Compliance Tools
Compliance and regulatory tools for GDPR, HIPAA, PCI-DSS, and other standards.
Accessibility Statement Generator
Generate an accessibility statement that carries every element the EU Web Accessibility Directive and Section 508 expect, including the honest disclosure of known non-conformances.
ADA Compliance Checklist
Ensure your website meets ADA standards for accessibility.
Ads.txt Generator
Authorize who can sell your ad inventory.
Age Verification Requirement Checker
Work out which age assurance obligations apply to an online service across the UK Online Safety Act, the Age Appropriate Design Code, COPPA, GDPR Article 8 and state laws, and what level of assurance each demands.
App-ads.txt Generator
Authorize ad sellers for mobile apps.
Asset Classification Tool
Help classify data assets (Public, Internal, Confidential, Restricted).
Audit Evidence Tracker
Track and organize audit evidence collection for compliance audits.
Audit Finding Severity
Calculate severity from Likelihood and Impact.
Audit Readiness Planner
Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Audit Sample Size Calculator
Calculate the sample size needed to test a control at a chosen confidence level and tolerable deviation rate, using exact binomial bounds rather than a lookup table, with the achieved upper deviation limit shown.
BCP RTO/RPO Calculator
Estimate the business cost of an outage from recovery time objective, recovery point objective, revenue per hour and data re-entry cost, to justify backup and DR investment.
Brazil LGPD Checklist
Generate a LGPD checklist for legal basis, notices, rights handling, and vendor management.
Breach Notification Deadline Calculator
Work out every notification deadline that follows a personal data breach across GDPR, NIS2, DORA, HIPAA, SEC and other regimes, counted in hours, business days or calendar days from the moment you specify.
CCPA Checklist
Interactive checklist for California Consumer Privacy Act.
China PIPL Checklist
Generate a PIPL checklist including notices, consent, cross-border transfers, and rights handling.
Compliance Calendar
Enter your frameworks and a start date to lay out a year of recurring compliance obligations (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF) with dates and an .ics download.
Compliance Gap Heatmap
Rate each control domain per framework and get a colour heatmap, per-framework readiness bars and a ranked gap list. Saved locally, exportable as CSV. You supply the scores.
Compliance KPI Dashboard
Generate compliance KPI dashboards for executive reporting.
Compliance Map Visualizer
A new tool extracted from the codebase.
Compliance Readiness Score
Score readiness against a compliance framework across policy, technical controls and evidence, and identify the gaps that block certification.
Compliance Req Finder
Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
Control Effectiveness
Score controls based on design and operation.
Control Testing Frequency Planner
Derive a testing frequency for each control from its risk and operating cadence, allocate the sample across the period, and produce a dated test calendar for the year.
Cookie Banner Generator
Generate a GDPR and ePrivacy compliant cookie consent banner. Accept, reject and per-category toggles, no signup, no monthly fee. Copy the HTML, CSS and JS.
Cookie Consent Banner Generator
Build a cookie consent setup with Google Consent Mode v2 defaults, per-category tag blocking and a consent API. Free, self-hosted, no CMP subscription.
Cookie Consent Text Generator
Generate cookie consent banner text and privacy-friendly wording for essential/analytics/ads cookies (non-legal template).
Cookie Lifespan Auditor
Paste the cookies your site sets and check each one against expiry guidance, Secure and SameSite flags, and the 13-month consent duration expected by European regulators.
Cookie Policy Generator
Generate a cookie policy page listing every cookie, its purpose, provider and retention. Covers GDPR, ePrivacy and CCPA disclosure. Free, no signup.
COPPA Checklist
Checklist for Children's Online Privacy Protection Act.
Crypto Algorithm Compliance Checker
Paste the cipher suites, hashes and key sizes your systems use and see which are FIPS-approved, which NIST has deprecated or disallowed, and which PCI DSS no longer accepts.
CSP Generator
Create a CSP header configuration to prevent XSS.
CSRD Readiness Checker
Score readiness for the Corporate Sustainability Reporting Directive across scope, double materiality, data availability and assurance, with the items that cannot be traded against a good score elsewhere.
