Technical audit · 2026-06-16

acm.nl

Website of the Dutch Authority for Consumers and Markets

Acm.nl is the website of the Authority for Consumers and Markets of the Netherlands (the competition and consumer protection regulator). Homepage scan: 37 requests total, 3 domains. An exemplary restrained configuration for a regulator. The only external contact is Siteimprove analytics, a private web-statistics package configured anonymously: per policy, only the regulator itself has access to the data, measures are in place to limit identifiability, and there is no cross-site tracking. The scan shows no Google Analytics, no Facebook, no advertising, no session recording, and no third-party trackers. Not a single cookie was set during the session. No violations were recorded.

Timeline of the leak

725 ms · Siteimprove private analytics
Siteimprove analytics loads — a private web-statistics package. Per policy, only the regulator has access to the collected data, and identifiability is limited. No cookie is set in the process.
analytics is anonymized, no cookie set
The analytics is configured anonymously and does not perform cross-site tracking, so it is exempt from consent requirements. Not a single cookie was set during the session. No other external services appear in the scan.

Declared versus actual

Siteimprove (analytics) — заявлен

Detected trackers

Context

www.acm.nl is the website of the Authority for Consumers and Markets (Autoriteit Consument & Markt): the regulator for competition, consumer protection, and regulated markets. The data controller is ACM, a government body. The site is informational in nature.

Scan: 37 requests to 3 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The technical stack is minimal.

Who receives the data

There are effectively no third-party recipients.

The only external service is Siteimprove analytics, and it is configured privately: per policy, only the regulator itself has access to the collected data, measures are in place to limit identifiability, and there is no cross-site tracking. The scan shows no Google Analytics, no advertising networks, no social media pixels, and no session recording.

A full consent banner is not required here: the only analytics tool is anonymized, does not set tracking cookies, and does not follow the user across sites. Not a single cookie was set during the entire session. The policy explicitly states that the data is accessible only to the regulator and that measures have been taken to limit identifiability.

Only private, anonymized analytics. Before any user interaction, a single external service runs — Siteimprove, in anonymized mode and without tracking cookies. The scan contains no Google analytics, no advertising domains, no social plugins, and no session recording.

Conclusion

Acm.nl is an example of a restrained configuration for a government regulator. The only external service is Siteimprove private analytics, configured anonymously: access limited to the regulator, identifiability restricted, no cross-site tracking. There is no third-party advertising, no Google analytics, no social media pixels, and no session recording whatsoever. The key takeaway for the reader: a regulator can manage perfectly well with private, anonymized statistics alone, and here that is achieved without a single third-party tracker, with the policy confirming both the anonymization and the restricted access to the data. No violations were recorded.

Evidence
Original (audit)
HAR file: nl/acm-nl-2026-06-16.har
SHA-256: 78d24af51bb4994ecccb45cc649a476bf5cf9daffc57116dab647ad128b3266b
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.