PVResponse.be
Contact Steden GBA & AVG JustOnWeb Voorbeeld Procedure FAQ Beveiliging Inloggen Registreren

GAS Rivierenland Analysis available

Website: gasrivierenland.be — Seat: Grote Markt 21, 2800 Mechelen.

Member municipalities (15): Berlaar, Bonheiden, Boortmeerbeek, Bornem, Duffel, Heist-op-den-Berg, Herent, Kortenberg, Lier, Mechelen, Nijlen, Putte, Puurs-Sint-Amands, Sint-Katelijne-Waver, Willebroek.

1. Identified GDPR and ePrivacy violations

A technical audit of gasrivierenland.be and its linked privacy and cookie pages reveals multiple shortcomings against the GDPR, the Belgian Law of 30 July 2018, and the Electronic Communications Act (art. 129 ECA).

FindingLegal basisRisk
No cookie banner on first visitArt. 129 ECA — prior consent requiredePrivacy breach
YouTube tracking cookies (YSC, PREF 10 years, VISITOR_INFO1_LIVE 240 days) without consentArt. 129 ECA + Art. 6 GDPRPersistent third-party tracking
“Refuse via browser settings” as consent mechanismBelgian DPA guidelines 2023 — not validInvalid consent model
Privacy policy last updated 30/12/2019Art. 5(2) GDPR — accountabilityOutdated documentation
No published DPO contactArt. 37 & 38 GDPR — mandatory for public authoritiesFormal non-compliance
Broken internal privacy link (/jouw-privacy → HTTP 410)Art. 12 GDPR — transparencyDuty to inform violated
Form collects national registry number without notice at point of collectionArt. 13 GDPR + Law 8 Aug 1983High-risk processing
No mention of right to complain to the DPAArt. 13(2)(d) GDPRData subject not informed
No retention periods statedArt. 13(2)(a) GDPRIndefinite storage possible
No information on international transfers (YouTube → Google US)Art. 13(1)(f) + Ch. V GDPRIncomplete transparency
No specific provision for minorsArt. 8 GDPRSpecific protection missing

2. GDPR articles violated (summary)

Article 5(1)(a) — Transparency

The 2019 privacy policy does not cover current processing activities.

Article 13 — Duty to inform

At the point of collection (forms for “other driver”, contestation, etc.) no dedicated privacy notice is shown.

Articles 37 & 38 — DPO

As a public authority, GAS Rivierenland is required to appoint a DPO and publish their contact details.

Article 129 ECA / ePrivacy — Cookies

Non-essential cookies are placed without prior, informed, granular consent. No reject button, no category split.

3. Online forms — security

Findings from a technical audit of the contestation form /snelheidsboete/andere-bestuurder and the landing page (April 2026).

FindingDetailRisk
No CSRF token on the POST contestation formPresent hidden inputs (pageNumber, __formName, MAX_FILE_SIZE, g-recaptcha-response, ...) do not include any anti-CSRF tokenCross-Site Request Forgery possible
Google reCAPTCHA on the formField g-recaptcha-response + loading of www.google.com/recaptcha; transfer to Google USNot disclosed in the privacy statement — art. 13 + Ch. V GDPR
Multiple US CDNs on the form pagefonts.googleapis.com, fonts.gstatic.com, cdnjs.cloudflare.com, maxcdn.bootstrapcdn.com, cdn.tiny.cloudInternational transfer (US) undisclosed
No Content-Security-Policy response headerThe server sends no CSPNo defence in depth against XSS / injection
National registry number as <input type="text">Without autocomplete="off" on this sensitive fieldBrowser caching; art. 32 GDPR
HSTS present (1 year, includeSubDomains)Positive; no preload, but a solid baseOK

4. Recommended defence arguments

  • Invoke Article 82 GDPR (right to compensation) when unlawfully processed data is used.
  • Argue that the controller itself fails to meet its duty to inform, which affects the lawfulness of the processing.
  • Complaint possible with the Data Protection Authority (www.dataprotectionauthority.be).
Note: Analysis based on a public audit of gasrivierenland.be (April 2026). You can verify the findings yourself via your browser's DevTools.

Download this analysis as a PDF attachment for your contestation:

German-speaking Community (DG) — 9 municipalities Analysis available

Members (9): Amel (Amblève), Büllingen, Burg-Reuland, Bütgenbach, Eupen, Kelmis, Lontzen, Raeren, Sankt Vith. All located in the Liège province.

Who handles GAS fines for DG municipalities?

The DG itself does not issue GAS fines. For its 9 municipalities, GAS is handled either by the municipality itself or by the Liège provincial sanctioning officer. The Liège provincial analysis therefore also applies.

Special language guarantees

RightLegal basisApplication
Proceedings in GermanArt. 4 and 30 Constitution + 1966 Language ActContestation may be filed in German; decision must be issued in German.
Translation at the registryArt. 22 Judicial Languages ActThe Eupen police court sits in German.
Free interpreterArt. 6 ECHR + 1935 Language ActIf the issuing authority cannot provide German.

Recommended defences

  • Demand that all notifications, PVs and decisions be issued in German. Notifications in French or Dutch to DG residents may be null.
  • Appeal to the Eupen police court (not Verviers or Liège), which operates in German.
Note: The DG is not itself a GAS authority; also use the Liège provincial analysis.

Download this analysis:

WVI (West-Flanders Intercommunale) Analysis available

Website: wvi.be — Seat: Baron Ruzettelaan 35, 8310 Bruges.

GDPR and ePrivacy breaches

FindingLegal basisRisk
Privacy + cookie policy at /privacy-policy / /cookie-policy but no last-updated dateArt. 5(2) GDPRObsolescence unverifiable
No cookie banner on first visit (only a "Cookie settings" link)Art. 129 ECANo prior consent
No DPO name publishedArt. 37(7) GDPRFormal non-compliance
Footer social links without prior info on trackingArt. 13 + Art. 129 ECAThird-party trackers
External dev agency ("Hannibal") processor not listedArt. 13(1)(e) + Art. 28 GDPRTransparency + DPA
No section on international transfersArt. 13(1)(f) + Chapter VSchrems II — incomplete

Recommended defences

  • A "Cookie settings" link is not enough — prior consent is required.
  • Complaint possible with the DPA.
Note: Analysis of wvi.be (22 April 2026). 52 West-Flanders municipalities.

Download this analysis:

Bruges & surroundings (GAS zone) Analysis available

Website: brugge.be — Seat: Burg 12, 8000 Bruges.

