Methodology
This page explains, end to end, how every statistic, risk guideline, and technical finding published on this site is produced. Our design principle throughout: observable facts in, deterministic outputs out — AI assists with discovery and summarization, but no AI model assigns a score or invents a statistic.
How the Website Scanner Works
The Website Privacy Laws Risk Scanner loads the target website in a real, instrumented browser (not a simple HTTP fetch). It records every network request the page makes — to first parties and third parties — along with the scripts that initiated them, cookies and identifiers set, and the timing of each transmission. The scanner visits multiple pages where available, including form-bearing pages.
Browser Instrumentation & Form Testing
To test what tracking technologies actually capture, the scanner types synthetic marker values (never real personal data) into visible form fields and observes whether those values appear in network transmissions before the form is submitted. This is how pre-submission capture by session replay, chat, and marketing scripts is detected empirically rather than assumed from vendor documentation.
Consent Interaction Testing
Where a consent banner is present, the scanner records which transmissions occur before any consent choice, then evaluates whether declining (where offered) actually stops transmission. A banner that hides itself without blocking network calls is treated as an observation, reported as such.
How Risk Scoring Works
Jurisdiction risk guidelines (0–100) are computed by a deterministic formula from stored facts. The overall guideline is composed of six weighted components:
- Statutory structure — 25%: current-law exposure (all-party consent, private right of action, statutory damages, remedies).
- Current litigation activity — 25%: recent filing activity and velocity over defined recent windows (for example 90 days, 6/12/24 months) — not lifetime volume.
- Prior precedent — 18%: authority-weighted outcomes, distinguishing binding appellate decisions from persuasive or trial-court rulings.
- GPC / universal opt-out posture — 15%: whether the state currently requires or recognizes universal opt-out preference signals such as Global Privacy Control, the proximity of enacted future requirements, and GPC-related enforcement activity. This measures the state's legal posture only — never any individual website's behavior. When a state's GPC status is limited data, this component is excluded and the remaining weights are renormalized, so limited data never reads as lower exposure.
- Regulatory enforcement — 9%: agency investigations, sweeps, settlements, guidance, and rulemaking, tracked separately from private lawsuits.
- Forward-looking 24-month horizon — 8%: enacted laws and final regulations with future effective dates (kept separate from merely pending legislation).
Evidence confidence (0–100%) reflects the tier, volume, freshness, and corroboration of underlying sources. The same inputs always produce the same outputs; scores change only when the underlying facts change. Administrators can apply documented manual overrides, which are recorded and displayed. Throughout, AI explains findings; it never assigns a numeric score.
Current Litigation vs. Precedent (Volume ≠ Legal Merit)
We deliberately measure two different things separately. Current litigation activity captures how much recent filing and demand activity a jurisdiction is seeing, using recent windows and velocity rather than lifetime counts — so a state with high historical activity but rapidly declining current filings reflects that decline. Precedential risk captures the authority of what courts have actually decided. A high number of filings does not by itself indicate strong plaintiff-favorable binding precedent; conversely, a jurisdiction with moderate activity but strong plaintiff-favorable appellate authority can carry meaningful legal exposure. We never collapse these into one figure.
How Precedent Is Weighted
Decisions are weighted by the authority of the court and the applicability of the ruling: U.S. Supreme Court and applicable federal circuit authority, a state supreme court interpreting that state's own law, state appellate courts, federal district courts, and state trial courts, followed by other persuasive authority. Deterministic logic controls this weighting; AI may summarize the significance. We do not treat a settlement as equivalent to a binding appellate decision, a dismissal for lack of standing as a holding that a technology is lawful, or a denial of a motion to dismiss as a final plaintiff victory. Merits decisions are distinguished from procedural rulings, and pending cases are distinguished from decided ones, with appeals tracked explicitly.
How Future Laws and Pending Legislation Are Treated
We track a rolling 24-month legal horizon of enacted laws and final regulations with future effective dates, along with material compliance deadlines. These may affect a jurisdiction's forward-looking risk but are never presented as currently enforceable. Merely introduced or pending bills are labeled separately as "legislation to watch" — we never state that a pending bill "will become law."
