (as amended by DUAA 2025)
  • Data Protection Act 2018
  • PECR 2003
  • Digital Markets, Competition and Consumers Act 2024

🇺🇸 United States — 12

  • CCPA / CPRA
  • COPPA — 16 CFR Part 312
  • CIPA — Cal. Penal Code §630 et seq.
  • VPPA — 18 U.S.C. §2710
  • CalOPPA — Cal. B&P §22575
  • FTC Act §5
  • Virginia CDPA
  • California AB 2013 — AI training data
  • California SB 942 — AI Transparency Act
  • California SB 1001 — bot disclosure
  • Texas TRAIGA (HB 149)
  • Utah AI Policy Act (SB 149)

🇨🇦 Canada — 2

  • PIPEDA
  • Quebec Law 25

🇹🇷 Türkiye — 7

  • KVKK — Law 6698
  • E-Commerce Law 6563
  • Distance Contracts Regulation
  • Price Tag Regulation
  • Commercial Electronic Messages / İYS
  • TCC Art. 1524 — mandatory website content
  • Accessibility Circular 2025/10 (WCAG 2.2)

38 laws, 5 jurisdictions. Plugins are jurisdiction-agnostic: one finding can cite GDPR Art. 13 and its UK GDPR / CCPA / Quebec / KVKK counterparts at once. Scans cover the whole site, not one URL — up to 10,000 pages with near-duplicate collapsing.

Regulation Radar

A scan tells you where you stand today. Regulation Radar answers the other half: the law just changed — does it touch anything we audited on your site?

It follows EUR-Lex, EDPB and the UK / US / CA / TR regulator feeds, classifies each change into plain English, and maps it to the exact checks that change makes stale. Then it matches those checks against the sites you actually audited. If none of your sites are affected, you hear nothing — no newsletter to translate into work.

When something is affected, one click re-audits those sites with those checks and returns a delta: the requirements that fail now and did not before.

AI classifications are labelled suspected and ship with their method and limitations. Not legal advice. How Regulation Radar works →

Leads for Advisors Early access

For compliance consultants and legal advisors: we surface websites our scans found non-compliant, as leads.

You get the site, the findings behind it and the articles they fall under — so the first conversation starts from evidence rather than a cold pitch.

Contacting the site owner is the advisor's own responsibility, as is any outreach's compliance with local marketing and data protection rules. We surface the finding; we do not contact anyone on your behalf.

This one is in development, not live yet — the card is here so you know it is coming. Ask for early access →

Who it's for

Anyone who is accountable for a site's legal surface

Digital agencies

Manage dozens of client sites from one panel. White-label reports, sub-tenants, per-client logo + accent.

In-house legal / DPO

Continuous monitoring with Regulation Radar: when a regulator moves, the affected plugins re-run and you get the diff — not a newsletter you have to translate into work.

Web developers

Consent banners, imprints and accessibility statements are easy to ship wrong. Scheduled scans catch the regression before the regulator's complaint form does.

Compliance / legal

Automatic GDPR + EU Tier 1 checks (DSA · AI Act · Omnibus · EmpCo · EAA · ePrivacy · ODR · Geo-blocking); findings also cite parallel UK GDPR / CCPA / Quebec references where they apply. Confidence taxonomy + EDPB Guidelines references; we never claim "this site is compliant."

Compliance advisors

Run a law-scoped audit for a single client, export the article-by-article matrix, and hand over a report whose every row states how it was measured and how confident we are.

Compliance + Radar

One scan, one panel, one evidence trail.

Compliance (GDPR + EU Tier 1 + WCAG 2.2) plus Regulation Radar — continuous law-change monitoring that re-scans the plugins a change actually touches.

compliance: cookie_consent
CRITICAL — Trackers loaded before consent
6 tracker families detected
Google Analytics 4PRE-CONSENT
Google Tag ManagerPRE-CONSENT
Microsoft ClarityPRE-CONSENT
Meta PixelPRE-CONSENT
GDPR Art. 7 + ePrivacy Recital 3011 refs
Compliance 🇪🇺 EU Tier 1

GDPR + EU Tier 1 — 12 laws in one scan

Built for SMBs and agencies that sell into the EU, UK, US, Canada, and Türkiye. Our 33 compliance plugins are jurisdiction-agnostic — a single finding can carry parallel references (GDPR Art. 13 alongside UK GDPR / CCPA / Quebec Law 25 / KVKK where they apply). Our formal article dataset covers 38 laws across 5 jurisdictions; confidence taxonomy + EDPB Guidelines references inline in every report.

