Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Home› Editorial› Privisy Review: What It Is, How It Works,…
DATA

Privisy Review: What It Is, How It Works, and What It Costs

Most companies that worry about the California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), eventually install a consent management platform, configure a cookie banner, publish a privacy policy, and move on.

Oct 7, 2026 10 min read

Know what’s on your site before a plaintiff’s firm does

A free privacy audit shows which cookies, pixels and trackers are running — and which ones commonly appear in privacy claims.

Get My Free Audit

Most companies that worry about the California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), eventually install a consent management platform, configure a cookie banner, publish a privacy policy, and move on. The uncomfortable question that often goes unasked is whether all of that still works on the live website months later. Privisy, found at getprivisy.com, is built around exactly that question. It is an outside-in CCPA/CPRA compliance verification tool that scans a public website the way a visitor or regulator would, records what actually fires on the network, and ties every issue it finds back to the specific section of California law behind it.

In this piece we break down what Privisy is, how its audit works, what the 56 checks cover, how its pricing is structured, who is behind it, and where it fits in a broader privacy program.

Privisy Privacy Platform

What Is Privisy?

Privisy describes itself as a CCPA/CPRA compliance verification service. Its pitch is simple: see where your site actually stands on CCPA. Rather than managing consent on your behalf, Privisy acts as an independent auditor. It loads your pages like a real visitor would, watches the network traffic, evaluates the visible privacy interface, tests how the site responds to Global Privacy Control (GPC) signals, and reviews the substance of your privacy policy.

The result is a graded report in which every finding carries three things: the evidence of what was observed, the recommended fix, and the CCPA regulation or statute section the issue falls under. That combination is designed to be useful to two very different audiences at once, the legal team that needs to understand exposure and the engineering team that needs to know what to change.

A key selling point is that there is nothing to install. Privisy advertises zero lines of code, no SDK, no snippet, and no access to your codebase or analytics. You provide a URL, and the scan runs from the outside. According to the company, most scans finish in under two minutes.

The Core Argument: Your Compliance Tool Grades Its Own Work

Privisy’s positioning rests on a pointed observation. A consent management platform (CMP) enforces the rules it was configured with, and many CMPs also scan for tags. But when a CMP reports on whether your site is compliant, it is reporting on the very setup it manages. Privisy compares this to letting a student grade their own test.

The company highlights three reasons an outside view matters:

  • Configuration drift and piggybacking. Marketing teams add tags, vendors load other vendors behind the scenes, and third-party scripts update on their own release schedules. Something that behaved correctly when your consent tool was set up is not automatically still behaving correctly this quarter.
  • No legal safe harbor. Privisy notes that in 2026, believing you were compliant is not a defense. The California Privacy Protection Agency (CPPA) is actively issuing fines, and your CMP vendor is not going to pay them for you.
  • Independent verification. An outside scan has no stake in the outcome. It reports what your pages actually send, whether or not that matches what your configuration intends.

This framing is worth taking seriously regardless of which tools you use. Consent tooling and verification are different jobs, and mature privacy programs increasingly treat them that way.

How the Privisy Audit Works

The process is presented in three steps:

  1. Submit your URLs. You enter the pages that matter most, such as checkout flows, signup forms, and anywhere users hand over personal data.
  2. The audit engine runs. Privisy’s scanner loads each page like a real visitor and checks it against 2026 CCPA/CPRA standards.
  3. You get the report. The output is a risk report with actionable remediation items intended for both legal and engineering stakeholders.

No account or credit card is required to run the free scan. Privisy also publishes a sample audit of a fictional storefront so you can see what a full report looks like before running one on your own site.

What the 56 Checks Cover

Every full Privisy audit evaluates 56 checks organized into four audit domains.

