The Danish government portal for homeowners — 93 requests, 4 domains. The policy states that statistics are collected only upon clicking 'Accepter.' In the capture, Siteimprove analytics fires prior to consent, transmitting the URL, page title, screen resolution, and a persistent visitor identifier. Siteimprove is not named in the policy, and the statistics are declared to be anonymous.
Timeline of the leak
Declared versus actual
Transfer timings
Siteimprove siteanalyze_273738.js. Analytics script.
Siteimprove beacon. URL + page title + screen resolution + visitor identifier.
Detected trackers
- Siteimprove Analytics (siteimproveanalytics.com, siteimproveanalytics.io)
- Cloudflare polyfill (cdnjs.cloudflare.com) — library
Indicators of GDPR non-compliance
- ePrivacy (Danish Cookiebekendtgørelse) + the policy's own stated ruleboligejer.dk's policy states that statistics cookies are set upon clicking 'Accepter,' and that no statistics are collected upon clicking 'Afvis' or in the absence of any choice. In the capture, Siteimprove analytics fires prior to consent: the script siteimproveanalytics.com/js/siteanalyze_273738.js (+122 ms) and the beacon 273738.global.siteimproveanalytics.io/image.aspx (+438 ms) transmit data, even though no cookies are set across the entire session and no choice has been made by the user. Siteimprove does not use cookies, so the literal condition regarding cookies is met — but the transmission of statistical data occurs prior to consent, contrary to the declared model.
- GDPR Art. 13(1)(e) + Art. 5(1)(a) — disclosure and anonymityThe Siteimprove beacon transmits the page URL, page title, screen resolution (1536x864), and a persistent visitor identifier (luid). The policy declares the statistics to be anonymous and not linked to the user, and does not name the Siteimprove service specifically. A persistent identifier and screen resolution are identifying parameters, which diverges from the declared anonymity.
Context
boligejer.dk is a Danish inter-agency government portal for homeowners (operated by Erhvervsstyrelsen, the Danish Business Authority), providing property data from land and address registers, property reports, and guides for home buyers and sellers. The data controller is the agency. The current cookie policy was retrieved from the site (the supplied document does not include a separate cookie declaration). Capture: 93 requests, 4 domains, recorded in a clean browser.
Direct Recipients of Data (prior to consent)
Siteimprove — the page URL, page title, screen resolution, and a persistent visitor identifier (luid).
Declared versus Actual
boligejer.dk’s policy describes its consent model directly: on the first visit, a cookie banner for statistics is displayed; clicking “Accepter” sets first- and third-party cookies for statistics, while clicking “Afvis” prevents statistics cookies from being set. The statistics collected are declared to be anonymous and not linked to an individual user. No specific statistics tool is named in the policy.
The capture shows analytics operating prior to consent. At +122 ms, the Siteimprove script loads (siteimproveanalytics.com/js/siteanalyze_273738.js), and at +438 ms a beacon is sent to 273738.global.siteimproveanalytics.io/image.aspx. The beacon transmits the page URL, its title, screen resolution (1536x864), and a persistent visitor identifier (luid). The session state at this point is one of no consent: not a single cookie is set across the entire session, and no choice has been made by the user. Since Siteimprove operates without cookies, the policy’s literal condition — that statistics cookies are not set before “Accepter” — is formally satisfied; however, the statistical transmission itself, including the persistent visitor identifier, occurs prior to consent, which diverges from the declared model of collecting statistics only upon clicking “Accepter.” The persistent identifier and screen resolution likewise diverge from the declared anonymity. The Siteimprove service is not named in the policy.
Separately: at +108 ms, a polyfill loads from cdnjs.cloudflare.com, served from Cloudflare’s secure mirror — this is a static library resource, not a tracking tool.
Timing Relative to Consent
The Siteimprove script loads at +122 ms; the beacon carrying the data at +438 ms. No choice has been made in the consent banner (Set-Cookie is zero), yet analytics has initialized and transmitted data carrying a persistent identifier.
What Cannot Be Asserted from This Capture
The capture covers the home page. Siteimprove operates without cookies; whether an exemption applies to it despite the transmission of a persistent identifier and screen resolution is a matter for the competent authority to assess. The visitor identifier is not reproduced in full in this publication. The polyfill is classified as a static library resource served from a secure mirror. Server-side processing is not visible in a browser-based capture.
Conclusion
The government portal for homeowners declares in its policy that statistics are collected only upon clicking “Accepter” and are anonymous. In the capture, Siteimprove analytics fires prior to consent and transmits the URL, page title, screen resolution, and a persistent visitor identifier; since the service is cookieless, the literal condition regarding cookies is met, but the statistical transmission carrying an identifier occurs prior to consent and outside the declared model. Siteimprove is not named in the policy, and the identifying parameters transmitted diverge from the declared anonymity. Remedy: make Siteimprove’s firing conditional on the outcome of the banner choice (hold it back until “Accepter”), name Siteimprove in the policy, and bring the description of the statistics into line with the parameters actually transmitted.
2225cba876ba6bf8be155845443b8b816734068a59aab315a0b406078362e680Where to file: Danish Data Protection Agency (Datatilsynet) — file a complaint online →
To: Danish Data Protection Agency (Datatilsynet) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website boligejer.dk. 2. Circumstances I visited the website boligejer.dk and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) boligejer.dk's policy states that statistics cookies are set upon clicking 'Accepter,' and that no statistics are collected upon clicking 'Afvis' or in the absence of any choice. In the capture, Siteimprove analytics fires prior to consent: the script siteimproveanalytics.com/js/siteanalyze_273738.js (+122 ms) and the beacon 273738.global.siteimproveanalytics.io/image.aspx (+438 ms) transmit data, even though no cookies are set across the entire session and no choice has been made by the user. Siteimprove does not use cookies, so the literal condition regarding cookies is met — but the transmission of statistical data occurs prior to consent, contrary to the declared model. 2) The Siteimprove beacon transmits the page URL, page title, screen resolution (1536x864), and a persistent visitor identifier (luid). The policy declares the statistics to be anonymous and not linked to the user, and does not name the Siteimprove service specifically. A persistent identifier and screen resolution are identifying parameters, which diverges from the declared anonymity. Full technical documentation is published at: https://gdpru.eu/en/audits/dk-boligejer-dk/ 3. Provisions violated ePrivacy (Danish Cookiebekendtgørelse) + the policy's own stated rule; GDPR Art. 13(1)(e) + Art. 5(1)(a) — disclosure and anonymity 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]