How GPC (Global Privacy Control) Testing Works
Global Privacy Control is a browser- or device-level opt-out preference signal, not a wiretap signal and not a blanket withdrawal of all consent. Our scanner runs the target site twice in clean, isolated browser contexts: a normal session with GPC not enabled, and a GPC-enabled session using the recognized Sec-GPC: 1 request header and the navigator.globalPrivacyControl JavaScript property. It independently verifies that the signal was actually transmitted before drawing any conclusion, then compares the two sessions to see whether relevant sale/share-related and targeted-advertising behavior changed. It also checks for a /.well-known/gpc.json transparency declaration and compares the site's stated privacy policy against observed behavior.
Results are reported as technical classifications — for example "GPC response detected", "partial GPC response", "no detectable GPC response", "potential GPC concern", or "GPC test inconclusive". We do not describe a site as "illegal" or as "violating" a law based on automated behavior. A GPC readiness assessment is computed deterministically; AI explains it. State-by-state GPC legal status (current requirement, future requirement, scope, enforcement) is tracked separately in each jurisdiction's canonical record and surfaced on the Global Privacy Control hub. Technical limitations apply: some sites cannot be reliably instrumented, and applicability of any state requirement depends on facts the scanner cannot determine.
Source Hierarchy
Every fact is tied to at least one source, classified by tier:
- Tier A — Primary authority: court opinions, dockets, statutes, government publications
- Tier B — Authoritative secondary: recognized legal press and bar publications
- Tier C — Professional analysis: law firm client alerts and practitioner commentary
- Tier D — Industry data: vendor and industry reports
- Tier E — General web: other public sources, used only with corroboration
Citations on public pages are prioritized by tier. Facts supported only by lower-tier sources are labeled accordingly or held back until corroborated.
How AI Is Used (and Not Used)
OpenAI models assist with two tasks: discovering candidate public sources through structured web research, and extracting structured facts (case names, courts, dates, statutes, technologies) from those sources. Every extraction stores its source URL, model, and confidence. AI is not used to assign risk scores, generate statistics, or write legal conclusions. Narrative text on jurisdiction pages is generated from stored facts and is constrained to describe only what the sources support.
Lawsuit vs. Demand Letter vs. Tracked Matter vs. Reported Claim
- Lawsuit: a filed court case identified in our source set
- Demand letter: pre-suit correspondence activity reported by tracked sources
- Tracked matter: a litigation-related matter we track that doesn't cleanly fit the above (arbitrations, consolidated activity, matters of uncertain posture)
- Reported claim: activity claimed by a source but not yet independently corroborated
These are counted separately and never combined into a single inflated figure. Statistics are labeled Official, Estimated, Tracked, or Reported to make provenance explicit.
Automatic Page Publication & Quality Gates
Case, statute, and technology pages are created automatically from the intelligence database, but only published when they meet minimum-content standards (identified jurisdiction, substantive summary, source support). Pages that don't meet the standard remain unpublished rather than published thin. Page "last updated" dates change only when the underlying facts change — never cosmetically.
Limitations
- Tracked counts reflect our source set, not a census of all litigation; absence of data is labeled "Limited Data", never "safe".
- Scanner findings reflect the pages scanned at the time of scanning; sites change.
- Public sources sometimes conflict; we favor higher-tier sources and note uncertainty.
- Nothing on this site is legal advice, a legal opinion, or a determination of liability.
Corrections
We correct errors promptly. If you believe any statement, statistic, or case description on this site is inaccurate, contact us via the contact page with the page URL; we will review the underlying sources and update the page, and material corrections are reflected in the page's revision history.
About the Publisher
Inspection-Ready Institute, Inc. (DBA Crandall Consulting) is an independent website compliance and risk consultancy. We are not a law firm, and we do not sell legal services. The scanner, the intelligence database, and these pages exist to give website operators an evidence-based, informational starting point.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website