Belgium's national news agency — 79 requests, 18 domains. A full advertising and analytics stack — Google Ads and GA4, LinkedIn Ads, Contentsquare session recording, Lead Forensics IP identification, Sentry — fires before consent. The CookieYes consent manager loads after the trackers have started and does not hold them back. Not a single service is named in the policy.
Timeline of the leak
Declared versus actual
Transfer timings
ccm/collect page_view with an advertising identifier (auid). Google Ads AW-1005663691, USA.
LinkedIn Ads attribution/collect, pid 4472417. USA.
Contentsquare pageview — behavior recording (uu).
GA4 g/collect page_view (cid). G-X90HZ8CS30.
Lead Forensics — visitor identification by IP. Account 97305.
Detected trackers
- Google Ads + GA4 + GTM (AW-1005663691, G-X90HZ8CS30)
- LinkedIn Ads (px.ads.linkedin.com, pid 4472417)
- Contentsquare — session recording/behavior
- Lead Forensics — B2B IP identification (97305)
- Sentry — error monitoring
- CookieYes — CMP (does not gate)
- Whizeo — news content platform (observed)
Indicators of GDPR non-compliance
- ePrivacy (Belgian implementation) + GDPR Art. 6(1) — trackers before consentThe CookieYes consent manager loads at +686 ms — after the advertising and analytics services have already started — and does not hold them back. Before consent, the following fire: Google Tag Manager with Google Ads (AW-1005663691) and GA4 (G-X90HZ8CS30), sending a page_view event 'Belga - Homepage' with an advertising identifier (auid) and a client identifier (cid); LinkedIn Ads (snap.licdn.com and px.ads.linkedin.com, pid 4472417); Contentsquare (session and behavior recording); Lead Forensics (B2B visitor identification by IP, account 97305); Sentry. Zero Set-Cookie headers for the entire session — no user choice was made.
- GDPR Art. 13(1)(e) — disclosure of recipientsBelga's policy mentions cookies and consent in general terms, but names not a single actual service: not Google, not LinkedIn, not Contentsquare, not Lead Forensics, not Sentry, not even the CookieYes consent manager itself. Data recipients are not disclosed.
- GDPR Chapter V — cross-border transferBefore consent, data is transmitted to recipients outside the EU: the page_view event, advertising identifier, and client identifier go to Google (USA); advertising events go to LinkedIn (USA); behavioral data goes to Contentsquare; IP-based identification goes to Lead Forensics. The transfer occurs without consent.
- Distinctive nature — IP-based identificationLead Forensics specializes in de-anonymizing corporate visitors by IP address (endpoint Track/Capture.aspx, account 97305). On the website of a national news agency, this allows visits — including those of journalists and organizations — to be linked to specific companies, before consent and without disclosure.
Context
belga.be is the website of Belga News Agency, Belgium’s national news agency and a news supplier to the country’s media. Controller: Belga News Agency NV. The privacy policy is relatively short (roughly 5,700 characters). Measurement: 79 requests, 18 domains, captured on a clean browser.
Who receives data directly (before consent)
Google, LinkedIn, Contentsquare, Lead Forensics, Sentry.
Declared versus actual
Belga’s policy repeatedly mentions cookies, and refers to consent and third parties in general terms, touching on advertising only in passing. It names not a single specific measurement, advertising, or identification service.
The measurement reveals an extensive stack that fires before consent. The load order is telling: advertising and analytics services start before the consent manager even appears. Google Tag Manager (+497 ms) launches Google Ads (AW-1005663691) and GA4 (G-X90HZ8CS30); the endpoint www.google.com/ccm/collect receives a page_view event four times, carrying the title “Belga - Homepage,” the page address, and an advertising identifier (auid), while region1.google-analytics.com/g/collect receives a GA4 event with a client identifier (cid). Running in parallel: LinkedIn Ads (snap.licdn.com and px.ads.linkedin.com, pid 4472417), Contentsquare’s session and behavior recording service (t.contentsquare.net, c.ba.contentsquare.net), Sentry error monitoring, and — separately significant — Lead Forensics (secure.leadforensics.com/Track/Capture.aspx, account 97305), a service that de-anonymizes corporate visitors by IP address.
The CookieYes consent manager only loads at +686 ms — that is, after some of the trackers have already started — and does not hold them back in the measurement: not a single cookie is set for the entire session, no user choice is made, and yet the services fire anyway. None of the listed services — Google, LinkedIn, Contentsquare, Lead Forensics, Sentry, CookieYes — is named in the policy. A number of requests to whizeo.com domains relate to Belga’s news content platform; their role as a tracking mechanism is not separately established and is not treated as grounds for a violation.
Timing relative to consent
Trackers start at +497 ms, the consent manager at +686 ms, and data-transmitting events continue through +4456 ms. The load order is such that consent could not technically have preceded the firing of advertising and analytics; and in fact, no consent was given during the session (zero Set-Cookie).
What cannot be claimed from the measurement
The measurement covers the homepage. Visitor identifiers (auid, cid, the Contentsquare identifier) are not fully reproduced in this publication; service account identifiers (AW-1005663691, G-X90HZ8CS30, LinkedIn pid 4472417, Lead Forensics 97305) belong to the site’s configuration, not to the visitor. The role of the Whizeo platform is attributed to news content delivery. Google, LinkedIn, and Contentsquare may use edge nodes within the EU, so the conclusion is drawn based on the recipients’ affiliation. Server-side processing is not visible in a browser-based measurement.
Conclusion
The website of Belgium’s national news agency launches a full commercial stack before consent: Google Ads and LinkedIn Ads advertising, GA4 analytics, Contentsquare session recording, Sentry monitoring, and — most sensitively — visitor identification by IP via Lead Forensics. A CookieYes consent manager is present on the site, but loads after the trackers have started and does not hold them back, and not a single service is named in the policy. The combination of advertising and identification services firing before consent, data transfer to recipients in the USA, and the complete absence of their disclosure constitutes a violation of the requirements for prior consent, disclosure of recipients, and cross-border transfer. Remedy: switch CookieYes to genuine blocking mode so that all non-technical services are held back until consent; prevent Google, LinkedIn, Contentsquare, and Lead Forensics from firing before the user’s choice; disclose all actually used services in the policy.
924ebfd9ad07d219dc3e64db18d1fd08e48f18335333ab08861409c83e3fb781Where to file: Autorité de protection des données (APD) — file a complaint online →
To: Autorité de protection des données (APD) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website belga.be. 2. Circumstances I visited the website belga.be and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 26 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) The CookieYes consent manager loads at +686 ms — after the advertising and analytics services have already started — and does not hold them back. Before consent, the following fire: Google Tag Manager with Google Ads (AW-1005663691) and GA4 (G-X90HZ8CS30), sending a page_view event 'Belga - Homepage' with an advertising identifier (auid) and a client identifier (cid); LinkedIn Ads (snap.licdn.com and px.ads.linkedin.com, pid 4472417); Contentsquare (session and behavior recording); Lead Forensics (B2B visitor identification by IP, account 97305); Sentry. Zero Set-Cookie headers for the entire session — no user choice was made. 2) Belga's policy mentions cookies and consent in general terms, but names not a single actual service: not Google, not LinkedIn, not Contentsquare, not Lead Forensics, not Sentry, not even the CookieYes consent manager itself. Data recipients are not disclosed. 3) Before consent, data is transmitted to recipients outside the EU: the page_view event, advertising identifier, and client identifier go to Google (USA); advertising events go to LinkedIn (USA); behavioral data goes to Contentsquare; IP-based identification goes to Lead Forensics. The transfer occurs without consent. 4) Lead Forensics specializes in de-anonymizing corporate visitors by IP address (endpoint Track/Capture.aspx, account 97305). On the website of a national news agency, this allows visits — including those of journalists and organizations — to be linked to specific companies, before consent and without disclosure. Full technical documentation is published at: https://gdpru.eu/en/audits/be-belga-be/ 3. Provisions violated ePrivacy (Belgian implementation) + GDPR Art. 6(1) — trackers before consent; GDPR Art. 13(1)(e) — disclosure of recipients; GDPR Chapter V — cross-border transfer; Distinctive nature — IP-based identification 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]