DIRECTIVE (EU) 2019/882 · IN FORCE SINCE 28 JUNE 2025 EU-HOSTED · GDPR-CLEAN
EAA Compliance

Rules · frame-title

Failure reference

Frames without a title.

Payment widgets, maps and chat bubbles ride in iframes. Untitled, each is announced as just "frame" — content with no door sign.

01

What fails — and who it fails

The failure, in plain language.

Third-party embeds (PSP forms, consent tools, maps, video players) shipped without a title attribute.

02

Detection — what the machine can and cannot judge

How the scanner finds it.

  • Every iframe is checked for a title describing its content.
03

The legal reading — factual, not fearful

Where this sits in enforcement.

Payment iframes make this a checkout-path finding — the sector and the flow regulators look at first for commerce services.

04

The fix — by pattern

The pattern that clears it.

Title the embed- <iframe src="https://psp.example/card"> + <iframe src="https://psp.example/card" title="Kartenzahlung — sicheres Formular">

Fix the template, not the page — one change typically clears every instance at once. The triage engine groups findings by template pattern for exactly that reason.

05

Verification — resolution is evidence, not a checkbox

Fixed means a scan said so.

On monitored domains, mark the finding fixed and the next scan verifies it: zero remaining instances converts the finding to Resolved, and both the claim and the confirmation land in the append-only ledger. Criteria that need human judgement close through sign-off in the coverage matrix — covered by the right method, never by assumption.

Related failures:

See where your templates stand.

A complimentary assessment renders up to 25 public pages in an EU-hosted browser and shows every instance of this failure — grouped, ranked, and honest about what still needs a human.