77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
The Abmahncheck: nine review areas, five severities, one statute per finding, and what the check expressly does not assess
Platform & Strategy

The Abmahncheck: nine review areas, five severities, one statute per finding, and what the check expressly does not assess

16 September 20269 min readBy CIVAC Redaktion
CIVAC

The Abmahncheck in CIVAC reads a website or an uploaded document and returns findings that each carry one category out of nine, one severity out of five, the statute the finding points to, a short evidence quote and a recommendation. This article describes what the check reviews field by field, how a finding is structured, why the result is a risk indication and not a legal assessment, and where its limits lie.

Key takeaways

  • The nine categories are fixed: legal notice (Impressum), data protection, cookies, accessibility, competition, terms and withdrawal, price indication, copyright, other. A finding cannot carry any other category.
  • The five severities are critical, high, medium, low and info. The overall rating of the artefact has only three levels: low, medium, high.
  • The legal notice is not reviewed as a whole but field by field: name and legal form, a full physical address with no P.O. box, authorised representative, email and phone number, register court and register number, VAT ID, for regulated professions the supervisory authority and chamber, for editorial content the responsible person, for shops the link to the dispute-resolution platform. The finding is meant to name the missing field, not to call the legal notice deficient.
  • For cookies the check reviews whether non-essential scripts load before consent, whether the banner offers an equivalent reject option and whether fonts load from the site's own server or a third party's. The list of loaded scripts is handed to the model; it does not have to find it itself.
  • Accessibility is reviewed only for offers to consumers, terms and withdrawal only for shops and bookings, price indication only where something is sold. For a plain company site with no sales, no findings arise in those three areas.
  • The check runs behind sign-in, a feature flag, a cost budget, rate limiting and the entitlement of the role. It is a function for appointed officers, not a public tool.

What goes in

The Abmahncheck takes exactly one of two inputs: a URL of at most two thousand characters, or the identifier of a previously uploaded document. Both at once the interface rejects, and so does neither. Added to that are the output language, German or English, and optionally the role the finding is to be assigned to. For a URL the system fetches the page and hands the model, alongside the content, the list of embedded scripts, so that the question of which services load before consent is not guessed from the text but answered from the list.

How a finding is structured

The output is a fixed schema, not free text. It contains a summary of two to three sentences, an overall rating with exactly three possible values, low, medium or high, a list of findings and a disclaimer. Every finding has five required fields: a short title, a severity from critical, high, medium, low or info, a category from nine values, the legal basis as a statute citation, for instance § 5 DDG or Art. 13 GDPR, and a recommendation. A sixth field is optional: an evidence quote of at most about two hundred characters from the reviewed artefact that triggered the finding, or a description of the missing element. The evidence quote is the part that lets an officer verify a finding in seconds: is that what the page says, or is it really missing?

The instruction to the model sets three rules worth knowing when reading the list. Every missing or incomplete mandatory element is its own finding, not part of a collective one. Missing mandatory elements are rated at least high. And the model must not invent anything: an element that is present may not be reported as missing. The instruction names three to fifteen findings as the usual range, sorted by severity; a page with thirty findings is therefore not thirty times as risky but a sign that the page lacks a great many mandatory elements at once, or that the model has split findings that belong together.

The nine areas, and what is reviewed in each

The legal notice under § 5 DDG is reviewed field by field for presence and plausibility: the provider's name with legal form, a full physical address with street, number, postcode and city, where a P.O. box expressly does not suffice, the authorised representative, fast electronic contact by email and phone, register court and register number, the VAT ID under § 27a UStG, for licensed or regulated professions the supervisory authority, chamber, statutory job title and granting state, for editorial content the responsible person under § 18(2) MStV, for shops the link to the dispute-resolution platform under Art. 14 of the ODR Regulation and the note under § 36 VSBG. The finding is meant to name which field is missing: phone number missing, register number missing, P.O. box instead of an address.

