Technical audit · 2026-06-16

kvk.nl

Website of the Dutch Chamber of Commerce (business registry)

Kvk.nl is the website of the Dutch Chamber of Commerce (business registry). Homepage scan: 109 requests, 18 domains. For a government registry, the set is dense. The site has its own consent banner, and the advertising portion is declined — this works in the site's favor. But analytics is granted by default: the consent signal for analytics is set to 'granted' before the user's choice, and Google Analytics along with the site's own server-side tag collector send a pageview before the choice. In parallel, a third-party data-collection service collects behavioral events, with the first one occurring even before the banner is shown, and this service isn't named in the policy.

Timeline of the leak

730–980 ms · content system and tag collector
A content management system and a client-side tag collector load. This is preparation for further data collection.
1997 ms · own consent mechanism
The site's own cookie-consent mechanism loads. A banner is present on the site.
2020 ms · behavior collection before the banner is shown
The third-party service Cloud Nine Digital records a behavioral event — interaction with a page component. This happens even before the consent banner is shown.
2275 ms · banner display
The collection service records an event marking the display of the consent banner — meaning it is already active by this point.
2380 ms · virtual pageview
The third-party service records a virtual pageview. Behavior collection is underway before the user's choice.
2554 ms · Google Analytics by default
Google Analytics sends a pageview with an 'analytics granted' signal, set by default. Advertising is declined, but analytics runs before the choice.
2639 ms · own server-side collector
The site's own server-side tag collector sends a pageview with analytics granted — also before the user's choice.
banner shown, analytics granted by default
The consent banner is shown, but analytics is set to 'granted' by default and runs before the choice. The advertising portion is declined. No cookies were set via headers during the session.

Declared versus actual

Google Analytics — заявлен
Sprinklr — заявлен
Mopinion — заявлен
+ Cloud Nine Digital — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.kvk.nl is the website of the Dutch Chamber of Commerce (Kamer van Koophandel): business registration, the trade register, company information, and services for entrepreneurs. The data controller is KVK, a government organization. The site is informational and service-oriented.

Scan: 109 requests to 18 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The site has its own consent banner. For a government registry, the technical stack is dense: analytics, third-party data collection, support chat, and surveys.

Who receives the data

Observed here: Google, Cloud Nine Digital.

Google receives data via analytics. Cloud Nine Digital is a third-party behavioral-data-collection service, recording component interactions and virtual pageviews. The site’s own server-side tag collector forwards analytics. Additionally, Sprinklr support chat, the Mopinion survey service, a content management system, and a translation service run. The scan contains no ad serving and no social media pixels.

Yes, the site has its own consent banner, and it appears at roughly the two-second mark. In the site’s favor: the advertising portion is declined — ad storage is switched off, and advertising is non-personalized.

But analytics is handled differently: its consent signal is set to “granted” by default, before the user’s choice. And third-party behavior collection begins even before the banner is shown.

Before the user’s choice, the following fire:

  • Google Analytics — with an “analytics granted” signal set by default;
  • the site’s own server-side tag collector — forwarding analytics;
  • the third-party service Cloud Nine Digital — collecting interactions and virtual pageviews, with the first event occurring even before the banner is shown.

The advertising portion is declined, and that counts in the site’s favor. But analytics and third-party behavior collection are non-technical purposes requiring consent. The site’s own policy explicitly states that consent is requested for non-essential cookies — yet analytics runs by default and before the choice.

Undisclosed recipient

A separate point. The policy names Google Analytics and the support chat, but the third-party behavioral-data-collection service Cloud Nine Digital is not mentioned in it. In other words, a separate recipient recording interactions and pageviews is not disclosed in the listing.

Conclusion

Kvk.nl is a moderate case with a mixed picture. The advertising portion is declined, which works in the site’s favor. But analytics is set to “granted” by default and sends data before the user’s choice, and a third-party behavior-collection service begins working even before the banner is shown — and this service isn’t named in the policy. The key takeaway for the reader: declining advertising doesn’t close the matter if analytics is granted by default and collects data before the choice, especially when the site’s own policy promises to ask for consent for non-essential cookies. It would be enough to set analytics to “denied” until the user’s choice and to disclose the third-party collection service in the policy.

Evidence
Original (audit)
HAR file: nl/kvk-nl-2026-06-16.har
SHA-256: a7d8d4be74192eb483bbdeb2b6ac8705faeb39009d7d7b9a6d4fa454d51a6387
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website kvk.nl.

2. Circumstances
I visited the website kvk.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has its own consent banner, and in this session it appears at roughly the two-second mark. It's worth noting in the site's favor: the advertising portion is denied — ad storage is switched off, and advertising is non-personalized. But analytics is handled differently: the consent signal for analytics is set to 'granted' by default, before the user has made any choice. As a result, Google Analytics and the site's own server-side tag collector send a pageview with analytics granted before the choice. In parallel, the third-party data-collection service Cloud Nine Digital collects behavioral events — component interactions and virtual pageviews — with the first such event recorded even before the banner is shown at all. The site's own policy explicitly states that consent is requested for non-essential cookies. In other words, analytics is classified as requiring consent, yet it runs by default and before the choice.

2) The policy names Google Analytics and the support chat, but the third-party behavioral-data-collection service Cloud Nine Digital, which collects interactions and virtual pageviews, is not mentioned in it. In other words, a separate recipient of behavioral data is not disclosed in the listing.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-kvk-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — analytics granted by default and data collected before the user's choice; Art. 13 GDPR — the third-party data-collection service Cloud Nine Digital is not named in the policy

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]