GDPR COMPLIANCE TOOL

Know what personal data
lives in your files

Upload any CSV, Excel or JSON file and get an instant report showing which columns contain personal data, how sensitive it is, and what GDPR says about it.

What is GDPR?
GDPR (General Data Protection Regulation) is an EU law that controls how organisations collect, store and share personal data. If your files contain information about real people — employees, customers, drivers — GDPR applies to you.
👤

Personal Data

Any information that can identify a living person — directly (their name, email) or indirectly (their employee ID, login alias, or tour ID combined with other data).

⚖

Why it matters

Sharing a file with employee emails, login aliases, or management hierarchy chains outside Amazon without proper controls is a GDPR violation. Fines can reach €20 million or 4% of global turnover.

📝

Data Subject Rights

Every person whose data you hold has the right to access it, correct it, or request deletion. Knowing exactly what data you hold is the first step to compliance.

🔐

What this tool does

It scans column headers and actual cell values in your file, matches them against GDPR risk patterns, and tells you exactly which fields are a concern — and why.

What the scanner checks for
Every finding is classified into one of four categories based on how sensitive it is under GDPR.
⛔

Art.9 Special Categories

The most protected class under GDPR Article 9. Processing is prohibited by default under Art. 9(1) and needs both an Art. 6 lawful basis and a separate Art. 9(2) condition — two tests, not one. Art. 10 (criminal convictions and offences, including alleged offences) additionally requires official authority or a Member State law authorising it.

  • Health & medical data
  • Biometrics (face ID, fingerprints)
  • Genetic / DNA data
  • Race or ethnic origin
  • Religion or beliefs
  • Political opinions
  • Sexual orientation
  • Criminal records
👤

Direct Identifiers

Fields that directly name or reach a specific person. No inference needed — the data alone identifies someone.

  • Full name, first/last name
  • Email address
  • Phone number
  • Passport / National ID
  • Date of birth
  • Bank account / IBAN
  • Credit card number
  • IP address
🔎

Indirect Identifiers

Fields that don't name someone directly but can identify them when combined with other data. Still personal data under GDPR.

  • Login / username / alias
  • Employee / user ID
  • Location & GPS coordinates
  • Address / postcode
  • Age or gender
  • Salary / pay grade
  • Device or session ID
  • Tour / contract ID
📊

Value Patterns

The scanner looks inside the actual cell values, not just column names. It uses regex patterns to detect personal data hiding in unexpected columns.

  • Email addresses in any column
  • Phone number formats
  • IBAN / card number patterns
  • IP addresses
  • GPS coordinate formats
  • Date-of-birth formats
  • National Insurance numbers
  • Passport-like IDs
Three steps, instant results
1

Upload your file

Drop in a CSV, Excel (.xlsx/.xls), JSON, TSV or TXT file. Nothing leaves your browser — all processing happens locally on your machine.

2

Two-pass scan

Pass 1 checks every column header against 29 GDPR rules. Pass 2 samples up to 200 rows per column and runs 9 regex patterns on the actual values.

3

Review & export

Get a risk score, category breakdown and sortable findings table. Export a clean HTML report to share with your team or compliance lead.

How risk is scored
Each finding gets a severity level. The overall risk score (0-100) adds them up.
LevelScore per fieldWhat it meansExamples
Critical+20 ptsArt.9 special categories, Art.10 criminal-offence data, or unique identifiers. Needs an Art. 6 basis plus an Art. 9(2) condition or Art. 10 authorisation.SSN, passport, IBAN, health data, biometrics, criminal record
High+12 ptsDirect identifiers that clearly point to a person. Should never appear in shared files without pseudonymisation.Email, phone, full name, date of birth, IP address, GPS
Medium+6 ptsIndirect identifiers. Low risk alone but can identify someone in combination with other fields.Login alias, employee ID, gender, age, address, device ID
Low+2 ptsOperational IDs loosely linked to people. Worth noting but unlikely to cause a violation on their own.Tour ID, contract ID, session token

Ready to scan your file?

Works entirely in your browser. No uploads, no servers, no data ever leaves your machine.

🔒 GDPR Compliance Scanner

Upload a data file to detect personal data fields and assess compliance risk

Build 2.3  ·  scans every sheet  ·  minimisation + singling-out + DPIA analysis  ·  25 file formats

Drag & drop your file here

or

Tabular  CSV · TSV · XLSX · XLS · XLSM · ODS · JSON
Documents  PDF · DOCX · PPTX · ODT · XML · HTML · TXT · MD · LOG
Images (OCR)  PNG · JPG · WEBP · BMP · TIFF

Every sheet in a workbook is scanned, not just the first. PDF and image reading downloads its engine on first use.

Risk Score

Detected Categories

Compliance Analysis

Derived from the file. Fields marked your input cannot be read from a spreadsheet.

Findings