Praxis.nl is the site of a major home improvement and DIY retail chain. Homepage scan: 141 requests, 19 domains. The site has a consent-collection platform installed, and the policy explicitly promises to request consent for tracking cookies. But in practice, before the user's choice, the personalization platform registers the visit and sends behavioral events, the search service sends behavioral data, and the Microsoft advertising pixel fires with action events. Consent in this session is recorded significantly later — after these services have already fired. In the site's favor, its own Google tag stays in 'consent not given' mode, but this does not extend to personalization, behavioral search, or advertising.
Timeline of the leak
Declared versus actual
Detected trackers
- Kameleoon (personalization and events, before consent)
- Constructor.io (search behavior, before consent)
- Bing Ads (advertising pixel, before consent)
- Google tag (in 'no consent' mode)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — personalization, behavioral search, and the advertising pixel fire before consent, contrary to the banner and the policy's own promiseThe site has a consent-collection platform installed, and the policy explicitly promises that consent is requested for tracking cookies. But in practice, before the user makes a choice, a whole set of non-technical services fires. The A/B-testing and personalization platform registers the visit, requests geolocation, and sends behavioral events about the user's actions. The product-search and recommendation service sends behavioral data. The Microsoft advertising pixel fires and sends action events. Consent in this session is recorded significantly later — after the listed services have already fired. In other words, neither the banner nor the policy's promise actually holds the trackers back in practice. All of these services — personalization, behavioral search, and advertising — are non-technical purposes requiring consent. It's worth separately noting, in the site's favor, that the site's own Google tag stays in 'consent not given' mode, but this does not extend to the other services.
- Art. 13 GDPR — the personalization platform, the behavioral search service, and the advertising pixel are not named in the main policyThe main policy names Google Analytics and the video platform, but the A/B-testing and personalization platform, the behavioral search service, and the Microsoft advertising pixel are not mentioned in it — the list is relegated to a separate document. In other words, three services that transmit data before consent are not disclosed in the main body of the policy describing the processing.
Context
www.praxis.nl is the site of a major Dutch home improvement, DIY, and garden retail chain. The data controller is Praxis. The site is commercial, an online store with search, recommendations, and an account area.
Scan: 141 requests to 19 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. A consent-collection platform is installed. The technical stack is loaded with personalization, search, and advertising services.
Who receives the data
Observed here: the A/B-testing and personalization platform, the behavioral search service, the Microsoft advertising pixel.
The personalization platform registers the visit and sends behavioral events. The search service sends behavioral data. The Microsoft advertising pixel transmits action events. The key issue is that all of them fire before consent.
Was there a consent banner
Yes, the site has a consent-collection platform installed, and the policy explicitly promises to request consent for tracking cookies. But in practice, consent in this session is recorded significantly after the point at which personalization, behavioral search, and the advertising pixel had already fired. In other words, neither the banner nor the policy’s promise actually holds these services back in practice.
In the site’s favor, it’s worth noting that its own Google tag stays in “consent not given” mode — the site handles this part correctly.
What fires before consent
Before consent, the following fire:
- the personalization platform — visit registration, geolocation, and behavioral events;
- the search service — sending behavioral data;
- the Microsoft advertising pixel — action events.
All of these services are non-technical purposes requiring consent. Against the backdrop of a correctly configured “no consent” mode for the Google tag, the remaining services fire before the choice, which is what constitutes the violation.
Undisclosed recipients
A separate point. The main policy names Google Analytics and the video platform, but the personalization platform, the behavioral search service, and the Microsoft advertising pixel are not mentioned in it — the list is relegated to a separate document. In other words, three services transmitting data before consent are not disclosed in the main body of the policy.
Conclusion
Praxis.nl is a case where a consent mechanism exists and the policy promises correct behavior, but in practice this isn’t followed through. The personalization platform, the behavioral search service, and the Microsoft advertising pixel send data before the user’s choice, even though the policy explicitly promises to ask for consent for tracking. Only the “no consent” mode for the Google tag is correctly configured. The key takeaway for the reader: having a banner and the right wording in the policy count for nothing if personalization, behavioral search, and advertising actually fire before consent. It would be enough to gate these services on consent — just as has already been done for the Google tag.
e633f9fdb9c4f19d401215ad579539e6b6256f4efe0dadade7ed51442b3bed3dWhere to file: Dutch Data Protection Authority (AP) — autoriteitpersoonsgegevens.nl
To: Dutch Data Protection Authority (AP) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website praxis.nl. 2. Circumstances I visited the website praxis.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has a consent-collection platform installed, and the policy explicitly promises that consent is requested for tracking cookies. But in practice, before the user makes a choice, a whole set of non-technical services fires. The A/B-testing and personalization platform registers the visit, requests geolocation, and sends behavioral events about the user's actions. The product-search and recommendation service sends behavioral data. The Microsoft advertising pixel fires and sends action events. Consent in this session is recorded significantly later — after the listed services have already fired. In other words, neither the banner nor the policy's promise actually holds the trackers back in practice. All of these services — personalization, behavioral search, and advertising — are non-technical purposes requiring consent. It's worth separately noting, in the site's favor, that the site's own Google tag stays in 'consent not given' mode, but this does not extend to the other services. 2) The main policy names Google Analytics and the video platform, but the A/B-testing and personalization platform, the behavioral search service, and the Microsoft advertising pixel are not mentioned in it — the list is relegated to a separate document. In other words, three services that transmit data before consent are not disclosed in the main body of the policy describing the processing. Full technical documentation is published at: https://gdpru.eu/en/audits/nl-praxis-nl/ 3. Provisions violated Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — personalization, behavioral search, and the advertising pixel fire before consent, contrary to the banner and the policy's own promise; Art. 13 GDPR — the personalization platform, the behavioral search service, and the advertising pixel are not named in the main policy 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]