Technical audit · 2026-06-15

www.chd.lu

Chamber of Deputies of Luxembourg

The site of the Luxembourg parliament — 48 requests, five hosts. The only external recipient is the TWIPLA analytics platform, but it operates in full: a persistent visitor identifier, a polls service, and a persistent WebSocket connection opened at the 2711th millisecond. No consent mechanism was found on the site. The data protection notice describes collection only via forms and petitions, and says nothing about processing during ordinary browsing — not a word about cookies, not a word about analytics.

Timeline of the leak

+0…+441 ms · entry
Four redirects: from an unsecured connection to a secured one, then to a www-prefixed address. The document is served at +811 ms, running Drupal with the 'chd' theme.
+924…+1215 ms · own resources
Styles, scripts, news images, and fonts — all from www.chd.lu. No third-party fonts or mapping libraries. The browser sent a DNT: 1 header.
+1726 ms · analytics platform
app-worker.visitor-analytics.io/main.js with a site identifier in the address. The initiator is the site theme's script, loaded from the page footer.
+1996 and +2001 ms · site settings
visits.visitor-analytics.io/api/standalone/websites/…/settings — monitoring configuration for this site, with a preliminary cross-origin permission request.
+2363 ms · log transmission
POST to visits.visitor-analytics.io/standalone/worker-log, response 201 — a record was created on the platform's side.
+2523 ms · second script
app-worker.visitor-analytics.io/ssr-worker.js.
+2527 ms · visitor-identifier transmission
lb-api.visitor-analytics.io/api/v2/websites/…/polls/targeting — a poll-targeting service. The address of the page being viewed and a persistent visitor identifier are transmitted in plain text in the request address.
+2711 ms · persistent connection
wss://visits.visitor-analytics.io/websocket, response code 101 — the protocol is switched, the channel is established and remains open.

Declared versus actual

Data controller — Chamber of Deputies, Rue du Marché-aux-Herbes 23, Luxembourg — заявлен
Data Protection Officer — external, provided by Deloitte Tax & Consulting — заявлен
Data is collected via the contact form, subscription to materials and transcripts, email inquiries, petitions — заявлен
Data categories: first name, last name, postal address, phone, email address, password; for a public petition, additionally place and date of birth — заявлен
Legal bases for processing — consent or performance of a task in the public interest — заявлен
Recipients: mailing contractors, other public administration bodies, the State Information Technology Centre — for checking a national-register entry for a public petition — заявлен
No transfers of data outside the European Union occur within the listed processing activities — заявлен
Channel encryption is used to protect data collected via the site — заявлен
+ TWIPLA / Visitor Analytics — the analytics platform, the only external recipient in the scan — не заявлен
+ A persistent visitor identifier, transmitted in plain text in the request address — не заявлен
+ A persistent WebSocket connection — не заявлен
+ A poll-targeting service — не заявлен
+ The very fact of data processing while browsing the site — not described in the document — не заявлен

Transfer timings

+1726 ms app-worker.visitor-analytics.io

main.js with a site identifier.

+1996 ms visits.visitor-analytics.io

Monitoring settings for the site.

+2363 ms visits.visitor-analytics.io

POST worker-log, response 201.

+2523 ms app-worker.visitor-analytics.io

ssr-worker.js.

+2527 ms lb-api.visitor-analytics.io

Page address and a persistent visitor identifier in plain text in the request address.

+2711 ms visits.visitor-analytics.io

WebSocket connection, code 101.

Detected trackers

Indicators of GDPR non-compliance

Context

chd.lu is the website of the Chamber of Deputies of Luxembourg, the unicameral parliament of the Grand Duchy. It publishes parliamentary files, deputies’ questions, plenary-session transcripts, petition materials, and educational sections. The data controller is the Chamber itself, Rue du Marché-aux-Herbes 23, Luxembourg; the Data Protection Officer role is performed by an external contractor from Deloitte Tax & Consulting. The platform is Drupal with a custom theme.

Scan: 48 requests, five hosts. Thirty-nine requests to the site’s own domains, nine to the analytics platform. Capture duration: 2.7 seconds; full page load completed at 2003 ms. Captured on June 15, 2026, on the French-language homepage.

A single document — a personal data protection notice — describes the processing.