GDPR and ePrivacy breaches

FindingLegal basisRisk
politiebrugge.be: Privacy & Cookie link without dateArt. 5(2) GDPRObsolescence unverifiable
No cookie banner on politiebrugge.beArt. 129 ECAePrivacy breach
No DPO name publishedArt. 37(7) GDPRFormal non-compliance
Police-zone coverage not listed on homepageArt. 12 GDPRTransparency failure
No cookie banner on brugge.beArt. 129 ECAePrivacy breach
No section on international transfersArt. 13(1)(f) + Chapter VSchrems II — incomplete

Recommended defences

  • The GAS fine is issued by the city but observation runs through the police zone — both data controllers must be GDPR-compliant, and neither is fully.
  • Complaint possible with the DPA.
Note: Analysis of brugge.be + politiebrugge.be (22 April 2026).

Download this analysis:

IDELUX Analysis available

Website: idelux.be — Seat: Drève de l’Arc-en-Ciel 98, 6700 Arlon.

GDPR and ePrivacy breaches

FindingLegal basisRisk
No visible granular cookie bannerArt. 129 ECAePrivacy breach
No explicit last-updated date on policyArt. 5(2) GDPRObsolescence unverifiable
No DPO name; only generic idelux@idelux.beArt. 37(7) GDPRFormal non-compliance
Social-media links (FB, LinkedIn, Instagram, Twitter, YouTube) without prior infoArt. 13 + Art. 129 ECAClick-triggered trackers
No section on international transfersArt. 13(1)(f) + Chapter VSchrems II — incomplete
No provision for minorsArt. 8 GDPRSpecial protection missing

Recommended defences

  • Lack of a valid cookie banner.
  • Complaint possible with the DPA.
Note: Analysis of idelux.be (22 April 2026).

Download this analysis:

INASEP Analysis available

Website: inasep.be — Seat: Rue des Viaux 1b, 5100 Naninne.

GDPR and ePrivacy breaches

FindingLegal basisRisk
No visible cookie bannerArt. 129 ECAePrivacy breach
Privacy policy present but no last-updated dateArt. 5(2) GDPRObsolescence unverifiable
No DPO name; only info@inasep.beArt. 37(7) GDPRFormal non-compliance
Site built by external agency ("Expansion") — processor not disclosedArt. 13(1)(e) + Art. 28 GDPRTransparency + DPA
No section on international transfersArt. 13(1)(f) + Chapter VSchrems II — incomplete
No provision for minorsArt. 8 GDPRSpecial protection missing

Recommended defences

  • Omission of "Expansion" as processor.
  • Complaint possible with the DPA.
Note: Analysis of inasep.be (22 April 2026).

Download this analysis:

BEP Analysis available

Website: bep.be — Seat: Avenue Sergent Vrithoff 2, 5000 Namur.

GDPR and ePrivacy breaches

FindingLegal basisRisk
"Charte de protection des données" last revised 26/11/2018 — over 7 years oldArt. 5(2) + Art. 24 GDPRSeverely outdated documentation
No visible cookie bannerArt. 129 ECAePrivacy breach
No DPO name publishedArt. 37(7) GDPRFormal non-compliance
Member municipalities not on the homepageArt. 12 GDPRTransparency failure
No section on international transfersArt. 13(1)(f) + Chapter VSchrems II — incomplete

Recommended defences

  • BEP uses a 2018 document — well before Schrems II (2020). Violates Art. 5(2).
  • Complaint possible with the DPA.
Note: Date 26/11/2018 quoted verbatim.

Download this analysis:

Intradel Analysis available

Website: intradel.be — Seat: Port de Herstal, 4040 Herstal.

GDPR and ePrivacy breaches

FindingLegal basisRisk
Privacy charter + cookie policy present but no visible dateArt. 5(2) GDPRObsolescence unverifiable
No cookie banner on first visitArt. 129 ECAePrivacy breach
No DPO name visibleArt. 37(7) GDPRFormal non-compliance
YouTube/social embeds without prior consentArt. 129 ECA + Art. 6 GDPRThird-party trackers
No section on international transfersArt. 13(1)(f) + Chapter VSchrems II — incomplete

Recommended defences

  • Documents exist but carry no date.
  • Complaint possible with the DPA.
Note: Analysis of intradel.be (22 April 2026).

Download this analysis:

TIBI (Charleroi) Analysis available

Website: tibi.be — Seat: Rue du Déversoir 1, 6010 Couillet.

GDPR and ePrivacy breaches

FindingLegal basisRisk
Cookie banner with only "J'accepte" — no reject button, no granular optionsArt. 129 ECA + DPA guidelines 2023Invalid consent model
No cookie categories or purposes shownArt. 13 GDPR + Art. 129 ECAConsent not informed
No DPO name or contactArt. 37(7) GDPRFormal non-compliance
No data-subject rights sectionArt. 13(2)(b)-(d) GDPRData subject uninformed
No date on legal noticesArt. 5(2) GDPRObsolescence unverifiable

Recommended defences

  • Strong ground: TIBI uses a banner without a reject option — the Belgian DPA has issued multiple decisions (notably 81/2023) condemning this practice.
  • Complaint possible with the DPA.
Note: Analysis of tibi.be (22 April 2026).

Download this analysis:

IPALLE Analysis available

Website: ipalle.be — Seat: Chemin de l’Eau Vive 1, 7503 Froyennes (Tournai).

GDPR and ePrivacy breaches

FindingLegal basisRisk
Privacy + legal notices + cookies present without visible dateArt. 5(2) GDPRObsolescence unverifiable
No visible granular cookie bannerArt. 129 ECAePrivacy breach
No DPO name publishedArt. 37(7) GDPRFormal non-compliance
No section on international transfersArt. 13(1)(f) + Chapter VSchrems II — incomplete
No provision for minorsArt. 8 GDPRSpecial protection missing

Recommended defences

  • No date on privacy documents.
  • Complaint possible with the DPA.
Note: Analysis of ipalle.be (22 April 2026).

Download this analysis:

HYGEA (Mons-Borinage) Analysis available

Website: hygea.be — Seat: Rue de la Biscuiterie 19, 7110 Houdeng-Goegnies.

GDPR and ePrivacy breaches

TLS certificate error detected — an automated check returned "unable to verify the first certificate" for hygea.be. For a public-facing site handling personal data, that is an immediate breach of Art. 32 GDPR (security of processing).
FindingLegal basisRisk
TLS certificate chain does not validateArt. 32 GDPRSecurity incident
Site content not reachable without bypassing the browser warningArt. 12 + 32 GDPRTransparency + security

Recommended defences

  • Strong ground: the TLS error is objectively verifiable and demonstrates a direct Art. 32 breach. Attach a screenshot of the browser warning.
  • Complaint possible with the DPA.
Note: Inspecting hygea.be on 22 April 2026 triggered an SSL/TLS error.

