Sample Report Preview

See exactly what's in your $99 Premium Compliance Report

This is a real WatchSuit audit, anonymized. Every section, every citation, every evidence snippet — exactly what lands in your inbox 48 hours after purchase.

The actual report

Real findings from a real scan. Company name anonymized. All citations, evidence snippets, and remediation steps are accurate.

WatchSuit Premium Compliance Report · PDF Preview
WatchSuit
Premium Compliance Report
Example Corp
examplecorp.com · Multi-page crawl · 5 frameworks
Overall Score
54
/ 100 · C
Scan Date
May 20, 2026
Frameworks
5 of 5
Violations Found
11
Section 1 — Executive Summary

Risk overview for Example Corp

Example Corp's public-facing website presents significant compliance risk across three of five audited frameworks. The most urgent exposures are in GDPR (missing lawful basis disclosures and incomplete data subject rights) and HIPAA (no Business Associate Agreement references despite visible health intake forms). These gaps represent enforceable violations — not aspirational best practices — and should be addressed before any EU or US regulatory engagement.

The site's EU AI Act posture is acceptable: no high-risk AI system signals were detected on the homepage or feature pages. CCPA performance is moderate; a Do Not Sell link exists but the data categories list is incomplete under Cal. Civ. Code §1798.110. SOC 2 readiness is the weakest area — there is no trust center, no security.txt, and no reference to an audit report or certification, which will materially affect enterprise sales cycles.

Of the 11 violations identified, 2 are Critical severity (potential regulatory fines exceeding $20M under GDPR Art. 83), 4 are High (reportable to regulators within 72 hours of breach discovery under GDPR Art. 33), and 5 are Medium (material compliance gaps requiring remediation within 30 days). No violations were found in 14 of the 25 checks performed.