  • DSA Art. 25 dark patterns, AI Act Art. 50 chatbot disclosure, Omnibus 2019/2161 price indication
  • EAA Art. 4(1)(c) accessibility statement, ODR, Imprint, EmpCo (2024/825), Pay-or-Consent
  • Pre-consent tracker detection (GA4/GTM/Clarity), IAB TCF v2.2 decode, cross-border transfer safeguards
  • We NEVER claim "this site is compliant" — only evidence + methodology + limitations
Agency tooling

White-label, multi-tenant, agency-ready

Ship to your clients under your own brand, not "Evidalux." Each sub-tenant has its own logo, accent color, custom domain. Your clients stay your clients.

  • Sub-tenant hierarchy (agency → up to 50 client tenants)
  • White-label: brand_name + logo + accent_color + custom_domain
dashboard: youragency.com
A
Your Agency
12 sub-clients · 47 sites
→ ACME Holding14 sites · 88 score
→ Northwind Retail3 sites · 76 score
→ Lumen Studio1 site · 92 score
→ NewsCorp1 site · 41 score
→ Test Services2 sites · 63 score
34 compliance plugins

What each plugin checks, and against which law

Every plugin below is registered and runs today. Names, legal references and scope are kept in step with the plugin registry by hand — if you find a row that disagrees with a report you received, that is a bug and we want to hear about it.