Download this analysis:

EcoWerf Analysis available

Website: ecowerf.be — Seat: Aarschotsesteenweg 210, 3012 Wilsele (Leuven).

GDPR and ePrivacy breaches

FindingLegal basisRisk
General privacy statement at /algemene-privacyverklaring present but no last-updated dateArt. 5(2) GDPRObsolescence unverifiable
No visible granular cookie bannerArt. 129 ECAePrivacy breach
Paddle CMS used; processor not listed in the privacy statementArt. 13(1)(e) + Art. 28 GDPRTransparency + DPA
No DPO name publishedArt. 37(7) GDPRFormal non-compliance
No section on international transfersArt. 13(1)(f) + Chapter VSchrems II — incomplete

Recommended defences

  • Paddle CMS not listed as processor.
  • Complaint possible with the DPA.
Note: Analysis of ecowerf.be (22 April 2026).

Download this analysis:

Leiedal Analysis available

Website: leiedal.be — Seat: President Kennedypark 10, 8500 Kortrijk.

GDPR and ePrivacy breaches

FindingLegal basisRisk
Terms + privacy + cookie policy present — no last-updated dateArt. 5(2) GDPRObsolescence unverifiable
No cookie banner on first visit (only a "Cookie preferences" link)Art. 129 ECANo prior consent
No DPO name publishedArt. 37(7) GDPRFormal non-compliance
Newsletter opt-in correctly worded (positive)Art. 6(1)(a) GDPROK
No section on international transfersArt. 13(1)(f) + Chapter VSchrems II — incomplete

Recommended defences

  • A "Cookie preferences" link is not enough — prior consent is still required for non-essential cookies.
  • Complaint possible with the DPA.
Note: Analysis of leiedal.be (22 April 2026).

Download this analysis:

IGEAN milieu & veiligheid — intergemeentelijke GAS-dienst Analysis available

Data controller: IGEAN milieu & veiligheid — Doornaardstraat 60, 2160 Wommelgem — Website: www.igean.be.

This annex is intended to supplement the contestation of a sanction or retribution by IGEAN milieu & veiligheid — intergemeentelijke GAS-dienst with a technical exposition. The findings were recorded on 22 August 2026 on www.igean.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=63072000 (2 years) + includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

IGEMO Analysis available

Website: igemo.be — Seat: Schoutetstraat 2, 2800 Mechelen. DPO: Sigrid Palmers — privacy@igemo.be.

1. Identified GDPR and ePrivacy breaches

FindingLegal basisRisk
Privacy statement last revised 23/06/2020 — more than 5 years oldArt. 5(2) + Art. 24 GDPRSeverely outdated documentation
“Analytics data kept for indefinite time”Art. 5(1)(e) GDPRUnlimited retention
Newsletter stored in MailChimp “for indefinite time”Art. 5(1)(e) + Art. 44 GDPRStorage limitation + US transfer
MailChimp, Combell, Microsoft named as processors but no SCCs or Schrems II measures documentedArt. 46 GDPR + Schrems IITransfer without legal basis
No section on international transfersArt. 13(1)(f) + Chapter VTransparency incomplete
No provision for minorsArt. 8 GDPRSpecial protection missing
No visible cookie banner with granular consentArt. 129 ECAePrivacy breach
Complaint form via Microsoft Forms without prior disclosure of US transferArt. 13 + Art. 46 GDPRTransparency + Schrems II

2. Breached GDPR articles (summary)

Art. 5(1)(e) — Storage limitation

Two explicit mentions of “indefinite” retention (analytics + newsletter) violate this principle.

Art. 5(2) — Accountability

A policy not updated since 2020 while processors have evolved is demonstrably in default.

Arts. 44-46 — International transfers (Schrems II)

MailChimp (Intuit, US) and Microsoft (US) explicitly named without documented SCCs or TIA.

Art. 129 ECA

No granular consent mechanism visible.

3. Recommended defences

  • Argue IGEMO has been in default for five years, undermining the credibility of its enforcement.
  • Schrems II (CJEU C-311/18) applies to Microsoft/MailChimp transfers without supplementary measures.
  • Complaint possible with the DPA.
Note: The date 23/06/2020 is quoted verbatim.

Download this analysis as a PDF annex:

IOK (Kempen) Analysis available

Website: iok.be — Seat: Antwerpseweg 1A bus 1, 2440 Geel. DPO contact: privacy@iok.be (via Welzijnszorg Kempen).

1. Identified GDPR and ePrivacy breaches

FindingLegal basisRisk
No explicit last-updated date on the privacy statementArt. 5(2) GDPRObsolescence unverifiable
DPO function outsourced without name of natural personArt. 37(7) GDPRFormal non-compliance
Retention periods only in non-public processing registerArt. 13(2)(a) GDPRInformation obligation breached
No section on international transfersArt. 13(1)(f) + Chapter VTransparency incomplete
No provision for minorsArt. 8 GDPRSpecial protection missing
No visible cookie banner with granular consentArt. 129 ECAePrivacy breach
Complaint right to DPA mentioned (positive)Art. 13(2)(d) GDPROK

2. Breached GDPR articles (summary)

Art. 13 — Information

Pointing to a non-public register for retention periods does not satisfy the information obligation.

Art. 37(7) — DPO

Outsourcing is permitted, but the name of the natural person in the role must be public.

Arts. 44-46 — Transfers

No mention of Schrems II safeguards.

Art. 129 ECA

No granular consent mechanism visible.

3. Recommended defences

  • Argue the reference to a non-public register violates Art. 13(2)(a) GDPR.
  • Complaint possible with the DPA.
  • Article 82 GDPR (compensation) if unlawful processing is proven.
Note: Analysis based on public inspection of iok.be (April 2026).

Download this analysis as a PDF annex:

Haviland (Halle-Vilvoorde) Analysis available

Website: haviland.be — Data controller: Haviland Regiopartners, Poverstraat 75 bus 47, 1731 Asse — Information security contact: informatieveiligheid@haviland.be.

Member municipalities (23): Affligem, Asse, Beersel, Dilbeek, Grimbergen, Kampenhout, Kapelle-op-den-Bos, Lennik, Liedekerke, Londerzeel, Machelen, Meise, Merchtem, Opwijk, Pepingen, Roosdaal, Sint-Pieters-Leeuw, Steenokkerzeel, Ternat, Vilvoorde, Wemmel, Zaventem, Zemst. Not every municipality participates in every GAS category (GAS 1-2-3, blue zone, GAS 4, GAS 5).

