GAS Rivierenland Analysis available
Website: gasrivierenland.be — Seat: Grote Markt 21, 2800 Mechelen.
Member municipalities (15): Berlaar, Bonheiden, Boortmeerbeek, Bornem, Duffel, Heist-op-den-Berg, Herent, Kortenberg, Lier, Mechelen, Nijlen, Putte, Puurs-Sint-Amands, Sint-Katelijne-Waver, Willebroek.
1. Identified GDPR and ePrivacy violations
A technical audit of gasrivierenland.be and its linked privacy and cookie pages reveals multiple shortcomings against the GDPR, the Belgian Law of 30 July 2018, and the Electronic Communications Act (art. 129 ECA).
| Finding | Legal basis | Risk |
|---|---|---|
| No cookie banner on first visit | Art. 129 ECA — prior consent required | ePrivacy breach |
YouTube tracking cookies (YSC, PREF 10 years, VISITOR_INFO1_LIVE 240 days) without consent | Art. 129 ECA + Art. 6 GDPR | Persistent third-party tracking |
| “Refuse via browser settings” as consent mechanism | Belgian DPA guidelines 2023 — not valid | Invalid consent model |
| Privacy policy last updated 30/12/2019 | Art. 5(2) GDPR — accountability | Outdated documentation |
| No published DPO contact | Art. 37 & 38 GDPR — mandatory for public authorities | Formal non-compliance |
| Broken internal privacy link (/jouw-privacy → HTTP 410) | Art. 12 GDPR — transparency | Duty to inform violated |
| Form collects national registry number without notice at point of collection | Art. 13 GDPR + Law 8 Aug 1983 | High-risk processing |
| No mention of right to complain to the DPA | Art. 13(2)(d) GDPR | Data subject not informed |
| No retention periods stated | Art. 13(2)(a) GDPR | Indefinite storage possible |
| No information on international transfers (YouTube → Google US) | Art. 13(1)(f) + Ch. V GDPR | Incomplete transparency |
| No specific provision for minors | Art. 8 GDPR | Specific protection missing |
2. GDPR articles violated (summary)
Article 5(1)(a) — Transparency
The 2019 privacy policy does not cover current processing activities.
Article 13 — Duty to inform
At the point of collection (forms for “other driver”, contestation, etc.) no dedicated privacy notice is shown.
Articles 37 & 38 — DPO
As a public authority, GAS Rivierenland is required to appoint a DPO and publish their contact details.
Article 129 ECA / ePrivacy — Cookies
Non-essential cookies are placed without prior, informed, granular consent. No reject button, no category split.
3. Online forms — security
Findings from a technical audit of the contestation form /snelheidsboete/andere-bestuurder and the landing page (April 2026).
| Finding | Detail | Risk |
|---|---|---|
| No CSRF token on the POST contestation form | Present hidden inputs (pageNumber, __formName, MAX_FILE_SIZE, g-recaptcha-response, ...) do not include any anti-CSRF token | Cross-Site Request Forgery possible |
| Google reCAPTCHA on the form | Field g-recaptcha-response + loading of www.google.com/recaptcha; transfer to Google US | Not disclosed in the privacy statement — art. 13 + Ch. V GDPR |
| Multiple US CDNs on the form page | fonts.googleapis.com, fonts.gstatic.com, cdnjs.cloudflare.com, maxcdn.bootstrapcdn.com, cdn.tiny.cloud | International transfer (US) undisclosed |
| No Content-Security-Policy response header | The server sends no CSP | No defence in depth against XSS / injection |
National registry number as <input type="text"> | Without autocomplete="off" on this sensitive field | Browser caching; art. 32 GDPR |
| HSTS present (1 year, includeSubDomains) | Positive; no preload, but a solid base | OK |
4. Recommended defence arguments
- Invoke Article 82 GDPR (right to compensation) when unlawfully processed data is used.
- Argue that the controller itself fails to meet its duty to inform, which affects the lawfulness of the processing.
- Complaint possible with the Data Protection Authority (www.dataprotectionauthority.be).
Download this analysis as a PDF attachment for your contestation:
German-speaking Community (DG) — 9 municipalities Analysis available
Members (9): Amel (Amblève), Büllingen, Burg-Reuland, Bütgenbach, Eupen, Kelmis, Lontzen, Raeren, Sankt Vith. All located in the Liège province.
Who handles GAS fines for DG municipalities?
The DG itself does not issue GAS fines. For its 9 municipalities, GAS is handled either by the municipality itself or by the Liège provincial sanctioning officer. The Liège provincial analysis therefore also applies.
Special language guarantees
| Right | Legal basis | Application |
|---|---|---|
| Proceedings in German | Art. 4 and 30 Constitution + 1966 Language Act | Contestation may be filed in German; decision must be issued in German. |
| Translation at the registry | Art. 22 Judicial Languages Act | The Eupen police court sits in German. |
| Free interpreter | Art. 6 ECHR + 1935 Language Act | If the issuing authority cannot provide German. |
Recommended defences
- Demand that all notifications, PVs and decisions be issued in German. Notifications in French or Dutch to DG residents may be null.
- Appeal to the Eupen police court (not Verviers or Liège), which operates in German.
Download this analysis:
WVI (West-Flanders Intercommunale) Analysis available
Website: wvi.be — Seat: Baron Ruzettelaan 35, 8310 Bruges.
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
Privacy + cookie policy at /privacy-policy / /cookie-policy but no last-updated date | Art. 5(2) GDPR | Obsolescence unverifiable |
| No cookie banner on first visit (only a "Cookie settings" link) | Art. 129 ECA | No prior consent |
| No DPO name published | Art. 37(7) GDPR | Formal non-compliance |
| Footer social links without prior info on tracking | Art. 13 + Art. 129 ECA | Third-party trackers |
| External dev agency ("Hannibal") processor not listed | Art. 13(1)(e) + Art. 28 GDPR | Transparency + DPA |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Schrems II — incomplete |
Recommended defences
- A "Cookie settings" link is not enough — prior consent is required.
- Complaint possible with the DPA.
Download this analysis:
Bruges & surroundings (GAS zone) Analysis available
Website: brugge.be — Seat: Burg 12, 8000 Bruges.
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| politiebrugge.be: Privacy & Cookie link without date | Art. 5(2) GDPR | Obsolescence unverifiable |
| No cookie banner on politiebrugge.be | Art. 129 ECA | ePrivacy breach |
| No DPO name published | Art. 37(7) GDPR | Formal non-compliance |
| Police-zone coverage not listed on homepage | Art. 12 GDPR | Transparency failure |
| No cookie banner on brugge.be | Art. 129 ECA | ePrivacy breach |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Schrems II — incomplete |
Recommended defences
- The GAS fine is issued by the city but observation runs through the police zone — both data controllers must be GDPR-compliant, and neither is fully.
