Policy changed — see what exactly · 2026-07-21 →
Funda.nl is the largest real estate portal in the Netherlands. Homepage scan: 65 requests, 19 domains. The Didomi consent-collection platform is present, and Google's advertising/analytics layer is held in a 'consent not given' state — this works in the site's favor. But Funda's own CDP-based analytics platform sends a behavioral event to its own servers before consent, while Google's advertising infrastructure loads in parallel, albeit in non-personalized mode. In other words, Google's advertising delivery respects the refusal, while the behavioral CDP analytics starts before the user's choice.
Timeline of the leak
Declared versus actual
Detected trackers
- Segment (Funda's CDP analytics)
- Google Ad Manager
- Google AdSense
- Google Analytics 4 (denied)
- Datadog RUM
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — behavioral CDP analytics and the advertising stack fire before consentThe site has the Didomi consent-collection platform, and it's worth noting in the site's favor: Google's advertising/analytics layer is held in a 'consent not given' state — the signal transmits a 'denied' status, analytics runs without cookies, and no personalized ad request is observed. But other data collection fires before consent. Funda's own analytics platform, built on a CDP (Segment), loads within the very first milliseconds and sends a behavioral event to its own servers. Google's advertising infrastructure (Ad Manager and AdSense) also loads before consent, albeit in non-personalized mode. A customer data platform is not anonymized statistics: it collects behavior and is capable of distributing it to recipients, and therefore requires consent. Under Dutch cookie law, consent must precede the collection of such data, yet here the behavioral event goes out before the user's choice.
Context
www.funda.nl is the largest real estate search portal in the Netherlands (buying and renting homes). The data controller is Funda’s operator. The site is commercial: a listings catalog, search, contact with agencies, an account area, and Google-account login.
Scan: 65 requests to 19 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The Didomi consent-collection platform is present. The site operates under the oversight of the Dutch regulator and Dutch cookie law, which requires consent before non-technical data collection.
Who receives the data
Observed here: Google, Segment.
Google is present with analytics and advertising infrastructure (Ad Manager and AdSense) — Funda displays ad blocks. Funda’s own analytics platform is built on a CDP (Segment), which collects behavioral events. Additionally, Datadog monitoring runs, along with Google-account login. A customer data platform is not just a counter: it collects behavior and is capable of distributing it to connected recipients.
Was there a consent banner
Yes, the site has the Didomi consent-collection platform. And it’s worth noting something positive here: Google’s advertising/analytics layer is held in a “consent not given” state — the signal transmits a “denied” status, analytics runs without cookies, and no personalized ad request is observed.
But the in-house CDP analytics sends a behavioral event before consent.
What fires before consent
Before consent, the following fire:
- Funda’s own CDP analytics — sending a behavioral event;
- Google’s advertising infrastructure — loading (in non-personalized mode);
- Datadog monitoring (technical).
A customer data platform collects behavior and potentially distributes it to recipients, and therefore falls under non-technical purposes requiring consent. Under Dutch cookie law, consent must precede such collection. Here, the behavioral event goes out before the choice is made.
What works in the site’s favor
It’s worth noting the positive aspects. Google’s advertising/analytics layer is set up correctly: in the absence of consent, analytics runs without cookies, and no personalized ad request is observed. The scan contains no third-party programmatic exchange and no social media pixels. In other words, the issue isn’t advertising leakage across many networks — it’s narrow: the in-house CDP analytics collects behavior before consent.
Conclusion
Funda.nl is a moderate case with a mixed picture. Google’s advertising delivery is configured to respect consent, and there are no third-party ad exchanges or social media pixels — this favorably distinguishes the site. But the in-house CDP-based analytics platform sends a behavioral event before consent, while Google’s advertising infrastructure loads in parallel. The key takeaway for the reader: consent compliance on the advertising side doesn’t close the matter if the in-house customer data platform collects behavior before the choice is made — and a customer data platform is not the same as anonymized statistics, since it’s capable of distributing behavior to recipients. It would be enough to gate its data collection on consent, just as has already been done for Google’s advertising delivery.
1134279396a3d7da38c5c264ba1aa599fcc57fc3b6e694d4d72080b8c03388f7Where to file: Dutch Data Protection Authority (AP) — autoriteitpersoonsgegevens.nl
To: Dutch Data Protection Authority (AP) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website funda.nl. 2. Circumstances I visited the website funda.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has the Didomi consent-collection platform, and it's worth noting in the site's favor: Google's advertising/analytics layer is held in a 'consent not given' state — the signal transmits a 'denied' status, analytics runs without cookies, and no personalized ad request is observed. But other data collection fires before consent. Funda's own analytics platform, built on a CDP (Segment), loads within the very first milliseconds and sends a behavioral event to its own servers. Google's advertising infrastructure (Ad Manager and AdSense) also loads before consent, albeit in non-personalized mode. A customer data platform is not anonymized statistics: it collects behavior and is capable of distributing it to recipients, and therefore requires consent. Under Dutch cookie law, consent must precede the collection of such data, yet here the behavioral event goes out before the user's choice. Full technical documentation is published at: https://gdpru.eu/en/audits/nl-funda-nl/ 3. Provisions violated Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — behavioral CDP analytics and the advertising stack fire before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]