Technical audit · 2026-06-16

praxis.nl

Website of a home improvement and DIY retail chain

Praxis.nl is the site of a major home improvement and DIY retail chain. Homepage scan: 141 requests, 19 domains. The site has a consent-collection platform installed, and the policy explicitly promises to request consent for tracking cookies. But in practice, before the user's choice, the personalization platform registers the visit and sends behavioral events, the search service sends behavioral data, and the Microsoft advertising pixel fires with action events. Consent in this session is recorded significantly later — after these services have already fired. In the site's favor, its own Google tag stays in 'consent not given' mode, but this does not extend to personalization, behavioral search, or advertising.

Timeline of the leak

749 ms · behavioral search service
The product search and recommendation service loads, which will later send behavioral data.
751 ms · consent platform
The consent-collection platform loads. A consent mechanism is present, and the policy promises to ask for consent for tracking.
1018 ms · personalization registers the visit
The A/B-testing and personalization platform registers the visit and requests geolocation. Before consent.
1824 ms · personalization sends behavioral events
The personalization platform sends behavioral events about the user's actions. Before consent.
3015 ms · Microsoft advertising pixel
The Microsoft advertising pixel fires and sends action events. Before consent.
4761 ms · Google tag in 'no consent' mode
The site's own Google tag sends a request with a 'consent not given' signal. The site handles this part correctly.
4959 ms · search behavior sent to the service
The search service sends data about user behavior. Before consent.
8156 ms · consent recorded, but trackers had already fired
Consent in this session is recorded significantly after the point at which personalization, behavioral search, and the advertising pixel had already sent data. No cookies were set via headers during the session.

Declared versus actual

Google Analytics — заявлен
YouTube — заявлен
+ Kameleoon — не заявлен
+ Constructor.io — не заявлен
+ Bing Ads (Microsoft) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.praxis.nl is the site of a major Dutch home improvement, DIY, and garden retail chain. The data controller is Praxis. The site is commercial, an online store with search, recommendations, and an account area.

Scan: 141 requests to 19 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. A consent-collection platform is installed. The technical stack is loaded with personalization, search, and advertising services.

Who receives the data

Observed here: the A/B-testing and personalization platform, the behavioral search service, the Microsoft advertising pixel.

The personalization platform registers the visit and sends behavioral events. The search service sends behavioral data. The Microsoft advertising pixel transmits action events. The key issue is that all of them fire before consent.

Yes, the site has a consent-collection platform installed, and the policy explicitly promises to request consent for tracking cookies. But in practice, consent in this session is recorded significantly after the point at which personalization, behavioral search, and the advertising pixel had already fired. In other words, neither the banner nor the policy’s promise actually holds these services back in practice.

In the site’s favor, it’s worth noting that its own Google tag stays in “consent not given” mode — the site handles this part correctly.

Before consent, the following fire:

  • the personalization platform — visit registration, geolocation, and behavioral events;
  • the search service — sending behavioral data;
  • the Microsoft advertising pixel — action events.

All of these services are non-technical purposes requiring consent. Against the backdrop of a correctly configured “no consent” mode for the Google tag, the remaining services fire before the choice, which is what constitutes the violation.

Undisclosed recipients

A separate point. The main policy names Google Analytics and the video platform, but the personalization platform, the behavioral search service, and the Microsoft advertising pixel are not mentioned in it — the list is relegated to a separate document. In other words, three services transmitting data before consent are not disclosed in the main body of the policy.

Conclusion

Praxis.nl is a case where a consent mechanism exists and the policy promises correct behavior, but in practice this isn’t followed through. The personalization platform, the behavioral search service, and the Microsoft advertising pixel send data before the user’s choice, even though the policy explicitly promises to ask for consent for tracking. Only the “no consent” mode for the Google tag is correctly configured. The key takeaway for the reader: having a banner and the right wording in the policy count for nothing if personalization, behavioral search, and advertising actually fire before consent. It would be enough to gate these services on consent — just as has already been done for the Google tag.

Evidence
Original (audit)
HAR file: nl/praxis-nl-2026-06-16.har
SHA-256: e633f9fdb9c4f19d401215ad579539e6b6256f4efe0dadade7ed51442b3bed3d
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website praxis.nl.

2. Circumstances
I visited the website praxis.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has a consent-collection platform installed, and the policy explicitly promises that consent is requested for tracking cookies. But in practice, before the user makes a choice, a whole set of non-technical services fires. The A/B-testing and personalization platform registers the visit, requests geolocation, and sends behavioral events about the user's actions. The product-search and recommendation service sends behavioral data. The Microsoft advertising pixel fires and sends action events. Consent in this session is recorded significantly later — after the listed services have already fired. In other words, neither the banner nor the policy's promise actually holds the trackers back in practice. All of these services — personalization, behavioral search, and advertising — are non-technical purposes requiring consent. It's worth separately noting, in the site's favor, that the site's own Google tag stays in 'consent not given' mode, but this does not extend to the other services.

2) The main policy names Google Analytics and the video platform, but the A/B-testing and personalization platform, the behavioral search service, and the Microsoft advertising pixel are not mentioned in it — the list is relegated to a separate document. In other words, three services that transmit data before consent are not disclosed in the main body of the policy describing the processing.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-praxis-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — personalization, behavioral search, and the advertising pixel fire before consent, contrary to the banner and the policy's own promise; Art. 13 GDPR — the personalization platform, the behavioral search service, and the advertising pixel are not named in the main policy

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]