Our Scanning Methodology & Legal Basis
Sitetals is an independent compliance research project. This page explains how we discover compliance issues, why we contact website operators, and what legal framework governs our outreach — in full transparency.
Who We Are
Sitetals is an independent security and compliance research project, not a law firm and not a service vendor. We conduct systematic technical reviews of publicly accessible websites to identify potential EU regulatory compliance risks (GDPR, TDDDG, DDG) and report our findings to website operators in good faith under the principles of Responsible Disclosure.
We have no commercial relationship with any regulatory authority (CNIL, the German data protection authorities, or others) and are not affiliated with them in any way.
Our Technical Methodology
Passive Discovery Only
All compliance checks are performed exclusively through standard, unauthenticated public HTTP(S) GET requests — the same method used by any ordinary web browser visiting a website. We do not:
- Use authenticated access, credentials, or session tokens
- Engage in directory brute-forcing or path fuzzing
- Attempt to bypass Web Application Firewalls (WAFs) or rate limits
- Access any non-public, password-protected, or member-only areas
- Store, index, or retain website content, or the personal data of website visitors
- Build profiles of, enrich, or re-identify the operators we contact
The only personal data we retain from a scan is the publicly-listed business contact email address, which we process under our documented Legitimate Interest Assessment (Art. 6(1)(f) GDPR) solely to send one disclosure email and to honour opt-out requests.
Our scanner reads only what any anonymous visitor can see. Technical logs are retained to demonstrate lawful, passive access in the event of a regulatory inquiry.
Contact Email Discovery
We locate contact email addresses exclusively from:
- Publicly listed email addresses on the website's homepage, Impressum, Mentions Légales, or contact page
- The
Contact:field in a/.well-known/security.txtfile (preferred — per RFC 9116 this is the designated channel for responsible disclosure)
We prioritise generic business addresses (info@, contact@, datenschutz@, security@). We do not contact personal named addresses unless explicitly listed in a security.txt file.
Legitimate Interest Assessment (LIA)
Legal basis for processing contact email addresses: Art. 6(1)(f) GDPR / Art. 6 Abs. 1 lit. f DSGVO
Purpose: Good-faith notification of potential EU regulatory compliance risks to website operators who may be unaware of their exposure.
Necessity: Email contact is the only viable channel to reach website operators when no other designated disclosure mechanism (such as security.txt) exists.
Balancing test: The minor intrusion of receiving a single informational email is proportionate to and outweighed by the benefit of potentially preventing regulatory sanctions (including GDPR fines) for the recipient's business. The email is sent once only, with no follow-up, no tracking, and an immediate opt-out mechanism. We do not send any outreach to German (.de) operators — Germany is scan-only. These notifications are purely informational and non-commercial: they carry no advertising and no link to any paid product or service, and refer the recipient only to our public website.
Direct link to professional activity (CNIL B2B condition): A compliance notification about potential regulatory risks on a website operator's own website is directly related to that operator's professional activity, satisfying the CNIL's B2B prospection condition for business-to-business electronic contact.
A full signed LIA document is maintained internally by Sitetals. In line with the accountability principle (Art. 5(2) GDPR) it can be produced at any time, and is made available to supervisory authorities within 14 days of a request.
Our Email Policy
One Email Only
We send exactly one notification per domain. We never send reminders, follow-ups, or re-contact operators who do not reply. If they do not act, the matter ends there.
Generic Business Addresses Only
We prioritise generic business addresses (info@, contact@, datenschutz@, security@, etc.) and exclude addresses that resolve to a named individual. We do not contact personal named email addresses unless they are explicitly published as a disclosure contact in a security.txt file.
Zero Tracking
Our outreach emails contain no open-tracking pixels, no link-click trackers, and no read receipts. We deliberately do not know whether our emails are opened — this is by design, not an oversight. This zero-tracking policy is fully consistent with the CNIL's final recommendation on consent for tracking pixels in emails (published 14 April 2026), which applies to both B2C and B2B: because we deploy no tracking pixels, the pixel-consent regime does not apply to our notifications.
Right to Object — Art. 21(4) GDPR / Art. 21 Abs. 4 DSGVO (immediate opt-out)
You have the right to object to this processing at any time (Art. 21(4) GDPR). Any reply with the subject "Abmelden" / "Désabonner" / "Unsubscribe", or an email to optout@compliance.sitetals.com, results in permanent removal from all outreach lists. No confirmation required. No delay. The address is suppressed immediately and never contacted again.
Germany: scan only — no outreach emails
Methodik (Deutsch)
Sitetals ist ein unabhängiges Sicherheits- und Compliance-Forschungsprojekt. Wir führen ausschließlich passive technische Überprüfungen öffentlich zugänglicher Webseiten durch (Standard-HTTP(S)-GET-Anfragen, ohne Authentifizierung) — identisch mit dem Vorgehen eines normalen Websitebesuchers.
Kein Outreach in Deutschland
Für deutsche Websites bieten wir ausschließlich den Scan an — wir versenden keinerlei Benachrichtigungs- oder Outreach-E-Mails an deutsche Betreiber.
Questions or Concerns?
If you received one of our disclosure emails and have questions about our methodology, want to be removed from our lists, or believe our scan results are inaccurate — please contact us directly.
Contact Us →