CRANDALL CONSULTING
Home › Methodology

Methodology

Published by Crandall Consulting · Informational litigation intelligence · Last substantive update: August 8, 2026

Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

This page explains, end to end, how every statistic, risk guideline, and technical finding published on this site is produced. Our design principle throughout: observable facts in, deterministic outputs out — AI assists with discovery and summarization, but no AI model assigns a score or invents a statistic.

How the Website Scanner Works

The Website Privacy Laws Risk Scanner loads the target website in a real, instrumented browser (not a simple HTTP fetch). It records every network request the page makes — to first parties and third parties — along with the scripts that initiated them, cookies and identifiers set, and the timing of each transmission. The scanner visits multiple pages where available, including form-bearing pages.

Browser Instrumentation & Form Testing

To test what tracking technologies actually capture, the scanner types synthetic marker values (never real personal data) into visible form fields and observes whether those values appear in network transmissions before the form is submitted. This is how pre-submission capture by session replay, chat, and marketing scripts is detected empirically rather than assumed from vendor documentation.

Consent Interaction Testing

Where a consent banner is present, the scanner records which transmissions occur before any consent choice, then evaluates whether declining (where offered) actually stops transmission. A banner that hides itself without blocking network calls is treated as an observation, reported as such.

How Risk Scoring Works

Jurisdiction risk guidelines (0–100) are computed by a deterministic formula from stored facts. The overall guideline is composed of six weighted components:

Evidence confidence (0–100%) reflects the tier, volume, freshness, and corroboration of underlying sources. The same inputs always produce the same outputs; scores change only when the underlying facts change. Administrators can apply documented manual overrides, which are recorded and displayed. Throughout, AI explains findings; it never assigns a numeric score.

Current Litigation vs. Precedent (Volume ≠ Legal Merit)

We deliberately measure two different things separately. Current litigation activity captures how much recent filing and demand activity a jurisdiction is seeing, using recent windows and velocity rather than lifetime counts — so a state with high historical activity but rapidly declining current filings reflects that decline. Precedential risk captures the authority of what courts have actually decided. A high number of filings does not by itself indicate strong plaintiff-favorable binding precedent; conversely, a jurisdiction with moderate activity but strong plaintiff-favorable appellate authority can carry meaningful legal exposure. We never collapse these into one figure.

How Precedent Is Weighted

Decisions are weighted by the authority of the court and the applicability of the ruling: U.S. Supreme Court and applicable federal circuit authority, a state supreme court interpreting that state's own law, state appellate courts, federal district courts, and state trial courts, followed by other persuasive authority. Deterministic logic controls this weighting; AI may summarize the significance. We do not treat a settlement as equivalent to a binding appellate decision, a dismissal for lack of standing as a holding that a technology is lawful, or a denial of a motion to dismiss as a final plaintiff victory. Merits decisions are distinguished from procedural rulings, and pending cases are distinguished from decided ones, with appeals tracked explicitly.

How Future Laws and Pending Legislation Are Treated

We track a rolling 24-month legal horizon of enacted laws and final regulations with future effective dates, along with material compliance deadlines. These may affect a jurisdiction's forward-looking risk but are never presented as currently enforceable. Merely introduced or pending bills are labeled separately as "legislation to watch" — we never state that a pending bill "will become law."

How GPC (Global Privacy Control) Testing Works

Global Privacy Control is a browser- or device-level opt-out preference signal, not a wiretap signal and not a blanket withdrawal of all consent. Our scanner runs the target site twice in clean, isolated browser contexts: a normal session with GPC not enabled, and a GPC-enabled session using the recognized Sec-GPC: 1 request header and the navigator.globalPrivacyControl JavaScript property. It independently verifies that the signal was actually transmitted before drawing any conclusion, then compares the two sessions to see whether relevant sale/share-related and targeted-advertising behavior changed. It also checks for a /.well-known/gpc.json transparency declaration and compares the site's stated privacy policy against observed behavior.

Results are reported as technical classifications — for example "GPC response detected", "partial GPC response", "no detectable GPC response", "potential GPC concern", or "GPC test inconclusive". We do not describe a site as "illegal" or as "violating" a law based on automated behavior. A GPC readiness assessment is computed deterministically; AI explains it. State-by-state GPC legal status (current requirement, future requirement, scope, enforcement) is tracked separately in each jurisdiction's canonical record and surfaced on the Global Privacy Control hub. Technical limitations apply: some sites cannot be reliably instrumented, and applicability of any state requirement depends on facts the scanner cannot determine.

Source Hierarchy

Every fact is tied to at least one source, classified by tier:

Citations on public pages are prioritized by tier. Facts supported only by lower-tier sources are labeled accordingly or held back until corroborated.

How AI Is Used (and Not Used)

OpenAI models assist with two tasks: discovering candidate public sources through structured web research, and extracting structured facts (case names, courts, dates, statutes, technologies) from those sources. Every extraction stores its source URL, model, and confidence. AI is not used to assign risk scores, generate statistics, or write legal conclusions. Narrative text on jurisdiction pages is generated from stored facts and is constrained to describe only what the sources support.

Lawsuit vs. Demand Letter vs. Tracked Matter vs. Reported Claim

These are counted separately and never combined into a single inflated figure. Statistics are labeled Official, Estimated, Tracked, or Reported to make provenance explicit.

Automatic Page Publication & Quality Gates

Case, statute, and technology pages are created automatically from the intelligence database, but only published when they meet minimum-content standards (identified jurisdiction, substantive summary, source support). Pages that don't meet the standard remain unpublished rather than published thin. Page "last updated" dates change only when the underlying facts change — never cosmetically.

Limitations

Corrections

We correct errors promptly. If you believe any statement, statistic, or case description on this site is inaccurate, contact us via the contact page with the page URL; we will review the underlying sources and update the page, and material corrections are reflected in the page's revision history.

About the Publisher

Inspection-Ready Institute, Inc. (DBA Crandall Consulting) is an independent website compliance and risk consultancy. We are not a law firm, and we do not sell legal services. The scanner, the intelligence database, and these pages exist to give website operators an evidence-based, informational starting point.

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website