Amsterdam.nl is the official website of the City of Amsterdam. Homepage scan: 72 requests, 10 domains. The city handles its web statistics exemplarily: on its own Piwik PRO platform, with the visitor's IP not stored, per policy — such statistics are anonymized and do not require consent. The scan shows no third-party advertising, no Google Analytics, and no social media pixels. But before consent, the page initializes a third-party co-browsing tool: it registers a device identifier on the third-party service's servers and opens a persistent connection. The screen display itself only occurs when the user contacts support, but the connection and third-party identifier are created upon page load, before the user's choice.
Timeline of the leak
Declared versus actual
Detected trackers
- Anonymized city statistics (Piwik PRO)
- Cobrowse.io (co-browsing)
- Salesforce (support chat)
- Dynatrace (monitoring)
- Usabilla (surveys)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — third-party co-browsing tool establishes a connection and identifier before consentThe site has its own consent banner, and in this session consent was not given. The city runs its web statistics correctly: on its own Piwik PRO platform with a non-anonymized IP that, per policy, is not stored — such statistics are anonymized and exempt from consent. The problem lies elsewhere. Before consent, the page initializes a third-party co-browsing tool (screen-sharing for support): it registers a device identifier on the third-party service's servers and opens a persistent connection via web socket. In other words, a connection is established and an identifier created with a third party before the user has made any choice. The screen-sharing itself only happens when the user contacts support, but the preparatory connection and third-party identifier arise on a simple page load. Co-browsing is not a function necessary for the page to work, so establishing such a connection before consent requires a legal basis under Dutch cookie law.
Context
www.amsterdam.nl is the official website of the City of Amsterdam (Gemeente Amsterdam): municipal services, information for residents, requests to city departments. The data controller is the Municipality of Amsterdam. The site is informational and service-oriented.
Scan: 72 requests to 10 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The site has its own consent banner. The technical stack includes anonymized statistics, support tools, and monitoring.
Who receives the data
Observed here: Cobrowse.io (co-browsing), Salesforce (support chat).
The city runs its web statistics on its own Piwik PRO platform, with the visitor’s IP not stored, per policy — this is anonymized statistics. Support uses a chat built on the Salesforce platform and a third-party co-browsing tool that lets an agent see the user’s screen when they reach out. Additionally, Dynatrace performance monitoring and a survey service are running. The scan shows no third-party advertising, no Google Analytics, and no social media pixels.
Was there a consent banner
Yes, the site has its own consent banner, and in this session consent was not given. Not a single cookie was set during the session.
The web statistics are set up correctly: they are anonymized (IP not stored) and exempt from consent. The co-browsing tool, however, establishes a connection and an identifier with a third party before the user’s choice.
What fires before consent
Before consent, the following fire:
- anonymized city statistics (Piwik PRO) — exempt from consent;
- co-browsing initialization — device identifier registration and a persistent connection to a third-party service;
- performance monitoring and support chat (technical and functional).
The statistics are not a concern here — they are anonymized. The key issue is co-browsing: the screen display itself only occurs when the user contacts support, but the preparatory connection and third-party identifier arise on a simple page load. Co-browsing is not required for the page to function, so such a connection before consent requires a legal basis.
What works in the site’s favor
This is worth highlighting. The city runs its statistics anonymized, without storing IP addresses, and uses no Google Analytics, no social media pixels, and no advertising networks. The main risk — a scatter of advertising trackers — is entirely absent here. The support tools (chat, co-browsing) are functional, not advertising-related.
Conclusion
Amsterdam.nl is, on the whole, a restrained municipal site with one narrow issue. The web statistics are anonymized and don’t require consent, and there is no advertising or third-party analytics at all. But the third-party co-browsing tool registers a device identifier and opens a persistent connection to a third-party service upon page load — before the user has given consent, even though the screen display itself is only needed when the user contacts support. The key takeaway for the reader: even a tool that is functional in purpose must, if it establishes a connection and identifier with a third party, be initialized only after consent or only at the moment the user actually requests support. It would be enough to defer the co-browsing connection until the user reaches out — and the site would be clean.
ae68ef81ba5b1c50c487bfb9ea140a41fecfd07ae017526f3c35f5849f08e3d5Where to file: Dutch Data Protection Authority (AP) — autoriteitpersoonsgegevens.nl
To: Dutch Data Protection Authority (AP) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website amsterdam.nl. 2. Circumstances I visited the website amsterdam.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has its own consent banner, and in this session consent was not given. The city runs its web statistics correctly: on its own Piwik PRO platform with a non-anonymized IP that, per policy, is not stored — such statistics are anonymized and exempt from consent. The problem lies elsewhere. Before consent, the page initializes a third-party co-browsing tool (screen-sharing for support): it registers a device identifier on the third-party service's servers and opens a persistent connection via web socket. In other words, a connection is established and an identifier created with a third party before the user has made any choice. The screen-sharing itself only happens when the user contacts support, but the preparatory connection and third-party identifier arise on a simple page load. Co-browsing is not a function necessary for the page to work, so establishing such a connection before consent requires a legal basis under Dutch cookie law. Full technical documentation is published at: https://gdpru.eu/en/audits/nl-amsterdam-nl/ 3. Provisions violated Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — third-party co-browsing tool establishes a connection and identifier before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]