Privacy Compliance Audit — TIMIT Solutions
Privacy Compliance Audit

Your Website Was Just Rebuilt.
Was Its Privacy Layer?

A plain-English, hands-on review of where your website actually stands under CCPA/CPRA, your state's privacy law, and — if it applies to you — GDPR. We read the policies, test the site the way a regulator or a plaintiff's firm would, and hand your leadership and counsel a findings report they can act on the same day.

What this is, in one sentence: a diagnostic your counsel uses to make the final call. Not a legal opinion, not a certification, and not a promise that no one will ever raise a claim.

Privacy Enforcement Is Following the Accessibility Playbook

Ten years ago, most mid-market companies had never heard of website accessibility claims. Then the pattern took hold: a legal standard few businesses understood, low awareness, and a growing population of firms actively looking for sites that fell short. Demand letters followed.

Privacy law is now tracing the same arc — a wave of state laws layered on top of California's, most businesses unaware of which ones apply to them, and regulators and plaintiffs' attorneys paying closer attention to consent banners, opt-out links, and what a website's forms actually collect. Companies that redesigned their site recently are especially exposed: a new build usually means new forms, new third-party tools, and policy language nobody updated to match.

Accessibility ADA / WCAG Privacy CCPA/CPRA · state laws · GDPR LAW EXISTS LOW AWARENESS ACTIVE ENFORCEMENT PART OF EVERY BUILD Standard on the books Few businesses aware Demand letters, suits Now a routine checklist item State laws multiplying Most mid-market unaware ← We are here Where this is heading
Illustrative pattern, not a legal timeline. Where any specific business sits depends on its own facts and jurisdictions.

Built for Companies That Have Counsel* but Not a Privacy Team

Most of our audit clients look like this. If two or more of these describe you, the audit is likely worth a conversation.

You collect personal data through your site

Contact forms, quote requests, job applications, newsletter signups, chat widgets — anything a visitor types in and sends.

You recently rebuilt or redesigned

Or you're about to. New builds bring new forms, new tools, and policy text that rarely gets updated to match.

You sell into California or a privacy-law state

Where your customers are matters as much as where you are. Several states now have active consumer privacy laws.

You have a lawyer, not a privacy office

Your counsel makes the legal calls. What they don't have is time to test every form and cookie banner on your site.

*Don't have an attorney who handles privacy law? TIMIT can refer you to one — the audit is still useful in the meantime, but findings should ultimately be reviewed by counsel.

Six Places Privacy Gaps Hide on a Website

Reading a privacy policy tells you what a company says it does. We check what the website actually does — and whether the two match.

Policy documents

Privacy Policy, Terms of Use, and Cookie Policy — reviewed against the laws that plausibly apply to your business, and against each other for contradictions.

Cookie consent behavior

Does the banner actually block non-essential cookies until consent is given? We test it hands-on, not just read what it claims.

Opt-out & Global Privacy Control

The "Do Not Sell or Share" path and whether the site honors browser-level GPC signals — a frequent gap on newly built sites.

Every data-collection point

Each form, application, and signup: what it collects, what it discloses at the point of collection, and whether the confirmation flow actually works.

Third-party tools

Analytics, chat, marketing pixels, form processors, and hosted applications — where data goes after it leaves your site, and whether your policy says so.

Legacy conflicts

Old Terms of Use clauses, placeholder contact details, and stale dates that survived the redesign and now contradict the new policy.

Five Steps, Ending in Verified Fixes

The audit doesn't end when the report is delivered. It ends when the findings are fixed and independently re-checked.

Scope

Identify which laws plausibly apply based on where you operate and who your visitors are — confirmed with your counsel.

Review

Read every policy document and every page that collects personal information, and log what's missing, vague, or contradictory.

Test

Exercise the consent banner, opt-out link, GPC signal, and each form's submission and confirmation flow as a real visitor would.

Report

Deliver a findings log and an executive summary written for leadership and counsel — specific, prioritized, nothing left vague.

Fix & re-verify

Coordinate remediation with your web developer, then independently re-test each item so you have confirmation, not just a claim.

What You Get — and What This Is Not

We keep both lists visible on purpose. The value of the audit depends on being precise about its limits.

