Scanned on 10 July 2026 at 04:24 UTC
As of , lakhay.com has a GDPR compliance score of 62/100 with 11 pre-consent tracking violations detected.
Only Privacy Score 100 means full compliance. These violations mean that before you could even click the Cookie Consent banner, this website already collected your personal data and shared it with third parties. Learn why this matters (our blog) →
Who is responsible? The website owner is solely responsible for these violations and in general often benefits monetarily (directly or indirectly) from collecting and sharing your data without your consent.
Consent platform: Google Consent
Collects usage statistics (pages visited, clicks, session duration) without consent.
Tracking cookies are used to identify and follow users across websites. Under GDPR, these require explicit consent before being set, but on this website they are active immediately.
Low-severity concerns: external fonts, empty tag containers, WebSocket connections, and third-party storage.
Services and cookies that comply with GDPR requirements. No consent needed.
Recognised and seen loading before consent, but we did not observe them transmit tracking data, so they are not counted in your score. Worth checking each still respects consent.
Recognised but not counted. No impact on your privacy score.
Pending classification by our team. No impact on your privacy score.
These items are pending classification. No impact on your privacy score.
Most findings on this page are configuration problems, not catastrophes. These plain-language guides explain what each one means and how to fix it, written for website owners rather than lawyers.
All guides live at gdprscanner.eu/guides.
lakhay.com has a GDPR compliance score of 62/100.
A score between 50 and 79 indicates moderate GDPR compliance issues. Analytics trackers or advertising scripts are likely loading before user consent, which may result in regulatory attention.
5 trackers detected loading before user consent:
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and Austrian DSB Decision (DSB-D155.027, 2022). Analytics trackers process personal data such as IP addresses and browsing behaviour. The Austrian Data Protection Authority ruled in January 2022 that Google Analytics use without consent violates GDPR, as data is transferred to the US without adequate safeguards. The ePrivacy Directive requires prior consent for accessing information on a user's device unless strictly necessary.
Legal basis: This violates ePrivacy Directive Article 5(3) and CJEU Planet49 (C-673/17). Third-party storage access (localStorage, sessionStorage) on external domains constitutes accessing device information without user consent. The Planet49 ruling confirmed that the ePrivacy Directive's consent requirement applies to all information stored on or accessed from a user's terminal equipment.
This GDPR compliance scan of lakhay.com was performed by GDPR Scanner, a pre-consent privacy scanning tool. The scan captures all trackers, cookies, and third-party scripts that load before a user clicks any consent button.
Under GDPR (General Data Protection Regulation), websites must obtain explicit consent before processing personal data. Any tracker or cookie that fires before consent is a potential violation of EU privacy law.
A privacy score of 100/100 means the website loads zero trackers and zero tracking cookies before the user gives consent. This is the standard required by GDPR Article 5(1)(a) and Article 7.
Essential cookies (session management, security tokens) and first-party functional cookies do not incur penalties, as they are covered by the legitimate interest legal basis. See an example: playhth.com scores 100/100.
Legal basis: This violates ePrivacy Directive Article 5(3) and CJEU Planet49 (C-673/17). Third-party storage access (localStorage, sessionStorage) on external domains constitutes accessing device information without user consent. The Planet49 ruling confirmed that the ePrivacy Directive's consent requirement applies to all information stored on or accessed from a user's terminal equipment.
| Cookie Name | Domain | Type | Service | Duration |
|---|---|---|---|---|
| _shopify_marketing | www.lakhay.com | 1st party | Shopify Marketing - Contains marketing data for buyer surfaces such as the storefront or checkout. | Session |
| _shopify_s | .lakhay.com | 1st party | Shopify - Shopify analytics. | Session |
| _shopify_y | .lakhay.com | 1st party | Shopify - Shopify analytics. | Session |
| _shopify_analytics | www.lakhay.com | 1st party | Shopify Analytics - Contains analytics data for buyer surfaces such as the storefront or checkout. | Session |
lakhay.com has 11 GDPR compliance violations with 5 trackers loading before user consent. This level of non-compliance carries meaningful regulatory risk.
Under GDPR Article 83, supervisory authorities can impose fines of up to €20 million or 4% of annual global turnover, whichever is higher. While fines for consent violations typically range from €10,000 to €500,000, larger organisations have faced fines exceeding €50 million.
Implementation of a properly configured Consent Management Platform (CMP) that blocks all non-essential scripts until consent is obtained is the recommended remediation step.
lakhay.com scores 62/100 with 11 violation(s) detected. Trackers or cookies were found loading before user consent.
Our scan detected 31 tracker(s) loading before consent, including Shopify CDN, Shopify E-commerce Platform, Shopify.
Yes, 8 cookie(s) were detected before the user interacted with any consent banner.
lakhay.com has a GDPR compliance score of 62/100 as of 10 July 2026. A score of 100 means no trackers or cookies load before consent. lakhay.com currently has 11 violation(s) affecting its score.
lakhay.com should implement a Consent Management Platform (CMP) that blocks all non-essential trackers and cookies until the visitor gives explicit consent. This includes configuring tag managers like Google Tag Manager to use consent-aware triggers, self-hosting external fonts, and auditing all third-party scripts. After making changes, re-scan with GDPR Scanner to verify compliance.