Non-custodial · GDPR · DORA · DPDP
DPDP Rules 2025 · Enforcement active
DORA in effect since Jan 2025

Be reliant, be JuroCompliant.

Scan any website for DPDP, GDPR & DORA risks in 60 seconds — find consent gaps, pre-consent tracking, and missing privacy notices. Instant results, no account required.

https://
or
Prefer a structured self-assessment?
A 10-minute checklist on your organisation's data practices. Covers DPDP, GDPR, and DORA end-to-end. No URL needed.
Take the self-assessment →
Regulatory sources
₹250 Cr
Max fine per instance under DPDP for consent violations
Personal
Data Fiduciaries are individually liable under DPDP Rules 2025
72 hrs
Your window to notify the Data Protection Board after a breach
DPDP full enforcement deadline
--days
--hours
--minutes
--seconds
May 13, 2027. Penalties start being imposed.
2,400+scans completed
3frameworks covered
60saverage scan time
Zerodata leaves your perimeter
80%+of scanned sites had pre-consent trackers
What a scan produces
Run a scan →
How it works

Four steps, no agent installed on your infrastructure

01
Point at the surface
Give Juro a public URL. No account, no code change, no agent to deploy.
02
Scan non-custodially
A headless browser inspects consent flows, trackers, and notices. Nothing you own leaves your perimeter.
03
Map to obligations
Each finding cites the exact DPDP section, GDPR article, or DORA article it relates to — not a vague recommendation.
04
Seal the result
Deep scans are signed into a deterministic artifact anyone can verify independently; the public-surface scan produces an unsigned posture score.
SCAN LOG: example.com
00:00.000Playwright browser spawned (Chromium headless)
00:00.412Navigating to https://example.com
00:01.103google-analytics.com/analytics.js loaded← PRE-CONSENT
00:01.104Consent banner detected (OneTrust CMP)
00:01.890connect.facebook.net/en_US/fbevents.js loaded← PRE-CONSENT
00:02.340Consent interaction simulated, checking "Reject All" availability
00:02.341No equivalent "Reject All" on first layer← VIOLATION
00:04.81223 network requests intercepted · 2 pre-consent trackers recorded
00:04.813Mapping to DPDP Sec. 5, GDPR Art. 6(1)(a), GDPR Art. 7 …
00:04.9013 violations found. Signed artifact generated.

Over 80% of sites scanned on Juro had at least one pre-consent tracker. Each finding cites the exact provision with no vague recommendations. 85% of websites globally collect data before any user interaction (PreConsent.io, 10,000+ sites, 2026).

Example findings This is what a real scan produces
WEB-001
Analytics scripts fire before user consent is obtained
Critical
Google Analytics and Meta Pixel load on page initialisation, before the consent banner is displayed or any user interaction occurs. Data is transmitted to third parties without a lawful basis.
Business impact Every user whose data was collected without consent can file a complaint with the Data Protection Board. There is no minimum threshold. A single complaint opens a full investigation. Fines reach ₹250 crore per instance under DPDP. Section 8(1) makes the data fiduciary responsible for processing carried out by vendors on its behalf, irrespective of any agreement to the contrary.
Sec. 5 DPDP · Art. 6 GDPR
Fix Block all analytics and advertising scripts from loading until the user grants explicit, granular consent. Use a consent management platform with tag manager integration.
WEB-002
Consent banner has no equivalent "Reject All" on first layer
High
The banner offers "Accept All" on the first layer but requires multiple clicks to reject non-essential cookies. Withdrawal must be as easy to exercise as consent.
Business impact Consent obtained this way is likely invalid under GDPR Art. 7 and DPDP Sec. 6. Any analytics or advertising data collected under it is unlawfully processed. Data Protection Authorities flag this pattern in the first round of any audit.
Sec. 6 DPDP · Art. 7 GDPR
Fix Add a clearly visible "Reject All" button on the first layer. Do not bury rejection behind a "Manage preferences" flow.

