ServiceUpdated on 25 April 2026
FREE eCommerce Legal Audit: Privacy Policy & Terms and Conditions based on 80+ Criteria
Head of Legal at CraftPolicy
Sofia, Bulgaria
About
Your Privacy Policy and Terms & Conditions are two of the most legally scrutinized documents your business publishes. Most eCommerce operators don't know they have critical compliance gaps until a regulator, enterprise client, or payment processor finds them first. CraftPolicy's eCommerce Legal Audit is built to find them before that happens.
A Methodology Built on Real Regulatory Logic
The audit evaluates your Privacy Policy against 37 defined compliance criteria, organized across four tiers of legal criticality — from organizational transparency and lawful basis documentation, through user rights architecture, to tracking technologies and accountability measures. Your Terms & Conditions go through an equivalent parallel framework. The combined scope exceeds 80 individual compliance checkpoints.
Each criterion is weighted by regulatory risk — critical exposures carry up to 5× the scoring weight, because those are exactly what supervisory authorities prioritize in enforcement. Interdependency rules are then applied across the scoring matrix: a weakness in lawful basis automatically adjusts scores for consent records and legitimate interest justification, reflecting how DPAs actually investigate. The result is not a surface pass/fail. It is a precise map of your legal exposure.
What Gets Audited
On the Privacy Policy side: controller identity and contact details, processing purposes and purpose limitation, lawful bases under Article 6, legitimate interest balancing tests, data categories and sources, recipient transparency, international transfer mechanisms (including Schrems II implications), retention periods, security measures, breach notification obligations, subject rights — access, erasure, objection, portability, withdrawal of consent — and complaint procedures including supervisory authority referral. The Terms & Conditions audit follows a comparable structure adapted to contractual obligations, liability, jurisdiction, and eCommerce-specific regulatory requirements.
The Output
A structured compliance report with your aggregate score, tier-by-tier breakdown, and a prioritized remediation plan. Every recommendation is linked to a specific GDPR article and regulatory risk level. This is not a document for your archive. It is a working tool with an unambiguous next step for every finding.
Why It Matters Now
EU supervisory authorities imposed over €1.2 billion in GDPR fines in 2025 alone. Breach notifications increased 22% year-over-year. More than 80% of policies audited by CraftPolicy contain at least one critical violation that is invisible without a structured legal framework. The audit identifies those vulnerabilities while fixing them is still a choice — not a regulatory obligation.
Type
- Consulting
- IPR, Legal and tax advisory
Organisation
Similar opportunities
Service
Legal audit of website Terms & Conditions (free)
- Consulting
- Law Firms / Legal Services
- IPR, Legal and tax advisory
Kristina Pavlova
Founder/ Lawyer of Pavlova Consult at Pavlova Consult
Sofia, Bulgaria
Partnership
Legal add-on for digital agencies
- Other
- Business
- Joint development
- Knowledge transfer
Kristina Pavlova
Founder/ Lawyer of Pavlova Consult at Pavlova Consult
Sofia, Bulgaria
Service
- Marketing
- Consulting
- Consulting / Training
- Marketplaces / Trading Platforms
- Marketing / Personalization / CRM
John Kiskipelis
Founder at UpCommerce
Athens / Thessaloniki, Greece