- Complaint possible with the DPA.
Download this analysis:
IDELUX Analysis available
Website: idelux.be — Seat: Drève de l’Arc-en-Ciel 98, 6700 Arlon.
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| No visible granular cookie banner | Art. 129 ECA | ePrivacy breach |
| No explicit last-updated date on policy | Art. 5(2) GDPR | Obsolescence unverifiable |
| No DPO name; only generic idelux@idelux.be | Art. 37(7) GDPR | Formal non-compliance |
| Social-media links (FB, LinkedIn, Instagram, Twitter, YouTube) without prior info | Art. 13 + Art. 129 ECA | Click-triggered trackers |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Schrems II — incomplete |
| No provision for minors | Art. 8 GDPR | Special protection missing |
Recommended defences
- Lack of a valid cookie banner.
- Complaint possible with the DPA.
Download this analysis:
INASEP Analysis available
Website: inasep.be — Seat: Rue des Viaux 1b, 5100 Naninne.
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| No visible cookie banner | Art. 129 ECA | ePrivacy breach |
| Privacy policy present but no last-updated date | Art. 5(2) GDPR | Obsolescence unverifiable |
| No DPO name; only info@inasep.be | Art. 37(7) GDPR | Formal non-compliance |
| Site built by external agency ("Expansion") — processor not disclosed | Art. 13(1)(e) + Art. 28 GDPR | Transparency + DPA |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Schrems II — incomplete |
| No provision for minors | Art. 8 GDPR | Special protection missing |
Recommended defences
- Omission of "Expansion" as processor.
- Complaint possible with the DPA.
Download this analysis:
BEP Analysis available
Website: bep.be — Seat: Avenue Sergent Vrithoff 2, 5000 Namur.
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| "Charte de protection des données" last revised 26/11/2018 — over 7 years old | Art. 5(2) + Art. 24 GDPR | Severely outdated documentation |
| No visible cookie banner | Art. 129 ECA | ePrivacy breach |
| No DPO name published | Art. 37(7) GDPR | Formal non-compliance |
| Member municipalities not on the homepage | Art. 12 GDPR | Transparency failure |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Schrems II — incomplete |
Recommended defences
- BEP uses a 2018 document — well before Schrems II (2020). Violates Art. 5(2).
- Complaint possible with the DPA.
Download this analysis:
Intradel Analysis available
Website: intradel.be — Seat: Port de Herstal, 4040 Herstal.
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| Privacy charter + cookie policy present but no visible date | Art. 5(2) GDPR | Obsolescence unverifiable |
| No cookie banner on first visit | Art. 129 ECA | ePrivacy breach |
| No DPO name visible | Art. 37(7) GDPR | Formal non-compliance |
| YouTube/social embeds without prior consent | Art. 129 ECA + Art. 6 GDPR | Third-party trackers |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Schrems II — incomplete |
Recommended defences
- Documents exist but carry no date.
- Complaint possible with the DPA.
Download this analysis:
TIBI (Charleroi) Analysis available
Website: tibi.be — Seat: Rue du Déversoir 1, 6010 Couillet.
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| Cookie banner with only "J'accepte" — no reject button, no granular options | Art. 129 ECA + DPA guidelines 2023 | Invalid consent model |
| No cookie categories or purposes shown | Art. 13 GDPR + Art. 129 ECA | Consent not informed |
| No DPO name or contact | Art. 37(7) GDPR | Formal non-compliance |
| No data-subject rights section | Art. 13(2)(b)-(d) GDPR | Data subject uninformed |
| No date on legal notices | Art. 5(2) GDPR | Obsolescence unverifiable |
Recommended defences
- Strong ground: TIBI uses a banner without a reject option — the Belgian DPA has issued multiple decisions (notably 81/2023) condemning this practice.
- Complaint possible with the DPA.
Download this analysis:
IPALLE Analysis available
Website: ipalle.be — Seat: Chemin de l’Eau Vive 1, 7503 Froyennes (Tournai).
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| Privacy + legal notices + cookies present without visible date | Art. 5(2) GDPR | Obsolescence unverifiable |
| No visible granular cookie banner | Art. 129 ECA | ePrivacy breach |
| No DPO name published | Art. 37(7) GDPR | Formal non-compliance |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Schrems II — incomplete |
| No provision for minors | Art. 8 GDPR | Special protection missing |
Recommended defences
- No date on privacy documents.
- Complaint possible with the DPA.
Download this analysis:
HYGEA (Mons-Borinage) Analysis available
Website: hygea.be — Seat: Rue de la Biscuiterie 19, 7110 Houdeng-Goegnies.
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| TLS certificate chain does not validate | Art. 32 GDPR | Security incident |
| Site content not reachable without bypassing the browser warning | Art. 12 + 32 GDPR | Transparency + security |
Recommended defences
- Strong ground: the TLS error is objectively verifiable and demonstrates a direct Art. 32 breach. Attach a screenshot of the browser warning.
- Complaint possible with the DPA.
Download this analysis:
EcoWerf Analysis available
Website: ecowerf.be — Seat: Aarschotsesteenweg 210, 3012 Wilsele (Leuven).
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
General privacy statement at /algemene-privacyverklaring present but no last-updated date | Art. 5(2) GDPR | Obsolescence unverifiable |
| No visible granular cookie banner | Art. 129 ECA | ePrivacy breach |
| Paddle CMS used; processor not listed in the privacy statement | Art. 13(1)(e) + Art. 28 GDPR | Transparency + DPA |
| No DPO name published | Art. 37(7) GDPR | Formal non-compliance |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Schrems II — incomplete |
Recommended defences
- Paddle CMS not listed as processor.
- Complaint possible with the DPA.
Download this analysis:
Leiedal Analysis available
Website: leiedal.be — Seat: President Kennedypark 10, 8500 Kortrijk.
GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| Terms + privacy + cookie policy present — no last-updated date | Art. 5(2) GDPR | Obsolescence unverifiable |
| No cookie banner on first visit (only a "Cookie preferences" link) | Art. 129 ECA | No prior consent |
| No DPO name published | Art. 37(7) GDPR | Formal non-compliance |
| Newsletter opt-in correctly worded (positive) | Art. 6(1)(a) GDPR | OK |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Schrems II — incomplete |
Recommended defences
- A "Cookie preferences" link is not enough — prior consent is still required for non-essential cookies.
