Anp.nl is the website of the Dutch national news agency. Homepage scan: 51 requests, 16 domains. The site has its own consent banner, but in practice it does not hold trackers back. Before the user's choice, the Facebook pixel sends a pageview event to Meta, Google Analytics runs in two generations at once — legacy and current, a third-party identification and attribution service contacts its own servers, and a video platform collects player statistics. Consent mode for Google is not configured. In other words, the banner is present, but the advertising pixel, analytics, and identification fire before the choice, and three of these recipients aren't even named in the policy.
Timeline of the leak
Declared versus actual
Detected trackers
- Facebook / Meta Pixel
- Google Analytics (Universal + GA4)
- Bending Spoons (identification/attribution)
- Vimeo (player analytics)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — advertising pixel and analytics fire before consent despite the bannerThe site has its own consent banner, but in practice it does not hold trackers back. A whole set of services fires before any user choice. The Facebook pixel sends a pageview event to Meta. Google Analytics runs in two generations at once — the legacy version and the current one — and sends its own requests. A third-party identification and attribution service sends a request to its own servers. The video platform collects player statistics. Consent mode for Google Analytics is not configured — requests go out without a consent signal. In other words, the banner exists, but the advertising pixel, analytics, and identification fire before the user's choice, as if it weren't there at all. All of these services are non-technical purposes requiring consent.
- Art. 13 GDPR — the Facebook pixel, video-platform analytics, and third-party identification are not disclosed in the policyThe policy names only Google Analytics. However, the Facebook pixel transmitting the visit to Meta, the video-platform analytics, and the third-party identification and attribution service are not mentioned in the policy. In other words, three data recipients, including a social-network advertising pixel, are undisclosed in the listing.
Context
www.anp.nl is the website of the Dutch national news agency (Algemeen Nederlands Persbureau): a news feed, photo bank, and services for editorial teams. The data controller is ANP. The site is informational, with an extension into media services.
Scan: 51 requests to 16 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The site has its own consent banner. For a news agency, the technical stack is heavily loaded with trackers.
Who receives the data
Observed here: Meta, Google, Bending Spoons, Vimeo.
Meta receives a pageview event via the Facebook pixel. Google is present with analytics from two generations at once. A third-party identification and attribution service sends a request to its own servers. A video platform collects player statistics. In other words, the fact of the visit goes out to several third-party services at once.
Was there a consent banner
Yes, the site has its own consent banner. But in practice it does not hold trackers back: the advertising pixel, analytics, and identification fire before the user’s choice. Consent mode for Google Analytics, moreover, is not configured — its requests go out with no consent signal at all.
In other words, the consent mechanism is present but doesn’t do its job.
What fires before consent
Before the user’s choice, the following fire:
- the Facebook pixel — a pageview event to Meta;
- Google Analytics — two generations, including the legacy one;
- a third-party identification and attribution service;
- video-player analytics.
All of these services are non-technical purposes requiring consent. It’s worth separately noting that one generation of Google Analytics has long been discontinued, yet continues running on this site.
Undisclosed recipients
A separate point. The policy names only Google Analytics. The Facebook pixel transmitting the visit to Meta, the video-platform analytics, and the third-party identification and attribution service are not mentioned in the policy. In other words, three data recipients, including a social-network advertising pixel, are undisclosed in the listing.
Conclusion
Anp.nl is a case where the consent mechanism exists but doesn’t work. The news agency’s site has a banner, yet the Facebook pixel, two generations of Google Analytics, third-party identification, and video-player analytics all fire before the user’s choice, and consent mode for Google is not configured. On top of that, three of these recipients aren’t named in the policy. The key takeaway for the reader: having a banner means nothing by itself if it doesn’t actually hold trackers back until consent, and if the recipient list is missing half of the services actually in use. It would be enough to configure blocking and consent mode so that the pixel and analytics wait for the user’s choice, to complete the recipient list, and to remove the legacy analytics.
d17b505addf51e1dfab21fd57b8fb7e16576461b43cd74ccc9904da1eaa0b4c8Where to file: Dutch Data Protection Authority (AP) — autoriteitpersoonsgegevens.nl
To: Dutch Data Protection Authority (AP) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website anp.nl. 2. Circumstances I visited the website anp.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has its own consent banner, but in practice it does not hold trackers back. A whole set of services fires before any user choice. The Facebook pixel sends a pageview event to Meta. Google Analytics runs in two generations at once — the legacy version and the current one — and sends its own requests. A third-party identification and attribution service sends a request to its own servers. The video platform collects player statistics. Consent mode for Google Analytics is not configured — requests go out without a consent signal. In other words, the banner exists, but the advertising pixel, analytics, and identification fire before the user's choice, as if it weren't there at all. All of these services are non-technical purposes requiring consent. 2) The policy names only Google Analytics. However, the Facebook pixel transmitting the visit to Meta, the video-platform analytics, and the third-party identification and attribution service are not mentioned in the policy. In other words, three data recipients, including a social-network advertising pixel, are undisclosed in the listing. Full technical documentation is published at: https://gdpru.eu/en/audits/nl-anp-nl/ 3. Provisions violated Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — advertising pixel and analytics fire before consent despite the banner; Art. 13 GDPR — the Facebook pixel, video-platform analytics, and third-party identification are not disclosed in the policy 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]