“How would anyone even know I sell there?” has a checkable answer. Six signals in your own page source, five of which you chose — and one you probably did not.
Most people who ask “how would they find me?” are picturing enforcement as a search: someone has to notice you, decide you matter, and come looking. Under that picture, being small is protection and being far away is protection.
The scope tests are not built that way. They do not ask whether anyone noticed you. They ask what your operation does — and your website is a continuous, public, machine-readable statement about what your operation does. Nobody has to find you to read it. It is already published.
Nothing here says anyone is coming. It says that the facts the scope tests turn on are facts you publish yourself, which means you can check exactly what a platform reviewer, a competitor or a supervisory authority would check — using nothing but your own browser, before anyone else looks.
This is compliance research, not legal advice. Sitetals is an independent website scanner, not a law firm, and is not affiliated with any data protection authority. Whether a particular law applies to a particular business is a question of fact and law that turns on that business’s own circumstances. Nothing here is a determination that any reader is subject to, or in breach of, anything. For a decision that carries risk, take advice from a practitioner qualified in the jurisdiction concerned.
GDPR Recital 23 names currency directly: the use of a currency generally used in one or more Member States, with the possibility of ordering goods and services in that currency, is among the factors that may make it apparent that a controller envisages offering services to data subjects in the Union. A price in euro is not a neutral formatting choice. Neither is a currency switcher that offers euro as an option.
Recital 23 names language in the same breath. An hreflang tag is more explicit
than prose: it is a machine-readable declaration that this page exists for readers of that
language in that region. hreflang="fr-FR" is your site stating who the page is for.
So is a translated checkout.
A shipping-country or billing-country selector is a list of the places you are willing to transact with. If a country is selectable at checkout, the page is offering to ship there. That is about as close to a plain statement of “offering goods” as a web page gets.
SEPA, Bancontact, giropay, iDEAL, Przelewy24, PayNow — these exist to take money from people in particular countries. Mounting one is a decision to accept payment from that market. The reasoning does not change with the region; it is the same for a Singapore-facing rail as for a European one.
“We ship worldwide” and “free EU delivery” are the plainest version of all. So is a VAT line, a customs note, or a returns policy that names a jurisdiction.
Analytics and advertising tags fire from your page source on first load. Under GDPR Art. 3(2)(b), monitoring the behaviour of people in the Union — as far as that behaviour takes place in the Union — is an independent trigger, separate from offering anything. A free blog with an advertising pixel and European readers engages that limb without ever taking a payment.
Art. 3(2) has two limbs and they operate separately. The first is about offering goods or services, irrespective of whether payment is required. The second is about monitoring behaviour. A site that sells nothing at all can engage the second one on its analytics configuration alone.
Points 1 through 5 are things you chose. Point 6 usually is not.
Most site owners did not decide to install tracking; a theme, a plugin, a tag manager or an agency did, and it has been firing ever since. The same is true of the country list in a checkout — platform defaults ship with every country enabled, and most people never open that setting.
So a site can be making statements about who it serves that its owner never made and would not recognise. That is worth checking precisely because it is not a decision you remember making.
Open your homepage, view source, and search it for each of these:
| Search your page source for | What a hit tells you |
|---|---|
A currency symbol or ISO code — €, EUR, SGD, BRL | Which markets your pricing is denominated for. |
hreflang | Which language and region audiences the page declares itself to be for. |
option value="FR" — or any country code | Which countries a customer can select. Check the checkout too, not only the homepage. |
| The name or domain of a payment provider | Which local payment rails are mounted, and therefore which markets you accept money from. |
| The domain of any analytics or advertising script | What is observing visitor behaviour, and whether it runs before any consent is given. |
Everything you find is a fact about your configuration. None of it, on its own, determines your legal position — scope turns on what your operation actually does, and thresholds and exemptions vary by regime. But knowing what your site publishes is the part you can settle today, without paying anyone.
Sitetals reads the public pages of your website and reports the compliance basics it can see from the outside — privacy policy, legal notice, cookie and consent essentials — for Singapore, France and Germany. The scope signals this article walks through are ones you can read off your own page source with the checklist above; they are not part of the scan’s output. Either way, it is a reading of what is published, not a finding of breach.
Run a free compliance checkFree, no account required. We do not store personal data from scanned sites.
Read the source yourself or let a scanner do it — the point is the same either way: stop guessing what your site says about you, and go read it.