Data Classification Wizard
Build a data classification scheme (Public, Internal, Confidential, Restricted) with definitions and handling rules.
Data Locality Checker
Check residency rules for specific countries.
Data Retention Finder
Determine recommended data retention periods by data type.
Data Retention Policy Generator
Build a records retention schedule from your own periods, with calculated disposal dates and structural checks for missing bases, absent trigger events, duplicates and open-ended retention.
Data Transfer Mechanism Selector
Work out which Chapter V transfer mechanism covers a specific international data transfer, which standard contractual clause module applies, and whether a transfer impact assessment is still required.
DORA Compliance Checklist
Generate a DORA checklist for ICT risk, incident reporting, resilience testing, and third-party management.
DPA Article 28 Clause Checker
Paste a data processing agreement and check it against every mandatory term Article 28(3) requires, with the specific wording each obligation needs and what is missing.
DSAR Deadline Calculator
Calculate the response deadline for a data subject access request under GDPR, UK GDPR, CCPA, LGPD, PIPL and other regimes, including whether an extension applies and how the clock is counted.
E-Verify Checklist
Checklist for employment eligibility verification.
Email Privacy Checker
Check if email addresses are visible in plain text on a webpage.
Employee Access Risk
Evaluate risk levels of employee access permissions.
EU AI Act Risk Classifier
Classify an AI system into minimal/limited/high/unacceptable risk using a simplified questionnaire.
Exception Builder
Draft auditor-friendly justifications for exceptions.
FACTA Disposal Checklist
Checklist for proper disposal of consumer report information.
FERPA Compliance Checklist
Checklist for Family Educational Rights and Privacy Act.
GDPR Checklist
Interactive checklist to track your GDPR compliance progress.
GDPR DPIA Generator
Build a GDPR Article 35 Data Protection Impact Assessment: necessity, proportionality, risk scoring and mitigations. Structured DPIA template, free.
GDPR DSAR Email Template
Generate a GDPR data subject access request (DSAR) email template.
GDPR Fine Exposure Calculator
Work out which GDPR fining cap applies to an infringement, what the statutory maximum is for your turnover, and where the EDPB fining methodology would place a starting amount before aggravating and mitigating factors.
GDPR Lawful Basis Selector
Determine appropriate GDPR lawful basis for data processing activities.
Gift and Hospitality Threshold Checker
Check a proposed gift or hospitality against your thresholds, the recipient cumulative limit, public official rules and tender timing, and see whether it needs approval, refusal or only a register entry.
GLBA Compliance Checklist
Checklist for Gramm-Leach-Bliley Act compliance.
Google Safe Browsing Checker
Check whether Google Safe Browsing currently lists a URL for malware, phishing or unwanted software, and what to do if your own site is flagged.
HIPAA Checklist
Self-assessment checklist for HIPAA compliance.
HIPAA Risk Assessment Tool
Assess HIPAA compliance risks for healthcare organizations.
HIPAA Safeguard Validator
Validate HIPAA technical, physical, and administrative safeguards.
Humans.txt Generator
Create a humans.txt file to credit the team behind the site.
India DPDP Act Checklist
Generate a DPDP checklist covering notice/consent, retention, DSAR, security safeguards, and vendor management.
ISO 27001 Checklist
Step-by-step checklist for ISO 27001 certification readiness.
ISO 27001 Gap Auto-Mapper
Map your current controls to ISO 27001 requirements and identify gaps.
ISO Clause Mapper
Determined if specific ISO clauses apply to your scope.
ISO Clause Mapping Tool
Map business processes to ISO 27001 Annex A controls.
K-Anonymity Calculator
Paste a CSV, choose the quasi-identifier columns, and measure k-anonymity, l-diversity and the number of unique records that could be re-identified, entirely in your browser.
K8s Manifest Auditor
A new tool extracted from the codebase.
Legitimate Interest Assessment Builder
Work through the purpose, necessity and balancing tests for relying on legitimate interests, with a scored balancing outcome and a copyable assessment record.
NIS2 Readiness Checklist
Generate a practical NIS2 readiness checklist template for governance, monitoring, IR, and supply chain.
NIST CSF Checklist
Checklist based on the NIST Cybersecurity Framework.
