# DSGVO.pro — German Digital-Law Compliance (remote · dsgvo.pro)

Search 26 German/EU statutes free — then scan any website against 33 compliance modules.

- Trust score: 63/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-20

## Components

- remote · `dsgvo.pro`: 63/100 (this document), [markdown](https://verifymcp.io/servers/pro-dsgvo-dsgvo-pro/api-mcp.md), [page](https://verifymcp.io/servers/pro-dsgvo-dsgvo-pro/api-mcp)

## Channel facts

- Endpoint: `https://dsgvo.pro/api/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-20.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 86/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Tool/resource definitions use about 2082 tokens (~63/item across 33 items; 6 tools + 27 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 20/100
  - Spec-recency check failed: implements MCP spec 2024-11-05; the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add --transport http pro-dsgvo-dsgvo-pro https://dsgvo.pro/api/mcp
```

### Codex

```toml
[mcp_servers.pro-dsgvo-dsgvo-pro]
url = "https://dsgvo.pro/api/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "pro-dsgvo-dsgvo-pro": {
      "type": "remote",
      "url": "https://dsgvo.pro/api/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add pro-dsgvo-dsgvo-pro --url https://dsgvo.pro/api/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  pro-dsgvo-dsgvo-pro:
    url: "https://dsgvo.pro/api/mcp"
```

### Other

```json
{
  "mcpServers": {
    "pro-dsgvo-dsgvo-pro": {
      "type": "http",
      "url": "https://dsgvo.pro/api/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-20 (score 63)

First indexed and scored.

## MCP tools (6)

### `search-law` (~211 tokens)

Search across all 26 German/EU statutes (DSGVO, KI-VO, BDSG, TDDDG, DDG, BFSG, UWG, BGB, PAngV, VSBG, UrhG, VerpackG, VerpackDG, ElektroG, JuSchG, GewO, MaBV, GEG, BRAO, FinVermV, HwO, IfSG, KosmetikVO, HWG, HOAI, MiLoG). Accepts paragraph references ("356a", "§ 312k", "Art. 42") for direct lookup AND free-text keywords ("Cookie", "Widerrufsbutton", "Einwilligung"). Returns matching articles/paragraphs with excerpts. Covers data protection, telecom & digital-services law, AI regulation, accessibility, unfair-competition (UWG), consumer and sector-specific law.

Input parameters:

- `law` (string): Optional: limit search to a specific law
- `query` (string, required): Search query text

### `get-article` (~86 tokens)

Get the full German text of a specific article or paragraph from a law. Returns full text and metadata.

Input parameters:

- `article` (string|number, required): The article or paragraph number. Letter suffixes are supported and required for norms like "356a" (§356a BGB Widerrufsbutton), "312k", "312j".
- `law` (string, required): The law identifier

### `list-laws` (~23 tokens)

List all available German/EU digital-law statutes with article/paragraph counts.

### `check-compliance` (~455 tokens)

🔑 Requires API key (Bearer header in MCP client config). Free tier: 3 scans/month — get a key at https://dsgvo.pro/api-keys. Start a compliance scan against up to 33 German digital law modules. Standard tier covers 20 modules across DSGVO, TDDDG, DDG, BFSG, UWG, BGB, PAngV including Schrems II hosting-location verification with SCC declaration audit, §312k BGB Kündigungsbutton, BFSG accessibility (active 28.06.2025). Pro/Agency tier (13 exclusive modules): §356a BGB Widerrufsbutton (active 19.06.2026 — currently the only EU compliance-scanner with this check), KI-VO transparency and data-processing requirements (Article 13/14 + Article 50 AI Act), advanced security audit (Art. 32 DSGVO — TLS protocol, mixed content, CMS-version CVE detection), tech-stack staleness (CMS/framework versions vs NVD CVE database), plus 8 industry-specific compliance modules — lawyer (BORA/BRAO), real-estate broker (§34c GewO + MaBV + §87 GEG energy-pass disclosure in listings), physician (BOÄ + HWG + Art. 9 GDPR sensitive-data), financial intermediary (§34d/f/h/i GewO + FinVermV), gastronomy (LMIV allergen labeling + PAngV + IfSG hygiene), cosmetics studio (KosmetikVO + HWG before/after imagery), construction (§34c GewO Bauträger-Erlaubnis + HwO + MiLoG/SOKA), hotel (BMG registration + PAngV tourist-tax inclusive pricing + GEG). Industry detection runs from page content — only triggers relevant checks. ⚠️ IMPORTANT: This tool returns only a scanId — NOT the results. The scan takes 60–120 seconds. After calling this, wait 60–90 seconds, then call get-scan-result with the scanId. Use get-scan-status to check progress without waiting for completion.

Input parameters:

- `url` (string, required): The website URL to scan (e.g. https://example.com)

### `get-scan-status` (~302 tokens)

Lightweight progress check for an in-progress compliance scan. Returns current status (pending/crawling/scanning/completed/failed) and how many modules have finished (20 Standard or up to 33 with Pro/Agency tier including Hosting-Standort (Schrems II) (Art. 13 lit. f DSGVO), Widerrufsbutton (§356a BGB), KI-Transparenz (Art. 50 KI-VO), Tech-Stack-Aktualität (Art. 32 DSGVO), Anwaltsspezifische Prüfung (BORA / BRAO), Maklerspezifische Prüfung (§34c GewO + MaBV + GEG), Arztspezifische Prüfung (BOÄ + HWG + Art. 9 DSGVO), Finanzvermittler-Prüfung (§34d/f/h/i GewO + FinVermV), Gastronomie-Prüfung (LMIV + PAngV + IfSG), Kosmetik-Prüfung (KosmetikVO + HWG + UWG), Bau-/Sanierung-Prüfung (§34c GewO + HwO + MiLoG), Hotel-/Beherbergung-Prüfung (BMG + PAngV + GEG + DSGVO)). Use this to poll progress. When status is 'completed', call get-scan-result for the full report.

Input parameters:

- `scanId` (string, required): The scan ID returned by check-compliance

### `get-scan-result` (~102 tokens)

Get the full compliance report for a completed scan. Returns score (0–100), financial risk in EUR, per-module results, and all violations with law references, fine estimates, and fix instructions. ⚠️ Only call after the scan is complete — check status first with get-scan-status. If called while scan is still running, returns current progress instead of an error.

Input parameters:

- `scanId` (string, required): The scan ID returned by check-compliance

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/pro-dsgvo-dsgvo-pro/api-mcp#diagnostics

## Score history

- 2026-08-20: 63

## Links

- Remote endpoint: https://dsgvo.pro/api/mcp
- Website: https://dsgvo.pro/mcp
- Changelog RSS feed: https://verifymcp.io/servers/pro-dsgvo-dsgvo-pro/api-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/pro-dsgvo-dsgvo-pro/api-mcp.json
- HTML version of this page: https://verifymcp.io/servers/pro-dsgvo-dsgvo-pro/api-mcp