- Complaint possible with the DPA.
Download this analysis:
IGEAN milieu & veiligheid — intergemeentelijke GAS-dienst Analysis available
Data controller: IGEAN milieu & veiligheid — Doornaardstraat 60, 2160 Wommelgem — Website: www.igean.be.
This annex is intended to supplement the contestation of a sanction or retribution by IGEAN milieu & veiligheid — intergemeentelijke GAS-dienst with a technical exposition. The findings were recorded on 22 August 2026 on www.igean.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=63072000 (2 years) + includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
IGEMO Analysis available
Website: igemo.be — Seat: Schoutetstraat 2, 2800 Mechelen. DPO: Sigrid Palmers — privacy@igemo.be.
1. Identified GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| Privacy statement last revised 23/06/2020 — more than 5 years old | Art. 5(2) + Art. 24 GDPR | Severely outdated documentation |
| “Analytics data kept for indefinite time” | Art. 5(1)(e) GDPR | Unlimited retention |
| Newsletter stored in MailChimp “for indefinite time” | Art. 5(1)(e) + Art. 44 GDPR | Storage limitation + US transfer |
| MailChimp, Combell, Microsoft named as processors but no SCCs or Schrems II measures documented | Art. 46 GDPR + Schrems II | Transfer without legal basis |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Transparency incomplete |
| No provision for minors | Art. 8 GDPR | Special protection missing |
| No visible cookie banner with granular consent | Art. 129 ECA | ePrivacy breach |
| Complaint form via Microsoft Forms without prior disclosure of US transfer | Art. 13 + Art. 46 GDPR | Transparency + Schrems II |
2. Breached GDPR articles (summary)
Art. 5(1)(e) — Storage limitation
Two explicit mentions of “indefinite” retention (analytics + newsletter) violate this principle.
Art. 5(2) — Accountability
A policy not updated since 2020 while processors have evolved is demonstrably in default.
Arts. 44-46 — International transfers (Schrems II)
MailChimp (Intuit, US) and Microsoft (US) explicitly named without documented SCCs or TIA.
Art. 129 ECA
No granular consent mechanism visible.
3. Recommended defences
- Argue IGEMO has been in default for five years, undermining the credibility of its enforcement.
- Schrems II (CJEU C-311/18) applies to Microsoft/MailChimp transfers without supplementary measures.
- Complaint possible with the DPA.
Download this analysis as a PDF annex:
IOK (Kempen) Analysis available
Website: iok.be — Seat: Antwerpseweg 1A bus 1, 2440 Geel. DPO contact: privacy@iok.be (via Welzijnszorg Kempen).
1. Identified GDPR and ePrivacy breaches
| Finding | Legal basis | Risk |
|---|---|---|
| No explicit last-updated date on the privacy statement | Art. 5(2) GDPR | Obsolescence unverifiable |
| DPO function outsourced without name of natural person | Art. 37(7) GDPR | Formal non-compliance |
| Retention periods only in non-public processing register | Art. 13(2)(a) GDPR | Information obligation breached |
| No section on international transfers | Art. 13(1)(f) + Chapter V | Transparency incomplete |
| No provision for minors | Art. 8 GDPR | Special protection missing |
| No visible cookie banner with granular consent | Art. 129 ECA | ePrivacy breach |
| Complaint right to DPA mentioned (positive) | Art. 13(2)(d) GDPR | OK |
2. Breached GDPR articles (summary)
Art. 13 — Information
Pointing to a non-public register for retention periods does not satisfy the information obligation.
Art. 37(7) — DPO
Outsourcing is permitted, but the name of the natural person in the role must be public.
Arts. 44-46 — Transfers
No mention of Schrems II safeguards.
Art. 129 ECA
No granular consent mechanism visible.
3. Recommended defences
- Argue the reference to a non-public register violates Art. 13(2)(a) GDPR.
- Complaint possible with the DPA.
- Article 82 GDPR (compensation) if unlawful processing is proven.
Download this analysis as a PDF annex:
Haviland (Halle-Vilvoorde) Analysis available
Website: haviland.be — Data controller: Haviland Regiopartners, Poverstraat 75 bus 47, 1731 Asse — Information security contact: informatieveiligheid@haviland.be.
Member municipalities (23): Affligem, Asse, Beersel, Dilbeek, Grimbergen, Kampenhout, Kapelle-op-den-Bos, Lennik, Liedekerke, Londerzeel, Machelen, Meise, Merchtem, Opwijk, Pepingen, Roosdaal, Sint-Pieters-Leeuw, Steenokkerzeel, Ternat, Vilvoorde, Wemmel, Zaventem, Zemst. Not every municipality participates in every GAS category (GAS 1-2-3, blue zone, GAS 4, GAS 5).
1. Identified GDPR and ePrivacy violations
A technical audit of haviland.be on 17 April 2026 reveals the following shortcomings against the GDPR, the Belgian Law of 30 July 2018, and art. 129 of the Electronic Communications Act.
| Finding | Legal basis | Risk |
|---|---|---|
Triple analytics stack: Google Analytics (_ga, _gat, _gid), Hotjar (_hjid) and Matomo (_pk_id, _pk_ses, ...) all active at once | Art. 5(1)(c) GDPR — proportionality & data minimisation | Excessive processing |
| Direct contradiction: the privacy statement declares “no data outside the EU”, while Google Analytics and Hotjar transfer to the United States | Art. 5(1)(a) GDPR — transparency & accuracy; Ch. V GDPR | False declaration / transparency breach |
AddThis cookies (__atuvc, __atuvs) still listed — AddThis was shut down by Oracle in May 2023 | Art. 5(2) GDPR — accountability | Outdated documentation |
Universal Analytics cookies (__utmb, __utmc, __utmz) listed, while UA was phased out by Google on 1 July 2023 | Art. 5(2) GDPR | Unmaintained documentation |
| No retention periods for any cookie | Art. 13(2)(a) GDPR | Potentially unlimited storage |
No DPO name or e-mail published (only a generic informatieveiligheid@ address) | Art. 37 & 38 GDPR | Formal non-compliance (public authority) |
| No certified CMP; no IAB TCF integration | Belgian DPA guidelines on cookies 2023 | No auditable consent records |
| Reference to “browser settings” to withdraw consent | Belgian DPA opinion 2023 — not valid | Invalid withdrawal |
| No international transfer disclosure despite GA/Hotjar/YouTube usage (Google US transfer) | Art. 13(1)(f) + Ch. V GDPR | Incomplete transparency |
| No named processors (only categories “hosting/logistics/security”) | Art. 13(1)(e) GDPR | Missing recipient information |
2. Key violations (summary)
Article 5(1)(a) — Transparency and accuracy
The privacy statement contains a factually incorrect claim: “Haviland Regiopartners does not share personal data with parties outside the EU”. This is incompatible with the use of Google Analytics, Hotjar and YouTube embeds, all of which transfer data to US processors.
