The six scoring axes
Every compliance tool we cover is evaluated against the same six criteria. Each axis is scored 0 – 5; the headline rating is a weighted average, not a simple mean.
| Axis | What we look for | Weight |
|---|---|---|
| Regulatory coverage | GDPR (EU + UK), CCPA / CPRA, PIPEDA, Quebec Law 25, LGPD, POPIA, and Australian Privacy Act. Multi-jurisdiction geo-switching behaviour matters as much as the list of supported laws. | 25% |
| Setup friction | Time to first compliant banner. Steps required, code edits needed, plugin availability for WordPress / Shopify / Webflow, default settings sanity. Lower friction = higher score. | 15% |
| Real total cost | Listed monthly cost plus hidden upgrade triggers (page views, domains, languages, branding removal). A "free" tier that requires a $25 upgrade to be production-usable doesn't get free-tier credit. | 20% |
| Integrations & standards | Google Consent Mode v2, IAB TCF 2.2, Microsoft UET Consent Mode, tag-manager support, Customer Privacy API for Shopify, accessibility (WCAG / EAA). Standards certifications count more than marketing claims. | 15% |
| Support & documentation | Response time on paid tiers, depth of public knowledge base, presence of an internal legal team for policy generators, transparency of changelogs. | 10% |
| Transparency | Plain pricing, no "contact us for a quote" floor pricing on SMB plans, clear data residency, public consent-log export, public security posture (SOC 2 / ISO 27001 where claimed). | 15% |
Evidence sources
For every tool we cover we triangulate the score across three independent evidence sources. A claim has to clear at least two of the three to make it into the body of a review.
1. First-hand use, where we have it
iubenda runs this site. The banner you see in the corner, the privacy policy at privacy-policy.html, the cookie policy, and the terms-and-conditions are all iubenda-generated and iubenda-hosted. That means our iubenda assessment is based on live operating experience: dashboard navigation, Consent Database queries, hosted-policy auto-update behaviour, the friction of upgrading between tiers, and what the banner actually looks like on a real live site.
For tools we do not run ourselves, the relevant review page opens with a clear "we have not deployed this tool" note and the rest of the evidence comes from sources 2 and 3 below.
2. Vendor documentation, pricing, and changelogs
We read each vendor's documentation end-to-end before publishing — setup guides, integration docs, pricing tiers (every tier, not just the headline one), changelogs going back at least 12 months, and the small-print on overage charges and renewal terms. Where pricing is "contact us" only, we note that as a transparency penalty rather than guessing.
3. Verified-user reviews and independent reporting
G2, Capterra, Trustpilot, Reddit (r/SaaS, r/smallbusiness, r/gdpr), Product Hunt, and Hacker News threads about each vendor. Verified-buyer reviews are weighted higher than unverified ones; reviews older than 18 months are discounted because privacy software changes fast. Vendor case studies are read but explicitly not used as scoring evidence.
Update cadence
Privacy compliance vendors change pricing, regulatory coverage, and free-tier limits constantly. To keep rankings honest we operate the following review cadence:
- Quarterly — every comparison and review is re-checked against current vendor pricing and feature pages.
- Within 14 days of a regulatory change — when a relevant regulation updates (e.g. ePrivacy Directive revision, new US state privacy law signed into force, Google Consent Mode upgrade) we audit every affected page.
- Within 7 days of a vendor pricing or tier change — when we become aware of one, via vendor email, changelog, or reader report.
- Within 48 hours of a reader correction — see Editorial corrections on the About page.
Every page carries a visible "Updated" date at the top. If you find a date older than 90 days, email corrections@privacycomply.io and we will prioritise a refresh.
Performance & Core Web Vitals observation
Cookie consent scripts execute on every page load and — if poorly built — can directly degrade Core Web Vitals, which Google uses as a ranking signal. We do not currently weight Core Web Vitals impact into the headline score (the testing required to do this defensibly across multiple traffic profiles is significant), but we track it as a public observation on each review:
- Largest Contentful Paint (LCP) — delayed if a heavy banner script blocks above-the-fold rendering.
- Cumulative Layout Shift (CLS) — triggered when a banner injects into the DOM without reserved CSS space and shifts page content downward.
- Interaction to Next Paint (INP) — hurt when poorly-coded consent storage queries lag the user's click on Accept / Decline.
Where vendors publish CDN architecture details, gzipped script weight, and async-loading behaviour, we surface those facts in the review. Tools served from globally distributed CDNs with sub-50KB async JavaScript bundles (Usercentrics, CookieHub) tend to be effectively invisible to Core Web Vitals; tools that synchronously inject blocking scripts or render banners without reserved layout space tend not to be. When we can independently verify a Core Web Vitals impact on a live deployment, we say so.
Conflict-of-interest rules
We earn affiliate commissions on outbound vendor links. Rankings are kept independent of commission size by three structural rules:
- The scoring rubric is published (this page) before any specific review goes live, and any change to the rubric is recorded in this page's history.
- The ordering of any "best of" comparison must match the weighted score from the six axes above. We do not promote a lower-scoring tool to the top of a ranking because the commission is bigger.
- If a vendor drops their affiliate program, the review does not change. Termly remains in our comparisons whether or not their affiliate program pays out, because the underlying score is unchanged.
The current list of affiliate relationships is on the About page. Every commercial page on the site carries an affiliate disclosure at the top, above the fold.
What we do not score on
- Brand recognition. Whether a vendor is well-known has no effect on score; we have ranked smaller tools above better-known ones when the evidence supported it.
- Sales-page polish. Marketing copy is explicitly not evidence.
- Investor backing or company size. Plenty of well-funded privacy tools have shipped worse defaults than self-funded ones. Funding does not enter the score.
What we are not
PrivacyComply is an editorial site, not a law firm and not an accredited compliance auditor. Nothing on this site is legal advice. For a specific legal situation — drafting a DPA, responding to a regulator, designing a cross-border transfer arrangement — hire a qualified data-protection lawyer in your jurisdiction. Our role stops at "which off-the-shelf tool is most likely to fit a website like yours."
Where to read more
- About PrivacyComply — affiliate disclosure, editorial standards, contact addresses
- Best Cookie Consent Tools 2026 — the ranking this methodology produces
- iubenda vs Termly vs Osano — the methodology applied to the three most-compared platforms