Skip to content
ComplyMynt
All articles

Website compliance

Is Your Website Breaking the Law? 10 Hidden Compliance Risks in 2026

· 20 min read

Glass website interface surrounded by ten privacy, accessibility, consent, and security inspection symbols with an emerald shield

A practical website compliance checklist for 2026: 10 hidden privacy, cookie, accessibility, AI, and security risks, plus evidence-backed remediation steps.

Is your website breaking the law? It might be exposing your business to legal risk, but the answer cannot be determined from its appearance or an automated score. A legally significant problem can sit inside a tag manager, a checkout flow, a chatbot, a consent record, or a vendor integration that nobody has reviewed since launch.

Website compliance is the process of identifying the privacy, consumer-protection, accessibility, security, and AI requirements that apply to your actual service, then implementing and verifying the controls that support those requirements. A website compliance checklist is useful only when each item is connected to an owner, a test, evidence, and a correction process.

This guide focuses on AI and SaaS businesses, subscription services, and commercial websites serving U.S., UK, or EU users. It explains ten common risk patterns, why they matter, what to test, and what an evidence-backed fix looks like. References in brackets correspond to the official sources linked below. Information reviewed October 9, 2026; legal requirements and guidance can change. ComplyMynt is not a law firm and this article is educational information, not legal advice.

Before the checklist: identify which requirements actually apply

Start with a jurisdiction and data map. Record where the business is established, where it offers services, where affected people are located, what information it collects, whether children use the service, whether customers are consumers or businesses, and whether the product operates in a regulated sector. Public availability around the world does not automatically mean every country's law applies; targeting, monitoring, transactions, and other connecting factors matter.

GDPR can reach businesses outside the EU in specified circumstances, including offering goods or services to people in the EU or monitoring their behavior there. CCPA covers businesses meeting its statutory criteria, not every small website with a California visitor. Accessibility duties vary by service, jurisdiction, and legal framework. Customer contracts can create requirements even where a particular statute does not apply. [1, 3, 5, 6]

Maintain an applicability register with the requirement, source, reason it applies, responsible owner, and next review date. This prevents two costly mistakes: ignoring a real obligation and spending engineering time implementing a rule that does not fit your business.

1. Your cookie banner appears after tracking has already started

The hidden risk: a site shows a professional consent banner, but analytics, advertising pixels, embedded media, or session-recording scripts already run before the visitor chooses. The banner is visible; the network requests are not. Saving a preference cannot retroactively authorize processing that already happened.

EU rules on storing or accessing information on a device generally require consent unless an applicable exception applies, while GDPR separately governs personal-data processing. UK PECR has its own exceptions; the ICO updated its storage-and-access guidance in April 2026 following legislative changes. Do not assume every analytics technology is treated identically across the EU and UK, or that calling a cookie 'essential' makes it exempt. Match each technology and purpose to the current rule. [1, 2, 13]

How to check: use a fresh browser profile, clear storage, open developer tools, and record requests before interacting with the banner. Repeat after rejection, granular acceptance, and withdrawal. Test mobile, embedded content, landing pages, and a second visit. Include local storage and similar technologies rather than reviewing cookies alone.

What a fix looks like: prevent non-exempt technologies from loading until the required permission exists; propagate preferences to embedded vendors and tag-manager triggers; separate purposes where required; and make withdrawal work. A consent-mode configuration or a cookieless request is not automatically lawful simply because it avoids a conventional cookie. Preserve the request traces, configuration version, and before/after test results.

  • Owner: marketing operations and engineering, supported by privacy review.
  • Evidence: tag inventory, purpose and exemption analysis, consent settings, and fresh-session network captures.
  • Priority trigger: advertising or recording begins before a required choice, or continues after rejection.

2. Your website ignores Global Privacy Control

The hidden risk: a covered business publishes a 'Do Not Sell or Share' link, but does not honor the visitor's browser-level opt-out signal. Another version is more subtle: the site records the preference locally while advertising vendors or server-side events continue the same sharing.

California's Attorney General explains that covered businesses must honor qualifying opt-out preference signals such as Global Privacy Control for sale or sharing. Sharing under CCPA includes specified cross-context behavioral advertising, so the absence of a cash sale is not the end of the analysis. Other state laws have different scope and universal opt-out requirements; maintain a market-specific implementation map. In September 2025, California, Colorado, and Connecticut announced a joint investigative sweep focused on honoring opt-out signals. [3, 4]

How to check: visit with GPC enabled, confirm that the signal reaches the application, and compare ad-related requests and downstream events with a baseline visit. Inspect both the browser and server-side integration. Test logged-out and logged-in journeys, including whether account preferences preserve the choice where required.