Built for the people who get asked "are we compliant?"

Engineers
See exactly which scripts fire before consent, which forms leak PII, and what to block. No vague recommendations: every finding cites the exact provision.
CISOs & Security Leads
Non-custodial scanning means nothing leaves the customer perimeter. Bring the check to the data, not the data to the check.
Compliance & Legal Teams
Get posture findings mapped to DPDP sections, GDPR articles, and DORA provisions — signed and deterministic for VPC-agent scans. Shareable with auditors and the Data Protection Board.

The difference shows up in evidence quality, not feature lists

OneTrust tells you a cookie exists. Juro tells you it fired 2.3 seconds before consent, violating GDPR Art. 6(1)(a). Deep scans produce a signed artifact your DPO can hand to a regulator.

Don't take our word for it. Verify any Juro artifact yourself with the open-source verifier.

Juro Legacy compliance suites Free cookie scanners
Architecture Non-custodial, agent-based Your data uploaded to their cloud Surface cookies only
Frameworks DPDP + GDPR + DORA One framework at a time GDPR only
Evidence Signed, deterministic artifacts Screenshot-based reports No evidence output
Surface scan $0, no account required Sales demo required Free, email-gated
India / DPDP Purpose-built from day one GDPR module adapted for DPDP Not covered
Regulatory risk

The exposure is real, and it applies whether or not you've been scanned yet

DPDP, GDPR, and DORA don't wait for a complaint to be credible — the obligations apply from the moment personal data is processed or a financial entity's ICT systems go live. A signed scan just makes the gap visible before a regulator, auditor, or plaintiff does.

Across sites scanned on Juro, the most common gap isn't an exotic misconfiguration — it's an analytics or advertising script that fires before the user has clicked anything on the consent banner. That single pattern touches DPDP Sec. 5, GDPR Art. 6(1)(a), and GDPR Art. 7 at once.

RegulationApplies toMaximum exposure
DPDP Act 2023 Any entity processing personal data of people in India ₹250 crore per instance
GDPR Any entity processing personal data of people in the EU €20M or 4% of global turnover
DORA Critical ICT third-party providers (Lead Overseer oversight, Art. 35(6)); EU financial entities separately, under each member state's supervisory penalty regime Up to 1% of average daily worldwide turnover (ICT third parties) · varies by member state (financial entities)
GDPR enforcement runs from four-figure fines to the multi-million-euro cases that make headlines — see the GDPR Enforcement Tracker for the full record. Small and mid-size fines are the norm, not the exception.
Verifiable evidence

Evidence you can check yourself, not a badge you take on faith

A scan result is only useful if someone other than us can confirm it hasn't been altered. Every signed artifact is built to be checked independently, not just displayed.

  • Ed25519 signatureEach artifact is signed so any single-byte change to a finding invalidates the signature.
  • Pinned rule-pack versionEvery finding cites the exact rule-pack version it was evaluated against, so results stay reproducible.
  • Independent verificationRun the open-source verifier yourself. No account and no callback to our servers required.
$ juro-verify
$ jc verify report-8841.jcz
checking canonical digest…
hash: VALID
signature: VERIFIED
rule-pack: dpdp-v2026.3, gdpr-v2026.1
verify: PASS
Pricing

Pay for evidence, not for a dashboard seat

Single scan
€390/report
  • One signed, verifiable scan artifact
  • DPDP + GDPR + DORA coverage
  • Full findings with regulatory citations
  • Independently verifiable, no account needed
Talk to us
Most adopted
Continuous
€1,850/mo
  • Everything in Single scan, scheduled
  • Re-scanned on a recurring cadence
  • Signed artifact history over time
  • Rule-pack version pinned per scan
Talk to us
Assurance
Custom
  • Tier 3 in-VPC deployment
  • Custom rule-pack scope
  • Signed evidence for auditors & the Data Protection Board
  • Direct engineering support
Contact sales
Partners

Working with a DPO consultancy or CA firm?