Article 5(1)(c) — Data minimisation
Running three analytics systems in parallel (GA + Hotjar + Matomo) exceeds what is necessary by definition.
Article 129 ECA / ePrivacy — Cookies
Non-essential cookies are linked to a “pop-up”, but without granular category buttons, without a reject button on equal footing with accept, and without documented pre-tick status.
Articles 37 & 38 — DPO
Haviland is an inter-municipal body (public authority) and must appoint a DPO and publish their contact details. A generic informatieveiligheid@haviland.be address does not satisfy Article 37(7) GDPR.
3. Online forms — security
Findings from a technical audit of haviland.be/nl and haviland.be/nl/contact (April 2026). Note: the contact form is likely client-rendered (Paddle CMS); only the page wrapper is statically inspectable.
| Finding | Detail | Risk |
|---|---|---|
| Social & tracking embeds load on every page (including the contact page) | Before any consent, the site loads www.facebook.com, www.linkedin.com, www.youtube.com, www.googletagmanager.com and cdn.jsdelivr.net | Art. 129 ECA + Ch. V GDPR (US transfer) |
| Google Tag Manager on every page | GTM loads Google Analytics at runtime — this explains the GA cookies listed, but simultaneously contradicts the “no data outside the EU” claim | Art. 5(1)(a) GDPR — transparency & accuracy |
| No Content-Security-Policy response header | The server sends no CSP | No defence in depth |
| Drupal “EU Cookie Compliance” module as cookie banner (no certified CMP) | No IAB TCF integration; “Withdraw consent” button marked visually-hidden in the markup | Belgian DPA 2023 guidelines not met |
Drupal Form-API anti-CSRF (form_build_id + form_id) | Present on the search forms; standard Drupal protection | Positive |
| HSTS present (2 years, includeSubDomains) | Strong HSTS configuration | Positive |
4. Recommended defence arguments
- Point to the demonstrable contradiction between the privacy policy and the cookie statement — this affects the lawfulness of the processing (Art. 6 GDPR).
- Invoke Article 82 GDPR (right to compensation) for unlawful use of tracking without valid consent.
- Complaint possible with the Data Protection Authority and the Flemish Supervisory Commission (both cited in the policy itself).
/nl/privacy, /nl/home/cookieverklaring and /nl/home/gas-overtredingen. The privacy policy was last updated 5 January 2026, yet the cookie list still contains trackers retired since 2023. You can verify the findings yourself via your browser's DevTools.
Download this analysis as a PDF attachment for your contestation:
City of Brussels / Stad Brussel / Ville de Bruxelles Analysis available
Website: brussel.be — Contestation portal: brucity.cityenforcement.com — Data controller: City of Brussels (KBO 0207.373.429), Hallenstraat 4, 1000 Brussels — DPO: dpo@brucity.be.
Member municipality: City of Brussels. Contestation deadline: 10 calendar days from receipt of the payment invitation. A contestation does not suspend the payment obligation; non-payment adds €15 in administrative costs.
1. Identified GDPR and ePrivacy violations
Audit on 17 April 2026 of the pages brussel.be/parkeren-bezwaar-tegen-retributie, brussel.be/wettelijke-vermeldingen and the portal brucity.cityenforcement.com.
| Finding | Legal basis | Risk |
|---|---|---|
| “Anonymous” claim on the form while plate + report reference are collected | Art. 4(1), 12 & 13 GDPR — DPA decision 56/2026 | Misleading the data subject |
| Privacy statement (version dated 18 June 2026) without parking-enforcement specifics | Art. 5(2), 12 & 13 GDPR | Outdated transparency |
Page /cookiebeleid returns HTTP 404 | Art. 129 ECA | Duty to inform breached |
| Social embeds (Facebook, Instagram, YouTube, TikTok, LinkedIn, Bluesky, Spotify) on the public page | Art. 129 ECA | Tracking before consent |
No Strict-Transport-Security, Content-Security-Policy, Referrer-Policy or Permissions-Policy on brussel.be | Art. 32 GDPR | No defence in depth |
| The portal CSP allows Microsoft Azure Application Insights telemetry | dc.services.visualstudio.com — transfer to a US processor | Ch. V GDPR, undisclosed |
| External processor cityenforcement; agreement not public | Art. 28(3) GDPR — DPA 29 Sept. 2023 | Retroactive contracts are invalid |
| No DPIA published for ANPR / scan vehicles | Art. 35 GDPR — DPA 129/2023, 56/2026 | High-risk processing without assessment |
| The portal does have strong security headers (CSP, HSTS preload, Referrer-Policy, Permissions-Policy) | Art. 32 GDPR | Positive |
2. GDPR articles violated (summary)
Articles 12 & 13 GDPR — transparency and duty to inform
Labelling the form “anonymous” while collecting plate and report reference misleads the data subject. A licence plate is personal data (art. 4(1) GDPR).
Article 6 GDPR — legal basis
General municipal traffic competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for transferring plate data or deploying ANPR without a specific legal basis and a DPIA.
Article 28(3) GDPR — processor agreements
The DPA (29 Sept. 2023) held retroactive processor agreements invalid. The cityenforcement contract must exist prior to processing and be public.
Article 32 GDPR / art. 129 ECA — security and cookies
The absence of HSTS/CSP/Referrer-Policy/Permissions-Policy on brussel.be, combined with a 404 cookie page and social trackers loading before consent, constitutes a structural breach.
3. Online forms — security
| Finding | Detail | Risk |
|---|---|---|
| The portal uses HSTS + preload | max-age=31536000; includeSubDomains; preload | Positive |
The portal has a strict CSP (default-src 'none') with form-action limited to self + Worldline payment | Good defence in depth; payment via payment-webinit.sips-services.com | Positive |
| The portal is a SPA | Form rendered client-side; audit requires runtime DevTools | Informational |
| Microsoft Azure telemetry allowed by the portal CSP | dc.services.visualstudio.com — transfer to Microsoft | Ch. V GDPR |
| brussel.be without HSTS/CSP/Referrer-Policy/Permissions-Policy | Session cookie cookiesession1 with no documented Secure or SameSite attributes | Art. 32 GDPR |
4. Recommended defence arguments
- Point to the factual contradiction between the anonymity claim and the collection of plate + report reference.