What a fix looks like: connect signal detection to the actual sale/sharing control, not just a label on the banner. Identify affected vendors and purposes, handle conflicting choices according to the applicable rule, and avoid demanding extra personal information merely to process an opt-out. Keep test evidence showing which processing stopped and why. GPC is not a universal request to delete all data or disable every necessary service.

  • Owner: privacy lead and advertising-integration owner.
  • Evidence: applicability decision, signal test, vendor mapping, and browser/server event comparison.
  • Priority trigger: an opt-out is acknowledged but advertising-related sharing continues.

3. Your privacy policy describes a website you no longer operate

The hidden risk: the policy was written before the site added a CRM, AI support assistant, enrichment service, analytics tool, or new market. It promises limited collection while a form sends detailed behavioral and contact information to several vendors. A copied policy can look complete while misstating the real processing.

GDPR Articles 13 and 14 specify transparency information for applicable processing, including purposes, legal basis, recipients or recipient categories, retention information, and relevant rights. CCPA requires notices for covered businesses, including notice at collection. These are not interchangeable documents, and a footer link is not a substitute for information needed at the collection point. [1, 3]

How to check: trace every form, registration, support widget, newsletter choice, and embedded service. For each field and event, identify its purpose, destination, retention, access permissions, and lawful processing rationale. Compare this inventory with notices, vendor contracts, and the claims made in the interface.

What a fix looks like: revise notices from the verified inventory, add timely collection information, and remove statements you cannot support. Minimize unnecessary fields and prevent sensitive information from reaching unrelated systems. Record the notice version and which journeys display it. Legal review should evaluate the wording and legal bases; engineering should verify that production behavior matches them.

  • Owner: privacy operations, product, and counsel.
  • Evidence: data-flow map, field inventory, vendor register, notice versions, and retention schedule.
  • Priority trigger: sensitive data or an undisclosed vendor receives information from a user journey.

4. People cannot complete your core journeys with assistive technology

The hidden risk: the homepage passes a quick automated check, but keyboard users cannot accept or reject cookies, a screen reader cannot identify form errors, or checkout focus becomes trapped in a modal. Accessibility is about completing the task, not just checking decorative images for alternative text.

The U.S. Department of Justice states that the ADA applies to web accessibility for state and local governments and businesses open to the public. The precise legal treatment of private websites can depend on jurisdiction and circumstances. Do not confuse the Title II rule for public entities with a universal private-sector technical mandate. In Europe, the European Accessibility Act covers specified products and services, including e-commerce, with requirements applying from June 28, 2025. Its scope, microenterprise service exemption, transitions, and national implementation require review. It does not cover every website in exactly the same way. [5, 6]

How to check: navigate signup, consent, purchase, cancellation, and support using a keyboard only. Test a screen reader, meaningful labels, focus order, error announcements, zoom and reflow, captions, and color contrast. Include third-party widgets and states that only appear after submission. WCAG 2.2 is a technical reference, not a promise that a scanner has decided your legal obligations. [7]

What a fix looks like: correct the underlying HTML semantics, focus management, labels, contrast, error handling, and content alternatives; then retest the complete journey. An accessibility overlay does not eliminate the need to fix source-level barriers. Preserve manual test results, the component version, affected pages, and known remaining limitations.

  • Owner: design-system and frontend teams with accessibility specialists.
  • Evidence: automated results plus manual keyboard, screen-reader, and journey tests.
  • Priority trigger: a person cannot consent, sign up, pay, cancel, or request help.

5. Your subscription flow makes agreement easy and cancellation difficult

The hidden risk: a trial quietly becomes paid, recurring charges are buried below the button, an optional purchase is preselected, or cancellation requires an inaccessible support exchange. A conversion experiment can become a compliance problem when it obscures what the customer is agreeing to.

For covered online negative-option transactions, the Restore Online Shoppers' Confidence Act requires clear disclosure of material terms before obtaining billing information, express informed consent before charging, and simple mechanisms to stop recurring charges. State automatic-renewal and consumer-protection laws can add duties. Do not use a headline about a changing federal 'click-to-cancel' rule as your entire compliance analysis: evaluate the underlying statute and current state requirements. [8]

How to check: run the complete trial-to-paid journey and cancellation path. Compare the advertised price with the charged amount, identify renewal disclosures, inspect preselected options, and verify how confirmations are delivered. Test cancellation on a phone and with a keyboard. Confirm that payment processing stops when the request is effective.