1. UI and Page Compliance (9 checks)

These are the surface-level disclosures and opt-out mechanisms a regulator is likely to review first. Examples of the highest-severity checks include:

  • Do Not Sell or Share link (rated critical): whether a business that sells or shares personal information provides a clear “Do Not Sell or Share My Personal Information” link, an Alternative Opt-out Link under § 7015, or frictionless opt-out preference signal processing with the required policy disclosures. Cited sections include § 7013, § 7015, and § 1798.135.
  • Privacy policy link (rated critical): whether the privacy policy is posted online and reachable from a conspicuous link that uses the word “privacy,” per § 7011.
  • Notice at collection (rated high): whether consumers are told, at or before the point of collection, what categories of personal information are collected, why, whether it is sold or shared, and how long it is retained, per § 7012 and § 1798.100.

2. Tracker and Network Leak Detection (3 checks)

This is where the network-level approach comes in. Privisy records what third-party trackers actually load and send data, producing a tracker inventory. Paid tiers include deeper network-layer analysis, which is particularly useful for catching piggybacked scripts that never appear in a tag manager.

3. Global Privacy Control Validation (13 checks)

GPC is a browser-level signal that tells a website the user wants to opt out of the sale or sharing of their data. California regulations (§ 7025) have required businesses to honor opt-out preference signals like GPC since 2023, and it has become a frequent enforcement theme. With 13 checks, GPC validation is the second-largest domain in the audit, which reflects how much regulatory attention this area is getting.

4. Privacy Policy Substance Review (31 checks)

The largest domain looks at what your privacy policy actually says, not just whether it exists. These 31 checks evaluate whether required CCPA disclosures are present and substantive. Privisy states its audit covers the full 2026 landscape, including Automated Decision-Making Technology (ADMT) disclosure requirements under §§ 7200, 7220, 7221, and 7222, which became operative January 1, 2026, with compliance due by January 1, 2027 for ADMT use that began before that date. It also covers the updated symmetry-of-choice and dark pattern rules under § 7004.

The company says it is also tracking AB 566, the California Opt Me Out Act, which requires browsers themselves to ship an opt-out preference signal starting January 1, 2027. That change is likely to dramatically increase the volume of GPC-style signals websites receive, making correct handling even more important.

Privisy Pricing

Privisy uses a freemium model with a clear upgrade path. Here is how the tiers break down based on the pricing published on its website.

Free Audit: $0

Every free scan is the full 56-check audit. You get the compliance verdict, section scores, and the name and severity of every check. What you do not get is the evidence, the specific tracker names, and the recommended fixes. No card or account is required, so this works well as a quick health check or a way to size up a client or prospect site.

Single Audit: $49 per audit

The one-time $49 purchase unlocks the report you already ran. It includes:

  • Full evidence, tracker names, and remediation steps
  • One credit equals one full audit of one URL, with all 56 checks
  • Pay-per-audit credits that never expire
  • Deep network-layer tracker analysis
  • Global Privacy Control verification
  • Automated privacy policy substance review

This tier suits teams that want a point-in-time snapshot before a launch, a board meeting, an acquisition review, or a response to a demand letter.

Privisy’s recommended plan re-audits one domain automatically every week. The pitch is to “catch the tag that shipped last Tuesday,” meaning a new vendor or broken opt-out surfaces within days instead of at the next annual review. The plan includes:

  • Automatic weekly re-audit of one domain
  • Every run is the full 56-check audit
  • A dated report for every weekly run, which builds a useful compliance record over time
  • Starting monitoring also unlocks the report you already ran
  • Audits of other URLs use credits as usual
  • Cancel online any time through the billing portal

At $348 per year, that works out to $29 per month, or roughly $6.70 per weekly audit, which is a meaningful discount compared to buying single audits.

Agency: Contact for pricing

For agencies and consultancies auditing multiple client sites, Privisy offers custom volume pricing. Every audit uses the same full 56-check engine, and the company asks prospects to share how many sites they manage so it can build a plan.