Accessibility (WCAG 2.2) WCAG 2.2 AA · EAA Annex I Runs axe-core in a real Chromium and reports every violated rule. The same rule failing on 80 pages collapses to one row with the affected URLs behind it.
EAA Legal Mapping EAA — Dir (EU) 2019/882 Translates the engineering-level axe violations into the EAA articles they breach, so legal reads obligations instead of CSS selectors.
Accessibility Statement EAA Art. 4(1)(c) + Annex VI Checks for a published accessibility statement and whether it declares conformance level, known non-conformities, an alternative-format contact and an assessment date.
Advertising Transparency DSA Art. 26 Tests whether ads are identifiable as ads in real time and whether the party on whose behalf they run is named.
Robust Age Assurance UK OSA 2025 · DSA Art. 28 · COPPA · TX SCOPE · FL HB 3 · Quebec Art. 14 Goes beyond a self-declared “are you 18?” gate — which several of these laws call insufficient — and looks for an actual third-party age-assurance vendor.
AI Disclosure (static) AI Act Art. 50(1) Detects chatbots and AI assistants, then checks whether the user is told they are talking to a machine.
AI Disclosure (visual) AI Act Art. 50(2) + 50(4) Takes a screenshot and asks a vision model whether synthetic media and deep-fakes carry the disclosure the article requires.
AI Training-Data Transparency California AB 2013 Checks whether a generative-AI developer publishes the dataset documentation summary the statute requires.
Content Credentials (C2PA) AI Act Art. 50(2) · California SB 942 Fetches a sample of the page's media and detects an embedded C2PA provenance manifest by its JUMBF structure — the marking mechanism both laws accept.
Child Consent GDPR Art. 8 · COPPA Decides whether the site addresses minors and, if it does, whether an age or parental-consent gate exists at all.
CIPA / VPPA Pixel Wiretap CIPA §631 / §638.51 · VPPA §2710 Records every outbound request before any consent interaction and flags session-replay and video pixels — the two US litigation waves that are web-observable.
Cookie Consent GDPR Art. 6-7 · ePrivacy Art. 5(3) Loads the page in a fresh browser profile and lists the trackers that fire before the visitor touches the banner, plus the banner's own quality.
Cross-Border Transfer GDPR Chapter V (Art. 44-49) Identifies non-EU processors loaded by the page, then reads the privacy policy for the SCC / BCR / adequacy / DPF safeguard that would justify them.
Dark Pattern (static) DSA Art. 25 · EDPB Guidelines 03/2022 Looks for pre-ticked consent, false-urgency copy and confirmshaming button text in the served HTML.
Dark Pattern (visual) DSA Art. 25 Compares the visual prominence of accept and reject controls in a screenshot — the asymmetry a text scrape cannot see.
Data Subject Request GDPR Art. 12 + 15 Checks that the rights channel actually works: a contact address, a form or request page, and the rights themselves named — not just “you have rights.”
DPO Contact GDPR Art. 37-39 Reads the linked privacy policy for a named data protection officer, a dedicated address or a working contact route.
Greenwashing (static) EmpCo Dir (EU) 2024/825 · FTC Green Guides Finds environmental and sustainability claims in body text and classifies whether each one is substantiated on the page.
Greenwashing (visual) EmpCo Dir (EU) 2024/825 Catches the green claims that live in badges, seals and imagery rather than in text.
EU Representative GDPR Art. 27 For controllers outside the EU that serve EU data subjects: is an EU representative designated and findable?
Geo-blocking Surface Reg (EU) 2018/302 Surfaces the single-region-observable signals of nationality, residence or establishment discrimination — country redirects, blocked checkouts, restricted payment options.
IAB TCF v2.2 (static) IAB TCF v2.2 Detects whether a TCF consent surface is installed at all, from the served markup.
IAB TCF v2.2 (live) IAB TCF v2.2 Invokes window.__tcfapi in a real browser and reads the returned TCData — purpose-level consent as the ad-tech chain actually receives it.
Legal Disclosure / Imprint e-Commerce Dir 2000/31 Art. 5 · TCC Art. 1524 Finds the imprint page and checks the minimum disclosure set: identity, geographic address, contact details and registration data.
Marketing Opt-in GDPR Art. 7 + 21 · ePrivacy Art. 13 · İYS Flags pre-ticked marketing boxes and opt-out-shaped signup — invalid consent under Planet49 (C-673/17).
EU ODR Link Reg (EU) 524/2013, repealed by 2024/3228 The ODR platform closed on 20 July 2025. This flags the stale link still pointing at it, which now sends consumers to a dead service.
Pay-or-Consent Wall EDPB Opinion 28/2024 · GDPR Art. 7(4) Detects the “consent or pay” model the EDPB held generally fails the freely-given-consent standard.
Political Advertising Reg (EU) 2024/900 Art. 11-12 Checks political ads for the required “this is a political advertisement” statement, the sponsor's identity and the per-ad transparency notice.
Pricing Indication Omnibus Dir 2019/2161 · Price Indication Dir 98/6 Tests discount claims against the 30-day prior-price rule and checks unit-price labelling.
Privacy Policy Content GDPR Art. 13 Reads the policy for its four required pillars: processing purposes, lawful basis, retention period and data subject rights.
Purchase Disclosure Consumer Rights Dir 2011/83 Art. 8(2) + 9 Checks that the order button states the payment obligation explicitly and that the right of withdrawal is disclosed before purchase.
Ranking & Marketplace Transparency Omnibus / UCPD Art. 7(4a) · CRD Art. 6a Looks for paid-placement labelling on listing surfaces and, on marketplaces, disclosure of trader status and the main ranking parameters.
Required Policy Pages GDPR Art. 13 · UK GDPR · CCPA · Quebec Law 25 Walks the homepage link graph for the four pages the law expects to be reachable: privacy, cookies, terms and the data-request route.
Review Authenticity Omnibus / UCPD Annex I 23b · UK DMCC 2024 Checks whether a site claiming genuine consumer reviews shows any sign of the verification steps that claim legally requires.

Regulation Radar adds no scan plugins of its own — it watches regulator feeds and re-runs the plugins a change actually touches.

Pricing

Three tiers · One meter (scan credits)

No card on Free. Regulation Radar is an add-on on Solo and included on Agency.

Free
€0/mo
One site, one scan at a time — for getting to know the product.
  • 5 scan credits / month
  • 1 URL · 1 user
  • Compliance module (34 plugins)
  • Up to 5 pages per site scan
  • Technical + client report
  • Regulation Radar
  • White-label
Start free
Agency
€199/mo
Agencies and advisors running a client portfolio.
  • 2,500 scan credits / month
  • 100 URLs · 10 users
  • Compliance + Regulation Radar included
  • Up to 500 pages per site scan
  • White-label + 50 sub-tenants
  • Custom domain
  • 500 LLM credits / month
  • Also covers all four PresenceLux modules — one plan, both products
Start Agency

A scan costs one credit. Need more than a tier allows, or SSO / on-prem / a custom DPA? Talk to us.