b2KIT

Privacy Risk Assessor

Evaluate the privacy risk of your website or app by answering questions about data collection and processing practices.

Tested tool guide Tested browser tools Checked August 16, 2026

What Privacy Risk Assessor does and how it behaves

Privacy Risk Assessor asks you a structured set of questions about how your website or app collects and processes personal data, then evaluates the privacy risk of the practices you describe. The assessment runs entirely on your answers - it does not scan, crawl, or inspect your site. That is the surprise most people hit: they expect a technical audit, but the tool can only evaluate what you tell it, so the result is only as accurate as your answers. Bring whoever knows your actual data flows, or the output will reflect the description, not the reality.

How the result is produced

1

Answer-driven assessment

Each question asks you to describe a data practice: what categories of personal data the site or app handles, and how that data is processed. Your answers are the only input. The tool does not verify them against the site itself, so the evaluation reflects the practices as described, not as implemented.

2

Risk evaluation from what you report

The tool weighs the practices you report and returns an evaluation of the resulting privacy risk. Treat the result as a structured assessment of the data practices you described, useful for comparing scenarios and prompting discussion - not as a legal opinion or a certification that the site complies with any particular privacy law.

Good uses

  • Before launching a new site or app, stepping through your planned data practices to see where privacy risk sits while the design can still be changed.
  • Reviewing an existing product whose real data flows you know, to identify which practices carry the most risk and where changes would matter.
  • Comparing alternative designs by rerunning the assessment with different answers - for example, keeping analytics logs for 30 days versus 24 months - and seeing which scenario evaluates as lower risk.

Limits and checks

  • Garbage in, garbage out. If the person answering does not know the actual data flows, or answers aspirationally about what the product should do, the evaluation is wrong even when every question is answered.
  • A risk evaluation is not a compliance check. The result cannot establish that the site meets a specific law such as the GDPR or CCPA, so do not present it as proof of compliance to users, clients, or regulators.
  • Context matters. The same practice can be low risk in one product and high risk in another - a health app and a habit tracker can collect the same data under very different expectations - so read the result as input to judgment, not a final verdict.

Common questions

Can the tool scan my website and find out what data it actually collects?

No. The tool works from the answers you give to its questions; it does not crawl or inspect your site, its code, or its network traffic. If you want an assessment of what the site really does, someone who knows the actual data flows has to answer the questions honestly, including the parts you would rather not admit.

Does a favorable result mean my site is compliant with privacy law?

No. The tool evaluates the privacy risk of the practices you describe; it is not a legal review, and its result does not establish compliance with any specific law. Treat a favorable result as a signal that the practices you described look reasonable, then have the actual implementation and any contracts reviewed against the laws that apply to you, such as the GDPR, CCPA, or other regulations.

References and verification

The behavioral notes were checked against the browser implementation. Standards and primary references below define the relevant format, formula, or platform behavior.

Related Tools