Who receives data directly

TWIPLA (Visitor Analytics).

Declared versus actual

The discrepancy here isn’t in the details — it’s in the very subject matter of the description.

The document doesn’t acknowledge that the site has visitors. The notice is built around situations where a person actively contacts the parliament: fills out a contact form, subscribes to parliamentary files or transcripts, writes an email, files or signs a petition. For each situation, the categories of data are honestly listed — down to place and date of birth for a public petition — with legal bases, retention periods, and recipients named, including the State Information Technology Centre for cross-checking against the national register.

The document says nothing about processing that occurs simply by opening the page. The word cookie doesn’t appear in it once. Nor do the words “analytics,” “visitor statistics,” “audience measurement.” The section on what data is collected opens with the contact form and subscriptions, exhaustively delineating collection and leaving no room for observation of the reader.

Yet observation does occur, and in a fully deployed form. From the 1726th millisecond, the TWIPLA platform deploys, also known under its former name Visitor Analytics. The sequence is: a script carrying a site identifier, a request for the site’s monitoring settings, a log transmission via POST with a 201 response — meaning a record on the platform’s side was created — a second script, a request to the poll-targeting service, and establishment of a persistent connection.

Two elements deserve particular attention.

The first is the request to the polls service at +2527 ms. The address of this request carries, in plain text, as ordinary parameters, the address of the page being viewed and a persistent visitor identifier. The identifier is a fixed-length base64-encoded string, used to recognize the same visitor on subsequent visits. It is not reproduced in full in this analysis.

The second is the connection at +2711 ms. The request goes out over the WebSocket protocol and receives a code of 101, meaning a protocol switch: the channel is established and remains open as long as the page is open. This is a fundamentally different mode from a one-off event transmission: over such a channel, data can be transmitted continuously, in both directions, without separate visible requests.

The platform’s second script is named ssr-worker.js. TWIPLA’s feature set includes session recording, and the abbreviation in the file name is consistent with that purpose; however, this cannot be stated as fact from a browser-based scan, where response bodies are not preserved — only the file name and the presence of a persistent channel are recorded.

There is no consent mechanism. Across all 48 requests, there is not a single request to a consent-management platform and not a single script bearing the corresponding hallmarks. Names of known platforms and general patterns in addresses were checked — zero matches.

What is worth noting in the site’s favor. There is only one external recipient in total. Fonts, images, theme scripts, and internal requests go exclusively to the site’s own domains — no mapping libraries, no third-party icon sets, no embedded players. A set of protective headers is present: strict transport security, a restriction on being embedded in a frame from an external source, a restriction on content-type sniffing, a restrictive referrer policy, and a separate header disabling the browser’s cohort-based advertising technology. The Content-Security-Policy header, however, is not set.

Separately, regarding third countries. The notice explicitly states that no transfers outside the European Union occur within the listed processing activities. TWIPLA is a Berlin-based company, and by its own statements, processing takes place within the Union; this is not verifiable by a browser-based scan. This observation is not recorded as a cross-border-transfer violation — the caveat “within the listed processing activities” simply does not apply to web analytics, since it is not part of that list.

Proven: there is no consent mechanism in the capture. Not a single request to a consent-management platform, not a single script bearing the corresponding hallmarks, across all 48 requests.

Proven: analytics ran in full and transmitted data. The log transmission received a 201 response, meaning a record was created on the platform’s side. The request to the polls service carries the visitor identifier and page address. A persistent connection was established with code 101.

Proven: loading does not depend on the user’s choice. The initiator of the platform’s script is recorded as the site’s own theme script, loaded from the page footer — meaning the call is built into the site’s code and executes as it runs. There is no condition tied to the user’s choice preceding it.

Not proven and not required: the absence of a text notice in the markup. Response bodies have been stripped from the published file, so the presence of an informational notice in the HTML cannot be checked from it. The conclusion is not built on this, but on the fact that analytics launches from the theme’s code and does not depend on any notice, and that no platform capable of managing it exists on the page.

Separately: the browser sent a DNT: 1 header during the capture. This had no effect on the composition or volume of the transmissions.

Limits of observation

The scan covers a single page — the French-language homepage — in a single state. The petitions sections, where the documents indicate name, date, and place of birth are collected, were not part of this scan, and this analysis makes no claims about them.

