Technical audit · 2026-06-16

gamma.nl

Home improvement and DIY retailer

Gamma.nl is a Dutch chain of home-improvement and DIY stores. Homepage scan: 113 requests, 20 domains. The OneTrust consent-collection platform is present, but its consent check is only recorded roughly at the seven-second mark, and by then the advertising pixel and analytics have already fired. The Facebook pixel sends a pageview event to Meta at roughly the four-second mark, and Adobe analytics executes from the first second. Notably, the site's own policy describes the Facebook cookie as advertising — used for ad delivery and real-time bidding. In other words, the platform acknowledges the pixel's advertising nature, which requires consent, yet it fires before the user's choice.

Timeline of the leak

462 ms · Adobe analytics
Adobe analytics (Launch and Analytics) loads and begins executing. This happens within the first second, before consent.
1141 ms · Facebook pixel library
The Facebook pixel library loads. The advertising service connects before consent.
1182 ms · OneTrust consent platform
The OneTrust consent-collection platform loads. A consent mechanism is present — meaning anything that fires before the choice occurs before consent.
3922 ms · survey service
The Mopinion survey service connects — a feedback-collection tool.
4241 ms · pageview event to Meta
The Facebook pixel sends a pageview event to Meta. Meta receives the fact of the visit before consent, and this is advertising data collection.
roughly 7 seconds · consent check
The OneTrust platform records a consent check roughly at the seven-second mark — meaning the Facebook pixel and Adobe analytics had already fired by this point. No cookies were set via headers during the session.

Declared versus actual

Facebook / Meta — заявлен
Adobe — заявлен
Google — заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.gamma.nl is a Dutch chain of home-improvement, construction, and DIY stores. The data controller is GAMMA’s operator. The site is commercial: a catalog, search, cart, account area, and checkout.

Scan: 113 requests to 20 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The OneTrust consent-collection platform is present. The technical stack includes an advertising pixel and analytics. The site operates under the oversight of the Dutch regulator and Dutch cookie law, which requires consent before placing and reading non-technical trackers.

Who receives the data

Observed here: Meta, Adobe.

Meta receives a pageview event via the Facebook advertising pixel. Adobe receives data via its own analytics (Launch and Analytics), which records visitor behavior. Additionally, the Mopinion survey service runs, along with a content-management system serving images. The site’s own policy describes the Facebook cookie as advertising, used in part for real-time bidding from external advertisers.

Yes, the site has the OneTrust consent-collection platform, but its consent check in the session is only recorded roughly at the seven-second mark. By this point, the advertising pixel and analytics had already fired.

The policy, meanwhile, explicitly classifies the Facebook cookie as advertising. In other words, the platform itself acknowledges that this pixel is advertising in nature and requires consent, yet it fires before the choice is made.

Before consent is recorded, the following fire:

  • the Facebook advertising pixel — a pageview event to Meta;
  • Adobe analytics — loading and execution;
  • the Mopinion survey service.

The advertising pixel and analytics are non-technical purposes requiring consent. Under Dutch cookie law, consent must precede the placement and reading of such trackers. Here, the visit goes out to Meta and Adobe analytics executes before consent.

Conclusion

Gamma.nl is a typical case: the Facebook advertising pixel transmits the fact of the visit to Meta, and Adobe analytics executes, before consent is recorded, which only appears around the seven-second mark. What stands out is that the site’s own policy calls the Facebook cookie advertising — meaning it acknowledges the need for consent for it — yet the pixel still fires earlier. The key takeaway for the reader: under Dutch cookie law, advertising and analytics trackers must wait for consent, and when a site’s own policy classifies a pixel as advertising, launching it before consent contradicts both the law and the site’s own documentation. It would be enough to gate the advertising pixel and analytics on consent.

Evidence
Original (audit)
HAR file: nl/gamma-nl-2026-06-16.har
SHA-256: 38e2d81424f9584be95f018f84c5138d918401a1b998d5e25e6e0f49bf5a8ade
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website gamma.nl.

2. Circumstances
I visited the website gamma.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has the OneTrust consent-collection platform, and its consent check is recorded roughly at the seven-second mark in this session. But the advertising pixel and analytics have already fired by then. The Facebook pixel sends a pageview event to Meta at roughly the four-second mark — that is, before consent. Adobe analytics loads and executes starting within the first second. A survey service also fires. Crucially, the site's own policy describes the Facebook cookie as an advertising cookie, used to deliver advertising products and real-time bids from external advertisers. In other words, the platform itself acknowledges the advertising nature of this pixel — meaning it requires consent. Under Dutch cookie law, consent must precede the placement and reading of such trackers, yet here the visit goes out to Meta before consent.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-gamma-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — the Facebook advertising pixel and Adobe analytics fire before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]