Quick Tier Comparison

Feature Free Audit Single Audit ($49) Monitoring ($348/yr)
Compliance verdict and section scores Yes Yes Yes
UI and banner checks Names and severity Detailed findings Detailed findings
Third-party tracker inventory Locked Full inventory Full inventory
Remediation steps No Yes Yes
Automatic weekly re-audit No No 1 domain
Account required No Yes Yes

Why the Timing Matters: CCPA Enforcement Is Real

Privisy leans on recent enforcement to make its case, and the numbers it cites are significant. According to the site, three actions alone total $15.87 million:

  • General Motors (OnStar), May 2026, $12.75 million. Described as the largest CCPA penalty to date, tied to selling drivers’ geolocation and behavior data to brokers despite a privacy policy saying otherwise.
  • The Walt Disney Company, February 2026, $2.75 million. Opt-out toggles applied to only one streaming service at a time, and GPC signals were honored per device instead of account-wide.
  • Ford Motor Company, March 2026, $375,000. Required email verification before honoring opt-outs and continued selling data after consumers opted out. Ford must now audit its tracking for GPC compliance.

The common thread across these cases is a gap between what a company said or intended and what its systems actually did. That gap is precisely what outside-in verification is designed to expose.

Who Is Behind Privisy?

Privisy was founded by Patrick Daly, who brings 17 years of experience leading digital experience, MarTech, and privacy programs at GM Financial and Santander Consumer USA. In his words on the site, he kept meeting companies that believed having a CMP meant they were compliant, and he built Privisy to give them an outside, network-level view of what their sites actually send.

Chris George serves as Chief Revenue Officer, with a decade of experience leading partnerships and business development at Vinli, Octopus Energy, and EVolve Houston.

Beyond the product, Privisy publishes a CCPA compliance blog, a regulation library, a CCPA reference, a GPC signal guide, a piece on CMP blind spots, and a free CCPA compliance checklist for teams that want to work through requirements on their own first.

Common Questions About Privisy

We already use a CMP. Why would we need this?

Privisy’s answer is that a CMP reports on the setup it manages. An independent scan checks whether your CMP’s blocking rules are still holding on the live site. If everything checks out, you have evidence instead of an assumption. If you want a top tier CMP solution then use Captain Compliance’s cookie consent solution.

Does Privisy need access to our code or analytics?

No. It scans your public-facing site from the outside, with no code installation and no access to internal systems.

Is it updated for 2026 rules?

According to the company, yes. It covers GPC obligations under § 7025, the new ADMT disclosure rules, the updated dark pattern and symmetry-of-choice rules, and it tracks AB 566.

Strengths and Limitations

Privisy’s strengths are clear. The free tier runs the entire audit, which makes it easy to try. Citing a specific legal section for every finding is genuinely helpful when translating technical issues for counsel. The zero-install approach removes procurement and security review friction. And weekly monitoring at under $30 a month is accessible for small and mid-sized businesses.

There are also limits worth noting. Privisy is focused on California’s CCPA/CPRA, so companies with obligations under GDPR, other U.S. state privacy laws, or international frameworks will need broader coverage. It is a verification tool, not a consent platform, so it tells you what is broken but does not itself manage consent, process data subject requests, or generate policies. The monitoring plan covers one domain, so organizations with many properties will want to look at agency or volume pricing.

Where Privisy Fits in a Privacy Program

The best way to think about Privisy is as a second set of eyes. Consent management, DSAR workflows, GPC handling, and dynamic privacy policies are the operational layer that actually makes a website compliant. Independent verification is the assurance layer that confirms the operational layer is still doing its job. Strong programs need both, and the enforcement actions above show what happens when the gap between intention and reality goes unnoticed.

If you run a website that collects data from California residents, running a free scan is a low-effort way to see your site the way a regulator might. Whatever the result, the exercise is a useful reminder that privacy compliance is not a one-time setup but an ongoing practice that needs regular, honest checking.

Put this into practice

Turn privacy guidance into working controls.

Captain Compliance helps teams discover tracking technologies, enforce consent, manage privacy requests and document the evidence behind every decision.

Book a demo Run a free scan