Technical audit · 2026-05-31

digst.dk

Danish Agency for Digital Government

The Danish Agency for Digital Government — 48 requests, 3 domains. The sole external domain is the Cookiebot consent management platform, on a European endpoint. There is no third-party analytics, Google, maps, advertising, or session recording in the capture; fonts are hosted locally, and no cookies are set. No violations have been recorded.

Timeline of the leak

+0 ms · portal load
Content, scripts, and fonts — served from the first-party domain digst.dk.
+111 ms · consent management platform
consent.cookiebot.eu/uc.js — Cookiebot loads on a European endpoint (.eu).
no third-party trackers
Analytics, Google, maps, advertising pixels, and session recording are absent from the capture.

Declared versus actual

A persondatapolitik document (general data processing policy) was provided — заявлен
+ Cookiebot — the consent tool, not named in the document provided — не заявлен

Transfer timings

+111 ms consent.cookiebot.eu

Cookiebot CMP on a European endpoint. A consent tool.

Detected trackers

Context

digst.dk is the official website of the Danish Agency for Digital Government (Digitaliseringsstyrelsen), the body responsible for the state’s digital infrastructure and, among other things, for oversight of tracking technologies and publication of cookie guidance. The data controller is the agency. Capture: 48 requests, 3 domains.

Declared versus Actual

Behaviorally, the site is clean. All resources — content, scripts, images, and fonts — load from the first-party domain digst.dk; fonts are hosted locally. The sole external domain is the Cookiebot consent management platform, loaded from the European endpoint consent.cookiebot.eu. Not a single analytics, advertising, or other third-party tracker fired across the entire session: no Google, no Google Fonts, no Google Maps, no reCAPTCHA, no Siteimprove, no Eulerian, no social media pixels, and no session recording. Inspection of the first-party domain’s paths revealed no hidden analytics or build endpoints. No cookies are set (Set-Cookie is zero).

The document provided is a general personal data processing policy; it does not contain a separate cookie declaration. Since no third-party trackers operate in the capture, no discrepancy between “declared” and “actual” substantively arises.

Cookiebot loads at +111 ms as the consent mechanism. No third-party tracker fired prior to consent, and no cookies are set. A consent management platform is present and holds back non-essential services.

What Cannot Be Asserted from This Capture

The capture covers the home page and the pre-consent state. Any audience-measurement tools that may be configured within Cookiebot and activated only after consent are not observed in this session; their behavior after clicking “accept” is not tested here. Server-side processing is not visible in a browser-based capture.

Conclusion

The Danish Agency for Digital Government — a body responsible, among other things, for oversight of tracking technologies — demonstrates a configuration for its own site that is clean as captured: all resources and fonts are hosted locally, the sole external domain is the Cookiebot consent management platform on a European endpoint, third-party analytics and advertising are absent, no cookies are set, and no trackers fire prior to consent. No violations have been recorded in the capture.

Evidence
Original (audit)
HAR file: dk/digst-dk-2026-05-31.har
SHA-256: 2bcf8271944785db24a9fcbdfb134a1a702b08d35966728fd1e9e500ef7304e5
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.