Policy changed — see what exactly · 2026-08-18 →
Austria's largest energy company — 112 requests, 16 domains. A massive advertising stack: Google, Meta, LinkedIn, Bing, DoubleClick. Everything fires after consent — the CCM19 CMP holds the line. 91 external requests, zero before consent.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Analytics 4
- Google Ads / DoubleClick (3 accounts)
- Microsoft Advertising / Bing Ads (2 accounts)
- Meta Pixel (Facebook)
- LinkedIn Insight Tag
- Spoteffects Analytics
Context
VERBUND AG is Austria’s largest electricity producer, predominantly hydroelectric. A publicly traded company, listed on the Vienna Stock Exchange. HAR: 112 requests, 16 domains.
An advertising stack — but only after consent
VERBUND has one of the largest advertising stacks in the Austrian series: Google Analytics, three separate Google Ads accounts, two Microsoft Advertising tags, Meta Pixel, LinkedIn Insight, and Spoteffects Analytics. 91 external requests per session. But the CCM19 CMP on the consent.verbund.com subdomain keeps all of it behind a barrier — the first external tracker (GTM) appears at +6806 ms, only after the consent system has finished initializing and recorded the user’s choice.
Spoteffects — niche, but declared
Among the trackers, trck.spoteffects.net stands out — an Austrian analytics platform, less well known than Google or Meta. Two requests: the main tracker and an IPv6 variant. It appears in the HAR after consent and is mentioned in the policy.
Conclusion
112 requests, a massive marketing stack, 16 domains — and yet zero violations. The consent gate works: CCM19 blocks everything until the user makes a choice. VERBUND is an example that the sheer volume of advertising tools is not itself a violation, provided the consent architecture is built correctly.
9c03aa95a220ae23faee4883f4f9eaad4d6f4ceed4ed8c530a823e68c9647ae6