- Invoke DPA decisions 56/2026 and 129/2023.
- Demand production of the DPIA for ANPR/scan vehicles and a valid processor agreement with cityenforcement.
- Complaint possible with the Belgian Data Protection Authority (Drukpersstraat 35, 1000 Brussels).
Download this analysis as a PDF attachment for your contestation:
Province de Hainaut Analysis available
Data controller: Province de Hainaut — Bureau provincial des Amendes Administratives — Avenue Général de Gaulle 102, 7000 Mons — Website: www.hainaut.be.
This annex is intended to supplement the contestation of a sanction or retribution by Province de Hainaut with a technical exposition. The findings were recorded on 22 August 2026 on www.hainaut.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS present but max-age=15552000 < 1 year — below the recommended duration | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Only partial Content-Security-Policy (only frame-ancestors, report-uri) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
| tarteaucitron as CMP — positive, European alternative | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Province de Liège Analysis available
Data controller: Province de Liège — Fonctionnaires sanctionnateurs provinciaux — Rue Ernest Solvay 11, 4000 Liège — Website: www.provincedeliege.be.
This annex is intended to supplement the contestation of a sanction or retribution by Province de Liège with a technical exposition. The findings were recorded on 22 August 2026 on www.provincedeliege.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Facebook, YouTube embeds present | Art. 129 WEC / LCE / GEK / ECA | Breach |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
| tarteaucitron as CMP — positive, European alternative | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Province de Namur Analysis available
Data controller: Province de Namur — Bureau des amendes administratives — Rue Henri Blès 190C, 5000 Namur — Website: www.province.namur.be.
This annex is intended to supplement the contestation of a sanction or retribution by Province de Namur with a technical exposition. The findings were recorded on 22 August 2026 on www.province.namur.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS present but max-age=16000000 < 1 year — below the recommended duration | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Frame-Options and no frame-ancestors (clickjacking not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Province de Luxembourg Analysis available
Data controller: Province de Luxembourg — Service des amendes administratives — Place Léopold 1, 6700 Arlon — Website: www.province.luxembourg.be.
This annex is intended to supplement the contestation of a sanction or retribution by Province de Luxembourg with a technical exposition. The findings were recorded on 22 August 2026 on www.province.luxembourg.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS 2 years + includeSubDomains + preload — strong configuration | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
| tarteaucitron as CMP — positive, European alternative | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Province du Brabant wallon Analysis available
Data controller: Province du Brabant wallon — Fonctionnaire sanctionnateur — Place du Brabant wallon 1, 1300 Wavre — Website: www.brabantwallon.be.
This annex is intended to supplement the contestation of a sanction or retribution by Province du Brabant wallon with a technical exposition. The findings were recorded on 22 August 2026 on www.brabantwallon.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Mechelen Analysis available
Data controller: Stad Mechelen — Grote Markt 21, 2800 Mechelen — Website: www.mechelen.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Mechelen with a technical exposition. The findings were recorded on 22 August 2026 on www.mechelen.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Frame-Options and no frame-ancestors (clickjacking not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Server banner with version information (Unit/1.33.0) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville d'Arlon Analysis available
Data controller: Ville d'Arlon — Rue Paul Reuter 8, 6700 Arlon — Website: www.arlon.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville d'Arlon with a technical exposition. The findings were recorded on 22 August 2026 on www.arlon.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Saint-Josse-ten-Noode / Gemeente Sint-Joost-ten-Node Analysis available
Data controller: Commune de Saint-Josse-ten-Noode / Gemeente Sint-Joost-ten-Node — Avenue de l'Astronomie 13, 1210 Saint-Josse-ten-Noode — Website: www.sjtn.brussels.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Saint-Josse-ten-Noode / Gemeente Sint-Joost-ten-Node with a technical exposition. The findings were recorded on 22 August 2026 on www.sjtn.brussels and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Provincie Vlaams-Brabant Analysis available
Data controller: Provincie Vlaams-Brabant — Provincieplein 1, 3010 Leuven — Website: www.vlaamsbrabant.be.
This annex is intended to supplement the contestation of a sanction or retribution by Provincie Vlaams-Brabant with a technical exposition. The findings were recorded on 22 August 2026 on www.vlaamsbrabant.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS present but max-age=16070400 < 1 year — below the recommended duration | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Content-Security-Policy present but permissive (default-src allows https:, wildcards or 'unsafe-inline') | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: same-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Provincie Oost-Vlaanderen Analysis available
Data controller: Provincie Oost-Vlaanderen — Gouvernementstraat 1, 9000 Gent — Website: oost-vlaanderen.be.
This annex is intended to supplement the contestation of a sanction or retribution by Provincie Oost-Vlaanderen with a technical exposition. The findings were recorded on 22 August 2026 on oost-vlaanderen.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Provincie Limburg Analysis available
Data controller: Provincie Limburg — Universiteitslaan 1, 3500 Hasselt — Website: www.limburg.be.
