Technical audit · 2026-06-16

nipv.nl

Website of the Dutch Institute for Public Safety

Nipv.nl is the website of the Dutch Institute for Public Safety (fire services, crisis management). Homepage scan: 167 requests, 20 domains. For a government institution, the set of trackers is unexpectedly heavy. The Cookiebot consent-collection platform is present, and in this session the user ultimately refused consent — but before the refusal, the LinkedIn advertising pixel and two session-recording tools at once, Hotjar and Contentsquare, had already fired. Google's advertising/analytics layer, meanwhile, is held in a 'consent not given' state, which works in the site's favor. But the LinkedIn advertising pixel and session recording run at full capacity, before consent, and these three services aren't even named in the policy.

Timeline of the leak

1193 ms · Cookiebot consent platform
The Cookiebot consent-collection platform loads. A consent mechanism is present — meaning anything that fires before the choice occurs before consent.
2640 ms · LinkedIn Insight Tag
The LinkedIn Insight tag loads. The social network's advertising service connects before consent.
2643 ms · Hotjar session recording
The Hotjar session-recording tool launches — capturing the user's on-page behavior. Before consent.
3110 ms · Contentsquare session recording
A second session-recording tool launches — Contentsquare. Two behavior-recording tools run simultaneously on the page.
3265 ms · LinkedIn advertising pixel
The LinkedIn advertising pixel sends visit data to LinkedIn's servers. Before consent.
3545–3591 ms · Google in 'no consent' mode
Google Analytics and the Google advertising tag send requests with a 'consent not given' signal — without cookies or personalization. Google handles this part correctly.
4225 ms · user refuses
The user refuses consent. After the refusal, the trackers send no new requests — meaning the refusal is respected. But the advertising pixel and session recording had already fired by this point.

Declared versus actual

Google Analytics — заявлен
+ LinkedIn — не заявлен
+ Hotjar — не заявлен
+ Contentsquare — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.nipv.nl is the website of the Dutch Institute for Public Safety (Nederlands Instituut Publieke Veiligheid): support for fire services, crisis management, and training. The data controller is NIPV, a government institution. The site is informational.

Scan: 167 requests to 20 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The Cookiebot consent-collection platform is present. For a government institution, the technical stack is unexpectedly loaded with advertising and behavioral tools.

Who receives the data

Observed here: LinkedIn, Hotjar, Contentsquare, Google.

LinkedIn receives visit data via the advertising pixel and the Insight tag. Hotjar and Contentsquare are two session-recording tools capturing the user’s on-page behavior. Google is present with analytics and an advertising tag, but in “consent not given” mode. Additionally, the MailPlus email service and Google Maps run.

Yes, the site has the Cookiebot consent-collection platform, and in this session the user ultimately refused consent. A positive point: after the refusal, the trackers send no new requests — the refusal is respected.

But the problem lies in what fired before the refusal. The LinkedIn advertising pixel and both session-recording tools fired within the second or third second — that is, before the user made a choice.

Before the user’s choice, the following fire:

  • the LinkedIn advertising pixel — sending visit data;
  • Hotjar session recording — capturing behavior;
  • Contentsquare session recording — a second behavior-capturing tool.

Google’s advertising/analytics layer, meanwhile, is held in a “consent not given” state — without cookies or personalization, and this counts in the site’s favor. But the LinkedIn advertising pixel and session recording are not switched into that state: they run at full capacity. Session recording and the advertising pixel are non-technical purposes requiring consent, and here they fire before the choice.

Undisclosed recipients

A separate point. The institute’s policy names Google statistics and mentions marketing cookies in general terms. But the LinkedIn advertising pixel and both session-recording tools — Hotjar and Contentsquare — are not named in it. In other words, recording of user behavior and transmission of the visit to LinkedIn occur, but are not disclosed in the document.

Conclusion

Nipv.nl is a serious case for a government institution. Google’s advertising/analytics layer is configured to respect consent, and trackers stop after the refusal — this works in the site’s favor. But before the user’s choice, on the site of a government public-safety institution, the LinkedIn advertising pixel and two session-recording tools at once manage to fire, and none of these three is named in the policy. The key takeaway for the reader: a government institution is particularly ill-suited to launching behavior recording and an advertising pixel before consent, let alone without disclosing them in the policy. It would be enough to gate the advertising pixel and both session-recording tools on consent — as has already been done for the Google layer — and to complete the recipient list.

Evidence
Original (audit)
HAR file: nl/nipv-nl-2026-06-16.har
SHA-256: ca844874a908ce2137f2c3e08f360726fd5795f521398f9f7d294f2b54d9e7a6
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website nipv.nl.

2. Circumstances
I visited the website nipv.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has the Cookiebot consent-collection platform, and in this session the user ultimately refused consent. But before that refusal, a whole set of non-technical trackers had already fired. The LinkedIn advertising pixel sends visit data to LinkedIn's servers. Two session-recording tools at once — Hotjar and Contentsquare — load and begin capturing the user's on-page behavior. This happens within the second or third second, whereas the refusal is recorded later. Google's advertising/analytics layer, meanwhile, is held in a 'consent not given' state, which counts in the site's favor. But the LinkedIn advertising pixel and session recording are not switched into that state — they run at full capacity. Session recording and the advertising pixel are non-technical purposes requiring consent; on the site of a government public-safety institute, they fire before the user's choice.

2) The institute's policy names Google statistics and mentions marketing cookies in general terms. However, the LinkedIn advertising pixel and both session-recording tools — Hotjar and Contentsquare — are not named in the policy. In other words, recording of user behavior and transmission of visit data to LinkedIn occur, but are not disclosed in the recipient list. For a government institution, undisclosed session recording carries particular weight.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-nipv-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — the advertising pixel and session recording fire before consent; Art. 13 GDPR — the LinkedIn advertising pixel and both session-recording tools are not named in the policy

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]