Belgium's Data Protection Authority (APD) — 26 requests, 2 domains. The only external resource is a federal government cloud CDN for styles and scripts. The Plausible analytics tool (open-source) declared in the policy does not fire before consent; no Google, no third-party trackers, no cookies. The privacy regulator meets its own requirements. No violations recorded.
Timeline of the leak
Declared versus actual
Transfer timings
Belgium's federal government cloud CDN. Styles and scripts.
Detected trackers
- Plausible — declared, does not fire before consent
- cdn.socialsecurity.be — federal government CDN
Context
autoriteprotectiondonnees.be is the website of Belgium’s Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit, APD/GBA), the country’s GDPR supervisory authority. Controller: APD. The cookie policy is detailed (roughly 8,800 characters). Measurement: 26 requests, 2 domains, captured on a clean browser.
Declared versus actual
APD’s policy explicitly names its analytics tool: alongside technical cookies, the authority uses Plausible — an open-source, privacy-oriented analytics tool — for aggregated statistics, and states explicitly that this occurs only with the visitor’s consent.
The measurement confirms the declared model. Plausible does not fire in a session without consent: there are no requests to Plausible domains, and no self-hosted analytics endpoint on the proprietary domain appears in the measurement. The only external domain is cdn.socialsecurity.be, Belgium’s federal government cloud CDN, which serves general styles and scripts (style.css, app.js); this is shared state infrastructure, not a third-party commercial service. No third-party trackers, Google services, advertising pixels, or session recording appear in the measurement. No cookies are set (zero Set-Cookie).
The declared and actual behavior therefore match: the privacy-friendly Plausible analytics tool is announced in the policy and correctly held back until consent, and external requests are limited to state infrastructure.
Timing relative to consent
Requests go to the proprietary domain and to the federal government CDN. The declared Plausible analytics does not activate before consent; no cookies are set. For a data protection supervisory authority, this is the expected and correct behavior.
What cannot be claimed from the measurement
The measurement covers the homepage and the pre-consent state. Plausible’s behavior after clicking “accept” is not observed here; if correctly configured, its activation with consent would be lawful. Server-side processing is not visible in a browser-based measurement.
Conclusion
Belgium’s Data Protection Authority demonstrates a configuration consistent with what it itself requires of others: the declared analytics tool — open-source, privacy-oriented Plausible — does not fire before consent, the only external resource is a federal government cloud CDN, and there are no third-party trackers, Google services, or cookies. What is declared in the policy matches actual behavior. No violations recorded in this measurement.
4e07437dca8a84d90621ea8a8ec26c63d439058947574d463c9e33c16f9881e1