Policy changed — see what exactly · 2026-07-13 →
The website of FIEC — the European Federation of the Construction Industry (Brussels), an umbrella body over 32 national federations, including Italy's Federcostruzioni. 99 requests, 11 domains. There is no consent banner at all, and two embedded YouTube videos in standard mode connect Google's advertising infrastructure within the very first second of the visit.
Timeline of the leak
Declared versus actual
Detected trackers
- YouTube in standard mode (www.youtube.com/embed) — two embedded videos
- Google DoubleClick (googleads.g.doubleclick.net, static.doubleclick.net) — advertising infrastructure
- Google reCAPTCHA
- Google Fonts
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — Google advertising from the first second, without consentThere is no consent mechanism on the site at all. Two embedded videos are connected in standard (non-privacy-enhanced) YouTube mode, and at +907 ms a connection is already established with Google's advertising infrastructure (googleads.g.doubleclick.net/pagead/id and static.doubleclick.net/instream/ad_status.js — twice, matching the number of videos), regardless of whether the user played anything. In parallel, reCAPTCHA and YouTube tracking pings are active. A curious detail: the policy itself states that cookies are set 'as soon as you consent' — but there is no banner on the site to actually ask for that consent.
- Art. 13(1)(e) and Art. 13(1)(f) GDPR — recipients not named, IP goes to the USAThe policy describes cookies in general terms — 'traffic log cookies for statistical analysis' — and names neither YouTube, nor DoubleClick, nor reCAPTCHA, nor Google Fonts. All these services belong to Google (USA), and requests to them transmit the visitor's IP address outside the EU. The policy contains no dedicated section on such a transfer.
Context
www.fiec.eu is the website of FIEC, the European Federation of the Construction Industry, headquartered in Brussels, bringing together 32 national federations, including Italy’s Federcostruzioni, reviewed earlier in this series. Built on Concrete CMS. The measurement recorded 99 requests to 11 domains. This is the first Belgian site in the batch added via the industry connection to the Italian topic. The measurement, like the whole series, was captured on a clean Edge browser with no VPN and no blocker.
The case is notable in that the European umbrella body behaves not better, but arguably worse, than its Italian member: a full Google advertising infrastructure is loaded here, and all of it without a single consent banner.
Who receives the data
Observed here: Google.
Was there a consent banner
There is no banner at all — no consent mechanism of any kind was found on the page. And there is a direct inconsistency with the document here: the policy states that cookies are placed on the device “as soon as you consent,” implying a consent step. But that step simply does not exist on the site: nothing is asked, and the trackers load immediately.
Standard YouTube pulls in Google’s advertising infrastructure
The main point. The page has two embedded videos, connected in standard YouTube mode rather than the privacy-enhanced mode. The difference matters: privacy-enhanced mode delays contact with Google until the video is played, standard mode contacts it immediately. Here, within the first second, with no playback whatsoever, a connection is established twice with Google’s advertising infrastructure. YouTube tracking pings and Google attestation requests follow. Add reCAPTCHA and Google fonts, and practically all of the site’s external requests lead to a single company.
Where the data goes — to Google, USA
The only significant recipient here is Google, wearing multiple hats: video, advertising infrastructure, form protection, fonts, attestation. All these requests transmit the visitor’s IP address to the USA. The policy has no dedicated section on transfer outside the EU, and the services themselves are not named. The fix is standard: privacy-enhanced mode for video, self-hosting the fonts, and honestly describing the rest in the document.
A family resemblance
Worth noting the connection to a site already reviewed. Italy’s Federcostruzioni, a member of this same federation, was guilty of the same thing — standard YouTube mode and the absence of genuine consent. The European umbrella body repeats the same habit and adds a full DoubleClick advertising infrastructure on top. This is not the quirk of one site, but a shared working style across the entire industry family.
What cannot be claimed from the measurement
A few honest caveats. Contact with the advertising infrastructure on loading an embedded video is standard YouTube-mode behavior, not separately configured advertising on the site; but the outcome for the visitor is the same — data goes to Google before any action is taken. reCAPTCHA is presumably protecting a form on the site. Cookie contents are not directly visible in this lightweight capture. The measurement covers the homepage.
Conclusion
The website of this Brussels-based European federation operates without a single consent banner, and two embedded YouTube videos in standard mode connect Google’s advertising infrastructure within the very first second — alongside reCAPTCHA, fonts, and attestation from Google. Practically all external recipients here reduce to a single overseas company. Meanwhile, the policy describes only generic “statistical cookies” and even implies a consent step that does not exist on the site. The key takeaway: both the national federation and its European umbrella body are built to the same pattern — an embedded video in standard mode, with no asking — except at the European level, Google’s advertising machine is added on top.
bc76838ed01f661a74f881214889f7197903d216aa753e20b04f45f56bf8228fWhere to file: Autorité de protection des données (APD) — file a complaint online →
To: Autorité de protection des données (APD) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website fiec.eu. 2. Circumstances I visited the website fiec.eu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) There is no consent mechanism on the site at all. Two embedded videos are connected in standard (non-privacy-enhanced) YouTube mode, and at +907 ms a connection is already established with Google's advertising infrastructure (googleads.g.doubleclick.net/pagead/id and static.doubleclick.net/instream/ad_status.js — twice, matching the number of videos), regardless of whether the user played anything. In parallel, reCAPTCHA and YouTube tracking pings are active. A curious detail: the policy itself states that cookies are set 'as soon as you consent' — but there is no banner on the site to actually ask for that consent. 2) The policy describes cookies in general terms — 'traffic log cookies for statistical analysis' — and names neither YouTube, nor DoubleClick, nor reCAPTCHA, nor Google Fonts. All these services belong to Google (USA), and requests to them transmit the visitor's IP address outside the EU. The policy contains no dedicated section on such a transfer. Full technical documentation is published at: https://gdpru.eu/en/audits/be-fiec-eu-be/ 3. Provisions violated Art. 6(1)(a) GDPR — Google advertising from the first second, without consent; Art. 13(1)(e) and Art. 13(1)(f) GDPR — recipients not named, IP goes to the USA 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]