Technical audit · 2026-06-15

fiec.eu

European Federation of the Construction Industry

The website of FIEC — the European Federation of the Construction Industry (Brussels), an umbrella body over 32 national federations, including Italy's Federcostruzioni. 99 requests, 11 domains. There is no consent banner at all, and two embedded YouTube videos in standard mode connect Google's advertising infrastructure within the very first second of the visit.

Timeline of the leak

+0–200 ms · load and Google fonts
The site runs on Concrete CMS. Google fonts and Font Awesome load from an external CDN as part of the general page load.
+267–277 ms · two standard YouTube embeds
Two embedded videos load via the standard www.youtube.com/embed domain (not privacy-enhanced). There is no consent banner on the page.
+438–839 ms · reCAPTCHA
Google reCAPTCHA fully deploys (api.js, anchor, bframe) — another Google service on the page.
+907–1218 ms · Google advertising infrastructure
A connection is established twice (matching the number of videos) with Google's advertising infrastructure: googleads.g.doubleclick.net/pagead/id and static.doubleclick.net/instream/ad_status.js. This happens without the video being played.
+2550–5152 ms · YouTube tracking and attestation
YouTube tracking pings (generate_204), Google attestation requests (jnn-pa.googleapis.com), and event logging go out. Not a single Set-Cookie header for the entire session.

Declared versus actual

+ YouTube (standard mode) — not declared
+ Google DoubleClick — not declared
+ Google reCAPTCHA — not declared
+ Google Fonts — not declared

Detected trackers

Indicators of GDPR non-compliance

Context

www.fiec.eu is the website of FIEC, the European Federation of the Construction Industry, headquartered in Brussels, bringing together 32 national federations, including Italy’s Federcostruzioni, reviewed earlier in this series. Built on Concrete CMS. The measurement recorded 99 requests to 11 domains. This is the first Belgian site in the batch added via the industry connection to the Italian topic. The measurement, like the whole series, was captured on a clean Edge browser with no VPN and no blocker.

The case is notable in that the European umbrella body behaves not better, but arguably worse, than its Italian member: a full Google advertising infrastructure is loaded here, and all of it without a single consent banner.

Who receives the data

Observed here: Google.

There is no banner at all — no consent mechanism of any kind was found on the page. And there is a direct inconsistency with the document here: the policy states that cookies are placed on the device “as soon as you consent,” implying a consent step. But that step simply does not exist on the site: nothing is asked, and the trackers load immediately.

Standard YouTube pulls in Google’s advertising infrastructure

The main point. The page has two embedded videos, connected in standard YouTube mode rather than the privacy-enhanced mode. The difference matters: privacy-enhanced mode delays contact with Google until the video is played, standard mode contacts it immediately. Here, within the first second, with no playback whatsoever, a connection is established twice with Google’s advertising infrastructure. YouTube tracking pings and Google attestation requests follow. Add reCAPTCHA and Google fonts, and practically all of the site’s external requests lead to a single company.

Where the data goes — to Google, USA

The only significant recipient here is Google, wearing multiple hats: video, advertising infrastructure, form protection, fonts, attestation. All these requests transmit the visitor’s IP address to the USA. The policy has no dedicated section on transfer outside the EU, and the services themselves are not named. The fix is standard: privacy-enhanced mode for video, self-hosting the fonts, and honestly describing the rest in the document.

A family resemblance

Worth noting the connection to a site already reviewed. Italy’s Federcostruzioni, a member of this same federation, was guilty of the same thing — standard YouTube mode and the absence of genuine consent. The European umbrella body repeats the same habit and adds a full DoubleClick advertising infrastructure on top. This is not the quirk of one site, but a shared working style across the entire industry family.

What cannot be claimed from the measurement

A few honest caveats. Contact with the advertising infrastructure on loading an embedded video is standard YouTube-mode behavior, not separately configured advertising on the site; but the outcome for the visitor is the same — data goes to Google before any action is taken. reCAPTCHA is presumably protecting a form on the site. Cookie contents are not directly visible in this lightweight capture. The measurement covers the homepage.

Conclusion

The website of this Brussels-based European federation operates without a single consent banner, and two embedded YouTube videos in standard mode connect Google’s advertising infrastructure within the very first second — alongside reCAPTCHA, fonts, and attestation from Google. Practically all external recipients here reduce to a single overseas company. Meanwhile, the policy describes only generic “statistical cookies” and even implies a consent step that does not exist on the site. The key takeaway: both the national federation and its European umbrella body are built to the same pattern — an embedded video in standard mode, with no asking — except at the European level, Google’s advertising machine is added on top.

Evidence
Original (audit)
HAR file: be/fiec-eu-2026-06-15.har
SHA-256: bc76838ed01f661a74f881214889f7197903d216aa753e20b04f45f56bf8228f
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Autorité de protection des données (APD)file a complaint online →

To: Autorité de protection des données (APD)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website fiec.eu.

2. Circumstances
I visited the website fiec.eu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) There is no consent mechanism on the site at all. Two embedded videos are connected in standard (non-privacy-enhanced) YouTube mode, and at +907 ms a connection is already established with Google's advertising infrastructure (googleads.g.doubleclick.net/pagead/id and static.doubleclick.net/instream/ad_status.js — twice, matching the number of videos), regardless of whether the user played anything. In parallel, reCAPTCHA and YouTube tracking pings are active. A curious detail: the policy itself states that cookies are set 'as soon as you consent' — but there is no banner on the site to actually ask for that consent.

2) The policy describes cookies in general terms — 'traffic log cookies for statistical analysis' — and names neither YouTube, nor DoubleClick, nor reCAPTCHA, nor Google Fonts. All these services belong to Google (USA), and requests to them transmit the visitor's IP address outside the EU. The policy contains no dedicated section on such a transfer.

Full technical documentation is published at: https://gdpru.eu/en/audits/be-fiec-eu-be/

3. Provisions violated
Art. 6(1)(a) GDPR — Google advertising from the first second, without consent; Art. 13(1)(e) and Art. 13(1)(f) GDPR — recipients not named, IP goes to the USA

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]