Technical audit · 2026-06-16

belastingdienst.nl

Website of the Dutch Tax and Customs Administration

Belastingdienst.nl is the website of the Dutch Tax and Customs Administration. Homepage scan: 62 requests, 4 domains. The configuration is exemplary, and particularly telling for a financial agency. In a clean session without consent, a single external service fired — ReadSpeaker, a page text-to-speech tool for accessibility. No analytics fired at all: no government statistics, no Google, no Facebook, no advertising, no session recording. Not a single cookie was set during the session. The policy mentions statistics, but in the no-consent scan it correctly does not launch — meaning it is held pending consent. No violations were recorded.

Timeline of the leak

1174 ms · site's own app banner
The site's own mobile-app banner loads. This is a technical interface element, not a consent collection mechanism or tracking.
4195 ms · accessibility text-to-speech
The ReadSpeaker page text-to-speech tool loads. Per policy, its associated functional cookie only activates speech synthesis when the 'read aloud' button is pressed.
consent-gated analytics did not fire, no cookie set
In a clean session without consent, analytics does not launch — only the functional text-to-speech tool fired. Not a single cookie was set during the session.

Declared versus actual

ReadSpeaker (text-to-speech, functional) — заявлен

Detected trackers

Context

www.belastingdienst.nl is the website of the Dutch Tax and Customs Administration (Belastingdienst): information on taxes, duties, tax returns, and requests. The data controller is the tax authority. The site is informational, with an extension into personal account services.

Scan: 62 requests to 4 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The technical stack is extremely minimal.

Who receives the data

There are no third-party recipients collecting data.

The only external service is ReadSpeaker, a page text-to-speech tool for accessibility. It helps users listen to the site’s content read aloud. The scan contains no analytics, advertising networks, social media pixels, or session recording at all — neither on the site’s own domains nor on third-party ones.

Consent was not given in this session, and importantly, nothing non-functional launches without it. The analytics mentioned in the policy did not fire in the clean scan — meaning it is held pending consent, as it should be. Only the functional text-to-speech tool fired, and its associated cookie, per policy, activates only when the “read aloud” button is pressed. Not a single cookie was set during the entire session.

Only functional text-to-speech for accessibility. Before any consent, a single external service fires — ReadSpeaker, which by its purpose belongs to accessibility rather than analytics or advertising. The scan contains no statistics, no advertising domains, no social plugins, and no session recording.

What works in the site’s favor

This is worth highlighting. On the financial agency’s site, in a clean session, not a single analytics or advertising tracker fired. The statistics described in the policy correctly do not launch without consent. The only thing that fires is an accessibility tool helping users listen to the page. This setup is a model of how non-functional data collection should wait for consent.

Conclusion

Belastingdienst.nl is an exemplary case for a government financial agency. In a clean session without consent, nothing fired except the functional accessibility text-to-speech tool: no analytics, no advertising, no session recording, not a single cookie. The statistics mentioned in the policy are held pending consent and do not launch without it. The key takeaway for the reader: this is correct architecture — functional accessibility works immediately, while everything non-functional waits for consent. No violations were recorded.

Evidence
Original (audit)
HAR file: nl/belastingdienst-nl-2026-06-16.har
SHA-256: 04f308177a014095b55c28e79fdc16c88a5cb3154b2782b3282ac8f82a41d708
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.