What a fix looks like: show material billing terms before commitment, capture the required agreement, provide a workable cancellation mechanism, and issue appropriate confirmations and notices. Save the exact checkout version, transaction consent record, cancellation test, and payment-system evidence. Test changes before rolling out a new growth experiment.

  • Owner: growth, billing operations, and product counsel.
  • Evidence: checkout screenshots, consent event, confirmation, and a completed cancellation test.
  • Priority trigger: unclear recurring charges or a cancellation request that fails to stop billing.

6. Session replay and embedded tools collect more than your team realizes

The hidden risk: a support recorder captures typed messages, an ad pixel receives a sensitive page URL, or a widget forwards search terms and identifiers. Information can escape through event payloads and URL parameters even when no form has been submitted.

Third-party tracking raises several separate questions: device-access permission, personal-data processing, sale/sharing, security, and potentially interception or wiretap law. Session-replay litigation is fact-specific and differs across courts; it is not accurate to say every recorder is illegal or that a footer disclosure always resolves the issue. Investigate what is captured, who receives it, when consent occurs, and which jurisdiction is relevant. [1, 2, 3]

How to check: inspect actual payloads from forms, search boxes, account pages, and sensitive routes. Enter only synthetic test values; do not collect real customer secrets for the audit. Verify masking, URL sanitization, custom events, and whether recording starts before a required choice. Review vendor defaults after updates rather than assuming settings remain unchanged.

What a fix looks like: remove unnecessary capture, mask at the source, exclude sensitive routes, reduce URL and event detail, and disable tools that lack a justified purpose. Complete vendor and contract review, implement permission controls where required, and verify that redacted values truly leave neither the browser nor the server. A screenshot of a masking setting is weaker evidence than a captured, correctly minimized payload.

  • Owner: analytics, support tooling, privacy, and security teams.
  • Evidence: synthetic payload tests, masking verification, route exclusions, and vendor review.
  • Priority trigger: credentials, payment information, health details, or private messages reach unrelated vendors.

7. Your public security posture is weak — or your promises are stronger than your controls

The hidden risk: exposed configuration, missing access checks, overly broad API responses, insecure sessions, or misconfigured storage make information available to the wrong person. Meanwhile, marketing says 'fully secure' or procurement answers promise controls that are not consistently implemented.

GDPR Article 32 requires appropriate technical and organizational measures for applicable processing, taking account of risk and other factors. Consumer-protection and contractual obligations may also matter. Security is broader than HTTP headers: a missing Content Security Policy can be a hardening finding, but it is not, by itself, proof that a website is breaking the law. Likewise, HTTPS does not prove that authorization or data handling is sound. [1, 9]

How to check: combine authorized external checks with a scoped review of identity, permissions, sensitive APIs, storage access, vendor connections, and incident processes. Test only systems you own or have permission to assess. Separate observable facts from hypotheses that need deeper investigation.

What a fix looks like: restrict exposure, correct access control, rotate exposed secrets, harden sessions and headers where appropriate, and align public security claims with evidence. If an incident may have occurred, follow the response process and seek legal advice on notification obligations; do not silently treat a potential breach as a routine backlog item. Retest the affected paths and document the fix.

  • Owner: security and engineering, with incident and legal support when needed.
  • Evidence: reproducible finding, authorized scope, corrected control, and verification result.
  • Priority trigger: active data exposure, unauthorized account access, or an exposed credential.

8. Your AI feature conceals its role or makes unsupported claims

The hidden risk: a chatbot appears human, generated media is presented as authentic, or the site claims an AI decision is unbiased, accurate, or legally compliant without an evidence base. Adding an AI vendor does not remove your responsibilities for how the feature is presented and used.

The EU AI Act introduces role-specific transparency obligations, including relevant requirements for direct interaction with AI, marking certain generated outputs, and disclosing specified synthetic content. The European Commission identifies August 2026 as the transparency implementation period. Scope and exceptions matter: not every AI-assisted sentence needs the same disclosure, and provider duties differ from deployer duties. High-risk system obligations follow their own implementation schedule, which should not be collapsed into a single deadline. [10]

How to check: inventory chatbots, recommendations, generated content, screening tools, and decisions affecting people. Identify the feature's role and market, examine disclosures at the point of interaction, and ask what evidence supports each performance or safety claim. Review escalation, human review, logging, and the handling of personal data in prompts.

