Policy changed — see what exactly · 2026-08-21 →
Ncsc.nl is the website of the Dutch National Cyber Security Centre. Homepage scan: 42 requests, 4 domains. The configuration is exemplary, which is particularly fitting for a cybersecurity center. There are two external services, both restrained: the government's centralized web-statistics platform, Piwik PRO, running in anonymized mode, and self-hosted error monitoring. The scan shows no Google Analytics, no Facebook, no advertising, no session recording, and no third-party commercial trackers. Not a single cookie was set during the session. The policy explicitly states that consent is not requested for the statistics, since it falls under an exemption in the telecommunications law. No violations were recorded.
Timeline of the leak
Declared versus actual
Detected trackers
- Government statistics (Piwik PRO, anonymized)
- Sentry (error monitoring, self-hosted)
Context
www.ncsc.nl is the website of the Dutch National Cyber Security Centre (Nationaal Cyber Security Centrum): threat warnings, security recommendations, incident response. The data controller is NCSC, a government organization. The site is informational.
Scan: 42 requests to 4 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The technical stack is minimal.
Who receives the data
There are no third-party commercial recipients.
There are two external services, both restrained: the government’s centralized web-statistics platform, built on Piwik PRO in anonymized mode, and self-hosted error monitoring — a technical tool for tracking failures. The scan shows no Google Analytics, no advertising networks, no social media pixels, and no session recording.
Was there a consent banner
A full banner for the statistics is not required here: it is configured anonymously. The policy explicitly states that consent is not requested for these cookies, since they fall under the telecommunications law’s exemption for privacy-friendly statistics. Not a single cookie was set during the entire session.
What fires before consent
Only anonymized statistics and technical monitoring. Before any interaction, the government’s centralized, anonymized statistics and self-hosted error monitoring fire. The scan contains no Google analytics, no advertising domains, no social plugins, and no session recording.
Conclusion
Ncsc.nl is a model of a restrained configuration, well suited to the nature of a cybersecurity center. There are two external services: the government’s anonymized web statistics and self-hosted error monitoring. There is no third-party advertising, no Google analytics, no social media pixels, and no session recording whatsoever, and no cookies are set. The key takeaway for the reader: a cybersecurity center can manage with anonymized government statistics and its own monitoring alone, and here that is achieved without a single third-party commercial tracker, with the exemption of the statistics explicitly confirmed by the policy. No violations were recorded.
82baf9c9d77e1854ece473cd42078a17f9ab3d04d37240deff760c428cb48064