1. Identified GDPR and ePrivacy violations

A technical audit of haviland.be on 17 April 2026 reveals the following shortcomings against the GDPR, the Belgian Law of 30 July 2018, and art. 129 of the Electronic Communications Act.

FindingLegal basisRisk
Triple analytics stack: Google Analytics (_ga, _gat, _gid), Hotjar (_hjid) and Matomo (_pk_id, _pk_ses, ...) all active at onceArt. 5(1)(c) GDPR — proportionality & data minimisationExcessive processing
Direct contradiction: the privacy statement declares “no data outside the EU”, while Google Analytics and Hotjar transfer to the United StatesArt. 5(1)(a) GDPR — transparency & accuracy; Ch. V GDPRFalse declaration / transparency breach
AddThis cookies (__atuvc, __atuvs) still listed — AddThis was shut down by Oracle in May 2023Art. 5(2) GDPR — accountabilityOutdated documentation
Universal Analytics cookies (__utmb, __utmc, __utmz) listed, while UA was phased out by Google on 1 July 2023Art. 5(2) GDPRUnmaintained documentation
No retention periods for any cookieArt. 13(2)(a) GDPRPotentially unlimited storage
No DPO name or e-mail published (only a generic informatieveiligheid@ address)Art. 37 & 38 GDPRFormal non-compliance (public authority)
No certified CMP; no IAB TCF integrationBelgian DPA guidelines on cookies 2023No auditable consent records
Reference to “browser settings” to withdraw consentBelgian DPA opinion 2023 — not validInvalid withdrawal
No international transfer disclosure despite GA/Hotjar/YouTube usage (Google US transfer)Art. 13(1)(f) + Ch. V GDPRIncomplete transparency
No named processors (only categories “hosting/logistics/security”)Art. 13(1)(e) GDPRMissing recipient information

2. Key violations (summary)

Article 5(1)(a) — Transparency and accuracy

The privacy statement contains a factually incorrect claim: “Haviland Regiopartners does not share personal data with parties outside the EU”. This is incompatible with the use of Google Analytics, Hotjar and YouTube embeds, all of which transfer data to US processors.

Article 5(1)(c) — Data minimisation

Running three analytics systems in parallel (GA + Hotjar + Matomo) exceeds what is necessary by definition.

Article 129 ECA / ePrivacy — Cookies

Non-essential cookies are linked to a “pop-up”, but without granular category buttons, without a reject button on equal footing with accept, and without documented pre-tick status.

Articles 37 & 38 — DPO

Haviland is an inter-municipal body (public authority) and must appoint a DPO and publish their contact details. A generic informatieveiligheid@haviland.be address does not satisfy Article 37(7) GDPR.

3. Online forms — security

Findings from a technical audit of haviland.be/nl and haviland.be/nl/contact (April 2026). Note: the contact form is likely client-rendered (Paddle CMS); only the page wrapper is statically inspectable.

FindingDetailRisk
Social & tracking embeds load on every page (including the contact page)Before any consent, the site loads www.facebook.com, www.linkedin.com, www.youtube.com, www.googletagmanager.com and cdn.jsdelivr.netArt. 129 ECA + Ch. V GDPR (US transfer)
Google Tag Manager on every pageGTM loads Google Analytics at runtime — this explains the GA cookies listed, but simultaneously contradicts the “no data outside the EU” claimArt. 5(1)(a) GDPR — transparency & accuracy
No Content-Security-Policy response headerThe server sends no CSPNo defence in depth
Drupal “EU Cookie Compliance” module as cookie banner (no certified CMP)No IAB TCF integration; “Withdraw consent” button marked visually-hidden in the markupBelgian DPA 2023 guidelines not met
Drupal Form-API anti-CSRF (form_build_id + form_id)Present on the search forms; standard Drupal protectionPositive
HSTS present (2 years, includeSubDomains)Strong HSTS configurationPositive

4. Recommended defence arguments

  • Point to the demonstrable contradiction between the privacy policy and the cookie statement — this affects the lawfulness of the processing (Art. 6 GDPR).
  • Invoke Article 82 GDPR (right to compensation) for unlawful use of tracking without valid consent.
  • Complaint possible with the Data Protection Authority and the Flemish Supervisory Commission (both cited in the policy itself).
Note: Audit performed on 17 April 2026 against the publicly available pages /nl/privacy, /nl/home/cookieverklaring and /nl/home/gas-overtredingen. The privacy policy was last updated 5 January 2026, yet the cookie list still contains trackers retired since 2023. You can verify the findings yourself via your browser's DevTools.

Download this analysis as a PDF attachment for your contestation:

City of Brussels / Stad Brussel / Ville de Bruxelles Analysis available

Website: brussel.be — Contestation portal: brucity.cityenforcement.com — Data controller: City of Brussels (KBO 0207.373.429), Hallenstraat 4, 1000 Brussels — DPO: dpo@brucity.be.

Member municipality: City of Brussels. Contestation deadline: 10 calendar days from receipt of the payment invitation. A contestation does not suspend the payment obligation; non-payment adds €15 in administrative costs.

1. Identified GDPR and ePrivacy violations

Audit on 17 April 2026 of the pages brussel.be/parkeren-bezwaar-tegen-retributie, brussel.be/wettelijke-vermeldingen and the portal brucity.cityenforcement.com.

FindingLegal basisRisk
“Anonymous” claim on the form while plate + report reference are collectedArt. 4(1), 12 & 13 GDPR — DPA decision 56/2026Misleading the data subject
Privacy statement (version dated 18 June 2026) without parking-enforcement specificsArt. 5(2), 12 & 13 GDPROutdated transparency
Page /cookiebeleid returns HTTP 404Art. 129 ECADuty to inform breached
Social embeds (Facebook, Instagram, YouTube, TikTok, LinkedIn, Bluesky, Spotify) on the public pageArt. 129 ECATracking before consent
No Strict-Transport-Security, Content-Security-Policy, Referrer-Policy or Permissions-Policy on brussel.beArt. 32 GDPRNo defence in depth
The portal CSP allows Microsoft Azure Application Insights telemetrydc.services.visualstudio.com — transfer to a US processorCh. V GDPR, undisclosed
External processor cityenforcement; agreement not publicArt. 28(3) GDPR — DPA 29 Sept. 2023Retroactive contracts are invalid
No DPIA published for ANPR / scan vehiclesArt. 35 GDPR — DPA 129/2023, 56/2026High-risk processing without assessment
The portal does have strong security headers (CSP, HSTS preload, Referrer-Policy, Permissions-Policy)Art. 32 GDPRPositive

2. GDPR articles violated (summary)

Articles 12 & 13 GDPR — transparency and duty to inform

Labelling the form “anonymous” while collecting plate and report reference misleads the data subject. A licence plate is personal data (art. 4(1) GDPR).