What a fix looks like: make applicable disclosures clear and timely, document the system's limits, remove unsupported guarantees, and provide appropriate escalation or review. Preserve model and interface versions, approval records, tests, and user-facing wording. A generic 'AI may be wrong' footer cannot replace every required transparency, privacy, or decision-specific control.

  • Owner: AI product lead, governance, privacy, and counsel.
  • Evidence: AI inventory, role and jurisdiction analysis, disclosures, testing, and claims substantiation.
  • Priority trigger: consequential decisions without appropriate review, or misleading claims about AI capability.

9. Children's data enters a system designed only for adults

The hidden risk: an education tool, game-like experience, support chatbot, or community collects children's information even though the policy says 'not intended for children.' Advertising, analytics, persistent identifiers, and uploaded content can create exposure beyond obvious name-and-email collection.

COPPA applies to covered operators of child-directed online services and operators with actual knowledge that they collect personal information from children under 13. The rule addresses notice, verifiable parental consent, parental rights, confidentiality and security, and retention. A proposed expansion or a 'COPPA 2.0' headline should not be described as enacted law without verification. Other jurisdictions and state laws can create additional protections for young people. [11]

How to check: assess the actual audience, design, marketing, sign-up flow, known user information, and vendor behavior. Determine whether a service is child-directed or has relevant actual knowledge rather than relying only on a checkbox. Review photographs, voice recordings, identifiers, chat logs, and ad integrations.

What a fix looks like: obtain specialist legal review of audience classification, reduce collection, implement applicable parental controls and permission processes, and constrain downstream vendors. Use age-assurance measures proportionately; collecting extra identity information can introduce a new privacy risk. Document retention and deletion rules and verify them in the actual systems.

  • Owner: product, trust and safety, privacy, and counsel.
  • Evidence: audience assessment, collection inventory, permission process, vendor restrictions, and deletion tests.
  • Priority trigger: a child-directed service sends children's personal information to advertising or unrelated vendors.

10. Privacy rights, retention, and international transfers exist only on paper

The hidden risk: a user clicks 'delete my data,' but information remains in the CRM, support tool, data warehouse, and AI logs. A rights request has no owner. A vendor is described as European-hosted, while overseas support access or a subprocessor creates a transfer the team never evaluated.

Under GDPR, applicable rights, retention principles, and international-transfer requirements must be operationalized. Chapter V addresses transfers of personal data to third countries; the European Commission's Standard Contractual Clauses are one available safeguard where appropriate, not a universal shortcut. CCPA rights also have defined scope and exceptions for covered businesses. Deletion does not always mean every record must disappear immediately, but any exception needs a documented basis. [1, 3, 12]

How to check: use a synthetic account to run an access, correction, or deletion request through all relevant systems. Map processors and subprocessors, locations, remote access, contracts, and onward transfers. Confirm who calculates deadlines, verifies identity proportionately, and communicates outcomes. Review retention against purpose rather than keeping data indefinitely 'just in case.'

What a fix looks like: create a rights workflow with accountable owners, connect it to downstream systems, define supported retention and exception rules, and assess transfer mechanisms and supplementary measures where needed. Keep a request audit trail without unnecessarily retaining the deleted content itself. Verify that the privacy policy accurately describes the working process.

  • Owner: privacy operations, data platform, vendor management, and counsel.
  • Evidence: end-to-end rights test, retention schedule, processor map, and transfer assessment.
  • Priority trigger: unanswered requests, indefinite sensitive-data retention, or an undocumented transfer.

A practical 30-day website compliance remediation plan

Prioritize by harm, exposure, and confidence, not by whichever finding is easiest to screenshot. Active data exposure, unauthorized access, tracking against a required choice, blocked essential journeys, and deceptive billing warrant prompt triage. A missing hardening header, an ambiguous notice, and an inaccessible purchase button are different problems and should not receive an identical response.

Days 1–5: establish authorized scope, map jurisdictions and critical journeys, inventory tags and vendors, collect baseline evidence, and contain urgent exposure. Days 6–15: correct high-priority engineering and operational failures, validate policy changes with counsel where appropriate, and assign remaining work. Days 16–25: retest consent, GPC, accessibility, billing, rights requests, and security across representative devices and account states. Days 26–30: approve the evidence register, document accepted limitations, and set change-triggered monitoring.

These are planning windows, not a promise that every website can be fixed in a month. Complex applications, vendor dependencies, legal analysis, or incident response may require a different schedule. Write the actual scope, owners, and delivery dates into the engagement.

