Scanned on 23 June 2026 at 07:02 UTC· 3 total scans
As of , laufen.de has a GDPR compliance score of 86/100 with 5 pre-consent tracking violations detected.
Only Privacy Score 100 means full compliance. These violations mean that before you could even click the Cookie Consent banner, this website already collected your personal data and shared it with third parties. Learn why this matters (our blog) →
Who is responsible? The website owner is solely responsible for these violations and in general often benefits monetarily (directly or indirectly) from collecting and sharing your data without your consent.
Collects usage statistics (pages visited, clicks, session duration) without consent.
Services and cookies that comply with GDPR requirements. No consent needed.
Most findings on this page are configuration problems, not catastrophes. These plain-language guides explain what each one means and how to fix it, written for website owners rather than lawyers.
All guides live at gdprscanner.eu/guides.
laufen.de has a GDPR compliance score of 86/100.
A score above 80 indicates minor issues such as non-essential fonts loaded from external servers or low-risk first-party cookies. The website has some room for improvement but avoids severe violations.
3 trackers detected loading before user consent:
Legal basis: This violates GDPR Article 6(1)(a), ePrivacy Directive Article 5(3), and Austrian DSB Decision (DSB-D155.027, 2022). Analytics trackers process personal data such as IP addresses and browsing behaviour. The Austrian Data Protection Authority ruled in January 2022 that Google Analytics use without consent violates GDPR, as data is transferred to the US without adequate safeguards. The ePrivacy Directive requires prior consent for accessing information on a user's device unless strictly necessary.
| Cookie Name | Domain | Type | Service | Duration |
|---|---|---|---|---|
| _pk_ses.1.552e | .www.laufen.de | 1st party |
This GDPR compliance scan of laufen.de was performed by GDPR Scanner, a pre-consent privacy scanning tool. The scan captures all trackers, cookies, and third-party scripts that load before a user clicks any consent button.
Under GDPR (General Data Protection Regulation), websites must obtain explicit consent before processing personal data. Any tracker or cookie that fires before consent is a potential violation of EU privacy law.
A privacy score of 100/100 means the website loads zero trackers and zero tracking cookies before the user gives consent. This is the standard required by GDPR Article 5(1)(a) and Article 7.
Essential cookies (session management, security tokens) and first-party functional cookies do not incur penalties, as they are covered by the legitimate interest legal basis. See an example: playhth.com scores 100/100.
| Matomo - Matomo session cookie |
| Session |
| _pk_id.1.552e | .www.laufen.de | 1st party | Matomo - Matomo unique visitor ID | Session |
laufen.de has minor GDPR compliance issues. While 5 violations were detected, these are typically low-severity items such as external font loading or empty tag containers.
Under GDPR, even minor violations can attract regulatory attention, particularly in jurisdictions with active data protection authorities such as France (CNIL), Ireland (DPC), and Austria (DSB). Addressing these issues proactively reduces legal risk.
The ePrivacy Directive requires consent for all non-essential device access. Even low-severity items like external fonts transfer visitor IP addresses to third-party servers without consent.
laufen.de scores 86/100 with 5 violation(s) detected. Trackers or cookies were found loading before user consent.
Our scan detected 3 tracker(s) loading before consent, including Matomo.
Yes, 2 cookie(s) were detected before the user interacted with any consent banner.
laufen.de has a GDPR compliance score of 86/100 as of 23 June 2026. A score of 100 means no trackers or cookies load before consent. laufen.de currently has 5 violation(s) affecting its score.
laufen.de should implement a Consent Management Platform (CMP) that blocks all non-essential trackers and cookies until the visitor gives explicit consent. This includes configuring tag managers like Google Tag Manager to use consent-aware triggers, self-hosting external fonts, and auditing all third-party scripts. After making changes, re-scan with GDPR Scanner to verify compliance.