Article 6 GDPR — legal basis

General municipal traffic competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for transferring plate data or deploying ANPR without a specific legal basis and a DPIA.

Article 28(3) GDPR — processor agreements

The DPA (29 Sept. 2023) held retroactive processor agreements invalid. The cityenforcement contract must exist prior to processing and be public.

Article 32 GDPR / art. 129 ECA — security and cookies

The absence of HSTS/CSP/Referrer-Policy/Permissions-Policy on brussel.be, combined with a 404 cookie page and social trackers loading before consent, constitutes a structural breach.

3. Online forms — security

FindingDetailRisk
The portal uses HSTS + preloadmax-age=31536000; includeSubDomains; preloadPositive
The portal has a strict CSP (default-src 'none') with form-action limited to self + Worldline paymentGood defence in depth; payment via payment-webinit.sips-services.comPositive
The portal is a SPAForm rendered client-side; audit requires runtime DevToolsInformational
Microsoft Azure telemetry allowed by the portal CSPdc.services.visualstudio.com — transfer to MicrosoftCh. V GDPR
brussel.be without HSTS/CSP/Referrer-Policy/Permissions-PolicySession cookie cookiesession1 with no documented Secure or SameSite attributesArt. 32 GDPR

4. Recommended defence arguments

  • Point to the factual contradiction between the anonymity claim and the collection of plate + report reference.
  • Invoke DPA decisions 56/2026 and 129/2023.
  • Demand production of the DPIA for ANPR/scan vehicles and a valid processor agreement with cityenforcement.
  • Complaint possible with the Belgian Data Protection Authority (Drukpersstraat 35, 1000 Brussels).
Note: Audit on 17 April 2026. The contested measure is a parking retribution (not a GAS fine or a criminal fine). Retributions fall entirely under the GDPR and cannot invoke the exceptions of Directive 2016/680 (law-enforcement).

Download this analysis as a PDF attachment for your contestation:

Province de Hainaut Analysis available

Data controller: Province de Hainaut — Bureau provincial des Amendes Administratives — Avenue Général de Gaulle 102, 7000 Mons — Website: www.hainaut.be.

This annex is intended to supplement the contestation of a sanction or retribution by Province de Hainaut with a technical exposition. The findings were recorded on 22 August 2026 on www.hainaut.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS present but max-age=15552000 < 1 year — below the recommended durationArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Only partial Content-Security-Policy (only frame-ancestors, report-uri)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant
tarteaucitron as CMP — positive, European alternativeArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Province de Liège Analysis available

Data controller: Province de Liège — Fonctionnaires sanctionnateurs provinciaux — Rue Ernest Solvay 11, 4000 Liège — Website: www.provincedeliege.be.

This annex is intended to supplement the contestation of a sanction or retribution by Province de Liège with a technical exposition. The findings were recorded on 22 August 2026 on www.provincedeliege.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Facebook, YouTube embeds presentArt. 129 WEC / LCE / GEK / ECABreach
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant
tarteaucitron as CMP — positive, European alternativeArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Province de Namur Analysis available

Data controller: Province de Namur — Bureau des amendes administratives — Rue Henri Blès 190C, 5000 Namur — Website: www.province.namur.be.

This annex is intended to supplement the contestation of a sanction or retribution by Province de Namur with a technical exposition. The findings were recorded on 22 August 2026 on www.province.namur.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS present but max-age=16000000 < 1 year — below the recommended durationArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Frame-Options and no frame-ancestors (clickjacking not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Province de Luxembourg Analysis available

Data controller: Province de Luxembourg — Service des amendes administratives — Place Léopold 1, 6700 Arlon — Website: www.province.luxembourg.be.

This annex is intended to supplement the contestation of a sanction or retribution by Province de Luxembourg with a technical exposition. The findings were recorded on 22 August 2026 on www.province.luxembourg.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS 2 years + includeSubDomains + preload — strong configurationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant
tarteaucitron as CMP — positive, European alternativeArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Province du Brabant wallon Analysis available

Data controller: Province du Brabant wallon — Fonctionnaire sanctionnateur — Place du Brabant wallon 1, 1300 Wavre — Website: www.brabantwallon.be.

This annex is intended to supplement the contestation of a sanction or retribution by Province du Brabant wallon with a technical exposition. The findings were recorded on 22 August 2026 on www.brabantwallon.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Mechelen Analysis available

Data controller: Stad Mechelen — Grote Markt 21, 2800 Mechelen — Website: www.mechelen.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Mechelen with a technical exposition. The findings were recorded on 22 August 2026 on www.mechelen.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Frame-Options and no frame-ancestors (clickjacking not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Server banner with version information (Unit/1.33.0)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville d'Arlon Analysis available

Data controller: Ville d'Arlon — Rue Paul Reuter 8, 6700 Arlon — Website: www.arlon.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville d'Arlon with a technical exposition. The findings were recorded on 22 August 2026 on www.arlon.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Saint-Josse-ten-Noode / Gemeente Sint-Joost-ten-Node Analysis available

Data controller: Commune de Saint-Josse-ten-Noode / Gemeente Sint-Joost-ten-Node — Avenue de l'Astronomie 13, 1210 Saint-Josse-ten-Noode — Website: www.sjtn.brussels.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Saint-Josse-ten-Noode / Gemeente Sint-Joost-ten-Node with a technical exposition. The findings were recorded on 22 August 2026 on www.sjtn.brussels and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Provincie Vlaams-Brabant Analysis available

Data controller: Provincie Vlaams-Brabant — Provincieplein 1, 3010 Leuven — Website: www.vlaamsbrabant.be.

This annex is intended to supplement the contestation of a sanction or retribution by Provincie Vlaams-Brabant with a technical exposition. The findings were recorded on 22 August 2026 on www.vlaamsbrabant.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS present but max-age=16070400 < 1 year — below the recommended durationArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Content-Security-Policy present but permissive (default-src allows https:, wildcards or 'unsafe-inline')Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: same-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Provincie Oost-Vlaanderen Analysis available

Data controller: Provincie Oost-Vlaanderen — Gouvernementstraat 1, 9000 Gent — Website: oost-vlaanderen.be.

This annex is intended to supplement the contestation of a sanction or retribution by Provincie Oost-Vlaanderen with a technical exposition. The findings were recorded on 22 August 2026 on oost-vlaanderen.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Provincie Limburg Analysis available

Data controller: Provincie Limburg — Universiteitslaan 1, 3500 Hasselt — Website: www.limburg.be.

