English
consentglass · GDPR scanner for websites

HomeGuides › Service

Setting up Complianz in a GDPR-compliant way

Complianz (complianz.io) is a consent plugin for WordPress developed in the Netherlands with regional logic (GDPR, ePrivacy, US laws). It combines a cookie scan, a configurable banner and a “Script Center” for blocking.

Complianz splits consent management into three building blocks: a wizard that determines the appropriate region and the required documents through questions about the website; a cookie scan that crawls the site and categorises the cookies and scripts it finds; and the Script Center, where scripts are blocked manually and assigned consent categories. The wizard is good guidance, but it does not replace legal advice.

The strength and at the same time the weakness of Complianz is the automatic scan. It reliably detects many common services, but it has inherent gaps: scripts that only load after a click or scroll, server-side tags and services that are only active on certain subpages. The scan should therefore run on several representative pages and the result should be compared against a self-maintained list of the tools in use.

For the German market, the region setting is decisive. Complianz can distinguish between “opt-in” (nothing loads before consent), “opt-out” and “do not sell” (US model). For Germany, only strict opt-in is correct: any non-essential access to the device only after active consent. A switch accidentally set to “opt-out” makes the entire banner ineffective.

Is this a risk?

The Complianz cookie scan only finds what is active at the time of the scan — scripts loaded dynamically or firing only after interaction can escape it. Relying on the scan alone can leave consent-requiring services running unblocked; the basis under Section 25(1) TDDDG is then missing. The regional “ePrivacy/GDPR” setting must also be set correctly to the German legal framework (consent before any non-essential access).

What you can do

Häufige Fragen

Is the Complianz cookie scan enough to capture all trackers?
No. The scan only finds what is active at the time of the scan. It can miss scripts that are loaded dynamically, triggered by a click or server-side. The result has to be checked manually.
Which region setting is right for Germany?
“Europe” with strict opt-in — no non-essential access to the device before consent. An opt-out or “do not sell” setting is insufficient for the German legal framework.
Can I use the privacy policy generated by Complianz directly?
As a draft yes, unchanged no. The generated texts cover standard cases but have to be adapted to the specific processing activities and ideally reviewed legally.
Complianz or Borlabs Cookie — which is better?
Both can be configured to be GDPR-compliant. Complianz offers more automation (scan, documents, regions), Borlabs more manual control over the script blocker. In both cases, the decisive factor is the complete maintenance of the blocked scripts.

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.