The observation records browser behavior, not the internal workings of the services: processing on the platform’s side, its contractual relationship with the parliament, the data it retains, and the geography of processing are not verified by a browser-based scan. Legal assessment falls to the competent authority — the Commission nationale pour la protection des données.

The file is published stripped of personal data: cookie headers, response bodies, the tab header, and the body of the transmitted log have been removed. The persistent visitor identifier is not reproduced in full in this analysis. The set of cookies on a device cannot be reconstructed from the published file, and no conclusion in this analysis relies on it: all statements rest on request addresses, their order, response codes, and recorded initiators.

Content transmitted over the persistent connection is not preserved in this kind of browser capture — only the fact of the channel’s establishment and the response code are recorded. The purpose of the ssr-worker.js script is inferred from its file name and the platform’s known capabilities; it cannot be verified from the scan.

Identification of the service relies on the visitor-analytics.io domains, the address pattern carrying a site identifier, and the response headers of the platform’s hosts.

Conclusion

The Luxembourg Chamber of Deputies’ data protection notice is written carefully and in detail — for those who write letters to the parliament, subscribe to transcripts, or file petitions. For those who simply open the site to read the news, there is not a single line: the word cookie does not appear once, analytics is not mentioned, and processing during browsing is not described as a phenomenon at all.

Meanwhile, an external analytics platform deploys on opening the homepage: it requests monitoring settings, transmits a log, carries a persistent visitor identifier along with the address of the page being viewed in the request address, and opens a persistent connection that stays held open for as long as the page remains open. No consent mechanism was found on the site — no banner, no platform, no stored choice.

Otherwise, the site is set up in a restrained manner: a single external recipient, its own fonts and images, a reasonable set of protective headers. This makes the gap between that restraint and the document’s complete silence about the one instance of monitoring that is nonetheless taking place all the more notable.

Remediation: introduce a consent mechanism that controls the loading of the analytics platform, and do not launch it from the theme’s code before the visitor’s choice; supplement the notice with a section on processing during site visits — naming the platform, the fields transmitted (including the visitor identifier), the purposes, the retention period, and the legal basis; describe the purpose of the persistent connection and the polls service.

Evidence
Original (audit)
HAR file: lu/chd-lu-2026-06-15.har
SHA-256: 06a00fceddcbe439097f2098bc5af64fdb52d611949b983be467a921f9555728
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Commission nationale pour la protection des données (CNPD)cnpd.lu

To: Commission nationale pour la protection des données (CNPD)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website www.chd.lu.

2. Circumstances
I visited the website www.chd.lu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) No consent-management mechanism was found on the site: across all 48 requests, there is not a single request to a consent platform and not a single script bearing the hallmarks of a banner. The TWIPLA analytics platform, meanwhile, runs in full: a script at +1726 ms, a request for site settings at +1996 ms, a log transmission at +2363 ms, a second script at +2523 ms, a request to the polls service at +2527 ms, and finally, establishment of a persistent WebSocket connection at +2711 ms with a 101 status code — meaning the channel is opened and held open.

2) The data protection notice names no web-data recipients at all. Its list of recipients consists of report-mailing contractors, other Luxembourg public administration bodies, and the State Information Technology Centre — the latter only in connection with checking a national-register entry when a public petition is filed. The analytics platform, to which every homepage visitor's data goes out in the scan, is absent from the document.

3) The notice describes personal-data collection with an exhaustive list: via the contact form, when subscribing to Chamber materials and transcripts, when writing by email, and when filing or signing petitions. The document says nothing about processing that occurs simply by browsing the site: the words cookie, analytics, and visitor statistics do not appear in it once. Meanwhile, on opening the homepage, a persistent visitor identifier is transmitted to an external platform along with the address of the page being viewed.

Full technical documentation is published at: https://gdpru.eu/en/audits/lu-chd-lu/

3. Provisions violated
ePrivacy — Loi du 30 mai 2005, Art. 4 (in conjunction with GDPR Art. 6(1)(a)); GDPR Art. 13(1)(e) — disclosure of recipients; GDPR Art. 5(1)(a) and Art. 13(1)(c) — transparency and purposes of processing

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]