2 Critical — GDPR Art. 83 4 High — Action within 72h on breach 5 Medium — 30-day remediation window
Section 2a — Framework Breakdown
GDPR (EU General Data Protection Regulation)
41
/ 100 framework score
✓ 2 passed ✗ 3 failed
Lawful Basis Disclosure Missing
GDPR Art. 13(1)(c), Art. 6
CRITICAL
The privacy policy does not specify which of the six GDPR lawful bases applies to each category of data processing. "We may use your data to improve our services" does not constitute a lawful basis disclosure under Art. 13(1)(c). The controller must specify the legal basis — consent (Art. 6(1)(a)), contract (Art. 6(1)(b)), or legitimate interests (Art. 6(1)(f)) — for each processing purpose.
Evidence — /privacy-policy (line 47)
"We collect and use your personal data to provide and improve our services, send you updates, and for other purposes we notify you about." — No lawful basis specified.
Remediation
For each processing purpose, add a lawful basis table specifying which Art. 6 ground applies. Example: "We process your email address to send transactional emails — lawful basis: performance of contract (Art. 6(1)(b))." Consult a DPA template from the ICO or CNIL if needed. Complete within 14 days.
Data Subject Rights Incomplete
GDPR Art. 15–22
CRITICAL
The privacy policy mentions a "right to delete" and a "right to access" but omits four additional rights required under GDPR Art. 15–22: right to rectification (Art. 16), right to restriction of processing (Art. 18), right to data portability (Art. 20), and right to object (Art. 21). Incomplete rights disclosure is an Art. 13 violation subject to fines under Art. 83(1) of up to €10M or 2% of global annual turnover.
Evidence — /privacy-policy (line 112)
"You have the right to access or delete your personal data at any time by contacting us at privacy@examplecorp.com." — Only 2 of 6 rights disclosed.
Remediation
Add a "Your Rights" section enumerating all six GDPR rights with a brief explanation of each and a mechanism to exercise each (online form, email address, or both). Include the right to lodge a complaint with a supervisory authority under Art. 77. Review the ICO's Rights guidance for compliant template language.
DPO Contact Details Missing
GDPR Art. 13(1)(b), Art. 37
HIGH
No Data Protection Officer contact information was found. Where a DPO is appointed (mandatory for public authorities and large-scale systematic processing under Art. 37), contact details must be disclosed under Art. 13(1)(b). Even where a DPO is not required, a privacy contact address must be provided.
Evidence — /privacy-policy (searched all pages)
No mention of "DPO", "Data Protection Officer", or dedicated privacy contact beyond generic support email. General support@examplecorp.com does not satisfy Art. 13(1)(b).
Remediation
If a DPO is appointed, add dpo@examplecorp.com with physical address to the privacy policy header and footer. If no DPO is required, designate a privacy contact role and disclose that address. Assess whether your processing operations trigger Art. 37 mandatory appointment.
Cookie Consent Mechanism Present
GDPR Art. 7, ePrivacy Directive
PASS
A cookie consent banner is present on the homepage. Analytics cookies are blocked prior to consent. The banner includes "Accept All" and "Reject All" options. The cookie policy is linked from the banner and includes cookie duration and third-party processor disclosures. Compliant with GDPR Art. 7 and ePrivacy Directive requirements.
Privacy Policy Accessible
GDPR Art. 12, 13
PASS
Privacy policy is linked from the footer of all pages, accessible at /privacy-policy, loads in under 2 seconds, and is written in plain language (Flesch-Kincaid Grade 9.2). Meets Art. 12 transparency and accessibility requirements.
Section 2b — Framework Breakdown
HIPAA (Health Insurance Portability and Accountability Act)
52
/ 100 framework score
✓ 2 passed ✗ 3 failed
Business Associate Agreement (BAA) Not Disclosed
45 CFR §164.504(e)
HIGH
The site's intake form collects fields consistent with Protected Health Information (patient name, date of birth, condition description). No mention of Business Associate Agreements with third-party processors (Salesforce CRM, HubSpot, Google Analytics — all detected as active on the page) was found in the privacy policy or BAA statement page. Under 45 CFR §164.504(e), a covered entity must enter into a BAA with each business associate before PHI is disclosed to that associate.
Evidence — /contact (intake form)
Form fields detected: "Patient name", "Date of birth", "Describe your condition". Active third-party scripts: ga.js (Google Analytics), hsforms.js (HubSpot), analytics.js (Segment). No BAA reference found in /privacy-policy or /terms-of-service.
Remediation
Obtain HIPAA-compliant BAAs from each vendor handling PHI (Google, HubSpot, Salesforce all offer BAA addenda for paid plans). Reference BAA existence in your privacy policy. If HIPAA-compliant alternatives aren't available, consider excluding PHI from forms processed by non-BAA vendors or self-hosting the form submission endpoint. Complete within 30 days.
Notice of Privacy Practices (NPP) Incomplete
45 CFR §164.520
HIGH
An NPP link was found on the footer, but the NPP document does not include three required elements under 45 CFR §164.520(b): (1) a description of uses and disclosures the covered entity is required to make, (2) the patient's right to request restrictions on certain disclosures, and (3) the covered entity's duties to protect PHI and to notify individuals following a breach. OCR cites incomplete NPPs in over 60% of enforcement actions.
Evidence — /notice-of-privacy-practices
NPP found at /npp. Missing required sections: "Uses and Disclosures We Are Required to Make", "Your Right to Request Restrictions", "Our Duty to Notify Following a Breach". Word count of NPP: 312 words. A compliant NPP typically runs 800–1,200 words.
Remediation
Use HHS's Model NPP as a baseline (available at hhs.gov). Add the three missing required sections. Have legal counsel review before publishing. Re-publish with an "effective date" header per 45 CFR §164.520(b)(1)(x). Distribute updated NPP to all existing patients within 60 days per 45 CFR §164.520(c)(1)(ii).
Breach Notification Procedure Not Documented
45 CFR §§164.400–414
MEDIUM
No breach notification policy was found on any publicly accessible page. Under 45 CFR §164.410, covered entities must notify affected individuals without unreasonable delay — and no later than 60 days after discovery of a breach. The policy must be documented. Absence of documented breach notification procedures is a standard finding in OCR investigations and was cited in the Lafourche ($480K) and Heritage Valley ($950K) settlements.
Evidence — searched: /privacy-policy, /npp, /terms, /security
No mention of "breach notification", "data breach", "HHS notification", or "60 days" found across any crawled page. The site has no /security, /security-policy, or /breach-response page.
Remediation
Add a breach notification section to your NPP and privacy policy stating: (1) what constitutes a reportable breach, (2) notification timeline (without unreasonable delay, max 60 days), (3) notification method (written notice to individuals, HHS, and media if >500 individuals in a state). Maintain internal breach log per 45 CFR §164.414.
HTTPS / TLS Encryption Active
HIPAA Security Rule, 45 CFR §164.312(e)(2)(ii)
PASS
All pages served over HTTPS with valid TLS 1.3 certificate. HSTS header present (max-age=31536000; includeSubDomains). No mixed content detected. Meets HIPAA addressable implementation specification for encryption of ePHI in transit.
Minimum Necessary Standard Language Present
45 CFR §164.502(b), §164.514(d)
PASS
Privacy policy includes explicit language: "We only collect the minimum information necessary to provide our services. We do not sell, rent, or otherwise disclose PHI beyond what is needed for direct care." Minimum necessary language found and consistent with 45 CFR §164.502(b) requirements.
Section 3 — Prioritized Remediation Roadmap

All violations by priority

Address Critical issues within 72 hours. High within 14 days. Medium within 30 days.