This annex is intended to supplement the contestation of a sanction or retribution by Provincie Limburg with a technical exposition. The findings were recorded on 22 August 2026 on www.limburg.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Only partial Content-Security-Policy (only report-uri)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Weak Referrer-Policy: no-referrer-when-downgradeArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Uses Piwik PRO (EU-hosted analytics) instead of Google AnalyticsArt. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Ieper Analysis available

Data controller: Stad Ieper (KBO 0207.518.630) — Grote Markt 34, 8900 Ieper — Website: www.ieper.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Ieper with a technical exposition. The findings were recorded on 22 August 2026 on www.ieper.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Only partial Content-Security-Policy (only connect-src, font-src, frame-src)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Eeklo Analysis available

Data controller: Stad Eeklo (KBO 0207.461.616) — Industrielaan 2, 9900 Eeklo — Website: www.eeklo.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Eeklo with a technical exposition. The findings were recorded on 22 August 2026 on www.eeklo.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Only partial Content-Security-Policy (only connect-src, font-src, frame-src)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Halle Analysis available

Data controller: Stad Halle (KBO 0207.528.640) — Oudstrijdersplein 18, 1500 Halle — Website: www.halle.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Halle with a technical exposition. The findings were recorded on 22 August 2026 on www.halle.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS 2 years + includeSubDomains + preload — strong configurationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Only partial Content-Security-Policy (only upgrade-insecure-requests, frame-ancestors, script-src)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Hotjar session recording/heatmaps presentArt. 129 WEC / LCE / GEK / ECABreach
Use of CookieScript as CMP — positiveArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Tienen Analysis available

Data controller: Stad Tienen (KBO 0207.537.929) — Grote Markt 27, 3300 Tienen — Website: www.tienen.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Tienen with a technical exposition. The findings were recorded on 22 August 2026 on www.tienen.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS 2 years + includeSubDomains + preload — strong configurationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Dinant Analysis available

Data controller: Ville de Dinant (BCE 0207.360.125) — Rue Grande 112, 5500 Dinant — Website: www.dinant.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Dinant with a technical exposition. The findings were recorded on 22 August 2026 on www.dinant.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS 2 years + includeSubDomains + preload — strong configurationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Frame-Options and no frame-ancestors (clickjacking not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
YouTube embeds presentArt. 129 WEC / LCE / GEK / ECABreach
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Wavre Analysis available

Data controller: Ville de Wavre (BCE 0207.381.392) — Place de l'Hôtel de Ville, 1300 Wavre — Website: www.wavre.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Wavre with a technical exposition. The findings were recorded on 22 August 2026 on www.wavre.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Huy Analysis available

Data controller: Ville de Huy (BCE 0207.348.088) — Grand-Place 1, 4500 Huy — Website: www.huy.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Huy with a technical exposition. The findings were recorded on 22 August 2026 on www.huy.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville d'Ath Analysis available

Data controller: Ville d'Ath (BCE 0207.362.500) — Rue de Pintamont 54, 7800 Ath — Website: www.ath.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville d'Ath with a technical exposition. The findings were recorded on 22 August 2026 on www.ath.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Waterloo Analysis available

Data controller: Commune de Waterloo (BCE 0216.694.712) — Rue François Libert 28, 1410 Waterloo — Website: www.waterloo.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Waterloo with a technical exposition. The findings were recorded on 22 August 2026 on www.waterloo.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Deinze Analysis available

Data controller: Stad Deinze (KBO 0207.489.352) — Brielstraat 2, 9800 Deinze — Website: www.deinze.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Deinze with a technical exposition. The findings were recorded on 22 August 2026 on www.deinze.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Content-Security-Policy present but permissive (default-src allows https:, wildcards or 'unsafe-inline')Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune d'Ixelles / Gemeente Elsene Analysis available

Data controller: Commune d'Ixelles (BCE 0207.387.826) — Chaussée d'Ixelles 168, 1050 Ixelles — Website: www.ixelles.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Ixelles / Gemeente Elsene with a technical exposition. The findings were recorded on 22 August 2026 on www.ixelles.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Only partial Content-Security-Policy (only frame-ancestors)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune d'Uccle / Gemeente Ukkel Analysis available

Data controller: Commune d'Uccle (BCE 0207.393.074) — Place Jean Vander Elst 29, 1180 Uccle — Website: www.uccle.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Uccle / Gemeente Ukkel with a technical exposition. The findings were recorded on 22 August 2026 on www.uccle.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Server banner with version information (Apache/2.4.58 (Ubuntu))Art. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Forest / Gemeente Vorst Analysis available

Data controller: Commune de Forest (BCE 0207.387.529) — Rue du Curé 2, 1190 Forest — Website: www.forest.brussels.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Forest / Gemeente Vorst with a technical exposition. The findings were recorded on 22 August 2026 on www.forest.brussels and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Jette / Gemeente Jette Analysis available

Data controller: Commune de Jette (BCE 0207.389.804) — Chaussée de Wemmel 100, 1090 Jette — Website: jette.brussels.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Jette / Gemeente Jette with a technical exposition. The findings were recorded on 22 August 2026 on jette.brussels and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant
Use of Klaro as CMP — positiveArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Koekelberg / Gemeente Koekelberg Analysis available

Data controller: Commune de Koekelberg (BCE 0207.387.727) — Place Henri Vanhuffel 6, 1081 Koekelberg — Website: www.koekelberg.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Koekelberg / Gemeente Koekelberg with a technical exposition. The findings were recorded on 22 August 2026 on www.koekelberg.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Frame-Options and no frame-ancestors (clickjacking not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Server banner with version information (Microsoft-IIS/10.0)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
Google reCAPTCHA present (US processor, undocumented)Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Berchem-Sainte-Agathe / Gemeente Sint-Agatha-Berchem Analysis available

Data controller: Commune de Berchem-Sainte-Agathe (BCE 0207.386.240) — Avenue du Roi Albert 33, 1082 Berchem-Sainte-Agathe — Website: www.1082.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Berchem-Sainte-Agathe / Gemeente Sint-Agatha-Berchem with a technical exposition. The findings were recorded on 22 August 2026 on www.1082.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Frame-Options and no frame-ancestors (clickjacking not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Server banner with version information (Apache/2.4.62 (Win64) OpenSSL/3.1.7 PHP/8.3.14 mod_fcgid/2.3)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Facebook embeds presentArt. 129 WEC / LCE / GEK / ECABreach
Use of CookieYes as CMP — positiveArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Watermael-Boitsfort / Gemeente Watermaal-Bosvoorde Analysis available

Data controller: Commune de Watermael-Boitsfort (BCE 0207.393.470) — Place Antoine Gilson 1, 1170 Watermael-Boitsfort — Website: www.watermael-boitsfort.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Watermael-Boitsfort / Gemeente Watermaal-Bosvoorde with a technical exposition. The findings were recorded on 22 August 2026 on www.watermael-boitsfort.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune d'Evere / Gemeente Evere Analysis available

Data controller: Commune d'Evere (BCE 0207.384.064) — Square Hoedemaekers 10, 1140 Evere — Website: www.evere.brussels.