  • Each finding: identifier, affected journey, applicability rationale, severity, reproducible evidence, owner, fix, and target date.
  • Each verification: tester, environment, version, method, result, and remaining limitations.
  • Each change trigger: new tag, form, AI model, vendor, market, checkout experiment, design component, or sensitive-data use.

What an automated website scan can — and cannot — establish

Automation is useful for finding repeatable signals: observable headers, insecure URLs, some tracking technologies, missing labels, link discovery, and basic markup defects. It helps teams gather evidence and detect regressions consistently. A finding should still be validated against the actual journey and applicable requirement.

A scanner cannot determine every legal obligation, read every vendor contract, establish the true audience, prove lawful international transfers, assess all screen-reader interactions, or decide whether a consequential AI decision has meaningful oversight. A public homepage scan also cannot reveal every authenticated workflow. Do not sell an automated score as a legal compliance certificate.

A stronger assessment combines authorized technical discovery, manual journey testing, policy and data-flow review, specialist judgment, remediation, and verification. The result should distinguish confirmed facts, unresolved questions, recommendations, and counsel-dependent conclusions.

Frequently asked questions about website compliance in 2026

Can a website be noncompliant even if it has a privacy policy? Yes. A policy can be inaccurate or the underlying processing can fail to meet applicable requirements. Review actual data flows, permissions, retention, and rights handling rather than treating the document as the control.

Do all websites need a cookie banner? No. The answer depends on the technologies, purposes, applicable law, and available exceptions. Some websites may not use technologies requiring consent. A banner should implement the required choices, not be added as decoration.

Does a WCAG score prove ADA compliance? No. Automated scores cover only part of accessibility testing and do not determine legal applicability. Assess complete journeys manually as well as technically, and obtain advice on the relevant legal standard.

Does CCPA apply to every SaaS company? No. Evaluate statutory business criteria, data activities, exemptions, and the relevant relationships. Having California users alone is not a complete applicability analysis. [3]

Does adding an AI disclaimer make a chatbot compliant? No. Disclosures are one control. Privacy, transparency, security, claims, use-case classification, and appropriate review may also matter, depending on the feature and jurisdiction.

How often should a website be reassessed? Reassess when its risk-bearing behavior changes, especially after adding vendors, tags, forms, markets, AI features, or checkout flows. Set a periodic review cadence according to risk and contractual obligations; a yearly policy refresh alone is rarely enough for a frequently changing product.

How ComplyMynt helps your team address hidden website risks

ComplyMynt assesses AI governance, privacy, consent, accessibility, public security posture, and legal/policy surfaces through an evidence-led engagement. The six stages are Discover, Collect, Assess, Remediate, Verify, and Monitor. The aim is to turn observed issues into a scoped, prioritized remediation plan rather than treat a scanner score as a legal verdict.

Depending on the agreed scope, deliverables include an executive summary, evidence-backed findings, an engineer-ready remediation backlog, remediation support, and verification. Continuous monitoring is recommended after an audit establishes a baseline. Review services at https://complymynt.com/services, compare engagement pricing at https://complymynt.com/pricing, or book a briefing at https://complymynt.com/contact. ComplyMynt is not a law firm and does not provide legal advice or guarantee compliance.

ComplyMynt · assessment, remediation & verification

Turn hidden website risks into a clear remediation plan

ComplyMynt helps AI and SaaS teams assess six domains: AI governance, privacy, consent, accessibility, public security posture, and legal/policy surfaces. Our six-stage engagement moves from Discover and Collect to Assess, Remediate, Verify, and Monitor.

  • Evidence-backed findings, severity and scope, an executive summary, and an engineer-ready remediation backlog.
  • Remediation support and verification within the agreed engagement scope — not just a list of warnings.
  • Monitoring after a baseline audit to catch tracker changes, accessibility regressions, and security drift.

ComplyMynt is not a law firm and does not provide legal advice. An assessment is not a certification or a guarantee of legal compliance; legal determinations belong with qualified counsel.

Starter

The core compliance surface, fully evidenced.

$2,995

one-time · single website or product

Growth

Deeper evidence across your full public surface.

$6,995

one-time · up to 3 websites or products

Professional

Manual depth and board-ready documentation.

$12,995

one-time · unlimited products in scope

Enterprise Assurance

A standing compliance function for multi-product, regulated organizations.

From $35,000

per year · annual assurance program

Continuous monitoring from $499/month is recommended after completing a ComplyMynt audit to establish a compliance baseline.

Keep reading