Technical audit · 2026-06-16

rijkswaterstaat.nl

Website of the Dutch Directorate-General for Public Works and Water Management

Rijkswaterstaat.nl is the website of the Dutch executive agency for infrastructure and water management, responsible for roads, waterways, and flood protection. Homepage scan: 33 requests, 11 domains. The site uses correctly configured, anonymized government statistics, but on top of that, two third-party services are connected with no consent mechanism whatsoever: Google Analytics, in two generations at once, sends requests without a consent signal, and a Microsoft session-recording and heatmap service actively records user behavior and transmits data. No consent-collection platform appears in the scan. For a government site, this is telling, since anonymized statistics — which would have been sufficient — already run alongside them.

Timeline of the leak

807 ms · legacy Google Analytics loads
The legacy generation of Google Analytics loads. This version has long been discontinued, but continues running here.
950 ms · anonymized government statistics
The government's centralized web-statistics platform loads in anonymized mode. This part is set up correctly.
1646 ms · legacy Google Analytics sends a pageview
The legacy generation of Google Analytics sends a request without any consent signal at all — consent mode is not configured.
1663 ms · Microsoft session recording loads
A Microsoft session-recording and heatmap service loads. Its purpose is to record the user's on-page behavior.
1924 ms · current Google Analytics sends a pageview
The current generation of Google Analytics sends a pageview — also without a consent signal.
2486 ms · session recording sends data
The session-recording service sends data about user behavior to its own servers. Without consent.
no consent mechanism, but data has already gone out
No consent-collection platform was found in the scan. Google Analytics and session recording operated freely. No cookies were set via headers during the session, but data has already been transmitted to third-party services.

Declared versus actual

Government statistics (Piwik PRO) — declared
+ Microsoft Clarity (session recording) — not declared
+ Google Analytics — not declared

Detected trackers

Indicators of GDPR non-compliance

Context

www.rijkswaterstaat.nl is the website of the Dutch executive agency for infrastructure and water management (Rijkswaterstaat): the main road network, waterways, water-system management, and flood protection. The data controller is Rijkswaterstaat, a government agency. The site is informational.

Scan: 33 requests to 11 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The technical stack combines correctly configured government statistics with two third-party commercial services.

Who receives the data

Observed here: Microsoft, Google.

Google Analytics is present in two generations and sends requests without a consent signal. A Microsoft session-recording and heatmap service actively records user behavior and transmits data. Correctly configured, anonymized government statistics run in parallel. The key issue is that Google Analytics and session recording operate with no consent mechanism whatsoever.

No consent-collection platform was found in the scan. Google Analytics sends requests without any consent signal at all — consent mode is not configured — and the session-recording service actively captures behavior. No cookies are set during the session, but data has already been transmitted to the analytics and session-recording services.

The following operate with no consent whatsoever:

  • Google Analytics — two generations, without a consent signal;
  • Microsoft session recording and heatmaps — capturing behavior and transmitting data.

Both purposes are non-technical and require consent. The anonymized government statistics running alongside them are not part of the concern — they are configured correctly.

Undisclosed recipient

A separate point. The policy mentions Microsoft only as a provider of office products, but the Microsoft session-recording and heatmap service, which records visitor behavior, is not named in it. In other words, the session-recording service is not disclosed as a data recipient.

Conclusion

Rijkswaterstaat.nl is a telling case for a government site. Correctly configured, anonymized government statistics already run here — but bolted on top of them are Google Analytics in two generations, without a consent signal, and a Microsoft session-recording service that captures user behavior. There is no consent-collection platform, and the session-recording service is additionally undisclosed in the policy. The key takeaway for the reader: the government agency would have been well served by the anonymized statistics it already has, and adding commercial analytics and session recording without consent turns an otherwise correct configuration into a violation. It would be enough to remove session recording and third-party analytics, or gate them on consent, while keeping the anonymized government statistics.

Evidence
Original (audit)
HAR file: nl/rijkswaterstaat-nl-2026-06-16.har
SHA-256: 639acc8adb911288834b8a3e2f112a269d6178a6fa26e557331dc8f691223e7f
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website rijkswaterstaat.nl.

2. Circumstances
I visited the website rijkswaterstaat.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site uses correctly configured, anonymized government statistics, but on top of that, two third-party commercial services are connected that operate with no consent mechanism whatsoever. Google Analytics is present in two generations at once — legacy and current — and sends requests without any consent signal at all: consent mode is not configured. Additionally, a session-recording and heatmap service from Microsoft runs, actively recording the user's on-page behavior and sending data to its own servers. No consent-collection platform was found in the scan, no cookies are set during the session, but this does not change the fact that analytics and session recording have already transmitted data to third-party services. Analytics and session recording are non-technical purposes requiring consent; here they operate without any consent at all. For a government site, this is especially telling, since anonymized government statistics — which would have been sufficient — already run alongside them.

2) The policy mentions Microsoft only as a provider of office products, but the Microsoft session-recording and heatmap service, which records visitor behavior, is not named in it. In other words, the session-recording service, which transmits data about user actions, is not disclosed as a recipient.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-rijkswaterstaat-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — Google Analytics and Microsoft session recording operate without consent; Art. 13 GDPR — the Microsoft session-recording service and Google Analytics as behavioral tools are not disclosed in the policy

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]