This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Evere / Gemeente Evere with a technical exposition. The findings were recorded on 22 August 2026 on www.evere.brussels and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Ganshoren / Gemeente Ganshoren Analysis available

Data controller: Commune de Ganshoren (BCE 0207.387.826) — Avenue Charles-Quint 140, 1083 Ganshoren — Website: www.ganshoren.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Ganshoren / Gemeente Ganshoren with a technical exposition. The findings were recorded on 22 August 2026 on www.ganshoren.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Google Maps (maps.googleapis.com) — US processorHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune d'Auderghem / Gemeente Oudergem Analysis available

Data controller: Commune d'Auderghem (BCE 0207.386.438) — Rue Emile Idiers 12, 1160 Auderghem — Website: www.auderghem.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Auderghem / Gemeente Oudergem with a technical exposition. The findings were recorded on 22 August 2026 on www.auderghem.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Woluwe-Saint-Lambert / Gemeente Sint-Lambrechts-Woluwe Analysis available

Data controller: Commune de Woluwe-Saint-Lambert (BCE 0207.397.034) — Avenue Paul Hymans 2, 1200 Woluwe-Saint-Lambert — Website: www.woluwe1200.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Woluwe-Saint-Lambert / Gemeente Sint-Lambrechts-Woluwe with a technical exposition. The findings were recorded on 22 August 2026 on www.woluwe1200.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Frame-Options and no frame-ancestors (clickjacking not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Woluwe-Saint-Pierre / Gemeente Sint-Pieters-Woluwe Analysis available

Data controller: Commune de Woluwe-Saint-Pierre (BCE 0207.395.153) — Avenue Charles Thielemans 93, 1150 Woluwe-Saint-Pierre — Website: www.woluwe1150.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Woluwe-Saint-Pierre / Gemeente Sint-Pieters-Woluwe with a technical exposition. The findings were recorded on 22 August 2026 on www.woluwe1150.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Only partial Content-Security-Policy (only frame-ancestors)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Facebook embeds presentArt. 129 WEC / LCE / GEK / ECABreach
Google reCAPTCHA present (US processor, undocumented)Hfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune d'Anderlecht / Gemeente Anderlecht Analysis available

Data controller: Commune d'Anderlecht (BCE 0207.393.470) — Place du Conseil 1, 1070 Anderlecht — Website: www.anderlecht.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Anderlecht / Gemeente Anderlecht with a technical exposition. The findings were recorded on 22 August 2026 on www.anderlecht.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Facebook embeds presentArt. 129 WEC / LCE / GEK / ECABreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Schaerbeek / Gemeente Schaarbeek Analysis available

Data controller: Commune de Schaerbeek (BCE 0207.377.988) — Place Colignon, 1030 Schaerbeek — Website: www.1030.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Schaerbeek / Gemeente Schaarbeek with a technical exposition. The findings were recorded on 22 August 2026 on www.1030.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Strict Content-Security-Policy (default-src 'self')Art. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune de Molenbeek-Saint-Jean / Gemeente Sint-Jans-Molenbeek Analysis available

Data controller: Commune de Molenbeek-Saint-Jean (BCE 0207.391.193) — Rue du Comte de Flandre 20, 1080 Molenbeek-Saint-Jean — Website: www.molenbeek.irisnet.be.

This annex is intended to supplement the contestation of a sanction or retribution by Commune de Molenbeek-Saint-Jean / Gemeente Sint-Jans-Molenbeek with a technical exposition. The findings were recorded on 22 August 2026 on www.molenbeek.irisnet.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Frame-Options and no frame-ancestors (clickjacking not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Commune d'Etterbeek Analysis available

Data controller: Commune d'Etterbeek (BCE 0207.383.274) — Avenue d'Auderghem 113-117, 1040 Etterbeek — Website: etterbeek.brussels.

This annex is intended to supplement the contestation of a sanction or retribution by Commune d'Etterbeek with a technical exposition. The findings were recorded on 22 August 2026 on etterbeek.brussels and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Turnhout Analysis available

Data controller: Stad Turnhout (KBO 0207.537.434) — Campus Blairon 200, 2300 Turnhout — Website: www.turnhout.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Turnhout with a technical exposition. The findings were recorded on 22 August 2026 on www.turnhout.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=63072000 (2 years) + includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Strict Content-Security-Policy (default-src 'self')Art. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Use of Klaro as CMP — positiveArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Beringen Analysis available

Data controller: Stad Beringen (KBO 0207.525.461) — Mijnschoolstraat 88, 3580 Beringen — Website: www.beringen.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Beringen with a technical exposition. The findings were recorded on 22 August 2026 on www.beringen.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Only partial Content-Security-Policy (only connect-src, font-src, frame-src)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Lommel Analysis available

Data controller: Stad Lommel (KBO 0207.519.026) — Hertog Janplein 1, 3920 Lommel — Website: www.lommel.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Lommel with a technical exposition. The findings were recorded on 22 August 2026 on www.lommel.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Only partial Content-Security-Policy (only connect-src, font-src, frame-src)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Geel Analysis available

Data controller: Stad Geel (KBO 0207.524.966) — Werft 20, 2440 Geel — Website: www.geel.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Geel with a technical exposition. The findings were recorded on 22 August 2026 on www.geel.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Content-Security-Policy present but permissive (default-src allows https:, wildcards or 'unsafe-inline')Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Mouscron Analysis available

Data controller: Ville de Mouscron (BCE 0207.356.899) — Grand-Place 1, 7700 Mouscron — Website: www.mouscron.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Mouscron with a technical exposition. The findings were recorded on 22 August 2026 on www.mouscron.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Kortrijk Analysis available

Data controller: Stad Kortrijk (KBO 0207.494.678) — Grote Markt 54, 8500 Kortrijk — Website: www.kortrijk.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Kortrijk with a technical exposition. The findings were recorded on 22 August 2026 on www.kortrijk.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Maps (maps.googleapis.com) — US processorHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant
Use of Klaro as CMP — positiveArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Oostende Analysis available

