Gamma.nl is a Dutch chain of home-improvement and DIY stores. Homepage scan: 113 requests, 20 domains. The OneTrust consent-collection platform is present, but its consent check is only recorded roughly at the seven-second mark, and by then the advertising pixel and analytics have already fired. The Facebook pixel sends a pageview event to Meta at roughly the four-second mark, and Adobe analytics executes from the first second. Notably, the site's own policy describes the Facebook cookie as advertising — used for ad delivery and real-time bidding. In other words, the platform acknowledges the pixel's advertising nature, which requires consent, yet it fires before the user's choice.
Timeline of the leak
Declared versus actual
Detected trackers
- Facebook / Meta Pixel
- Adobe Analytics
- Mopinion (surveys)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — the Facebook advertising pixel and Adobe analytics fire before consentThe site has the OneTrust consent-collection platform, and its consent check is recorded roughly at the seven-second mark in this session. But the advertising pixel and analytics have already fired by then. The Facebook pixel sends a pageview event to Meta at roughly the four-second mark — that is, before consent. Adobe analytics loads and executes starting within the first second. A survey service also fires. Crucially, the site's own policy describes the Facebook cookie as an advertising cookie, used to deliver advertising products and real-time bids from external advertisers. In other words, the platform itself acknowledges the advertising nature of this pixel — meaning it requires consent. Under Dutch cookie law, consent must precede the placement and reading of such trackers, yet here the visit goes out to Meta before consent.
Context
www.gamma.nl is a Dutch chain of home-improvement, construction, and DIY stores. The data controller is GAMMA’s operator. The site is commercial: a catalog, search, cart, account area, and checkout.
Scan: 113 requests to 20 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The OneTrust consent-collection platform is present. The technical stack includes an advertising pixel and analytics. The site operates under the oversight of the Dutch regulator and Dutch cookie law, which requires consent before placing and reading non-technical trackers.
Who receives the data
Observed here: Meta, Adobe.
Meta receives a pageview event via the Facebook advertising pixel. Adobe receives data via its own analytics (Launch and Analytics), which records visitor behavior. Additionally, the Mopinion survey service runs, along with a content-management system serving images. The site’s own policy describes the Facebook cookie as advertising, used in part for real-time bidding from external advertisers.
Was there a consent banner
Yes, the site has the OneTrust consent-collection platform, but its consent check in the session is only recorded roughly at the seven-second mark. By this point, the advertising pixel and analytics had already fired.
The policy, meanwhile, explicitly classifies the Facebook cookie as advertising. In other words, the platform itself acknowledges that this pixel is advertising in nature and requires consent, yet it fires before the choice is made.
What fires before consent
Before consent is recorded, the following fire:
- the Facebook advertising pixel — a pageview event to Meta;
- Adobe analytics — loading and execution;
- the Mopinion survey service.
The advertising pixel and analytics are non-technical purposes requiring consent. Under Dutch cookie law, consent must precede the placement and reading of such trackers. Here, the visit goes out to Meta and Adobe analytics executes before consent.
Conclusion
Gamma.nl is a typical case: the Facebook advertising pixel transmits the fact of the visit to Meta, and Adobe analytics executes, before consent is recorded, which only appears around the seven-second mark. What stands out is that the site’s own policy calls the Facebook cookie advertising — meaning it acknowledges the need for consent for it — yet the pixel still fires earlier. The key takeaway for the reader: under Dutch cookie law, advertising and analytics trackers must wait for consent, and when a site’s own policy classifies a pixel as advertising, launching it before consent contradicts both the law and the site’s own documentation. It would be enough to gate the advertising pixel and analytics on consent.
38e2d81424f9584be95f018f84c5138d918401a1b998d5e25e6e0f49bf5a8adeWhere to file: Dutch Data Protection Authority (AP) — autoriteitpersoonsgegevens.nl
To: Dutch Data Protection Authority (AP) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website gamma.nl. 2. Circumstances I visited the website gamma.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has the OneTrust consent-collection platform, and its consent check is recorded roughly at the seven-second mark in this session. But the advertising pixel and analytics have already fired by then. The Facebook pixel sends a pageview event to Meta at roughly the four-second mark — that is, before consent. Adobe analytics loads and executes starting within the first second. A survey service also fires. Crucially, the site's own policy describes the Facebook cookie as an advertising cookie, used to deliver advertising products and real-time bids from external advertisers. In other words, the platform itself acknowledges the advertising nature of this pixel — meaning it requires consent. Under Dutch cookie law, consent must precede the placement and reading of such trackers, yet here the visit goes out to Meta before consent. Full technical documentation is published at: https://gdpru.eu/en/audits/nl-gamma-nl/ 3. Provisions violated Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — the Facebook advertising pixel and Adobe analytics fire before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]