A plain-English, hands-on review of where your website actually stands under CCPA/CPRA, your state's privacy law, and — if it applies to you — GDPR. We read the policies, test the site the way a regulator or a plaintiff's firm would, and hand your leadership and counsel a findings report they can act on the same day.
Ten years ago, most mid-market companies had never heard of website accessibility claims. Then the pattern took hold: a legal standard few businesses understood, low awareness, and a growing population of firms actively looking for sites that fell short. Demand letters followed.
Privacy law is now tracing the same arc — a wave of state laws layered on top of California's, most businesses unaware of which ones apply to them, and regulators and plaintiffs' attorneys paying closer attention to consent banners, opt-out links, and what a website's forms actually collect. Companies that redesigned their site recently are especially exposed: a new build usually means new forms, new third-party tools, and policy language nobody updated to match.
Most of our audit clients look like this. If two or more of these describe you, the audit is likely worth a conversation.
Contact forms, quote requests, job applications, newsletter signups, chat widgets — anything a visitor types in and sends.
Or you're about to. New builds bring new forms, new tools, and policy text that rarely gets updated to match.
Where your customers are matters as much as where you are. Several states now have active consumer privacy laws.
Your counsel makes the legal calls. What they don't have is time to test every form and cookie banner on your site.
*Don't have an attorney who handles privacy law? TIMIT can refer you to one — the audit is still useful in the meantime, but findings should ultimately be reviewed by counsel.
Reading a privacy policy tells you what a company says it does. We check what the website actually does — and whether the two match.
Privacy Policy, Terms of Use, and Cookie Policy — reviewed against the laws that plausibly apply to your business, and against each other for contradictions.
Does the banner actually block non-essential cookies until consent is given? We test it hands-on, not just read what it claims.
The "Do Not Sell or Share" path and whether the site honors browser-level GPC signals — a frequent gap on newly built sites.
Each form, application, and signup: what it collects, what it discloses at the point of collection, and whether the confirmation flow actually works.
Analytics, chat, marketing pixels, form processors, and hosted applications — where data goes after it leaves your site, and whether your policy says so.
Old Terms of Use clauses, placeholder contact details, and stale dates that survived the redesign and now contradict the new policy.
The audit doesn't end when the report is delivered. It ends when the findings are fixed and independently re-checked.
Identify which laws plausibly apply based on where you operate and who your visitors are — confirmed with your counsel.
Read every policy document and every page that collects personal information, and log what's missing, vague, or contradictory.
Exercise the consent banner, opt-out link, GPC signal, and each form's submission and confirmation flow as a real visitor would.
Deliver a findings log and an executive summary written for leadership and counsel — specific, prioritized, nothing left vague.
Coordinate remediation with your web developer, then independently re-test each item so you have confirmation, not just a claim.
We keep both lists visible on purpose. The value of the audit depends on being precise about its limits.
A mid-market industrial company launched a newly redesigned website built by a design agency. The site looked excellent. The agency, reasonably, was not equipped to say whether it was privacy-compliant — that wasn't what they were hired for. Not long after launch, the company received a warning letter from a law firm alleging the site did not comply with applicable privacy laws.
Every item was remediated by the client's developer, then independently re-tested by TIMIT. The closing report was delivered with zero open items.
None of these were exotic. They were ordinary gaps that a redesign creates and nobody is assigned to catch. Finding them before launch meant the site went live with privacy handled — instead of discovered later by someone else.
Details generalized to protect client confidentiality.
Every audit is quoted to the specific site — the number of forms, tools, and jurisdictions in play. These are the shapes engagements typically take.
A single public website reviewed and functionally tested against CCPA/CPRA and the state privacy law(s) that plausibly apply, through remediation and re-verification.
For sites with meaningful EU or UK traffic: extends the review to GDPR and UK GDPR consent, disclosure, and data-subject-rights requirements.
A lighter recheck once a redesigned site goes live, or after major changes — confirming nothing regressed and new tools were disclosed.
Your build is great. Is the privacy layer? TIMIT works alongside agencies as the audit partner you bring in before launch — so your client never discovers the gap after the fact.
No. TIMIT is a technology consulting firm, not a law firm. The audit is a technical and content diagnostic. Your attorney makes the final determination about what the law requires of your business — the audit gives them a tested, specific picture to work from.
It means every issue we identified was resolved and independently re-verified as of the closing date. It is not a certification, and no audit can promise that a regulator or plaintiff will never raise a question. Compliance is an ongoing obligation, not a one-time status.
The California Consumer Privacy Act as amended by the CPRA is the baseline for most U.S. businesses. Beyond that, we scope to the state laws that plausibly apply given where you operate and sell — confirmed with your counsel — and add GDPR/UK GDPR when you have meaningful European or UK traffic.
Very little. Most of the audit is performed as a visitor would experience your site, plus a read of your published policies. We'll ask for a list of third-party tools in use and a contact at your web developer for the remediation phase. We don't need admin access to your website or internal systems.
We coordinate the fixes with whoever maintains your site — your developer or agency — and then independently re-test each item. Keeping the fixing and the verifying separate is what makes the closing report meaningful.
It's the ideal time. Auditing a site in staging, before launch, means privacy is handled as part of the build rather than retrofitted after — and it's far cheaper to correct a form or a policy before it goes live.
A short conversation is enough to scope the audit and tell you honestly whether it's worth doing. No pitch, no pressure.
Schedule an Audit Conversation Prefer email? Contact TIMIT and mention the Privacy Compliance Audit.The TIMIT Privacy Compliance Audit is a technical and content review provided for informational purposes. It does not constitute legal advice, a legal opinion, or a certification or guarantee of compliance with any law. Findings describe the condition of a website as tested on a specific date and may be affected by subsequent changes to the site, its third-party tools, or applicable law. Determinations about legal obligations and risk should be made by qualified legal counsel. References to specific laws are for identification only and do not represent a conclusion that any law applies to a particular business.