This annex is intended to supplement the contestation of a sanction or retribution by Provincie Limburg with a technical exposition. The findings were recorded on 22 August 2026 on www.limburg.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Only partial Content-Security-Policy (only report-uri) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Weak Referrer-Policy: no-referrer-when-downgrade | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Uses Piwik PRO (EU-hosted analytics) instead of Google Analytics | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Ieper Analysis available
Data controller: Stad Ieper (KBO 0207.518.630) — Grote Markt 34, 8900 Ieper — Website: www.ieper.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Ieper with a technical exposition. The findings were recorded on 22 August 2026 on www.ieper.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Only partial Content-Security-Policy (only connect-src, font-src, frame-src) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Eeklo Analysis available
Data controller: Stad Eeklo (KBO 0207.461.616) — Industrielaan 2, 9900 Eeklo — Website: www.eeklo.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Eeklo with a technical exposition. The findings were recorded on 22 August 2026 on www.eeklo.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Only partial Content-Security-Policy (only connect-src, font-src, frame-src) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Halle Analysis available
Data controller: Stad Halle (KBO 0207.528.640) — Oudstrijdersplein 18, 1500 Halle — Website: www.halle.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Halle with a technical exposition. The findings were recorded on 22 August 2026 on www.halle.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS 2 years + includeSubDomains + preload — strong configuration | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Only partial Content-Security-Policy (only upgrade-insecure-requests, frame-ancestors, script-src) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
| Hotjar session recording/heatmaps present | Art. 129 WEC / LCE / GEK / ECA | Breach |
| Use of CookieScript as CMP — positive | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Tienen Analysis available
Data controller: Stad Tienen (KBO 0207.537.929) — Grote Markt 27, 3300 Tienen — Website: www.tienen.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Tienen with a technical exposition. The findings were recorded on 22 August 2026 on www.tienen.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS 2 years + includeSubDomains + preload — strong configuration | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Dinant Analysis available
Data controller: Ville de Dinant (BCE 0207.360.125) — Rue Grande 112, 5500 Dinant — Website: www.dinant.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Dinant with a technical exposition. The findings were recorded on 22 August 2026 on www.dinant.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS 2 years + includeSubDomains + preload — strong configuration | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Frame-Options and no frame-ancestors (clickjacking not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| YouTube embeds present | Art. 129 WEC / LCE / GEK / ECA | Breach |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Wavre Analysis available
Data controller: Ville de Wavre (BCE 0207.381.392) — Place de l'Hôtel de Ville, 1300 Wavre — Website: www.wavre.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Wavre with a technical exposition. The findings were recorded on 22 August 2026 on www.wavre.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Huy Analysis available
Data controller: Ville de Huy (BCE 0207.348.088) — Grand-Place 1, 4500 Huy — Website: www.huy.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Huy with a technical exposition. The findings were recorded on 22 August 2026 on www.huy.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville d'Ath Analysis available
Data controller: Ville d'Ath (BCE 0207.362.500) — Rue de Pintamont 54, 7800 Ath — Website: www.ath.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville d'Ath with a technical exposition. The findings were recorded on 22 August 2026 on www.ath.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Waterloo Analysis available
Data controller: Commune de Waterloo (BCE 0216.694.712) — Rue François Libert 28, 1410 Waterloo — Website: www.waterloo.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Waterloo with a technical exposition. The findings were recorded on 22 August 2026 on www.waterloo.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Deinze Analysis available
Data controller: Stad Deinze (KBO 0207.489.352) — Brielstraat 2, 9800 Deinze — Website: www.deinze.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Deinze with a technical exposition. The findings were recorded on 22 August 2026 on www.deinze.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Content-Security-Policy present but permissive (default-src allows https:, wildcards or 'unsafe-inline') | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune d'Ixelles / Gemeente Elsene Analysis available
Data controller: Commune d'Ixelles (BCE 0207.387.826) — Chaussée d'Ixelles 168, 1050 Ixelles — Website: www.ixelles.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Ixelles / Gemeente Elsene with a technical exposition. The findings were recorded on 22 August 2026 on www.ixelles.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Only partial Content-Security-Policy (only frame-ancestors) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune d'Uccle / Gemeente Ukkel Analysis available
Data controller: Commune d'Uccle (BCE 0207.393.074) — Place Jean Vander Elst 29, 1180 Uccle — Website: www.uccle.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Uccle / Gemeente Ukkel with a technical exposition. The findings were recorded on 22 August 2026 on www.uccle.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Server banner with version information (Apache/2.4.58 (Ubuntu)) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Forest / Gemeente Vorst Analysis available
Data controller: Commune de Forest (BCE 0207.387.529) — Rue du Curé 2, 1190 Forest — Website: www.forest.brussels.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Forest / Gemeente Vorst with a technical exposition. The findings were recorded on 22 August 2026 on www.forest.brussels and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Jette / Gemeente Jette Analysis available
Data controller: Commune de Jette (BCE 0207.389.804) — Chaussée de Wemmel 100, 1090 Jette — Website: jette.brussels.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Jette / Gemeente Jette with a technical exposition. The findings were recorded on 22 August 2026 on jette.brussels and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
| Use of Klaro as CMP — positive | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Koekelberg / Gemeente Koekelberg Analysis available
Data controller: Commune de Koekelberg (BCE 0207.387.727) — Place Henri Vanhuffel 6, 1081 Koekelberg — Website: www.koekelberg.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Koekelberg / Gemeente Koekelberg with a technical exposition. The findings were recorded on 22 August 2026 on www.koekelberg.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Frame-Options and no frame-ancestors (clickjacking not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Server banner with version information (Microsoft-IIS/10.0) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| Google reCAPTCHA present (US processor, undocumented) | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Berchem-Sainte-Agathe / Gemeente Sint-Agatha-Berchem Analysis available
Data controller: Commune de Berchem-Sainte-Agathe (BCE 0207.386.240) — Avenue du Roi Albert 33, 1082 Berchem-Sainte-Agathe — Website: www.1082.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Berchem-Sainte-Agathe / Gemeente Sint-Agatha-Berchem with a technical exposition. The findings were recorded on 22 August 2026 on www.1082.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Frame-Options and no frame-ancestors (clickjacking not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Server banner with version information (Apache/2.4.62 (Win64) OpenSSL/3.1.7 PHP/8.3.14 mod_fcgid/2.3) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Facebook embeds present | Art. 129 WEC / LCE / GEK / ECA | Breach |
| Use of CookieYes as CMP — positive | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Watermael-Boitsfort / Gemeente Watermaal-Bosvoorde Analysis available
Data controller: Commune de Watermael-Boitsfort (BCE 0207.393.470) — Place Antoine Gilson 1, 1170 Watermael-Boitsfort — Website: www.watermael-boitsfort.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Watermael-Boitsfort / Gemeente Watermaal-Bosvoorde with a technical exposition. The findings were recorded on 22 August 2026 on www.watermael-boitsfort.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune d'Evere / Gemeente Evere Analysis available
Data controller: Commune d'Evere (BCE 0207.384.064) — Square Hoedemaekers 10, 1140 Evere — Website: www.evere.brussels.