Juro's signed evidence is built to sit inside an advisory engagement, not replace it. See how DPO consultancies, CA firms, and CISOs use Juro reports with their own clients.

See the partner program →

Things people ask before trusting a scan tool

How do I know the scan is accurate?

The scanner doesn't guess. It intercepts actual network requests as a real browser loads your page. If a script fires before the consent interaction, the scanner records the URL, the timestamp, and the exact millisecond offset. That's a deterministic fact, not a heuristic. Deep scans bundle every finding into a signed artifact: the same inputs always produce the same SHA-256 hash, so any auditor can independently verify that the output hasn't been altered after the fact. The public-surface scan produces the same deterministic findings as an unsigned posture score.

What is DPDP compliance and when does it start?

DPDP (Digital Personal Data Protection Act 2023) is India's data protection law. The DPDP Rules 2025 were notified on November 13, 2025, and enforcement is phased. Full compliance obligations become enforceable on May 13, 2027. It requires websites to obtain explicit user consent before collecting personal data, provide clear privacy notices in plain language, and implement data security measures. Fines reach ₹250 crore per violation. Under Section 8(1), the data fiduciary remains responsible for compliance, including for processing carried out by a data processor on its behalf, irrespective of any agreement to the contrary.

How does the compliance scanner work?

A headless Chromium browser loads your URL, intercepts every network request, and records which scripts fire before the consent interaction. Rules then match the observed behaviour against DPDP sections, GDPR articles, and DORA provisions. The result is a deterministic artifact, signed for deep scans: not a screenshot, not a checklist. It maps each finding to the specific provision it relates to and includes remediation steps.

Does the website compliance scanner cost anything to run?

No. The surface scanner is $0 to run and requires no account. It checks website-layer compliance including consent flows, tracker timing, and privacy notice presence. For deeper infrastructure assessments (backend APIs, PII in logs, unencrypted data columns), contact us for a technical readiness assessment.

What is the difference between GDPR, DORA, and DPDP?

GDPR (General Data Protection Regulation) is the EU's data protection law covering all organisations processing EU residents' data. DORA (Digital Operational Resilience Act) is the EU's financial sector cybersecurity regulation that took effect January 17, 2025, covering ICT risk management, incident reporting, and third-party oversight. DPDP (Digital Personal Data Protection Act) is India's data protection law covering processing of digital personal data of Indian residents. The scanner checks for all three simultaneously.

What does the scanner detect on my website?

The scanner detects analytics and advertising scripts that fire before user consent, consent banners without an equivalent "Reject All" button, missing or incomplete privacy notices, forms that collect personal data without a lawful basis, and third-party trackers that transmit data without consent. Each finding cites the exact regulatory provision it maps to.

How is Juro different from OneTrust, Vanta, or cookie scanners?

Juro is non-custodial: your data never leaves your perimeter. Legacy compliance suites like OneTrust and Vanta require you to upload data to their cloud. Free cookie scanners only check surface cookies and do not map findings to regulatory provisions. Juro's VPC-agent scans produce signed, deterministic artifacts that can be independently verified; the public-surface scan is an unsigned starting point. Juro covers DPDP, GDPR, and DORA in a single scan.

Does Juro store or process my website data?

The scanner runs server-side against your public URL. Your page content, cookies, and user data are never written to disk. Only the analysis output is retained, for 90 days, to power the scan cache. For infrastructure assessments, the agent runs inside your VPC with a read-only IAM role and produces signed findings locally. Nothing is uploaded to our cloud.

From the blog All posts →
DPDP 29 Aug 2026 · 9 min read
You Can Delete the Record. You Cannot Un-Train the Model.
Deleting a source record does not un-train a model that memorised it. How DPDP erasure plays out across training, fine-tuning, RAG, and on-device AI systems.
Notice