Technical audit · 2026-06-15

entsoe.eu

European Network of Transmission System Operators for Electricity

The website of ENTSO-E (European Network of Transmission System Operators for Electricity), Brussels. 31 requests, 2 domains — both belonging to the organization itself. Matomo analytics is deployed on the proprietary domain, and in the captured session did not even send an actual measurement event — and not a single cookie for the whole session.

Timeline of the leak

+0–164 ms · loading the proprietary stack
A proprietary content management system. The Matomo library loads from the organization's own domain (/matomo/matomo.js), not from a third-party subdomain or cloud service.
not applicable
No visible cookie banner appears in the captured session. There is also no actual visit measurement (matomo.php) — only the library loaded, so there is essentially nothing to reconcile.
+1035–1401 ms · proprietary content only
Graphics, images, and a request to the organization's own consultation platform — all on the organization's own domains. Not a single external request, not a single Set-Cookie header for the entire session.

Detected trackers

Context

www.entsoe.eu is the website of ENTSO-E, the European Network of Transmission System Operators for Electricity: an international nonprofit association under Belgian law, headquartered in Brussels, bringing together the operators of Europe’s high-voltage electricity grids. The measurement recorded 31 requests to two domains, both belonging to the organization itself — its website and its own consultation platform. The controller, correctly, is the association itself. The measurement, like the whole series, was captured on a clean Edge browser with no VPN and no blocker.

This is a clean result — and an interesting contrast to the previous Belgian site in the series.

Who receives the data

There are no third-party recipients: the analytics are self-hosted, and nothing leaves the organization’s own domains.

No visible banner appears in the captured session. But this doesn’t create a problem here: the analytics are self-hosted, and in this session it loaded only the library and sent no actual measurement event, and not a single cookie was set. In other words, there is effectively nothing to reconcile.

Technically clean

Unlike most sites reviewed in this series, there is not a single third-party tracker domain here. Matomo is loaded from the organization’s own domain, not from a third-party subdomain or cloud service — and in the captured session it did not even get as far as sending an actual measurement event, stopping at loading the library. This is arguably the most minimal case of self-hosted analytics in the series: no external requests, no cookies, no data transmitted anywhere outside.

A note on the scope of the review

To be transparent about the boundary of this check: the organization’s policy is structured as a hub page (“Privacy – Key Facts”) linking to a dozen separate documents — a general site policy, a cookie policy, events, the newsletter, and so on. The content of these individual documents was not part of the capture, so I cannot confirm the completeness of the declaration from the available text. But that is a question about the document, not about the site’s behavior: the behavior itself is clean.

What cannot be claimed from the measurement

A few honest caveats. I did not capture the detailed cookie policy that the hub page links to, so my assessment of compliance is based on behavior alone. The actual Matomo measurement event did not fire in this session — it may be sent under other conditions; I am simply noting its absence in the captured session. The measurement covers the homepage, and all domains belong to the organization.

Conclusion

A clean result: everything is first-party, the analytics are self-hosted and did not even register a measurement event on this visit, there are no third-party domains, and there are no cookies. Following the European construction federation from the same Belgian batch, where practically all external traffic went to Google with no banner at all, this network of grid operators is its complete opposite — everything stays within its own infrastructure. The one open point is documentary: the detailed cookie policy is tucked behind a hub page that could not be read. As for the site’s actual behavior, there is nothing to fault.

Evidence
Original (audit)
HAR file: be/www-entsoe-eu-2026-06-15.har
SHA-256: 62f06b0134536c59db3747e65709a89f618842d807822882e68ed9ed48fecbb6
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.