Data protection under Art. 13 and 14 GDPR is reviewed for presence, linking and completeness: controller with contact, data protection officer where applicable, purposes and legal bases per processing operation, recipients and processors, third-country transfer with safeguards, retention period, data subject rights, right to complain, and whether the services actually used, such as analytics, fonts, maps, social embeds and the consent tool, are named. Cookies and consent under § 25 TDDDG: whether non-essential cookies or trackers load before consent, whether the banner has an equivalent reject option, whether fonts load locally or from a third-party server.

Accessibility under the BFSG, in force since 28 June 2025, is reviewed only for offers to consumers, that is shops, bookings and services: whether an accessibility statement exists and whether recognisable defects such as missing alt texts, contrasts, keyboard operability or a missing feedback channel are present. Competition law under the UWG: misleading or unsubstantiated advertising claims and missing advertising labels. Terms and withdrawal only for shops and bookings: withdrawal notice, model withdrawal form and the wording of the order button under § 312j BGB. Price indication under the PAngV only where something is sold: total prices including VAT, unit prices, shipping costs. Copyright: photos, fonts and maps with no recognisable licence or source. The ninth category, other, catches what fits none of the eight.

Why this is an indication and not an assessment

The check's system instruction contains a paragraph that precedes every review rule: the model is not legal advice and not a lawyer, it delivers a risk indication citing the relevant statute and no legally binding assessment, and it is to phrase every finding as an indication. That is not a footnote but the construction. CIVAC is not a law firm; the German Legal Services Act permits the legal review of an individual case only to those authorised to do so. A finding therefore says: here a field required by § 5 DDG is missing, and this is how it is usually remedied. It does not say: this site infringes § 5 DDG and will receive a warning letter. Whether a finding constitutes an infringement in the specific case, what its consequences are and whether a warning letter is likely is a question for a law firm.

The instruction describes the manner of review as that of an experienced competition and IT lawyer. That is a statement about how thoroughly and field by field the reading should be, not about what the result is. The result remains a list of indications with statute citations, meant as a working list for the officer and as the basis for the conversation with the legal department or law firm, not as their replacement.

What the check cannot do

It reads what it is handed: the content of a URL with its script list, or a document. What sits behind a login, what appears only after interaction, or what is on a subpage that was not handed over, it does not see. It reviews presence and plausibility, not correctness: a register number that is present but wrong it cannot detect. It judges advertising claims for substantiation from the text, not from the evidence the company actually holds. And it is a language model under a strict instruction, not a rule engine: two runs over the same page can differ in wording and number of findings even when the mandatory elements are the same. The evidence quote per finding is the remedy for both: it makes every finding verifiable in seconds.

How an officer reads the list

First the findings rated critical and high, and for each hold the evidence quote against the page. Then check the area-bound categories: if findings on withdrawal or prices appear although the site sells nothing, that is a sign the model has misjudged the site type, and those findings are to be discarded. Then take the recommendations into the project as tasks, with the statute as the reason. And for everything that calls for an assessment, whether an advertising claim is tenable, whether a third-country transfer is adequately safeguarded, whether an accessibility statement suffices, pass the question to the law firm, with the finding as the brief.

Does the Abmahncheck review my whole website?

No. It reviews the URL handed to it with its content and script list, or an uploaded document. Subpages, content behind a login and content that appears only after interaction are not part of the review.

Which categories and severities are there?

Nine categories: legal notice, data protection, cookies, accessibility, competition, terms and withdrawal, price indication, copyright, other. Five severities per finding: critical, high, medium, low, info. The overall rating has three levels: low, medium, high.

Is a finding a legal determination?

No. Every finding is a risk indication with a statute citation; that is fixed in the check's instruction. Whether an infringement exists and whether a warning letter is likely can only be assessed by a law firm; CIVAC is not one.

Why does the check report nothing on withdrawal or prices for a plain company site?

Because terms and withdrawal are reviewed only for shops and bookings, price indication only where something is sold, and accessibility only for offers to consumers. If such findings appear anyway, the model has misjudged the site type and the findings should be discarded.

Can I use the check without signing in?

No. The check runs behind sign-in, a feature flag, a cost budget, rate limiting and the entitlement of the respective role. It is part of the workspace for appointed officers.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles