Technical audit · 2026-05-26

crossroads.be

Belgian Digital Media Production Studio

crossroads.be — the website of Crossroads digital media, a Belgian production studio working in museography (museum exhibition scenography), documentary film, serious games, and corporate video. Clients include museums and cultural institutions, television, and corporations. For the purposes of this measurement, the site operator, Crossroads, is treated as the controller. Measurement: 108 requests, 5 domains, captured on a clean browser.

Timeline of the leak

+0 ms · portal load
Content and resources served from crossroads.be (OVH hosting, Belgium/EU).
+215 ms · Google WebFont Loader before consent
ajax.googleapis.com/ajax/libs/webfont/1.4.7/webfont.js — the Google web font loader. The visitor's IP address goes to Google (USA).
+231 ms · jQuery from CloudFront
d1tdp7z6w94jbb.cloudfront.net/js/jquery-3.3.1.min.js — a library served from AWS CloudFront (USA).
+257 ms · Google Fonts before consent
fonts.googleapis.com (Open Sans) and fonts.gstatic.com — Google Fonts. The visitor's IP address goes to Google (USA).
policy not found
No privacy policy page was found on the site; there is no disclosure of data recipients.

Declared versus actual

+ Google Fonts, Google WebFont Loader, jQuery via CloudFront — transmit the IP address to Google and AWS (USA) before consent — не заявлен
+ No privacy policy found on the site — не заявлен
+ No consent manager present — не заявлен

Transfer timings

+215 ms ajax.googleapis.com

Google WebFont Loader. Google, USA.

+231 ms d1tdp7z6w94jbb.cloudfront.net

jQuery. AWS CloudFront, USA.

+257 ms fonts.googleapis.com

Google Fonts (Open Sans). Google, USA.

Detected trackers

Indicators of GDPR non-compliance

Context

crossroads.be is a Belgian website on the crossroads.be domain, hosted on OVH infrastructure. The nature of the owner’s activities cannot be established from a single browser measurement and is not assumed here. Measurement: 108 requests, 5 domains, captured on a clean browser.

Google (USA) — IP address via Google Fonts and Google WebFont Loader; AWS CloudFront (USA) — IP address via the jQuery load.

Declared versus actual

Comparison against a policy is not possible here for an objective reason: no privacy policy page was found on the site. This alone is significant: where processing transmits data to third parties, the absence of any policy means the obligation to inform the visitor of data recipients, purposes, and legal bases is not fulfilled at all.

The measurement records data transfer to external recipients. At +215 ms, the Google WebFont Loader loads from ajax.googleapis.com; at +257 ms, Google Fonts CSS and files (Open Sans) load from fonts.googleapis.com and fonts.gstatic.com; both requests transmit the visitor’s IP address to Google (a US company). At +231 ms, the jQuery library loads from d1tdp7z6w94jbb.cloudfront.net — the AWS CloudFront distribution network (USA). There is no consent manager on the site, not a single cookie is set for the entire session, and no user choice is made — meaning all external requests occur before any consent.

External resources load at +215–257 ms, at the start of the session. There is no consent mechanism; the transfer of the IP address to Google and AWS occurs unconditionally, before and outside of any user choice.

What cannot be claimed from the measurement

The measurement covers the homepage. Google and AWS may use edge nodes within the EU, so the conclusion is drawn based on the recipients’ affiliation (US companies), not the physical location of the nodes. The nature of the site’s activity and the identity of the operator cannot be established from the measurement. The absence of a policy is noted based on a check of the site; if the policy is hosted at a non-standard address not linked from the site, this should be verified separately. Server-side processing is not visible in a browser-based measurement.

Conclusion

The crossroads.be website, before consent and with no consent manager present, transmits the visitor’s IP address to Google (via Google Fonts and WebFont Loader) and to AWS (via the jQuery load from CloudFront). At the same time, no privacy policy page was found on the site, meaning disclosure of data recipients is entirely absent. The combination of data transfer to third-party recipients in the USA before consent and the absence of a policy constitutes a violation of the requirements for consent, disclosure of recipients, cross-border transfer, and informing the data subject. Remedy: host the fonts and libraries locally, implement a consent mechanism that holds back third-party requests until a choice is made, and publish a privacy policy listing the data recipients.

Evidence
Original (audit)
HAR file: be/crossroads-be-2026-05-26.har
SHA-256: a1d3c6276076a14820aa398b2602581c9a1db28fa58adfd58ccbbc53837cd3fa
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Autorité de protection des données (APD)file a complaint online →

To: Autorité de protection des données (APD)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website crossroads.be.

2. Circumstances
I visited the website crossroads.be and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 26 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) No privacy policy was found on the site. Meanwhile, the site transmits visitor data to third-party recipients (see below). The absence of any policy means the requirement to inform the data subject of recipients and processing purposes is not met at all.

2) Before consent, on page load, the following load: Google WebFont Loader (ajax.googleapis.com, +215 ms), Google Fonts (fonts.googleapis.com + fonts.gstatic.com, Open Sans, +257 ms), and the jQuery library from CloudFront (d1tdp7z6w94jbb.cloudfront.net, +231 ms). These requests transmit the visitor's IP address to Google (USA) and to AWS infrastructure (USA). The recipients are disclosed nowhere.

3) There is no consent manager on the site. All external requests occur on page load, before any choice. Zero Set-Cookie headers for the entire session.

Full technical documentation is published at: https://gdpru.eu/en/audits/be-crossroads-be/

3. Provisions violated
GDPR Art. 13 — absence of information; GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and transfer; ePrivacy (Belgian implementation) — third-party resources before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]