Technical audit · 2026-05-31

boligejer.dk

Danish Government Portal for Homeowners

The Danish government portal for homeowners — 93 requests, 4 domains. The policy states that statistics are collected only upon clicking 'Accepter.' In the capture, Siteimprove analytics fires prior to consent, transmitting the URL, page title, screen resolution, and a persistent visitor identifier. Siteimprove is not named in the policy, and the statistics are declared to be anonymous.

Timeline of the leak

+0 ms · portal load
Content and resources served from boligejer.dk.
+108 ms · library from a CDN
cdnjs.cloudflare.com/polyfill/v2 — a polyfill served from Cloudflare's secure mirror. A static library resource.
+122 ms · analytics script
siteimproveanalytics.com/js/siteanalyze_273738.js — the Siteimprove tracker loads.
+438 ms · data transfer without consent
273738.global.siteimproveanalytics.io/image.aspx — the Siteimprove beacon transmits the URL, page title, screen resolution, and a persistent visitor identifier (luid).

Declared versus actual

Statistics cookies are set upon clicking 'Accepter'; they are not set upon clicking 'Afvis' or in the absence of any choice — заявлен
The statistics are declared to be anonymous, not linked to an individual user — заявлен
+ Siteimprove Analytics — the actual analytics service, fires prior to consent, carries a persistent visitor identifier and screen resolution; not named in the policy — не заявлен

Transfer timings

+122 ms siteimproveanalytics.com

Siteimprove siteanalyze_273738.js. Analytics script.

+438 ms 273738.global.siteimproveanalytics.io

Siteimprove beacon. URL + page title + screen resolution + visitor identifier.

Detected trackers

Indicators of GDPR non-compliance

Context

boligejer.dk is a Danish inter-agency government portal for homeowners (operated by Erhvervsstyrelsen, the Danish Business Authority), providing property data from land and address registers, property reports, and guides for home buyers and sellers. The data controller is the agency. The current cookie policy was retrieved from the site (the supplied document does not include a separate cookie declaration). Capture: 93 requests, 4 domains, recorded in a clean browser.

Siteimprove — the page URL, page title, screen resolution, and a persistent visitor identifier (luid).

Declared versus Actual

boligejer.dk’s policy describes its consent model directly: on the first visit, a cookie banner for statistics is displayed; clicking “Accepter” sets first- and third-party cookies for statistics, while clicking “Afvis” prevents statistics cookies from being set. The statistics collected are declared to be anonymous and not linked to an individual user. No specific statistics tool is named in the policy.

The capture shows analytics operating prior to consent. At +122 ms, the Siteimprove script loads (siteimproveanalytics.com/js/siteanalyze_273738.js), and at +438 ms a beacon is sent to 273738.global.siteimproveanalytics.io/image.aspx. The beacon transmits the page URL, its title, screen resolution (1536x864), and a persistent visitor identifier (luid). The session state at this point is one of no consent: not a single cookie is set across the entire session, and no choice has been made by the user. Since Siteimprove operates without cookies, the policy’s literal condition — that statistics cookies are not set before “Accepter” — is formally satisfied; however, the statistical transmission itself, including the persistent visitor identifier, occurs prior to consent, which diverges from the declared model of collecting statistics only upon clicking “Accepter.” The persistent identifier and screen resolution likewise diverge from the declared anonymity. The Siteimprove service is not named in the policy.

Separately: at +108 ms, a polyfill loads from cdnjs.cloudflare.com, served from Cloudflare’s secure mirror — this is a static library resource, not a tracking tool.

The Siteimprove script loads at +122 ms; the beacon carrying the data at +438 ms. No choice has been made in the consent banner (Set-Cookie is zero), yet analytics has initialized and transmitted data carrying a persistent identifier.

What Cannot Be Asserted from This Capture

The capture covers the home page. Siteimprove operates without cookies; whether an exemption applies to it despite the transmission of a persistent identifier and screen resolution is a matter for the competent authority to assess. The visitor identifier is not reproduced in full in this publication. The polyfill is classified as a static library resource served from a secure mirror. Server-side processing is not visible in a browser-based capture.

Conclusion

The government portal for homeowners declares in its policy that statistics are collected only upon clicking “Accepter” and are anonymous. In the capture, Siteimprove analytics fires prior to consent and transmits the URL, page title, screen resolution, and a persistent visitor identifier; since the service is cookieless, the literal condition regarding cookies is met, but the statistical transmission carrying an identifier occurs prior to consent and outside the declared model. Siteimprove is not named in the policy, and the identifying parameters transmitted diverge from the declared anonymity. Remedy: make Siteimprove’s firing conditional on the outcome of the banner choice (hold it back until “Accepter”), name Siteimprove in the policy, and bring the description of the statistics into line with the parameters actually transmitted.

Evidence
Original (audit)
HAR file: dk/boligejer-dk-2026-05-31.har
SHA-256: 2225cba876ba6bf8be155845443b8b816734068a59aab315a0b406078362e680
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Danish Data Protection Agency (Datatilsynet)file a complaint online →

To: Danish Data Protection Agency (Datatilsynet)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website boligejer.dk.

2. Circumstances
I visited the website boligejer.dk and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) boligejer.dk's policy states that statistics cookies are set upon clicking 'Accepter,' and that no statistics are collected upon clicking 'Afvis' or in the absence of any choice. In the capture, Siteimprove analytics fires prior to consent: the script siteimproveanalytics.com/js/siteanalyze_273738.js (+122 ms) and the beacon 273738.global.siteimproveanalytics.io/image.aspx (+438 ms) transmit data, even though no cookies are set across the entire session and no choice has been made by the user. Siteimprove does not use cookies, so the literal condition regarding cookies is met — but the transmission of statistical data occurs prior to consent, contrary to the declared model.

2) The Siteimprove beacon transmits the page URL, page title, screen resolution (1536x864), and a persistent visitor identifier (luid). The policy declares the statistics to be anonymous and not linked to the user, and does not name the Siteimprove service specifically. A persistent identifier and screen resolution are identifying parameters, which diverges from the declared anonymity.

Full technical documentation is published at: https://gdpru.eu/en/audits/dk-boligejer-dk/

3. Provisions violated
ePrivacy (Danish Cookiebekendtgørelse) + the policy's own stated rule; GDPR Art. 13(1)(e) + Art. 5(1)(a) — disclosure and anonymity

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]