Technical audit · 2026-06-23

coolblue.nl

Website of Coolblue electronics retailer

Coolblue.nl is the website of a major Dutch electronics retailer. Homepage scan: 143 requests, 11 domains. In a clean session without consent, an analytics/behavioral layer deploys immediately: Google Analytics 4 sends events (session_start at 5232 ms, page_view at 5259 ms, later scroll and conversion), and the consent signal within the GA4 requests themselves marks analytics storage as granted (analytics_storage = granted), even though the user has made no choice. In parallel, Crazy Egg fires — session recording, heatmaps, and surveys (script at 839 ms, tracking beacon at 6781 ms) — along with Optimizely, an A/B-testing platform (client-side storage at 4452 ms, events to the log collector at 5924 ms). Analytics, session recording, and experiments are non-technical purposes requiring consent, and here all three fire before it is given.

Timeline of the leak

838–839 ms · tag manager and Crazy Egg
Google Tag Manager (838 ms) and the Crazy Egg script (839 ms) load — a session recording, heatmap, and survey tool. Crazy Egg's loading is one of the first things to fire, before consent.
4452 ms · Optimizely
Optimizely's client-side storage loads — an A/B-testing platform. This is behavioral bucketing of users into variants, a non-technical purpose.
5232–5259 ms · Google Analytics 4 events
GA4 sends a conversion event (5232 ms) and a page_view event (5259 ms). The consent signal in the requests (gcs=G101) shows analytics storage marked as granted (analytics_storage = granted) — even though the user has made no choice. The advertising portion is marked as non-personalized.
5924 ms · Optimizely events
Events go to Optimizely's log collector (eu.logx.optimizely.com). The experiments fire before consent.
6781 ms · Crazy Egg tracking beacon
A tracking beacon fires to tracking.crazyegg.com — recording user behavior on the page. Before consent.
8458–29358 ms · GA4 continues
GA4 continues sending events (including scroll) at 8458, 13463, 24350, and 29358 ms — all in the same 'analytics granted' mode.
GA4 consent signal — 'analytics granted' by default, before the user's choice
No separate third-party consent mechanism is visible in the scan; consent is implemented via Consent Mode, and the signal in the GA4 requests (gcs=G101) shows analytics as granted by default. By the time the user could have made any choice, GA4, Crazy Egg, and Optimizely had already fired.

Declared versus actual

Google Analytics (named in the policy, described as 'low impact' with IP masking) — заявлен
+ Crazy Egg (not named in the privacy policy) — не заявлен
+ Optimizely (not named in the privacy policy) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.coolblue.nl is the site of Coolblue, one of the largest electronics and home-appliance retailers in the Netherlands and Belgium (catalog, account area, delivery and installation). The data controller is Coolblue B.V. (Rotterdam, Netherlands). The site is commercial.

Scan: 143 requests to 11 domains, homepage, captured in a clean browser without a VPN or ad blocker. Consent on the site is implemented via Consent Mode.

Who receives the data

Directly, before consent: Google (Analytics), Crazy Egg, Optimizely.

Google Analytics 4 sends events to region1.google-analytics.com — session_start, page_view, scroll, and conversion. Crazy Egg (script.crazyegg.com, tracking.crazyegg.com) runs session recording, heatmaps, and surveys. Optimizely (cdn.optimizely.com, eu.logx.optimizely.com) runs A/B experiments and sends events to its own log collector. On the first-party side, there’s a real-time connection to mimir.coolblue.nl on the site’s own domain (websocket).

No separate third-party consent mechanism (CMP) is visible in the scan; consent is implemented via Consent Mode. The key issue: the consent signal within the GA4 requests themselves (gcs=G101) marks analytics storage as granted (analytics_storage = granted) by default — meaning analytics is treated as consented before the user has made any choice. The advertising portion, meanwhile, is marked as non-personalized, which works in the site’s favor — but analytics, session recording, and experiments had already fired by the time any choice could have been made.

Before the user’s choice, the following fire:

  • Google Analytics 4 — session_start, page_view, scroll, and conversion events (from 5232 ms), in “analytics granted” mode;
  • Crazy Egg — session recording, heatmaps, surveys (script at 839 ms, beacon at 6781 ms);
  • Optimizely — A/B experiments and event logging (from 4452 ms).

All three are non-technical purposes requiring consent. Session recording and heatmaps are especially sensitive: they capture the user’s on-page behavior. Here they fire before any choice is made.

Why “analytics granted by default” is a problem

This point matters for understanding the issue. Consent Mode itself is a proper mechanism: it allows tags to respect the user’s choice. But the default value here is set so that analytics storage is marked as granted (analytics_storage = granted) before any choice is made. As a result, GA4 sends full-fledged events, including conversion, rather than limited cookieless pings. Coolblue’s policy describes Google Analytics as a “low-impact” tool with partial IP masking — but the observed behavior is broader than exempted, privacy-friendly analytics: it is standard GA4 data collection in consent-granted mode. On top of this, Crazy Egg and Optimizely are not named in the privacy policy at all.

Conclusion

Coolblue.nl is a case where consent is respected for advertising but not for analytics and behavioral tools. In the site’s favor, the advertising portion is marked as non-personalized. But Google Analytics 4 sends full-fledged events marked “analytics granted” by default, Crazy Egg runs session recording, heatmaps, and surveys, and Optimizely runs experiments — and all three fire before consent. The key takeaway for the reader: the default Consent Mode value for analytics should be switched to “denied” until the user makes a choice, and session recording and experiments should be held pending consent. That would bring the configuration in line with the very legal basis (consent) the policy itself relies on.

Evidence
Original (audit)
HAR file: nl/coolblue-nl-2026-06-23.har
SHA-256: 5cc3828073813c2ca5e3f8051a254d9af5737272143304eca099cc265cf4690c
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website coolblue.nl.

2. Circumstances
I visited the website coolblue.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 23 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) In a clean session, without any user choice, a full analytics/behavioral layer deploys immediately. Google Analytics 4 sends session_start (5232 ms), page_view (5259 ms), and later scroll and conversion events; the consent signal within the GA4 requests themselves (gcs=G101) shows analytics storage marked as granted (analytics_storage = granted) — meaning analytics is treated as consented by default, even though the user has not made any choice. The advertising portion, meanwhile, is marked as non-personalized. In parallel, Crazy Egg loads and fires — a session recording, heatmap, and survey tool: its script loads at 839 ms, and a tracking beacon fires at 6781 ms. Optimizely, an A/B-testing platform, also fires: its client-side storage loads at 4452 ms, and events go to its log collector at 5924 ms. Analytics, session recording, and experiments are non-technical purposes requiring consent under art. 11.7a Telecommunicatiewet and Art. 6(1)(a) GDPR, and here all three fire before consent. Coolblue's policy describes Google Analytics as a 'low-impact' tool with IP masking, but the observed GA4 traffic sends full-fledged events, including conversion, in an 'analytics granted' mode; Crazy Egg and Optimizely are not named in the privacy policy at all.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-coolblue-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — analytics, session recording, and experiments fire before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]