This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Evere / Gemeente Evere with a technical exposition. The findings were recorded on 22 August 2026 on www.evere.brussels and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Ganshoren / Gemeente Ganshoren Analysis available
Data controller: Commune de Ganshoren (BCE 0207.387.826) — Avenue Charles-Quint 140, 1083 Ganshoren — Website: www.ganshoren.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Ganshoren / Gemeente Ganshoren with a technical exposition. The findings were recorded on 22 August 2026 on www.ganshoren.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
Google Maps (maps.googleapis.com) — US processor | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune d'Auderghem / Gemeente Oudergem Analysis available
Data controller: Commune d'Auderghem (BCE 0207.386.438) — Rue Emile Idiers 12, 1160 Auderghem — Website: www.auderghem.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Auderghem / Gemeente Oudergem with a technical exposition. The findings were recorded on 22 August 2026 on www.auderghem.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Woluwe-Saint-Lambert / Gemeente Sint-Lambrechts-Woluwe Analysis available
Data controller: Commune de Woluwe-Saint-Lambert (BCE 0207.397.034) — Avenue Paul Hymans 2, 1200 Woluwe-Saint-Lambert — Website: www.woluwe1200.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Woluwe-Saint-Lambert / Gemeente Sint-Lambrechts-Woluwe with a technical exposition. The findings were recorded on 22 August 2026 on www.woluwe1200.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Frame-Options and no frame-ancestors (clickjacking not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Woluwe-Saint-Pierre / Gemeente Sint-Pieters-Woluwe Analysis available
Data controller: Commune de Woluwe-Saint-Pierre (BCE 0207.395.153) — Avenue Charles Thielemans 93, 1150 Woluwe-Saint-Pierre — Website: www.woluwe1150.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Woluwe-Saint-Pierre / Gemeente Sint-Pieters-Woluwe with a technical exposition. The findings were recorded on 22 August 2026 on www.woluwe1150.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Only partial Content-Security-Policy (only frame-ancestors) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Facebook embeds present | Art. 129 WEC / LCE / GEK / ECA | Breach |
| Google reCAPTCHA present (US processor, undocumented) | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune d'Anderlecht / Gemeente Anderlecht Analysis available
Data controller: Commune d'Anderlecht (BCE 0207.393.470) — Place du Conseil 1, 1070 Anderlecht — Website: www.anderlecht.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Anderlecht / Gemeente Anderlecht with a technical exposition. The findings were recorded on 22 August 2026 on www.anderlecht.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
| Facebook embeds present | Art. 129 WEC / LCE / GEK / ECA | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Schaerbeek / Gemeente Schaarbeek Analysis available
Data controller: Commune de Schaerbeek (BCE 0207.377.988) — Place Colignon, 1030 Schaerbeek — Website: www.1030.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Schaerbeek / Gemeente Schaarbeek with a technical exposition. The findings were recorded on 22 August 2026 on www.1030.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Strict Content-Security-Policy (default-src 'self') | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune de Molenbeek-Saint-Jean / Gemeente Sint-Jans-Molenbeek Analysis available
Data controller: Commune de Molenbeek-Saint-Jean (BCE 0207.391.193) — Rue du Comte de Flandre 20, 1080 Molenbeek-Saint-Jean — Website: www.molenbeek.irisnet.be.
This annex is intended to supplement the contestation of a sanction or retribution by Commune de Molenbeek-Saint-Jean / Gemeente Sint-Jans-Molenbeek with a technical exposition. The findings were recorded on 22 August 2026 on www.molenbeek.irisnet.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Frame-Options and no frame-ancestors (clickjacking not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Commune d'Etterbeek Analysis available
Data controller: Commune d'Etterbeek (BCE 0207.383.274) — Avenue d'Auderghem 113-117, 1040 Etterbeek — Website: etterbeek.brussels.
This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Etterbeek with a technical exposition. The findings were recorded on 22 August 2026 on etterbeek.brussels and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Turnhout Analysis available
Data controller: Stad Turnhout (KBO 0207.537.434) — Campus Blairon 200, 2300 Turnhout — Website: www.turnhout.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Turnhout with a technical exposition. The findings were recorded on 22 August 2026 on www.turnhout.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=63072000 (2 years) + includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Strict Content-Security-Policy (default-src 'self') | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
| Use of Klaro as CMP — positive | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Beringen Analysis available
Data controller: Stad Beringen (KBO 0207.525.461) — Mijnschoolstraat 88, 3580 Beringen — Website: www.beringen.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Beringen with a technical exposition. The findings were recorded on 22 August 2026 on www.beringen.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Only partial Content-Security-Policy (only connect-src, font-src, frame-src) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Lommel Analysis available
Data controller: Stad Lommel (KBO 0207.519.026) — Hertog Janplein 1, 3920 Lommel — Website: www.lommel.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Lommel with a technical exposition. The findings were recorded on 22 August 2026 on www.lommel.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Only partial Content-Security-Policy (only connect-src, font-src, frame-src) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Geel Analysis available
Data controller: Stad Geel (KBO 0207.524.966) — Werft 20, 2440 Geel — Website: www.geel.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Geel with a technical exposition. The findings were recorded on 22 August 2026 on www.geel.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Content-Security-Policy present but permissive (default-src allows https:, wildcards or 'unsafe-inline') | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Mouscron Analysis available
Data controller: Ville de Mouscron (BCE 0207.356.899) — Grand-Place 1, 7700 Mouscron — Website: www.mouscron.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Mouscron with a technical exposition. The findings were recorded on 22 August 2026 on www.mouscron.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Kortrijk Analysis available
Data controller: Stad Kortrijk (KBO 0207.494.678) — Grote Markt 54, 8500 Kortrijk — Website: www.kortrijk.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Kortrijk with a technical exposition. The findings were recorded on 22 August 2026 on www.kortrijk.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Google Maps (maps.googleapis.com) — US processor | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
| Use of Klaro as CMP — positive | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Oostende Analysis available
Data controller: Stad Oostende (KBO 0207.473.295) — Vindictivelaan 1, 8400 Oostende — Website: www.oostende.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Oostende with a technical exposition. The findings were recorded on 22 August 2026 on www.oostende.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Only partial Content-Security-Policy (only connect-src, font-src, frame-src) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Sint-Niklaas Analysis available
Data controller: Stad Sint-Niklaas (KBO 0207.486.859) — Grote Markt 1, 9100 Sint-Niklaas — Website: www.sint-niklaas.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Sint-Niklaas with a technical exposition. The findings were recorded on 22 August 2026 on www.sint-niklaas.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| Use of Cookiebot as CMP — positive | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Aalst Analysis available
Data controller: Stad Aalst (KBO 0207.449.148) — Grote Markt 3, 9300 Aalst — Website: aalst.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Aalst with a technical exposition. The findings were recorded on 22 August 2026 on aalst.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Genk Analysis available
Data controller: Stad Genk (KBO 0207.522.491) — Stadsplein 1, 3600 Genk — Website: www.genk.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Genk with a technical exposition. The findings were recorded on 22 August 2026 on www.genk.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Only partial Content-Security-Policy (only connect-src, frame-src, img-src 'self') | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Roeselare Analysis available
