Technical audit · 2026-06-16

anp.nl

Website of the Dutch national news agency

Anp.nl is the website of the Dutch national news agency. Homepage scan: 51 requests, 16 domains. The site has its own consent banner, but in practice it does not hold trackers back. Before the user's choice, the Facebook pixel sends a pageview event to Meta, Google Analytics runs in two generations at once — legacy and current, a third-party identification and attribution service contacts its own servers, and a video platform collects player statistics. Consent mode for Google is not configured. In other words, the banner is present, but the advertising pixel, analytics, and identification fire before the choice, and three of these recipients aren't even named in the policy.

Timeline of the leak

2098 ms · own consent banner
The site's own consent banner loads. By design, it should hold non-technical services back until the user makes a choice.
2126 ms · tag manager
A tag manager loads, through which analytics and pixels are deployed.
2663 ms · Facebook pixel library
The Facebook pixel library loads. The advertising service connects before consent.
2691 ms · legacy Google Analytics
The legacy generation of Google Analytics loads and sends a request. This version of analytics has long been discontinued, but continues to run here.
3434 ms · video player statistics
The video platform collects player statistics. Before consent.
3686 ms · current Google Analytics
The current generation of Google Analytics sends a request without a consent signal — consent mode is not configured.
3708 ms · third-party identification
A third-party identification and attribution service sends a request to its own servers. Before consent.
4559 ms · pageview event to Meta
The Facebook pixel sends a pageview event to Meta. Meta receives the fact of the visit before consent.
banner present, but not blocking
The site's own consent banner is present, but the advertising pixel, analytics, and identification had already fired before the user's choice. No cookies were set via headers during the session.

Declared versus actual

Google Analytics — заявлен
+ Facebook Pixel — не заявлен
+ Vimeo (analytics) — не заявлен
+ Bending Spoons — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.anp.nl is the website of the Dutch national news agency (Algemeen Nederlands Persbureau): a news feed, photo bank, and services for editorial teams. The data controller is ANP. The site is informational, with an extension into media services.

Scan: 51 requests to 16 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The site has its own consent banner. For a news agency, the technical stack is heavily loaded with trackers.

Who receives the data

Observed here: Meta, Google, Bending Spoons, Vimeo.

Meta receives a pageview event via the Facebook pixel. Google is present with analytics from two generations at once. A third-party identification and attribution service sends a request to its own servers. A video platform collects player statistics. In other words, the fact of the visit goes out to several third-party services at once.

Yes, the site has its own consent banner. But in practice it does not hold trackers back: the advertising pixel, analytics, and identification fire before the user’s choice. Consent mode for Google Analytics, moreover, is not configured — its requests go out with no consent signal at all.

In other words, the consent mechanism is present but doesn’t do its job.

Before the user’s choice, the following fire:

  • the Facebook pixel — a pageview event to Meta;
  • Google Analytics — two generations, including the legacy one;
  • a third-party identification and attribution service;
  • video-player analytics.

All of these services are non-technical purposes requiring consent. It’s worth separately noting that one generation of Google Analytics has long been discontinued, yet continues running on this site.

Undisclosed recipients

A separate point. The policy names only Google Analytics. The Facebook pixel transmitting the visit to Meta, the video-platform analytics, and the third-party identification and attribution service are not mentioned in the policy. In other words, three data recipients, including a social-network advertising pixel, are undisclosed in the listing.

Conclusion

Anp.nl is a case where the consent mechanism exists but doesn’t work. The news agency’s site has a banner, yet the Facebook pixel, two generations of Google Analytics, third-party identification, and video-player analytics all fire before the user’s choice, and consent mode for Google is not configured. On top of that, three of these recipients aren’t named in the policy. The key takeaway for the reader: having a banner means nothing by itself if it doesn’t actually hold trackers back until consent, and if the recipient list is missing half of the services actually in use. It would be enough to configure blocking and consent mode so that the pixel and analytics wait for the user’s choice, to complete the recipient list, and to remove the legacy analytics.

Evidence
Original (audit)
HAR file: nl/anp-nl-2026-06-16.har
SHA-256: d17b505addf51e1dfab21fd57b8fb7e16576461b43cd74ccc9904da1eaa0b4c8
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website anp.nl.

2. Circumstances
I visited the website anp.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has its own consent banner, but in practice it does not hold trackers back. A whole set of services fires before any user choice. The Facebook pixel sends a pageview event to Meta. Google Analytics runs in two generations at once — the legacy version and the current one — and sends its own requests. A third-party identification and attribution service sends a request to its own servers. The video platform collects player statistics. Consent mode for Google Analytics is not configured — requests go out without a consent signal. In other words, the banner exists, but the advertising pixel, analytics, and identification fire before the user's choice, as if it weren't there at all. All of these services are non-technical purposes requiring consent.

2) The policy names only Google Analytics. However, the Facebook pixel transmitting the visit to Meta, the video-platform analytics, and the third-party identification and attribution service are not mentioned in the policy. In other words, three data recipients, including a social-network advertising pixel, are undisclosed in the listing.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-anp-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — advertising pixel and analytics fire before consent despite the banner; Art. 13 GDPR — the Facebook pixel, video-platform analytics, and third-party identification are not disclosed in the policy

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]