Security & GDPR · Framer
Is my Framer app GDPR compliant?
Framer turns a design into a live site in minutes — and marketing sites lean on exactly the things regulators care about: web fonts loaded from Google, analytics and embeds that fire before any consent, and often no imprint or privacy policy. For visitors in the EU, that's your responsibility as the site operator (Art. 3(2) GDPR).
What we typically find on Framer apps
- Google Fonts loaded directly from Google Art. 44 GDPR
- Tracking loads before anyone could consent § 25 TDDDG
- Third-party tracking service embedded Art. 6 GDPR
- No privacy policy found Art. 13 GDPR
- No imprint (Impressum) found § 5 DDG
Common questions
Does Framer make my site GDPR compliant by default?
No — the platform is solid, but fonts, analytics, embeds and legal pages are configured by you, and the common defaults transmit visitor data before consent.
What does the scan check on a Framer site?
Whether fonts load from Google, third-party tracking and US transfers, consent timing, an imprint and privacy policy, and transport security headers.
Will the scan touch my site or my data?
No. The free check is passive: it loads your site like a normal visitor (GET requests only) and observes what it sends out. No login attempts or active testing. We retain only a limited result digest, not page contents.