Technical audit · 2026-06-16

ns.nl

Website of the Dutch national railway operator

Ns.nl is the website of the Dutch national railway operator. Homepage scan: 96 requests, 19 domains. The site has a consent-collection platform installed, but before the user's choice, an entire behavioral stack fires: a customer data platform starts profiling the visit with the very first third-party request, A/B tests load, product analytics bundled with session recording sends events, and a survey-intercept system connects in parallel. Consent is recorded significantly later — after all of this has already fired. The policy describes some of these services as used with consent, but in the scan they fire before it, while the A/B-testing platform and product analytics with session recording aren't named at all.

Timeline of the leak

545 ms · customer data platform begins profiling
The very first third-party request launches a customer data platform. Its purpose is to profile the visitor and build a unified profile. This happens at half a second, well before consent.
1298 ms · A/B tests and personalization
Configuration for the A/B-testing and personalization platform loads. Before consent.
2115 ms · product analytics
Product analytics loads. Before consent.
2846 ms · session recording
The session-recording module of the product analytics connects — capturing the user's on-page actions. Before consent.
2934 ms · survey intercept
A survey-intercept system connects. Before consent.
5090 ms · analytics sends events
Product analytics sends events to its own servers. This happens before consent is recorded.
6908 ms · consent recorded, but the stack had already fired
Consent in this session is recorded significantly after the point when profiling, experiments, session recording, and surveys had already fired. No cookies were set via headers during the session.

Declared versus actual

BlueConic — заявлен
Qualtrics — заявлен
+ Optimizely — не заявлен
+ Amplitude (+ session recording) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.ns.nl is the website of the Dutch national railway operator (Nederlandse Spoorwegen): timetables, tickets, a trip planner, and train information. The data controller is NS. The site is commercial and service-oriented, with high traffic.

Scan: 96 requests to 19 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. A consent-collection platform is installed. The technical stack is loaded with profiling, experiment, analytics, and survey services.

Who receives the data

Observed here: a customer data platform, an A/B-testing platform, product analytics with session recording, and a survey system.

The customer data platform profiles the visitor and builds a unified profile. The A/B-testing platform selects page variants. Product analytics captures events and records sessions. The survey system intercepts visitors for questionnaires. The key issue is that this entire set fires before consent.

Yes, the site has a consent-collection platform installed. But consent in this session is recorded significantly after the point when profiling, experiments, session recording, and surveys had already fired. In other words, the banner is present but in practice does not hold these services back.

It’s worth separately noting that the policy describes the customer data platform and the survey system as used with the user’s consent — yet in the scan they fire before consent.

Before consent, the following fire:

  • the customer data platform — profiling the visit (with the very first request);
  • the A/B-testing platform — selecting page variants;
  • product analytics — events and session recording;
  • the survey-intercept system.

All of these services are non-technical purposes requiring consent. It’s especially telling that profiling launches with the very first third-party request, and that product analytics includes session recording — both require consent, and both fire before the choice.

Undisclosed recipients

A separate point. The policy names the customer data platform and the survey system, but the A/B-testing platform and product analytics with its session-recording module are not mentioned in it. In other words, two services, including one that records sessions, which transmit data before consent, are not disclosed in the listing.

Conclusion

Ns.nl is one of the more serious cases. On the national operator’s site, an entire behavioral stack fires before consent: a customer data platform profiles the visit with the very first request, A/B tests run, and product analytics records sessions and sends events. The consent-collection platform is present but in practice does not hold these services back, and some of them are additionally not named in the policy. The key takeaway for the reader: profiling, experiments, and session recording are among the most sensitive types of data collection, and it is precisely these that are launched here before the user’s choice. It would be enough to gate this entire set on consent and to complete the recipient list.

Evidence
Original (audit)
HAR file: nl/ns-nl-2026-06-16.har
SHA-256: 1832fdbafe9e58721bb0fa2073c7f7af49ddc453f53989551874ec0871686df8
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website ns.nl.

2. Circumstances
I visited the website ns.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has a consent-collection platform installed, but before the user makes a choice, an entire behavioral stack fires. The very first third-party request, at half a second, launches a customer data platform, whose purpose is to profile the visitor and build a unified profile. Next, an A/B-testing and personalization platform loads. Then comes product analytics, bundled with a session-recording module that captures the user's on-page actions; it sends events to its own servers. In parallel, a survey-intercept system connects. Consent in this session is recorded significantly later — after this entire set has already fired. In other words, the consent-collection platform is present, but in practice holds back neither profiling, nor experiments, nor session recording. All of these services are non-technical purposes requiring consent. It's worth separately noting that the policy describes some of these services as used 'with your consent,' yet in the scan they fire before consent.

2) The policy names the customer data platform and the survey system, but the A/B-testing platform and product analytics with a session-recording module are not mentioned in it. In other words, two services, including one that records sessions, which transmit data before consent, are not disclosed in the listing.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-ns-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — the customer data platform, A/B tests, product analytics with session recording, and surveys fire before consent; Art. 13 GDPR — the A/B-testing platform and product analytics with session recording are not named in the policy

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]