Technical audit · 2026-05-26

autoriteprotectiondonnees.be

Belgian Data Protection Authority

Belgium's Data Protection Authority (APD) — 26 requests, 2 domains. The only external resource is a federal government cloud CDN for styles and scripts. The Plausible analytics tool (open-source) declared in the policy does not fire before consent; no Google, no third-party trackers, no cookies. The privacy regulator meets its own requirements. No violations recorded.

Timeline of the leak

+0 ms · portal load
Content, images, and fonts served from the proprietary domain autoriteprotectiondonnees.be.
+726 ms · federal government CDN
cdn.socialsecurity.be — styles and scripts (style.css, app.js) from Belgium's federal government cloud CDN. Shared state infrastructure, not a third-party tracker.
no third-party trackers
No Google, no maps, no advertising, no session recording appear in the measurement; Plausible does not fire without consent.

Declared versus actual

Plausible (open-source analytics) — for statistics, with consent — заявлен
The cookie policy describes cookie types and consent in detail — заявлен
+ cdn.socialsecurity.be — federal government CDN, not separately identified in the policy (state infrastructure, noted for observation) — не заявлен

Transfer timings

+726 ms cdn.socialsecurity.be

Belgium's federal government cloud CDN. Styles and scripts.

Detected trackers

Context

autoriteprotectiondonnees.be is the website of Belgium’s Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit, APD/GBA), the country’s GDPR supervisory authority. Controller: APD. The cookie policy is detailed (roughly 8,800 characters). Measurement: 26 requests, 2 domains, captured on a clean browser.

Declared versus actual

APD’s policy explicitly names its analytics tool: alongside technical cookies, the authority uses Plausible — an open-source, privacy-oriented analytics tool — for aggregated statistics, and states explicitly that this occurs only with the visitor’s consent.

The measurement confirms the declared model. Plausible does not fire in a session without consent: there are no requests to Plausible domains, and no self-hosted analytics endpoint on the proprietary domain appears in the measurement. The only external domain is cdn.socialsecurity.be, Belgium’s federal government cloud CDN, which serves general styles and scripts (style.css, app.js); this is shared state infrastructure, not a third-party commercial service. No third-party trackers, Google services, advertising pixels, or session recording appear in the measurement. No cookies are set (zero Set-Cookie).

The declared and actual behavior therefore match: the privacy-friendly Plausible analytics tool is announced in the policy and correctly held back until consent, and external requests are limited to state infrastructure.

Requests go to the proprietary domain and to the federal government CDN. The declared Plausible analytics does not activate before consent; no cookies are set. For a data protection supervisory authority, this is the expected and correct behavior.

What cannot be claimed from the measurement

The measurement covers the homepage and the pre-consent state. Plausible’s behavior after clicking “accept” is not observed here; if correctly configured, its activation with consent would be lawful. Server-side processing is not visible in a browser-based measurement.

Conclusion

Belgium’s Data Protection Authority demonstrates a configuration consistent with what it itself requires of others: the declared analytics tool — open-source, privacy-oriented Plausible — does not fire before consent, the only external resource is a federal government cloud CDN, and there are no third-party trackers, Google services, or cookies. What is declared in the policy matches actual behavior. No violations recorded in this measurement.

Evidence
Original (audit)
HAR file: be/autoriteprotectiondonnees-be-2026-05-26.har
SHA-256: 4e07437dca8a84d90621ea8a8ec26c63d439058947574d463c9e33c16f9881e1
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.