Technical audit · 2026-06-16

bna.nl

Website of the Dutch industry association of architecture firms

Bna.nl is the website of the Dutch industry association of architecture firms. Homepage scan: 108 requests, 14 domains. For a professional association, the advertising stack is unexpectedly heavy. The site has a consent banner with built-in tracker blocking, but in practice it blocks nothing: before any user choice, the Facebook pixel sends a pageview event to Meta, the LinkedIn advertising pixel transmits the visit, and Google's advertising system and analytics send their own requests. Consent mode for Google is not configured. In other words, the banner is present, but trackers fire before the choice, as if it weren't there at all.

Timeline of the leak

328–1447 ms · consent banner with blocking
A consent banner loads in consent-before-collection mode, with built-in tracker blocking. By design, it should hold advertising and analytics back until the user's choice.
556 ms · tag manager
A tag manager loads, through which advertising and analytics services are later deployed.
2178 ms · LinkedIn Insight Tag
The LinkedIn Insight tag loads. The social network's advertising service connects before consent.
2194 ms · Facebook pixel library
The Facebook pixel library loads. The advertising service connects before consent.
2733 ms · Google analytics and advertising without a consent signal
Google Analytics and Google's advertising system send requests. No consent signal is transmitted at all — consent mode is not configured.
2858 ms · LinkedIn advertising pixel
The LinkedIn advertising pixel sends visit data to LinkedIn's servers. Before consent.
3181 ms · pageview event to Meta
The Facebook pixel sends a pageview event to Meta. Meta receives the fact of the visit before consent.
banner present, but not blocking
The site's consent banner is present and advertised as blocking trackers, but in practice the advertising pixels and analytics fired before the user's choice. No cookies were set via headers during the session.

Declared versus actual

Google Analytics — заявлен
Google Tag Manager — заявлен
+ Facebook Pixel (advertising) — не заявлен
+ LinkedIn (advertising) — не заявлен
+ DoubleClick — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.bna.nl is the website of the Dutch industry association of architecture firms (Branchevereniging Nederlandse Architectenbureaus): a professional body representing architecture firms. The data controller is BNA. The site is informational, built on WordPress.

Scan: 108 requests to 14 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The site has a consent banner with built-in tracker blocking. For a professional association, the technical stack is heavily loaded with advertising pixels.

Who receives the data

Observed here: Meta, LinkedIn, Google.

Meta receives a pageview event via the Facebook pixel. LinkedIn receives visit data via the Insight tag and an advertising pixel. Google is present with analytics and a remarketing advertising system. In other words, the fact of the visit goes out to three advertising platforms at once.

Yes, the site has a consent banner in consent-before-collection mode, and it is advertised as having built-in tracker blocking. But in practice it blocks nothing: the advertising pixels and analytics fire before the user’s choice. Consent mode for Google’s services, moreover, is not configured — their requests go out with no consent signal at all.

In other words, the consent mechanism is present on the site but doesn’t do its job.

Before the user’s choice, the following fire:

  • the Facebook pixel — a pageview event to Meta;
  • the LinkedIn advertising pixel — transmission of the visit;
  • Google’s advertising system (remarketing);
  • Google Analytics — with no consent signal.

All of these services are non-technical purposes requiring consent. Under Dutch cookie law, consent must precede their launch. Here, however, the visit goes out to several advertising platforms at once before the choice is made.

Undisclosed advertising recipients

A separate point. The policy names Google Analytics and mentions advertising cookies in general terms. But the Facebook and LinkedIn advertising pixels are mentioned only as social networks one can follow, not as pixels on the site transmitting the visit to those platforms. Google remarketing is not separately disclosed. In other words, the transmission of the visit to Meta and LinkedIn is not reflected in the list of advertising recipients.

Conclusion

Bna.nl is a typical case where the consent mechanism is present but doesn’t work. The professional association’s site has a banner advertised as blocking trackers, yet the Facebook pixel, the LinkedIn advertising pixel, Google remarketing, and Google Analytics all fire before the user’s choice, and consent mode for Google is not configured at all. The key takeaway for the reader: having a banner means nothing by itself if it doesn’t actually hold trackers back until consent. It would be enough to properly configure blocking and consent mode — so that the advertising pixels and analytics genuinely wait for the choice — and to complete the list of advertising recipients in the policy.

Evidence
Original (audit)
HAR file: nl/bna-nl-2026-06-16.har
SHA-256: 04bff5404e39af7072b79ab29e563b80f3e439f94e4d62e5382d0025763157df
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website bna.nl.

2. Circumstances
I visited the website bna.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has a consent banner in consent-before-collection mode, with built-in tracker blocking. But in practice it blocks nothing. Before any user choice, a full advertising stack fires on the page: the Facebook pixel sends a pageview event to Meta, the LinkedIn advertising pixel sends visit data, and Google's advertising system and analytics send their own requests. Consent mode for Google analytics and advertising is not configured — requests go out with no consent signal whatsoever. In other words, the banner exists, but trackers fire before the user's choice, as if it weren't there at all. Social-network advertising pixels and analytics are non-technical purposes requiring consent, and here they fire before it is given.

2) The policy names Google Analytics and mentions advertising cookies in general terms. However, the Facebook and LinkedIn advertising pixels are mentioned only in the context of following the association on social media, not as advertising pixels on the site that transmit the visit to those platforms. Google's remarketing system is also not disclosed separately. In other words, the visit is transmitted to Meta and LinkedIn, but this is not reflected in the list of advertising recipients.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-bna-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — advertising pixels and analytics fire before consent despite the banner; Art. 13 GDPR — Facebook and LinkedIn advertising pixels and Google remarketing are not disclosed in the policy as advertising recipients

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]