The Danish Medicines Agency — 47 requests, 4 domains. The jQuery and Font Awesome libraries are hosted on the first-party domain; a Cookiebot consent management platform is present and holds back trackers. There is no analytics, Google, reCAPTCHA, maps, or advertising services in the capture, and no cookies are set. The sole external non-first-party resource is a single jQuery UI CSS theme from code.jquery.com.
Timeline of the leak
Declared versus actual
Transfer timings
Cookiebot CMP — the consent tool.
A single jQuery UI CSS theme. Fastly CDN. Not a tracker.
Detected trackers
- Cookiebot (consent.cookiebot.com) — CMP
- code.jquery.com — external CDN (a single jQuery UI CSS theme)
Context
laegemiddelstyrelsen.dk is the official website of the Danish Medicines Agency (Lægemiddelstyrelsen), the body responsible for overseeing the circulation of medicines and medical devices. The data controller is the agency. A persondatapolitik document (approximately 10,500 characters) was provided. Capture: 47 requests, 4 domains, recorded in a clean browser.
Declared versus Actual
Behaviorally, the site is clean. The jQuery libraries and Font Awesome icon sets are hosted on the first-party domain laegemiddelstyrelsen.dk (Azure infrastructure), rather than being pulled from third-party CDNs. The Cookiebot consent management platform loads at the start of the session and serves as the consent mechanism. Not a single analytics or advertising tracker fired across the entire session: no Google, reCAPTCHA, Google Maps, Eulerian, or Siteimprove, and no social media pixels or session recording. No cookies are set (Set-Cookie is zero).
The sole external non-first-party resource besides Cookiebot is a single jQuery UI CSS styling theme, loaded from code.jquery.com (Fastly CDN). This is a static library resource, not a tracking tool: it sets no cookies and transmits no behavioral data, though its loading, like any external request, does disclose the visitor’s IP address to the CDN. Hosting this file locally would eliminate even this one remaining external contact; this is noted as an observation regarding completeness, not as a violation.
The document provided is a general personal data processing policy and does not contain a detailed cookie list; since no third-party trackers operate in the capture, no discrepancy between “declared” and “actual” substantively arises.
Timing Relative to Consent
Cookiebot loads at +92 ms; the CSS theme from code.jquery.com at +95 ms. No third-party tracker fired prior to consent, and no cookies are set. A consent management platform is present and holds back non-essential services.
What Cannot Be Asserted from This Capture
The capture covers the home page and the pre-consent state. Any audience-measurement tools that may be configured within Cookiebot and activated only after consent are not observed in this session; their behavior after clicking “accept” is not tested here. A detailed cookie declaration is absent from the document provided. Server-side processing is not visible in a browser-based capture.
Conclusion
The Danish Medicines Agency demonstrates a configuration that is clean as captured: libraries and fonts are hosted on the first-party domain, a Cookiebot consent management platform is present and holds back trackers, third-party analytics, Google, reCAPTCHA, and advertising services are absent, and no cookies are set. The sole external non-first-party resource is a single jQuery UI CSS theme from an external CDN, which constitutes a static library resource rather than a tracking tool. No violations have been recorded in the capture. For the sake of completeness, it would be worth hosting this CSS theme locally as well and publishing a detailed cookie declaration.
db309e4cffdde38261f153b658e87e4ca05aaeede44939ab463dc1414636096f