Policy changed — see what exactly · 2026-07-23 →
Coolblue.nl is the website of a major Dutch electronics retailer. Homepage scan: 143 requests, 11 domains. In a clean session without consent, an analytics/behavioral layer deploys immediately: Google Analytics 4 sends events (session_start at 5232 ms, page_view at 5259 ms, later scroll and conversion), and the consent signal within the GA4 requests themselves marks analytics storage as granted (analytics_storage = granted), even though the user has made no choice. In parallel, Crazy Egg fires — session recording, heatmaps, and surveys (script at 839 ms, tracking beacon at 6781 ms) — along with Optimizely, an A/B-testing platform (client-side storage at 4452 ms, events to the log collector at 5924 ms). Analytics, session recording, and experiments are non-technical purposes requiring consent, and here all three fire before it is given.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Analytics 4 (events before consent, analytics_storage = granted)
- Crazy Egg (session recording, heatmaps, surveys — before consent)
- Optimizely (A/B experiments and event logging — before consent)
- Google Tag Manager
- mimir.coolblue.nl (first-party real-time, websocket)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — analytics, session recording, and experiments fire before consentIn a clean session, without any user choice, a full analytics/behavioral layer deploys immediately. Google Analytics 4 sends session_start (5232 ms), page_view (5259 ms), and later scroll and conversion events; the consent signal within the GA4 requests themselves (gcs=G101) shows analytics storage marked as granted (analytics_storage = granted) — meaning analytics is treated as consented by default, even though the user has not made any choice. The advertising portion, meanwhile, is marked as non-personalized. In parallel, Crazy Egg loads and fires — a session recording, heatmap, and survey tool: its script loads at 839 ms, and a tracking beacon fires at 6781 ms. Optimizely, an A/B-testing platform, also fires: its client-side storage loads at 4452 ms, and events go to its log collector at 5924 ms. Analytics, session recording, and experiments are non-technical purposes requiring consent under art. 11.7a Telecommunicatiewet and Art. 6(1)(a) GDPR, and here all three fire before consent. Coolblue's policy describes Google Analytics as a 'low-impact' tool with IP masking, but the observed GA4 traffic sends full-fledged events, including conversion, in an 'analytics granted' mode; Crazy Egg and Optimizely are not named in the privacy policy at all.
Context
www.coolblue.nl is the site of Coolblue, one of the largest electronics and home-appliance retailers in the Netherlands and Belgium (catalog, account area, delivery and installation). The data controller is Coolblue B.V. (Rotterdam, Netherlands). The site is commercial.
Scan: 143 requests to 11 domains, homepage, captured in a clean browser without a VPN or ad blocker. Consent on the site is implemented via Consent Mode.
Who receives the data
Directly, before consent: Google (Analytics), Crazy Egg, Optimizely.
Google Analytics 4 sends events to region1.google-analytics.com — session_start, page_view, scroll, and conversion. Crazy Egg (script.crazyegg.com, tracking.crazyegg.com) runs session recording, heatmaps, and surveys. Optimizely (cdn.optimizely.com, eu.logx.optimizely.com) runs A/B experiments and sends events to its own log collector. On the first-party side, there’s a real-time connection to mimir.coolblue.nl on the site’s own domain (websocket).
Was there a consent banner
No separate third-party consent mechanism (CMP) is visible in the scan; consent is implemented via Consent Mode. The key issue: the consent signal within the GA4 requests themselves (gcs=G101) marks analytics storage as granted (analytics_storage = granted) by default — meaning analytics is treated as consented before the user has made any choice. The advertising portion, meanwhile, is marked as non-personalized, which works in the site’s favor — but analytics, session recording, and experiments had already fired by the time any choice could have been made.
What fires before consent
Before the user’s choice, the following fire:
- Google Analytics 4 — session_start, page_view, scroll, and conversion events (from 5232 ms), in “analytics granted” mode;
- Crazy Egg — session recording, heatmaps, surveys (script at 839 ms, beacon at 6781 ms);
- Optimizely — A/B experiments and event logging (from 4452 ms).
All three are non-technical purposes requiring consent. Session recording and heatmaps are especially sensitive: they capture the user’s on-page behavior. Here they fire before any choice is made.
Why “analytics granted by default” is a problem
This point matters for understanding the issue. Consent Mode itself is a proper mechanism: it allows tags to respect the user’s choice. But the default value here is set so that analytics storage is marked as granted (analytics_storage = granted) before any choice is made. As a result, GA4 sends full-fledged events, including conversion, rather than limited cookieless pings. Coolblue’s policy describes Google Analytics as a “low-impact” tool with partial IP masking — but the observed behavior is broader than exempted, privacy-friendly analytics: it is standard GA4 data collection in consent-granted mode. On top of this, Crazy Egg and Optimizely are not named in the privacy policy at all.
Conclusion
Coolblue.nl is a case where consent is respected for advertising but not for analytics and behavioral tools. In the site’s favor, the advertising portion is marked as non-personalized. But Google Analytics 4 sends full-fledged events marked “analytics granted” by default, Crazy Egg runs session recording, heatmaps, and surveys, and Optimizely runs experiments — and all three fire before consent. The key takeaway for the reader: the default Consent Mode value for analytics should be switched to “denied” until the user makes a choice, and session recording and experiments should be held pending consent. That would bring the configuration in line with the very legal basis (consent) the policy itself relies on.
5cc3828073813c2ca5e3f8051a254d9af5737272143304eca099cc265cf4690cWhere to file: Dutch Data Protection Authority (AP) — autoriteitpersoonsgegevens.nl
To: Dutch Data Protection Authority (AP) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website coolblue.nl. 2. Circumstances I visited the website coolblue.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 23 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) In a clean session, without any user choice, a full analytics/behavioral layer deploys immediately. Google Analytics 4 sends session_start (5232 ms), page_view (5259 ms), and later scroll and conversion events; the consent signal within the GA4 requests themselves (gcs=G101) shows analytics storage marked as granted (analytics_storage = granted) — meaning analytics is treated as consented by default, even though the user has not made any choice. The advertising portion, meanwhile, is marked as non-personalized. In parallel, Crazy Egg loads and fires — a session recording, heatmap, and survey tool: its script loads at 839 ms, and a tracking beacon fires at 6781 ms. Optimizely, an A/B-testing platform, also fires: its client-side storage loads at 4452 ms, and events go to its log collector at 5924 ms. Analytics, session recording, and experiments are non-technical purposes requiring consent under art. 11.7a Telecommunicatiewet and Art. 6(1)(a) GDPR, and here all three fire before consent. Coolblue's policy describes Google Analytics as a 'low-impact' tool with IP masking, but the observed GA4 traffic sends full-fledged events, including conversion, in an 'analytics granted' mode; Crazy Egg and Optimizely are not named in the privacy policy at all. Full technical documentation is published at: https://gdpru.eu/en/audits/nl-coolblue-nl/ 3. Provisions violated Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — analytics, session recording, and experiments fire before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]