Data controller: Stad Roeselare (KBO 0207.490.219) — Botermarkt 2, 8800 Roeselare — Website: www.roeselare.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Roeselare with a technical exposition. The findings were recorded on 22 August 2026 on www.roeselare.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS present but max-age=15552000 < 1 year — below the recommended duration | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
| Use of Klaro as CMP — positive | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Tournai Analysis available
Data controller: Ville de Tournai (BCE 0207.352.297) — Rue Saint-Martin 52, 7500 Tournai — Website: www.tournai.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Tournai with a technical exposition. The findings were recorded on 22 August 2026 on www.tournai.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=63072000 without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Weak Referrer-Policy: no-referrer-when-downgrade | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de La Louvière Analysis available
Data controller: Ville de La Louvière (BCE 0207.382.086) — Place Communale 1, 7100 La Louvière — Website: www.lalouviere.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de La Louvière with a technical exposition. The findings were recorded on 22 August 2026 on www.lalouviere.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Seraing Analysis available
Data controller: Ville de Seraing (BCE 0207.335.221) — Place Communale 8, 4100 Seraing — Website: www.seraing.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Seraing with a technical exposition. The findings were recorded on 22 August 2026 on www.seraing.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31536000 (1 year) without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Weak Referrer-Policy: no-referrer-when-downgrade | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Frame-Options and no frame-ancestors (clickjacking not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| tarteaucitron as CMP — positive, European alternative | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Verviers Analysis available
Data controller: Ville de Verviers (BCE 0207.356.048) — Place du Marché 55, 4800 Verviers — Website: www.verviers.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Verviers with a technical exposition. The findings were recorded on 22 August 2026 on www.verviers.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Liège Analysis available
Data controller: Ville de Liège (BCE 0207.343.238) — Place du Marché 2, 4000 Liège — Website: www.liege.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Liège with a technical exposition. The findings were recorded on 22 August 2026 on www.liege.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| YouTube embeds present | Art. 129 WEC / LCE / GEK / ECA | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Namur Analysis available
Data controller: Ville de Namur (BCE 0207.341.854) — Hôtel de Ville, 5000 Namur — Website: www.namur.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Namur with a technical exposition. The findings were recorded on 22 August 2026 on www.namur.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| YouTube embeds present | Art. 129 WEC / LCE / GEK / ECA | Breach |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Mons Analysis available
Data controller: Ville de Mons (BCE 0207.272.119) — Grand-Place 22, 7000 Mons — Website: www.mons.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Mons with a technical exposition. The findings were recorded on 22 August 2026 on www.mons.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with includeSubDomains (1 year) — solid baseline | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Ville de Charleroi Analysis available
Data controller: Ville de Charleroi (BCE 0207.362.105) — Place Charles II 14-15, 6000 Charleroi — Website: www.charleroi.be.
This annex is intended to supplement the contestation of a sanction or retribution by Ville de Charleroi with a technical exposition. The findings were recorded on 22 August 2026 on www.charleroi.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Weak Referrer-Policy: no-referrer-when-downgrade | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No X-Content-Type-Options: nosniff | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Server banner with version information (Apache/2.4.68 (Debian)) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Antwerpen Analysis available
Data controller: Stad Antwerpen (KBO 0207.500.123) — Dienst Mobiliteit & Parkeren — Grote Markt 1, 2000 Antwerpen — Website: www.antwerpen.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Antwerpen with a technical exposition. The findings were recorded on 22 August 2026 on www.antwerpen.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS present but max-age=15552000 < 1 year — below the recommended duration | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Strict Content-Security-Policy (default-src 'self') | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Content-Security-Policy contains an invalid directive (undefined) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Correct Referrer-Policy: no-referrer | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Gent Analysis available
Data controller: Stad Gent (KBO 0207.451.227) — Botermarkt 1, 9000 Gent — Website: stad.gent.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Gent with a technical exposition. The findings were recorded on 22 August 2026 on stad.gent and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS 2 years + includeSubDomains + preload — strong configuration | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Strict Content-Security-Policy (default-src 'self') | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
Permissions-Policy header present — restricts sensors/geolocation | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
| Google Tag Manager loads Google Analytics at runtime (US transfer) | Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. V | Breach |
| Use of CookieYes as CMP — positive | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Brugge Analysis available
Data controller: Stad Brugge (KBO 0207.528.035) — Burg 12, 8000 Brugge — Website: www.brugge.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Brugge with a technical exposition. The findings were recorded on 22 August 2026 on www.brugge.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
HSTS with max-age=31557600 without includeSubDomains | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Correct Referrer-Policy: strict-origin-when-cross-origin | Art. 32 AVG / RGPD / DSGVO / GDPR | ✓ Compliant |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
| Uses Matomo (more privacy-friendly than Google Analytics) | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
| Use of CookieScript as CMP — positive | Art. 129 WEC / LCE / GEK / ECA | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Leuven Analysis available
Data controller: Stad Leuven (KBO 0207.475.077) — Professor Van Overstraetenplein 1, 3000 Leuven — Website: www.leuven.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Leuven with a technical exposition. The findings were recorded on 22 August 2026 on www.leuven.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
| No Content-Security-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.
Stad Hasselt Analysis available
Data controller: Stad Hasselt (KBO 0207.476.069) — Groenplein 1, 3500 Hasselt — Website: www.hasselt.be.
This annex is intended to supplement the contestation of a sanction or retribution by Stad Hasselt with a technical exposition. The findings were recorded on 22 August 2026 on www.hasselt.be and indicate shortcomings in GDPR, ePrivacy and security of processing.
1. Identified shortcomings
| Finding | Legal basis | Risk |
|---|---|---|
No Strict-Transport-Security response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
Only partial Content-Security-Policy (only frame-ancestors, report-uri) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
No Referrer-Policy response header | Art. 32 AVG / RGPD / DSGVO / GDPR | Breach |
No Permissions-Policy header (sensors/geolocation not restricted) | Art. 32 AVG / RGPD / DSGVO / GDPR | Informational |
Google Fonts (fonts.googleapis.com) — undisclosed US transfer | Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPR | Breach |
| Uses Piwik PRO (EU-hosted analytics) instead of Google Analytics | Art. 5(1)(c) AVG / GDPR / DSGVO | ✓ Compliant |
2. Legal qualification
Article 5(1)(a) GDPR — transparency
Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.
Article 6 GDPR — legal basis
General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.
Chapter V GDPR — transfers
Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.
Article 32 GDPR — security
The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.
Article 129 ECA — ePrivacy
Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.
3. Recommended defence arguments
- the contested sanction be set aside or reformed for unlawful processing of personal data;
- the identified technical shortcomings be placed on record;
- in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
- the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
- the reservation of the right to compensation under article 82 GDPR be acknowledged.