---
title: "Fohrkast - your EU compliance, run from one place"
description: "EU compliance toolkit for business websites: one subscription covering GDPR, ePrivacy, EU Accessibility Act, EU AI Act and whistleblowing (Directive (EU) 2019/1937) readiness, with scanning, generated documents, consent, DSAR and trust pages."
canonical: "https://fohrkast.com/"
group: "Product"
updated: "2026-07-02"
---
# Fohrkast - your EU compliance, run from one place

Fohrkast is an EU compliance toolkit for business websites. We draft. We flag. You decide. No overlays. No fake guarantees. One scan checks your site against GDPR, ePrivacy and the EU Accessibility Act and returns a risk report: a readiness score, your exposure, and a prioritized fix list. The same subscription runs your consent banner, generated policies, DSAR desk, whistleblowing channel, AI Act readiness and a hosted trust page. It is an automated readiness toolkit, not legal advice and not a guarantee of conformance.

## What is inside: detect, document, operate, prove

**Detect**

- Site scanner: scans your site for cookies, trackers, and common accessibility issues.
- Radar monitoring: re-scans on a schedule and flags what changed since your last report.
- Risk report: one report with a readiness score, your exposure, and a prioritized fix list.
- AI Act classifier: a short wizard returns an indicative risk category for each AI system. Not legal advice.

**Document**

- Policy generator: drafts your privacy, cookie, and company documents from what the scan finds, for your review.
- DPA and RoPA: generates the processing agreement and records that business customers ask for.
- EAA statement: drafts an accessibility statement under Directive (EU) 2019/882 Annex V from your scan and profile, for your review.
- AI Act doc pack: Annex IV technical documentation and impact-assessment templates, pre-filled for your review.

**Operate**

- Shield consent: a consent banner that blocks the non-essential trackers it detects until visitors agree, and records the proof.
- DSAR desk: tracks statutory deadlines, verifies requester identity, and keeps an audit trail for every data request.
- Whistleblowing channel: a hosted internal reporting channel under Directive (EU) 2019/1937, with case codes and statutory timers.

**Prove**

- Trust page: a hosted page with your sub-processors, policies, and security answers for buyer due diligence.
- Consent proof: every consent choice is logged, stored in the EU, and exportable.
- Version-stamped documents: every generated document carries its date and rulebook version.

## The EU rulebooks covered, and what each asks of you

- **GDPR** (Regulation (EU) 2016/679): asks you to process personal data on a lawful basis, answer data-subject requests on time, and document your processing. Penalty ceiling: up to EUR 20M or 4% of worldwide annual turnover, whichever is higher (Art 83).
- **ePrivacy** (Directive 2002/58/EC): asks you to get consent before setting non-essential cookies and trackers on visitors' devices. Penalties set by each member state's national implementing law.
- **European Accessibility Act** (Directive (EU) 2019/882, applies since 28 June 2025): asks in-scope services to be accessible and to publish accessibility information about how they meet the requirements. Penalties set by each member state (Art 30).
- **EU AI Act** (Regulation (EU) 2024/1689): asks you to know the risk category of each AI system you provide or deploy, and to meet the duties that category carries. Penalty ceiling: up to EUR 35M or 7% of worldwide turnover for prohibited practices; lower bands for other breaches (Art 99).
- **Whistleblower Protection** (Directive (EU) 2019/1937): asks legal entities with 50 or more workers to run an internal reporting channel with acknowledgement and feedback deadlines. Penalties set by each member state (Art 23).

Statute names, dates and penalty ceilings are cited from the directives and regulations named. What Fohrkast provides for each is an automated readiness toolkit, not legal advice.

## How it works

1. **Scan**: Enter your URL. One automated check returns your risk report in about a minute.
2. **Generate**: Fohrkast drafts your documents and consent banner from the scan, ready for your review before anything goes live.
3. **Operate**: Consent is recorded, data requests are tracked against statutory deadlines, reports are handled, and documents stay versioned.

## What Fohrkast does

- Scans your site for cookies, trackers, and common accessibility issues.
- Generates policies, processing records, and statements from scan findings, for your review.
- Runs your consent banner, DSAR desk, and whistleblowing channel with timers and audit logs.
- Stamps every generated document with its date and rulebook version.

## What Fohrkast does not claim

- We do not call you compliant. That is a legal judgment we cannot make.
- We do not guarantee any outcome, certification, or protection from fines.
- We do not present automated scans as a substitute for legal advice.
- We do not flag color contrast or JavaScript-rendered content as a pass. Those require human review.

## Why this matters: rules with teeth, read honestly

The billion-euro headlines are Big Tech cases, and we will not pretend otherwise. For a small business the exposure looks different: a complaint to your data protection authority, a legal letter, a blocked enterprise deal, a checkout your customers cannot use. Published regulator decisions, for context:

- **EUR 3,000** (Spanish DPA/AEPD, 2020): Small online shop with a cookie banner that provided no way to reject all cookies.
- **EUR 60M** (CNIL, France, 2021): Consent process where refusing cookies was made harder than accepting them.
- **EUR 390M** (Irish DPC, 2023): Inadequate legal basis for ads-related data processing.

*Note: These are published regulator decisions shown for context, not as a prediction of any individual outcome.*

The fine is the headline. The uncertainty is the cost. Would you build a business on either?

## Readiness assessment

The automated readiness check returns:

- A score (illustrative example: 73/100) indicating overall readiness across compliance areas.
- A list of findings flagged as either complete or needing manual review. Items requiring human judgment are marked as "needs review," not as a pass or fail.
- Signals only; this is not a legal verdict.

## For agencies

Agencies can run compliance for every client from one place: group domains by client, white-label the documents and trust pages, and hand over clean readiness reports. The whistleblowing channel is included with the Business plan, and available as a EUR 39/month add-on on other paid plans.

## Getting started

A free scan requires no account and no payment. Enter your site URL to run an automated readiness check. Nothing is stored until you create an account. This is an automated check, not a legal certification or guarantee of conformance.

## Data and location

Fohrkast stores account, consent proof, and hosted documents in the EU (Supabase, Frankfurt; Vercel, Frankfurt). As the operator is established outside the European Union, Fohrkast has appointed Prighter EU Rep GmbH as its representative in the Union under Article 27 GDPR. The platform uses Irish Public Sector Data from the CRO (Company Records), licensed under CC BY 4.0.

## About Fohrkast

Fohrkast is an EU compliance-readiness toolkit providing automated scanning, document generation, consent management, DSAR handling, whistleblowing intake, AI Act readiness and hosted trust pages for business websites. It offers general compliance information and guidance, not legal advice. The automated scan checks against GDPR, ePrivacy and the European Accessibility Act; it does not check the Digital Services Act, consumer law, or CCPA. It is built for businesses operating in or serving the EU.

---

Source: https://fohrkast.com/
This is automated readiness information, not legal advice or a guarantee of conformance. Last reviewed 2026-07-02.
