The Danish Agency for Digital Government — 48 requests, 3 domains. The sole external domain is the Cookiebot consent management platform, on a European endpoint. There is no third-party analytics, Google, maps, advertising, or session recording in the capture; fonts are hosted locally, and no cookies are set. No violations have been recorded.
Timeline of the leak
Declared versus actual
Transfer timings
Cookiebot CMP on a European endpoint. A consent tool.
Detected trackers
- Cookiebot (consent.cookiebot.eu) — CMP
Context
digst.dk is the official website of the Danish Agency for Digital Government (Digitaliseringsstyrelsen), the body responsible for the state’s digital infrastructure and, among other things, for oversight of tracking technologies and publication of cookie guidance. The data controller is the agency. Capture: 48 requests, 3 domains.
Declared versus Actual
Behaviorally, the site is clean. All resources — content, scripts, images, and fonts — load from the first-party domain digst.dk; fonts are hosted locally. The sole external domain is the Cookiebot consent management platform, loaded from the European endpoint consent.cookiebot.eu. Not a single analytics, advertising, or other third-party tracker fired across the entire session: no Google, no Google Fonts, no Google Maps, no reCAPTCHA, no Siteimprove, no Eulerian, no social media pixels, and no session recording. Inspection of the first-party domain’s paths revealed no hidden analytics or build endpoints. No cookies are set (Set-Cookie is zero).
The document provided is a general personal data processing policy; it does not contain a separate cookie declaration. Since no third-party trackers operate in the capture, no discrepancy between “declared” and “actual” substantively arises.
Timing Relative to Consent
Cookiebot loads at +111 ms as the consent mechanism. No third-party tracker fired prior to consent, and no cookies are set. A consent management platform is present and holds back non-essential services.
What Cannot Be Asserted from This Capture
The capture covers the home page and the pre-consent state. Any audience-measurement tools that may be configured within Cookiebot and activated only after consent are not observed in this session; their behavior after clicking “accept” is not tested here. Server-side processing is not visible in a browser-based capture.
Conclusion
The Danish Agency for Digital Government — a body responsible, among other things, for oversight of tracking technologies — demonstrates a configuration for its own site that is clean as captured: all resources and fonts are hosted locally, the sole external domain is the Cookiebot consent management platform on a European endpoint, third-party analytics and advertising are absent, no cookies are set, and no trackers fire prior to consent. No violations have been recorded in the capture.
2bcf8271944785db24a9fcbdfb134a1a702b08d35966728fd1e9e500ef7304e5