Technical audit · 2026-06-16

vno-ncw.nl

Website of the Dutch employers' federation

Vno-ncw.nl is the website of the largest employers' federation in the Netherlands. Homepage scan: 69 requests, 15 domains. Overall, consent is set up carefully: Google's advertising delivery is held in a 'consent not given' state before consent, while session recording, analytics, and the site's own collector launch only after consent is accepted — this works in the site's favor. But one data collection falls outside this scheme: before consent, the page transmits the visitor's IP address to a third-party geolocation service to determine their location. IP address is personal data, and here it goes out to a commercial third-party service before the user's choice, and this service isn't named in the policy.

Timeline of the leak

1201 ms · tag manager
A tag manager loads, through which analytics and advertising are later deployed.
1834–2030 ms · Google advertising in 'no consent' mode
Google's advertising delivery sends requests with a 'consent not given' signal — non-personalized. The site handles this part correctly.
2011 ms · IP transmitted to geolocation service
The page contacts a third-party IP-geolocation service and transmits the visitor's address to it. This happens before consent and transmits personal data to a third-party service.
1948 ms · Cookiebot consent platform
The Cookiebot consent-collection platform loads. A consent mechanism is present.
5601 ms · user accepts consent
The user accepts consent. After this, session recording, analytics, and the site's own collector launch — meaning they correctly waited for the choice.
5710 ms · session recording after consent
Session recording loads only after consent is accepted. This is correct behavior — it waited for the choice.
5889 ms · analytics and own collector after consent
Analytics and the site's own data collector send requests after consent. Their launch is tied to the user's choice.

Declared versus actual

Google Analytics — заявлен
Hotjar — заявлен
+ extreme-ip-lookup.com — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.vno-ncw.nl is the website of the largest employers’ federation in the Netherlands (VNO-NCW): representing business interests, news, publications, events. The data controller is VNO-NCW. The site is informational.

Scan: 69 requests to 15 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The Cookiebot consent-collection platform is present. The technical stack includes analytics, advertising, session recording, and a third-party geolocation service.

Who receives the data

Observed here: a third-party IP-geolocation service, Google, Hotjar.

The third-party geolocation service receives the visitor’s IP address in order to determine their location. Google is present with analytics and advertising delivery. Hotjar performs session recording. The key difference is in the timing: most services wait for consent, while the geolocation service does not.

Yes, the site has the Cookiebot consent-collection platform, and in this session the user accepted consent. It’s worth noting something positive here: Google’s advertising delivery is held in a “consent not given” state before consent, while session recording, analytics, and the site’s own data collector launch only after acceptance. In other words, the main measurement tools are set up to wait for the choice.

But one data collection falls outside this scheme: before consent, the page transmits the visitor’s IP address to a third-party geolocation service.

Before consent, the following fire:

  • transmission of the visitor’s IP address to the third-party geolocation service;
  • Google’s advertising delivery — in “consent not given” mode (non-personalized).

Google’s advertising portion is not a concern here — it respects the absence of consent. The key issue is the geolocation service: it receives the IP address, which is personal data, before the user’s choice.

What works in the site’s favor

This is worth highlighting, because it’s done correctly. Session recording, analytics, and the site’s own data collector launch only after consent is accepted, and Google’s advertising delivery is non-personalized before consent. In other words, the main measurement tools are tied to the user’s choice, and in this respect the site is set up carefully.

Undisclosed recipient

A separate point. The policy lists measurement tools — Google Analytics, session recording, social media pixels. But the third-party IP-geolocation service, to which the visitor’s address is transmitted, is not mentioned in the policy. In other words, the recipient of the IP address is not disclosed in the listing.

Conclusion

Vno-ncw.nl is, on the whole, a carefully configured site with one narrow issue. Session recording, analytics, and the site’s own collector wait for consent, and Google’s advertising delivery is non-personalized before consent — this favorably distinguishes the site. But before consent, the page transmits the visitor’s IP address to a third-party geolocation service, and this service isn’t named in the policy. The key takeaway for the reader: even with correctly configured consent for the main trackers, a separate transmission of the IP address to a third-party service before the choice remains a violation. It would be enough to gate the geolocation request on consent and disclose this service in the policy — and the site would become consistent.

Evidence
Original (audit)
HAR file: nl/vno-ncw-nl-2026-06-16.har
SHA-256: 749f3f638d8abc5c73b31ef2089eee69be7d8970e78f8cca30d1c64ed6152605
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website vno-ncw.nl.

2. Circumstances
I visited the website vno-ncw.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has the Cookiebot consent-collection platform, and on the whole it is set up carefully: Google's advertising delivery is held in a 'consent not given' state and non-personalized before consent, and session recording, analytics, and the site's own collector launch only after the user accepts consent. This works in the site's favor. But one data collection falls outside this scheme. Before consent, the page contacts a third-party IP-geolocation service and transmits the visitor's address to it in order to determine their location. IP address is personal data, and here it goes out to a commercial third-party service before the user has made any choice. Under Dutch cookie law and processing rules, such a transmission requires a legal basis, and in this scan it occurs before consent.

2) The policy lists measurement tools in detail — Google Analytics, session recording, and social media pixels. But the third-party IP-geolocation service, to which the visitor's address is transmitted, is not mentioned in the policy. In other words, the recipient of the IP address is not disclosed in the listing.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-vno-ncw-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — the visitor's IP address is transmitted to a third-party geolocation service before consent; Art. 13 GDPR — the third-party IP-geolocation service is not named in the policy

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]