Technical audit · 2026-05-29

zdb.de

German Central Association of the Construction Industry

Germany's Central Association of the Construction Industry. 35 requests, 1 domain. TYPO3 CMS. Barlow and Font Awesome served locally. Not a single external domain. No Google, no Meta, no counters. Set-Cookie — zero. The policy mentions Matomo, Facebook, Instagram, Twitter, and YouTube — none of them show up in the HAR.

Timeline of the leak

+0 ms · homepage
www.zdb.de/ — HTML, Apache. All subsequent resources served exclusively from www.zdb.de.
+94 ms · styles and scripts
TYPO3-merged CSS and JS from typo3temp/assets/compressed/ — all local.
+169 ms · fonts
Barlow (Regular, 700, 800) and Font Awesome (fa-brands, fa-solid) — woff2 files, all from typo3conf/ext/zdb_content/Resources/Public/. No Google Fonts, no Adobe Fonts.
+248 ms · favicon
manifest.json, favicon.ico, favicon-32x32.png — local.

Declared versus actual

Matomo — mentioned in the policy as consent-based analytics — заявлен
Facebook, Instagram, Twitter, YouTube — mentioned as social media plugins — заявлен
Microsoft Teams / LifeSize — mentioned for video conferencing — заявлен

Context

ZDB (Zentralverband des Deutschen Baugewerbes) is Germany’s central association of the construction trade, representing roughly 35,000 businesses. Founded in 1899, headquartered in Berlin. TYPO3 CMS, Apache. HAR: 35 requests, 1 domain.

Clean architecture

All 35 requests go exclusively to www.zdb.de. CSS and JS are assembled by TYPO3’s merger in /typo3temp/assets/compressed/. The Barlow typeface (Regular, Bold 700, ExtraBold 800) and the Font Awesome icon set (brands and solid) are hosted locally within the zdb_content extension. There are no requests to Google Fonts, Adobe Fonts, or any third-party CDN. Set-Cookie — zero.

Policy vs. HAR: declared and actual

The privacy policy (version dated 17.05.2021) declares the use of Matomo and Facebook, Instagram, Twitter, and YouTube plugins. None of these services appear in the HAR — no trackers, no SDKs, no pixel requests. The integrations may exist on internal pages or behind authorization, or may have been removed after the policy was written. On the public homepage, nothing that is declared is actually activated.

The policy references Microsoft Teams and LifeSize in the context of video conferencing — this is offline infrastructure, unrelated to the website.

Not one of the 35 requests sets a cookie via Set-Cookie.

Conclusion

www.zdb.de does not transmit visitor data to third parties. One domain, local resources, no trackers, no cookies. The policy is written with a margin beyond the site’s actual state — this is not itself a violation, but it creates inflated expectations for the reader. No GDPR violations recorded at the time of the audit.

Evidence
Original (audit)
HAR file: de/zdb-de-2026-05-29.har
SHA-256: bc49a8cb752fe04000755f9233a385234a8977626b858f8f2d38030775e485ea
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.