Password Policy Compliance Checker
Check a password policy against NIST SP 800-63B, PCI DSS 4.0 and CIS Benchmarks, including the rules that changed and the composition and rotation requirements that current guidance now advises against.
PCI DSS SAQ Selector
Answer a few questions about how your business handles card data and find which PCI DSS self-assessment questionnaire applies, how many requirements it contains, and what would move you to a shorter one.
PCI-DSS Checklist
Interactive checklist of the 12 PCI DSS requirements for handling card data, with progress saved in your browser. Covers what changed in version 4.0.
Permissions Policy Generator
Generate HTTP Permissions-Policy header to control browser features.
Policy Gap Identifier
Identify missing critical security policies based on frameworks.
Policy Lifecycle Tracker
Track when each security and compliance policy was last reviewed, set an annual, quarterly or two-year cycle, and see which reviews fall due within 30 days.
Privacy by Design Scorer
Score a system or feature against data protection by design and by default, covering defaults, technical measures, transparency and lifecycle, with the essential requirements that cannot be traded away.
Privacy Notice Template
Generate a simple privacy notice template with data categories and contact information.
Privacy Policy Checker
Check if your policy covers standard requirements (GDPR/CCPA basics).
Records Destruction Certificate Generator
Generate a certificate of destruction that records what was destroyed, when, by which method, under whose authority and against which retention rule, with checks for the fields auditors ask about.
Referrer Policy Generator
Configure how much referrer information is sent with requests.
Retention Schedule Conflict Checker
Paste your retention schedule and find rules that contradict each other, overlapping record types with different periods, missing legal bases and categories that no rule covers.
Risk Register Generator
Generate a pre-filled risk register template.
ROPA Article 30 Generator
Build an Article 30 record of processing activities from your activity list, with every mandatory field checked, gaps flagged, and a copyable record in the structure supervisory authorities expect.
S3 Policy Checker
A new tool extracted from the codebase.
Sanctions Name Screening Matcher
Compare a customer list against a watchlist you supply using Jaro-Winkler, token and phonetic matching, with a tunable threshold and a report of which technique produced each hit.
Saudi PDPL Checklist
Generate a PDPL checklist for data inventory, notices, cross-border transfers, and security safeguards.
Section 508 Checklist
Accessibility checklist for US Federal agencies.
Security.txt Generator
Generate a security.txt file so researchers can report vulnerabilities to the right place.
SOC 2 Control Coverage Checker
Check which SOC 2 controls you've implemented across TSC categories.
SOC 2 Control Mapper
Map SOC 2 controls to identifying teams.
SOC 2 Evidence Readiness
Interactive checklist to gauge your SOC 2 evidence readiness.
SOX Compliance Checklist
Sarbanes-Oxley Act compliance checklist for public companies.
SRI Hash Generator
Generate subresource integrity hashes so the browser verifies a CDN script has not been altered before executing it.
SSL Checker
Check a site's TLS certificate: expiry, issuer, chain completeness, hostname match and protocol support.
Terms & Conditions Generator
Generate a T&C agreement for your website.
Training Coverage Checker
Check if your training program covers required compliance topics.
Transfer Impact Assessment Builder
Build and score a transfer impact assessment covering the transfer map, the destination law analysis, supplementary measures and the reasoned conclusion, with the elements that cannot be omitted.
Vendor Compliance Risk Matrix
Assess vendor compliance risks across multiple frameworks.
Vendor Risk Tiering Calculator
Score a vendor on data sensitivity, access, criticality and concentration to produce a defensible risk tier, the due diligence depth it warrants, and the review frequency that follows.
WCAG Checklist
Checklist for Web Content Accessibility Guidelines.
Whistleblower Policy Checklist
Check a whistleblowing programme against the EU Whistleblower Directive, covering channels, the seven-day and three-month deadlines, confidentiality, the reversed burden of proof and retaliation protection.
No tools found
Try a different search term
Other Categories
View AllAbout Compliance Tools
Our compliance tools are designed with developers, designers, and digital professionals in mind. Each tool is built to be fast, secure, and easy to use, with a focus on privacy and client-side processing whenever possible. All tools are completely free to use with no registration required.