Belastingdienst.nl is the website of the Dutch Tax and Customs Administration. Homepage scan: 62 requests, 4 domains. The configuration is exemplary, and particularly telling for a financial agency. In a clean session without consent, a single external service fired — ReadSpeaker, a page text-to-speech tool for accessibility. No analytics fired at all: no government statistics, no Google, no Facebook, no advertising, no session recording. Not a single cookie was set during the session. The policy mentions statistics, but in the no-consent scan it correctly does not launch — meaning it is held pending consent. No violations were recorded.
Timeline of the leak
Declared versus actual
Detected trackers
- ReadSpeaker (accessibility text-to-speech, functional)
Context
www.belastingdienst.nl is the website of the Dutch Tax and Customs Administration (Belastingdienst): information on taxes, duties, tax returns, and requests. The data controller is the tax authority. The site is informational, with an extension into personal account services.
Scan: 62 requests to 4 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The technical stack is extremely minimal.
Who receives the data
There are no third-party recipients collecting data.
The only external service is ReadSpeaker, a page text-to-speech tool for accessibility. It helps users listen to the site’s content read aloud. The scan contains no analytics, advertising networks, social media pixels, or session recording at all — neither on the site’s own domains nor on third-party ones.
Was there a consent banner
Consent was not given in this session, and importantly, nothing non-functional launches without it. The analytics mentioned in the policy did not fire in the clean scan — meaning it is held pending consent, as it should be. Only the functional text-to-speech tool fired, and its associated cookie, per policy, activates only when the “read aloud” button is pressed. Not a single cookie was set during the entire session.
What fires before consent
Only functional text-to-speech for accessibility. Before any consent, a single external service fires — ReadSpeaker, which by its purpose belongs to accessibility rather than analytics or advertising. The scan contains no statistics, no advertising domains, no social plugins, and no session recording.
What works in the site’s favor
This is worth highlighting. On the financial agency’s site, in a clean session, not a single analytics or advertising tracker fired. The statistics described in the policy correctly do not launch without consent. The only thing that fires is an accessibility tool helping users listen to the page. This setup is a model of how non-functional data collection should wait for consent.
Conclusion
Belastingdienst.nl is an exemplary case for a government financial agency. In a clean session without consent, nothing fired except the functional accessibility text-to-speech tool: no analytics, no advertising, no session recording, not a single cookie. The statistics mentioned in the policy are held pending consent and do not launch without it. The key takeaway for the reader: this is correct architecture — functional accessibility works immediately, while everything non-functional waits for consent. No violations were recorded.
04f308177a014095b55c28e79fdc16c88a5cb3154b2782b3282ac8f82a41d708