English
consentglass · GDPR scanner for websites

www.figma.com

Checked on 9/4/2026 · https://www.figma.com/

A
98 / 100
Cookie banner: Cookie Consent · Privacy-policy link: yes · Legal-notice link: yes

Best-case value: the issues found are the minimum. Behind a tag manager or cookie banner, further services can load that this scan does not see — the real value is likely lower.

No critical items in the delivered HTML · to review: 1.

How is the score calculated? (100 starting points)
Third-party CDN: jsDelivr CDN-5
Third-party CDN: unpkg CDN (additional)-2
Cookie banner detected (Cookie Consent)+5
Result98 / 100

Multiple services of the same kind count on a sliding scale. The score is a guide, not a legal verdict.

What this scan doesn't see consentglass reads only the first, unmodified HTML — without executing JavaScript. Because a cookie banner (Cookie Consent) is active, the actual trackers almost always load only afterwards and don't appear here. So a good result here doesn't automatically mean “GDPR-compliant”. Monitoring runs the full test with JavaScript enabled.
Tiefen-Scan (mit JavaScript) Lädt die Seite wie ein echter Browser, führt JavaScript aus und protokolliert, welche Dritt-Dienste vor einer Einwilligung feuern und wie sich das Banner beim Ablehnen verhält. Dauert etwa eine Minute.

Findings

To review

Cookie banner detected (Cookie Consent) — does it load before consent anyway?

A banner is embedded. Whether the services really load only after consent cannot be determined conclusively from the initial HTML.

What you should do: Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.

Next steps

  1. Cookie banner detected (Cookie Consent) — does it load before consent anyway?. Test it yourself: open the page in a private window, developer tools → “Network”, reload and see whether e.g. google-analytics appears before a click on “Accept”. Monitoring does this test automatically.

Third parties detected (2)

ServicePurposeVendorCountryLegal basis
jsDelivr CDN
jsdelivr.net
Delivery of libraries or maps via third-party servers jsDelivr EU Grey area — better to self-host; otherwise consent
unpkg CDN
unpkg.com
Delivery of libraries or maps via third-party servers Cloudflare/npm US ⚠ Grey area — better to self-host; otherwise consent

⚠ Established outside the EU/EEA — the transfer needs an additional basis (e.g. the EU-US Data Privacy Framework or standard contractual clauses).

Monitor this URL automatically?

Weekly re-scan, email as soon as a new tracker appears — coming soon.

Method & limits

On 9/4/2026 we checked the HTML that www.figma.com delivers on first load without a login (normal desktop browser, EU location). Detected: services embedded in the source (scripts, stylesheets, iframes, pixels), a cookie banner based on known providers, cookies from the server response, and links to the privacy policy and legal notice.

Not checked: anything that loads only via JavaScript, content behind a login, subpages, behaviour after clicking “Accept”/“Reject”, server locations and data-processing agreements. The result is an automated snapshot and not a substitute for legal advice.

Scan another website