Violation Severity Framework Regulation Effort Action
Lawful Basis Not Disclosed CRITICAL GDPR Art. 13(1)(c) 2–4 hrs Add lawful basis table to privacy policy
Data Subject Rights Incomplete CRITICAL GDPR Art. 15–22 3–6 hrs Add all 6 rights with exercise mechanism
BAA Not Referenced HIGH HIPAA 45 CFR §164.504(e) 1–2 days Execute BAAs with Google, HubSpot, Segment
NPP Incomplete (3 sections) HIGH HIPAA 45 CFR §164.520 4–8 hrs Revise NPP using HHS model template
DPO Contact Missing HIGH GDPR Art. 13(1)(b), Art. 37 1 hr Add dpo@ contact to privacy policy + footer
No Trust Center / SOC 2 Reference HIGH SOC 2 TSC CC6.1, CC9.2 2–5 days Create /security page, reference audit status
Breach Notification Undocumented MEDIUM HIPAA 45 CFR §§164.400–414 2–4 hrs Add breach notification section to NPP
CCPA Data Categories Incomplete MEDIUM CCPA Cal. Civ. Code §1798.110 2–3 hrs Enumerate all 11 CCPA data categories collected
No Incident Response Policy MEDIUM SOC 2 TSC A1.3, CC7.4 1–3 days Publish incident response procedure page
security.txt Missing MEDIUM SOC 2 RFC 9116, TSC CC7.1 30 min Add /.well-known/security.txt with contact
No Subprocessor List MEDIUM SOC 2 TSC CC9.2 1–2 hrs Publish /subprocessors with vendor list
Section 4 — Scan Metadata
Pages Crawled
7
Homepage, /privacy-policy, /terms-of-service, /npp, /contact, /about, /cookie-policy
Checks Performed
25 checks
5 per framework × 5 frameworks (GDPR, EU AI Act, CCPA, HIPAA, SOC 2)
Scan Duration
4m 22s
Multi-page crawl with network-level signal analysis
Third-party Scripts
11 detected
Google Analytics, HubSpot, Segment, Intercom, Hotjar + 6 others analyzed for PHI/PII exposure
Scan Methodology
Automated + AI review
Regex pattern matching + LLM context analysis for nuanced policy interpretation
Report Delivered
May 22, 2026
48-hour turnaround from purchase confirmation on May 20, 2026

Free scan vs. Premium Report

The free scanner is a fast signal check. The Premium Report is a deliverable you can take to your legal team, your board, and your auditor.

Free
Instant Scan
$0
  • 25 checks across homepage only
  • Pass/fail per check, no citations
  • Generic remediation suggestions
  • No evidence snippets or page references
  • No PDF export
  • Single snapshot, no monitoring
Premium
Full Report
$99
  • 25 checks across all crawled pages (7–12 pages)
  • Exact regulation citations (Art. 13, 45 CFR §164.504)
  • Evidence snippets — exact line + page URL for each finding
  • Specific, actionable remediation steps
  • Prioritized roadmap (Critical → High → Medium → Low)
  • Branded PDF — shareable with counsel and auditors
  • 48-hour turnaround SLA
Curious how your peers are doing? See the 50 worst-scoring SaaS companies →
Ready?

Get your own report — $99

48-hour turnaround. Exact citations. Actionable remediation steps. Everything you just saw — for your domain.

Order Premium Report →
48-hr delivery SLA · Refundable if not delivered · Shareable PDF included

Frequently Asked Questions

48-hour turnaround from purchase confirmation. We crawl multiple pages of your site, run all 25 checks across 5 frameworks, compile citations and evidence, and deliver a branded PDF + online report to your email.
We crawl your homepage, privacy policy, terms of service, cookie policy, and up to 10 additional pages (contact forms, signup flows, data request pages) — anywhere compliance signals appear. You can specify priority pages at checkout.
Yes. The Premium Report is delivered as a branded PDF designed for internal circulation, legal review, and board-level reporting. It includes regulation citations and evidence snippets that can be used to brief outside counsel.
Full refund within 48 hours if we haven't delivered your report yet. After delivery, we offer a revision if you find factual errors. We don't refund because you dispute our findings — the findings are based on what's publicly visible on your site.
You get a clean report — which is valuable documentation to show regulators, investors, and customers. A WatchSuit all-pass report is evidence of proactive compliance diligence. We don't artificially inflate findings.

About this sample: The company shown above is anonymized. All findings, citations, and evidence excerpts are based on a real WatchSuit scan. WatchSuit is not a law firm and nothing in this report constitutes legal advice. Compliance requirements are fact-specific to your organization. Consult qualified counsel for regulatory guidance. Last updated: May 2026.