What you get

  • A findings log: every issue, where it is, why it matters, and what would resolve it
  • An executive summary your leadership and counsel can read in one sitting
  • Hands-on functional test results, not just a document review
  • Coordination with your web developer through remediation
  • Independent re-verification of each fix, with a closing status report

What this is not

  • Not legal advice or a legal opinion — TIMIT is not a law firm
  • Not a certification, seal, or guarantee of compliance
  • Not a review of your internal data handling, vendors, or back-office systems — the scope is your public website
  • Not permanent — findings reflect your site as tested on a specific date; laws and websites both change
  • Not a substitute for your counsel's judgment on what the law requires of you

What an Audit Found on a Freshly Rebuilt Site

The situation

A mid-market industrial company launched a newly redesigned website built by a design agency. The site looked excellent. The agency, reasonably, was not equipped to say whether it was privacy-compliant — that wasn't what they were hired for. Not long after launch, the company received a warning letter from a law firm alleging the site did not comply with applicable privacy laws.

What we found

  • Placeholder contact information still live in the privacy policy
  • Applicable state and federal frameworks not addressed at all
  • No disclosure of how long personal data is retained
  • A form confirmation flow that silently failed
  • A legacy Terms of Use clause that contradicted the new policy

What happened

Every item was remediated by the client's developer, then independently re-tested by TIMIT. The closing report was delivered with zero open items.

Why it matters

None of these were exotic. They were ordinary gaps that a redesign creates and nobody is assigned to catch. Finding them before launch meant the site went live with privacy handled — instead of discovered later by someone else.

Details generalized to protect client confidentiality.

Scoped to Your Site, Not a One-Size Package

Every audit is quoted to the specific site — the number of forms, tools, and jurisdictions in play. These are the shapes engagements typically take.

Most common

Core Audit

A single public website reviewed and functionally tested against CCPA/CPRA and the state privacy law(s) that plausibly apply, through remediation and re-verification.

Add-on

GDPR / UK Coverage

For sites with meaningful EU or UK traffic: extends the review to GDPR and UK GDPR consent, disclosure, and data-subject-rights requirements.

Follow-up

Post-Launch Check

A lighter recheck once a redesigned site goes live, or after major changes — confirming nothing regressed and new tools were disclosed.

Web design and development agencies

Your build is great. Is the privacy layer? TIMIT works alongside agencies as the audit partner you bring in before launch — so your client never discovers the gap after the fact.

Talk about a partnership

What Leaders Ask Before Starting

Is this legal advice?

No. TIMIT is a technology consulting firm, not a law firm. The audit is a technical and content diagnostic. Your attorney makes the final determination about what the law requires of your business — the audit gives them a tested, specific picture to work from.

If every finding is fixed, does that mean we're compliant?

It means every issue we identified was resolved and independently re-verified as of the closing date. It is not a certification, and no audit can promise that a regulator or plaintiff will never raise a question. Compliance is an ongoing obligation, not a one-time status.

Which privacy laws does the audit cover?

The California Consumer Privacy Act as amended by the CPRA is the baseline for most U.S. businesses. Beyond that, we scope to the state laws that plausibly apply given where you operate and sell — confirmed with your counsel — and add GDPR/UK GDPR when you have meaningful European or UK traffic.

What do you need access to?

Very little. Most of the audit is performed as a visitor would experience your site, plus a read of your published policies. We'll ask for a list of third-party tools in use and a contact at your web developer for the remediation phase. We don't need admin access to your website or internal systems.

Do you fix the issues yourselves?

We coordinate the fixes with whoever maintains your site — your developer or agency — and then independently re-test each item. Keeping the fixing and the verifying separate is what makes the closing report meaningful.

We're mid-redesign right now. Is it too early?

It's the ideal time. Auditing a site in staging, before launch, means privacy is handled as part of the build rather than retrofitted after — and it's far cheaper to correct a form or a policy before it goes live.

Find Out Where Your Website Stands

A short conversation is enough to scope the audit and tell you honestly whether it's worth doing. No pitch, no pressure.

Schedule an Audit Conversation Prefer email? Contact TIMIT and mention the Privacy Compliance Audit.

The TIMIT Privacy Compliance Audit is a technical and content review provided for informational purposes. It does not constitute legal advice, a legal opinion, or a certification or guarantee of compliance with any law. Findings describe the condition of a website as tested on a specific date and may be affected by subsequent changes to the site, its third-party tools, or applicable law. Determinations about legal obligations and risk should be made by qualified legal counsel. References to specific laws are for identification only and do not represent a conclusion that any law applies to a particular business.