Bna.nl is the website of the Dutch industry association of architecture firms. Homepage scan: 108 requests, 14 domains. For a professional association, the advertising stack is unexpectedly heavy. The site has a consent banner with built-in tracker blocking, but in practice it blocks nothing: before any user choice, the Facebook pixel sends a pageview event to Meta, the LinkedIn advertising pixel transmits the visit, and Google's advertising system and analytics send their own requests. Consent mode for Google is not configured. In other words, the banner is present, but trackers fire before the choice, as if it weren't there at all.
Timeline of the leak
Declared versus actual
Detected trackers
- Facebook / Meta Pixel
- LinkedIn (Insight + advertising)
- Google DoubleClick (remarketing)
- Google Analytics 4
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — advertising pixels and analytics fire before consent despite the bannerThe site has a consent banner in consent-before-collection mode, with built-in tracker blocking. But in practice it blocks nothing. Before any user choice, a full advertising stack fires on the page: the Facebook pixel sends a pageview event to Meta, the LinkedIn advertising pixel sends visit data, and Google's advertising system and analytics send their own requests. Consent mode for Google analytics and advertising is not configured — requests go out with no consent signal whatsoever. In other words, the banner exists, but trackers fire before the user's choice, as if it weren't there at all. Social-network advertising pixels and analytics are non-technical purposes requiring consent, and here they fire before it is given.
- Art. 13 GDPR — Facebook and LinkedIn advertising pixels and Google remarketing are not disclosed in the policy as advertising recipientsThe policy names Google Analytics and mentions advertising cookies in general terms. However, the Facebook and LinkedIn advertising pixels are mentioned only in the context of following the association on social media, not as advertising pixels on the site that transmit the visit to those platforms. Google's remarketing system is also not disclosed separately. In other words, the visit is transmitted to Meta and LinkedIn, but this is not reflected in the list of advertising recipients.
Context
www.bna.nl is the website of the Dutch industry association of architecture firms (Branchevereniging Nederlandse Architectenbureaus): a professional body representing architecture firms. The data controller is BNA. The site is informational, built on WordPress.
Scan: 108 requests to 14 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The site has a consent banner with built-in tracker blocking. For a professional association, the technical stack is heavily loaded with advertising pixels.
Who receives the data
Observed here: Meta, LinkedIn, Google.
Meta receives a pageview event via the Facebook pixel. LinkedIn receives visit data via the Insight tag and an advertising pixel. Google is present with analytics and a remarketing advertising system. In other words, the fact of the visit goes out to three advertising platforms at once.
Was there a consent banner
Yes, the site has a consent banner in consent-before-collection mode, and it is advertised as having built-in tracker blocking. But in practice it blocks nothing: the advertising pixels and analytics fire before the user’s choice. Consent mode for Google’s services, moreover, is not configured — their requests go out with no consent signal at all.
In other words, the consent mechanism is present on the site but doesn’t do its job.
What fires before consent
Before the user’s choice, the following fire:
- the Facebook pixel — a pageview event to Meta;
- the LinkedIn advertising pixel — transmission of the visit;
- Google’s advertising system (remarketing);
- Google Analytics — with no consent signal.
All of these services are non-technical purposes requiring consent. Under Dutch cookie law, consent must precede their launch. Here, however, the visit goes out to several advertising platforms at once before the choice is made.
Undisclosed advertising recipients
A separate point. The policy names Google Analytics and mentions advertising cookies in general terms. But the Facebook and LinkedIn advertising pixels are mentioned only as social networks one can follow, not as pixels on the site transmitting the visit to those platforms. Google remarketing is not separately disclosed. In other words, the transmission of the visit to Meta and LinkedIn is not reflected in the list of advertising recipients.
Conclusion
Bna.nl is a typical case where the consent mechanism is present but doesn’t work. The professional association’s site has a banner advertised as blocking trackers, yet the Facebook pixel, the LinkedIn advertising pixel, Google remarketing, and Google Analytics all fire before the user’s choice, and consent mode for Google is not configured at all. The key takeaway for the reader: having a banner means nothing by itself if it doesn’t actually hold trackers back until consent. It would be enough to properly configure blocking and consent mode — so that the advertising pixels and analytics genuinely wait for the choice — and to complete the list of advertising recipients in the policy.
04bff5404e39af7072b79ab29e563b80f3e439f94e4d62e5382d0025763157dfWhere to file: Dutch Data Protection Authority (AP) — autoriteitpersoonsgegevens.nl
To: Dutch Data Protection Authority (AP) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website bna.nl. 2. Circumstances I visited the website bna.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has a consent banner in consent-before-collection mode, with built-in tracker blocking. But in practice it blocks nothing. Before any user choice, a full advertising stack fires on the page: the Facebook pixel sends a pageview event to Meta, the LinkedIn advertising pixel sends visit data, and Google's advertising system and analytics send their own requests. Consent mode for Google analytics and advertising is not configured — requests go out with no consent signal whatsoever. In other words, the banner exists, but trackers fire before the user's choice, as if it weren't there at all. Social-network advertising pixels and analytics are non-technical purposes requiring consent, and here they fire before it is given. 2) The policy names Google Analytics and mentions advertising cookies in general terms. However, the Facebook and LinkedIn advertising pixels are mentioned only in the context of following the association on social media, not as advertising pixels on the site that transmit the visit to those platforms. Google's remarketing system is also not disclosed separately. In other words, the visit is transmitted to Meta and LinkedIn, but this is not reflected in the list of advertising recipients. Full technical documentation is published at: https://gdpru.eu/en/audits/nl-bna-nl/ 3. Provisions violated Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — advertising pixels and analytics fire before consent despite the banner; Art. 13 GDPR — Facebook and LinkedIn advertising pixels and Google remarketing are not disclosed in the policy as advertising recipients 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]