Technical audit · 2026-06-23

jumbo.com

Website of Jumbo supermarkets

Jumbo.com is the site of the Jumbo supermarket chain. Homepage scan: 335 requests, 16 domains, but the stack is largely first-party. No third-party advertising or analytics trackers were found — no Google Analytics, no social media pixels, no advertising, no programmatic exchanges; Google Tag Manager loads but deploys no commercial tags. The site has the OneTrust consent mechanism, with consent recorded at 8127 ms. This works in the site's favor. But before consent, primary analytics fires: a series of POST events goes to the site's own /api/pixel endpoint from as early as 3648 ms — before the banner even finishes rendering — and continues thereafter without interruption. Primary behavioral data collection requires consent, and here it fires before it is given.

Timeline of the leak

855–858 ms · tag manager and performance monitoring
Google Tag Manager (855 ms) and mPulse performance monitoring (go-mpulse.net, 858 ms) load. GTM deploys no commercial tags; mPulse is technical RUM.
2258 ms · bot protection
Akamai's bot-protection pixel fires (/akam/). This is a security measure, not tracking.
3648 ms · primary analytics pixel
A POST with an event goes to the site's own endpoint www.jumbo.com/api/pixel. This is primary behavioral data collection, and it begins before the consent banner even finishes rendering (repeats continuously: 3896, 3901, 3989, 5596, 5878 ms, and onward).
3610–5474 ms · consent mechanism loads
The OneTrust consent mechanism loads (otSDKStub, banner, TCF vendor list), and geolocation is determined. Since a mechanism exists, anything that fired earlier occurred before consent.
consent recorded at 8127 ms; the analytics pixel had already fired and continues
Consent is recorded at 8127 ms (consentreceipts). But the primary analytics pixel /api/pixel had already fired by this point (from 3648 ms) and continues sending events afterward. The scan contains no third-party advertising or analytics trackers.

Declared versus actual

Advertising and personalization — gated on consent (policy) — заявлен
Aggregate-level analytics / legitimate interest (policy, cookies chapter) — заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.jumbo.com is the site of Jumbo, the Netherlands’ second-largest supermarket chain (catalog, recipes, loyalty program, online ordering and delivery). The data controller is Jumbo. The site is commercial.

Scan: 335 requests to 16 domains, homepage, captured in a clean browser without a VPN or ad blocker. The stack is largely first-party. The site has the OneTrust consent mechanism.

Who receives the data

There are no third-party commercial data recipients before consent in this session.

Primary analytics go to the site’s own endpoint www.jumbo.com/api/pixel. Google Tag Manager loads but deploys no commercial tags. The scan contains no third-party Google Analytics, no social media pixels, no advertising networks, and no programmatic exchanges whatsoever. On the technical and functional side, there’s mPulse/Akamai performance monitoring, Akamai bot protection, functional chat (Google chat-messenger SDK), and the Mopinion reviews widget (loading).

Yes, the site has the OneTrust consent mechanism (via the IAB TCF framework): the loader script starts at 3610 ms, the banner finishes rendering by 5474 ms, and consent is recorded at 8127 ms (consentreceipts).

The key issue is that primary analytics fired earlier: the /api/pixel pixel went out in a series starting at 3648 ms — before the banner finished rendering — and continued after consent was recorded.

Before consent is recorded, the following fire:

  • the primary analytics pixel /api/pixel (from 3648 ms) — series of POST events;
  • the GTM tag manager (855 ms) — without deploying commercial tags;
  • mPulse performance monitoring (858 ms) — technical;
  • Akamai bot protection (2258 ms) — security.

The tag manager, performance monitoring, and bot protection raise no concerns — these are functional, technical, and security purposes, and GTM in particular deploys nothing third-party. The concern is the primary analytics pixel: this is behavioral data collection, and it fires before consent.

Why “first-party” is not a free pass

This point matters for understanding the issue. The fact that Jumbo keeps analytics on its own infrastructure and involves almost no third-party trackers is indeed better than a scatter of external advertising tools. But legally, the question isn’t who receives the data — it’s on what legal basis it’s collected. The primary analytics pixel is behavioral data collection requiring consent, and the site has the OneTrust consent mechanism, which records the choice. Launching the pixel before that choice is inconsistent with the very legal basis the site itself relies on. The content of the events cannot be assessed from the sanitized HAR, since the payload has been stripped — so the behavior itself is what’s recorded: primary event requests before consent.

Conclusion

Jumbo.com is a case of an overall restrained setup with one inconsistency at the analytics level. Much works in the site’s favor: there are no third-party advertising or analytics trackers, GTM deploys no commercial tags, performance monitoring and chat are functional, and the OneTrust consent mechanism is present. But the primary analytics pixel /api/pixel sends events before consent is recorded, even though the site’s own policy classifies advertising and personalization as consent-based processing. The key takeaway for the reader: the absence of third-party recipients does not eliminate the consent requirement — the in-house analytics pixel should be gated on consent. It would be enough to defer these event requests until after the user’s choice.

Evidence
Original (audit)
HAR file: nl/jumbo-com-2026-06-23.har
SHA-256: bc711f3be2b5724e8c0cb2a67f9fb5d832fa9c65625e2cf009aa96d56a42bc22
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website jumbo.com.

2. Circumstances
I visited the website jumbo.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 23 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site is built largely on its own infrastructure, and a third-party commercial layer is practically absent: the scan contains no Google Analytics, no social media pixels, no advertising networks, and no programmatic exchanges. Google Tag Manager loads but does not deploy any commercial tags. The site has the OneTrust consent mechanism, and consent is recorded at 8127 ms (a request to privacyportal-de.onetrust.com/request/v1/consentreceipts). This works in the site's favor. However, before consent is recorded, primary analytics fires: a series of POST requests with events goes out to the site's own endpoint www.jumbo.com/api/pixel (from 3648 ms — that is, before the consent banner even finishes rendering — and continuing thereafter without interruption). This is primary behavioral data collection, a non-technical purpose requiring consent under art. 11.7a Telecommunicatiewet and Art. 6(1)(a) GDPR. Jumbo's own policy classifies advertising and personalization as consent-based processing. Here, however, the analytics pixel fires before the user's choice. The content of the events cannot be assessed from the sanitized HAR, since the payload has been stripped — so the behavior itself is what's recorded: primary event requests before consent. Performance monitoring (mPulse/Akamai), functional chat, and the reviews widget are not part of the concern.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-jumbo-com/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — the primary analytics pixel runs before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]