Policy changed — see what exactly · 2026-07-11 →
Autotrack.nl is a major Dutch car-classifieds platform (part of the AutoScout24 group, with ad monetization handled via DPG Media). Homepage scan: 89 requests, 15 domains (requests to edge.microsoft.com among these are Edge's built-in page-translation feature, not site tracking). A consent mechanism is present — AutoScout24 Privacy Manager, with consent mode initialized as 'denied by default.' This works in the site's favor. But before any consent, DPG Media's advertising/analytics layer fires: before the CMP even loads, the advertising module posts data to its own endpoint, the programmatic stack (Xandr, prebid header bidding) then spins up along with a request to the Opt Out Advertising ad network, and Snowplow analytics sends a pageview to a third-party collector. This layer is not named in the policy the site presents.
Timeline of the leak
Declared versus actual
Detected trackers
- DPG Snowplow analytics (pageview before consent)
- DPG programmatic advertising: Xandr + prebid header bidding (before consent)
- Opt Out Advertising — request to ad network (before consent)
- DPG advertising module (POST before CMP loads)
- Microsoft UET (Consent Mode 'default' — denied)
- New Relic (performance monitoring)
- AutoScout24 Privacy Manager (consent mechanism)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — the programmatic advertising stack and third-party analytics fire before consentThe site has a consent mechanism (AutoScout24 Privacy Manager), and in many respects it is set up correctly: consent mode initializes in a 'denied by default' state (Consent Mode default), which keeps the Google and Microsoft (UET) tags in cookieless mode. This works in the site's favor. However, an entire advertising/analytics layer manages to fire before any consent is given. Even before the CMP itself loads, at 1762 ms, the DPG Media advertising module sends a POST request to its own endpoint. The DPG programmatic stack (Xandr and prebid header bidding) then spins up, and a request goes out to the Opt Out Advertising ad network (an ad-serving request). In parallel, Snowplow analytics sends a pageview to a third-party DPG collector. All of these requests transmit the IP address and visit context — i.e., personal data — to third parties for advertising and analytics purposes, and this happens before the user's choice. Compounding the picture, this entire layer (DPG Media, Snowplow, Xandr, prebid, Opt Out Advertising) is not named at all in the privacy policy the site presents — a group-wide AutoScout24 statement. The fact that consent mode defaults to 'denied' mitigates the assessment somewhat, but does not eliminate the fact that analytics pageviews and advertising requests to third parties go out before consent.
Context
www.autotrack.nl is one of the major Dutch car-sales classifieds platforms. According to the policy the site presents, the data controller is AutoScout24 Nederland B.V. (part of the AutoScout24 group); ad monetization on the platform is handled via DPG Media. The site is commercial, with a listings search and an advertising-based model.
Scan: 89 requests to 15 domains, homepage, captured in a clean browser without a VPN or ad blocker. Worth noting separately: the requests to edge.microsoft.com in this scan are Edge’s built-in page-translation feature, not site tracking; the cdn.amv.nl domain serves images (content). The site has a consent mechanism — AutoScout24 Privacy Manager.
Who receives the data
Directly, before consent: DPG Media (advertising and Snowplow analytics), Opt Out Advertising (ad network).
The DPG advertising module sends a POST request to its own endpoint even before the CMP loads. The DPG programmatic stack (Xandr, prebid header bidding) then spins up, and an ad-serving request goes out to the Opt Out Advertising network. Snowplow analytics, served from a DPG domain, sends a pageview to a third-party collector. All of these requests transmit the IP address and visit context to third parties for advertising and analytics purposes.
On the functional side, there’s New Relic performance monitoring (error and speed tracking). The platform itself runs its own tag telemetry (AutoScout24 tag-monitor), which in particular shows that consent mode is initialized as “denied by default.”
Was there a consent banner
Yes, a consent mechanism is present — AutoScout24 Privacy Manager. And a number of things are done correctly: consent mode initializes in a “denied by default” state (Consent Mode default), and the Google and Microsoft (UET) tags are held in cookieless mode.
The key issue: part of the advertising layer fired before the CMP itself even loaded, and analytics pageviews and advertising requests went out to third parties before consent.
What fires before consent
Before the user’s choice, the following fire:
- the DPG advertising module — a POST request even before the CMP loads;
- the DPG programmatic stack — Xandr and prebid header bidding;
- the Opt Out Advertising network — an ad-serving request;
- Snowplow analytics — a pageview sent to a third-party DPG collector;
- New Relic performance monitoring — technical.
Performance monitoring is not a concern: it’s a technical purpose, and the policy describes it as processing under legitimate interest. The concern is the ad auction and Snowplow: these are advertising and analytics purposes, and they contact third parties before consent.
Why “consent mode denied by default” is not a free pass
This point matters for understanding the issue. “Denied by default” consent mode is indeed a genuine strength: it keeps the Google and Microsoft tags in a restricted mode. But legally, the issue is broader. The IP address and visit context transmitted to the ad auction and the third-party analytics collector are personal data, and processing them for advertising and analytics before consent requires a legal basis that is absent here. The fact that the DPG advertising module contacts its own endpoint even before the CMP itself loads shows that this layer is not tied to the user’s decision.
Conclusion
Autotrack.nl is a case where discipline around consent mode coexists with an advertising layer that fires too early. Much works in the site’s favor: a CMP is present, consent mode initializes as “denied,” the Google and Microsoft tags are held in cookieless mode, and performance monitoring is technical. But DPG’s programmatic advertising (Xandr, prebid, the request to Opt Out Advertising) and the Snowplow pageview go out to third parties before consent, and the DPG advertising module contacts its own endpoint even before the CMP loads. On top of that, this entire layer is not named in the policy the site presents — the group-wide AutoScout24 statement. The key takeaway for the reader: it would be enough to hold the ad auction and Snowplow analytics pending consent — just as has already been done for the Google and Microsoft tags — and to tie the advertising module to the user’s decision, in order to make the configuration clean.
52dc18efed1bd371069cd89753e8e33bd05d7034c3111a55d2cda2abd035683eWhere to file: Dutch Data Protection Authority (AP) — autoriteitpersoonsgegevens.nl
To: Dutch Data Protection Authority (AP) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website autotrack.nl. 2. Circumstances I visited the website autotrack.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 23 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has a consent mechanism (AutoScout24 Privacy Manager), and in many respects it is set up correctly: consent mode initializes in a 'denied by default' state (Consent Mode default), which keeps the Google and Microsoft (UET) tags in cookieless mode. This works in the site's favor. However, an entire advertising/analytics layer manages to fire before any consent is given. Even before the CMP itself loads, at 1762 ms, the DPG Media advertising module sends a POST request to its own endpoint. The DPG programmatic stack (Xandr and prebid header bidding) then spins up, and a request goes out to the Opt Out Advertising ad network (an ad-serving request). In parallel, Snowplow analytics sends a pageview to a third-party DPG collector. All of these requests transmit the IP address and visit context — i.e., personal data — to third parties for advertising and analytics purposes, and this happens before the user's choice. Compounding the picture, this entire layer (DPG Media, Snowplow, Xandr, prebid, Opt Out Advertising) is not named at all in the privacy policy the site presents — a group-wide AutoScout24 statement. The fact that consent mode defaults to 'denied' mitigates the assessment somewhat, but does not eliminate the fact that analytics pageviews and advertising requests to third parties go out before consent. Full technical documentation is published at: https://gdpru.eu/en/audits/nl-autotrack-nl/ 3. Provisions violated Art. 6(1)(a) GDPR — the programmatic advertising stack and third-party analytics fire before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]