Technical audit · 2026-06-16

raadvanstate.nl

Website of the Council of State of the Netherlands

Raadvanstate.nl is the website of the Council of State of the Netherlands, the highest administrative court and the government's main advisory body on legislation. Homepage scan: 47 requests, 4 domains. The configuration is exemplary. No analytics, trackers, or advertising fired at all in the clean, no-consent session: only fonts and an accessibility text-to-speech tool loaded — both functional. The policy states that cookies are used to study site usage, but in the scan they correctly did not fire — analytics is held pending consent. Not a single cookie was set during the session. No violations were recorded.

Timeline of the leak

577 ms · web fonts
Web fonts load from a font service — a functional resource for page styling.
582 ms · accessibility text-to-speech
An accessibility page text-to-speech tool loads — an assistive feature, not tracking.
consent-gated analytics, did not fire in the scan
The site has its own consent check. Per policy, cookies are used to study site usage, but in the clean, no-consent session, analytics correctly did not launch — not a single tracker fired. Not a single cookie was set during the session.

Declared versus actual

Analytics (consent-gated, per policy) — заявлен

Detected trackers

Context

www.raadvanstate.nl is the website of the Council of State of the Netherlands (Raad van State): the highest administrative court and the government’s main advisory body on draft legislation. The data controller is the Council of State. The site is informational.

Scan: 47 requests to 4 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The technical stack is extremely restrained.

Who receives the data

There are no third-party data recipients in this session.

Only functional services loaded in the scan — a font service and an accessibility text-to-speech tool. Analytics, which is provided for on the site per policy, did not fire in the clean, no-consent session. The scan shows no Google Analytics, no advertising networks, no social media pixels, and no session recording.

The site has its own consent check, and it is set up correctly: the policy states that cookies are used to study site usage, but in the clean, no-consent session, analytics correctly did not launch. Not a single tracker fired, and not a single cookie was set during the entire session.

Only functional elements. Before consent, web fonts and the accessibility text-to-speech tool load. The scan contains no analytics, no advertising domains, no social plugins, and no session recording — analytics is held pending the user’s choice.

Conclusion

Raadvanstate.nl is a model of correct consent handling for a high government body. Analytics is provided for on the site but is held pending consent: in the clean, no-consent session, not a single tracker fired, and only functional services — fonts and accessibility text-to-speech — loaded. There is no third-party advertising, no Google analytics, no social media pixels, and no session recording whatsoever, and no cookies are set. The key takeaway for the reader: even the analytics that is provided for is correctly held pending consent here, and nothing non-functional fires before the user’s choice. No violations were recorded.

Evidence
Original (audit)
HAR file: nl/raadvanstate-nl-2026-06-16.har
SHA-256: bb2859efbd57897a3f499ba2dde97dd8d9b05709346ecd826d3fc8c32dbf92ef
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.