Privacy Audit — MediaMarkt Netherlands · 13 trackers · 31 cookies
Scroll for the full story →
Privacy Audit ##04 in the datagobes.dev series
How many cookies exist before you interact with the banner vs after clicking Accept.
Network requests fired before any user interaction — these happen without consent.
New requests triggered immediately after clicking Accept All.
New requests triggered immediately after clicking Accept All.
Whether the consent interface makes it equally easy to accept or reject tracking.
Rejection fully honoured — zero trackers fired and only a consent-preference cookie (pwaconsent) was set after clicking "Opslaan" with all toggles off
Side-by-side comparison of what gets loaded depending on your consent choice.
Requests that still fire after explicitly clicking Reject — these shouldn't exist.
Whether cookies are used for the purpose the site claims in its consent banner.
Volume of third-party network requests per domain, split by consent phase.
Volume of third-party network requests per domain, split by consent phase.
Where your data travels — each destination's jurisdiction and legal safeguards.
All browser storage mechanisms used — cookies, localStorage, IndexedDB, and more.
Sites increasingly use storage APIs to avoid cookie regulations
Browser fingerprinting techniques detected — these work even without cookies.
How easy it is to withdraw consent after initially accepting.
How well the privacy policy covers the 13 GDPR-required information items.
How accessible GDPR rights are — data access, deletion, portability, and objection.
How many clicks to exercise each right?
Custom PWA consent layer with granular toggles and GPC support, but no explicit reject button, asymmetric styling, and broken revocation (cookies persist)
Zero tracker fires pre-consent (good), but aggressive fingerprinting via Canvas/WebGL/WebRTC/MediaDevices APIs before consent interaction
Full suite of legal documents with comprehensive cookie policy listing ~80 cookies. Privacy policy covers 9/13 Art. 13 elements; missing Art. 22 profiling disclosure
Heavy US data flows (Google, Meta, Pinterest, Dotomi, Yahoo) — most DPF-certified. Some unknown-jurisdiction domains (Forter, UserZoom, DAX)
Only HSTS and X-Frame-Options present (2/6). No CSP, no Referrer-Policy, no Permissions-Policy. Zero SRI coverage on 5 external scripts
31 cookies after consent, several exceeding CNIL's 13-month guideline (forterToken, _ga, dtm_token at ~400 days). Cookie policy is detailed but some cookies undisclosed
Accept button has ~2x visual prominence (filled red vs outlined save). No explicit reject; user must understand "Opslaan" with toggles off = rejection