Methodology: how we evaluate privacy compliance tools

Short version: Every PrivacyComply review and comparison is built from three evidence sources — first-hand use where we have it (iubenda runs this site), vendor documentation read end-to-end, and verified-user reviews on G2 / Capterra / Trustpilot / Reddit. We score on six axes (regulatory coverage, setup friction, total cost, integrations, support, transparency), re-check every page at least quarterly, and disclose affiliate relationships on every commercial page. Rankings are never tied to commission size.

The six scoring axes

Every compliance tool we cover is evaluated against the same six criteria. Each axis is scored 0 – 5; the headline rating is a weighted average, not a simple mean.

AxisWhat we look forWeight
Regulatory coverage GDPR (EU + UK), CCPA / CPRA, PIPEDA, Quebec Law 25, LGPD, POPIA, and Australian Privacy Act. Multi-jurisdiction geo-switching behaviour matters as much as the list of supported laws. 25%
Setup friction Time to first compliant banner. Steps required, code edits needed, plugin availability for WordPress / Shopify / Webflow, default settings sanity. Lower friction = higher score. 15%
Real total cost Listed monthly cost plus hidden upgrade triggers (page views, domains, languages, branding removal). A "free" tier that requires a $25 upgrade to be production-usable doesn't get free-tier credit. 20%
Integrations & standards Google Consent Mode v2, IAB TCF 2.2, Microsoft UET Consent Mode, tag-manager support, Customer Privacy API for Shopify, accessibility (WCAG / EAA). Standards certifications count more than marketing claims. 15%
Support & documentation Response time on paid tiers, depth of public knowledge base, presence of an internal legal team for policy generators, transparency of changelogs. 10%
Transparency Plain pricing, no "contact us for a quote" floor pricing on SMB plans, clear data residency, public consent-log export, public security posture (SOC 2 / ISO 27001 where claimed). 15%

Evidence sources

For every tool we cover we triangulate the score across three independent evidence sources. A claim has to clear at least two of the three to make it into the body of a review.

1. First-hand use, where we have it

iubenda runs this site. The banner you see in the corner, the privacy policy at privacy-policy.html, the cookie policy, and the terms-and-conditions are all iubenda-generated and iubenda-hosted. That means our iubenda assessment is based on live operating experience: dashboard navigation, Consent Database queries, hosted-policy auto-update behaviour, the friction of upgrading between tiers, and what the banner actually looks like on a real live site.

For tools we do not run ourselves, the relevant review page opens with a clear "we have not deployed this tool" note and the rest of the evidence comes from sources 2 and 3 below.

2. Vendor documentation, pricing, and changelogs

We read each vendor's documentation end-to-end before publishing — setup guides, integration docs, pricing tiers (every tier, not just the headline one), changelogs going back at least 12 months, and the small-print on overage charges and renewal terms. Where pricing is "contact us" only, we note that as a transparency penalty rather than guessing.

3. Verified-user reviews and independent reporting

G2, Capterra, Trustpilot, Reddit (r/SaaS, r/smallbusiness, r/gdpr), Product Hunt, and Hacker News threads about each vendor. Verified-buyer reviews are weighted higher than unverified ones; reviews older than 18 months are discounted because privacy software changes fast. Vendor case studies are read but explicitly not used as scoring evidence.

Update cadence

Privacy compliance vendors change pricing, regulatory coverage, and free-tier limits constantly. To keep rankings honest we operate the following review cadence:

Every page carries a visible "Updated" date at the top. If you find a date older than 90 days, email corrections@privacycomply.io and we will prioritise a refresh.

Performance & Core Web Vitals observation

Cookie consent scripts execute on every page load and — if poorly built — can directly degrade Core Web Vitals, which Google uses as a ranking signal. We do not currently weight Core Web Vitals impact into the headline score (the testing required to do this defensibly across multiple traffic profiles is significant), but we track it as a public observation on each review:

Where vendors publish CDN architecture details, gzipped script weight, and async-loading behaviour, we surface those facts in the review. Tools served from globally distributed CDNs with sub-50KB async JavaScript bundles (Usercentrics, CookieHub) tend to be effectively invisible to Core Web Vitals; tools that synchronously inject blocking scripts or render banners without reserved layout space tend not to be. When we can independently verify a Core Web Vitals impact on a live deployment, we say so.

Conflict-of-interest rules

We earn affiliate commissions on outbound vendor links. Rankings are kept independent of commission size by three structural rules:

The current list of affiliate relationships is on the About page. Every commercial page on the site carries an affiliate disclosure at the top, above the fold.

What we do not score on

What we are not

PrivacyComply is an editorial site, not a law firm and not an accredited compliance auditor. Nothing on this site is legal advice. For a specific legal situation — drafting a DPA, responding to a regulator, designing a cross-border transfer arrangement — hire a qualified data-protection lawyer in your jurisdiction. Our role stops at "which off-the-shelf tool is most likely to fit a website like yours."

Where to read more