Data controller: Stad Oostende (KBO 0207.473.295) — Vindictivelaan 1, 8400 Oostende — Website: www.oostende.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Oostende with a technical exposition. The findings were recorded on 22 August 2026 on www.oostende.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Only partial Content-Security-Policy (only connect-src, font-src, frame-src)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Sint-Niklaas Analysis available

Data controller: Stad Sint-Niklaas (KBO 0207.486.859) — Grote Markt 1, 9100 Sint-Niklaas — Website: www.sint-niklaas.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Sint-Niklaas with a technical exposition. The findings were recorded on 22 August 2026 on www.sint-niklaas.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
Use of Cookiebot as CMP — positiveArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Aalst Analysis available

Data controller: Stad Aalst (KBO 0207.449.148) — Grote Markt 3, 9300 Aalst — Website: aalst.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Aalst with a technical exposition. The findings were recorded on 22 August 2026 on aalst.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Genk Analysis available

Data controller: Stad Genk (KBO 0207.522.491) — Stadsplein 1, 3600 Genk — Website: www.genk.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Genk with a technical exposition. The findings were recorded on 22 August 2026 on www.genk.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Only partial Content-Security-Policy (only connect-src, frame-src, img-src 'self')Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Roeselare Analysis available

Data controller: Stad Roeselare (KBO 0207.490.219) — Botermarkt 2, 8800 Roeselare — Website: www.roeselare.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Roeselare with a technical exposition. The findings were recorded on 22 August 2026 on www.roeselare.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS present but max-age=15552000 < 1 year — below the recommended durationArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant
Use of Klaro as CMP — positiveArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Tournai Analysis available

Data controller: Ville de Tournai (BCE 0207.352.297) — Rue Saint-Martin 52, 7500 Tournai — Website: www.tournai.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Tournai with a technical exposition. The findings were recorded on 22 August 2026 on www.tournai.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=63072000 without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Weak Referrer-Policy: no-referrer-when-downgradeArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de La Louvière Analysis available

Data controller: Ville de La Louvière (BCE 0207.382.086) — Place Communale 1, 7100 La Louvière — Website: www.lalouviere.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de La Louvière with a technical exposition. The findings were recorded on 22 August 2026 on www.lalouviere.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Seraing Analysis available

Data controller: Ville de Seraing (BCE 0207.335.221) — Place Communale 8, 4100 Seraing — Website: www.seraing.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Seraing with a technical exposition. The findings were recorded on 22 August 2026 on www.seraing.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31536000 (1 year) without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Weak Referrer-Policy: no-referrer-when-downgradeArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Frame-Options and no frame-ancestors (clickjacking not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
tarteaucitron as CMP — positive, European alternativeArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Verviers Analysis available

Data controller: Ville de Verviers (BCE 0207.356.048) — Place du Marché 55, 4800 Verviers — Website: www.verviers.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Verviers with a technical exposition. The findings were recorded on 22 August 2026 on www.verviers.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Liège Analysis available

Data controller: Ville de Liège (BCE 0207.343.238) — Place du Marché 2, 4000 Liège — Website: www.liege.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Liège with a technical exposition. The findings were recorded on 22 August 2026 on www.liege.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
YouTube embeds presentArt. 129 WEC / LCE / GEK / ECABreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Namur Analysis available

Data controller: Ville de Namur (BCE 0207.341.854) — Hôtel de Ville, 5000 Namur — Website: www.namur.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Namur with a technical exposition. The findings were recorded on 22 August 2026 on www.namur.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
YouTube embeds presentArt. 129 WEC / LCE / GEK / ECABreach

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Mons Analysis available

Data controller: Ville de Mons (BCE 0207.272.119) — Grand-Place 22, 7000 Mons — Website: www.mons.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Mons with a technical exposition. The findings were recorded on 22 August 2026 on www.mons.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with includeSubDomains (1 year) — solid baselineArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Ville de Charleroi Analysis available

Data controller: Ville de Charleroi (BCE 0207.362.105) — Place Charles II 14-15, 6000 Charleroi — Website: www.charleroi.be.

This annex is intended to supplement the contestation of a sanction or retribution by Ville de Charleroi with a technical exposition. The findings were recorded on 22 August 2026 on www.charleroi.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Weak Referrer-Policy: no-referrer-when-downgradeArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No X-Content-Type-Options: nosniffArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Server banner with version information (Apache/2.4.68 (Debian))Art. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Antwerpen Analysis available

Data controller: Stad Antwerpen (KBO 0207.500.123) — Dienst Mobiliteit & Parkeren — Grote Markt 1, 2000 Antwerpen — Website: www.antwerpen.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Antwerpen with a technical exposition. The findings were recorded on 22 August 2026 on www.antwerpen.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS present but max-age=15552000 < 1 year — below the recommended durationArt. 32 AVG / RGPD / DSGVO / GDPRInformational
Strict Content-Security-Policy (default-src 'self')Art. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Content-Security-Policy contains an invalid directive (undefined)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Correct Referrer-Policy: no-referrerArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Gent Analysis available

Data controller: Stad Gent (KBO 0207.451.227) — Botermarkt 1, 9000 Gent — Website: stad.gent.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Gent with a technical exposition. The findings were recorded on 22 August 2026 on stad.gent and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS 2 years + includeSubDomains + preload — strong configurationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Strict Content-Security-Policy (default-src 'self')Art. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Permissions-Policy header present — restricts sensors/geolocationArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
Google Tag Manager loads Google Analytics at runtime (US transfer)Art. 5(1)(a) + Hfd. V AVG / Ch. V / Kap. V / Ch. VBreach
Use of CookieYes as CMP — positiveArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Brugge Analysis available

Data controller: Stad Brugge (KBO 0207.528.035) — Burg 12, 8000 Brugge — Website: www.brugge.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Brugge with a technical exposition. The findings were recorded on 22 August 2026 on www.brugge.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
HSTS with max-age=31557600 without includeSubDomainsArt. 32 AVG / RGPD / DSGVO / GDPRInformational
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Correct Referrer-Policy: strict-origin-when-cross-originArt. 32 AVG / RGPD / DSGVO / GDPR✓ Compliant
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Uses Matomo (more privacy-friendly than Google Analytics)Art. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant
Use of CookieScript as CMP — positiveArt. 129 WEC / LCE / GEK / ECA✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Leuven Analysis available

Data controller: Stad Leuven (KBO 0207.475.077) — Professor Van Overstraetenplein 1, 3000 Leuven — Website: www.leuven.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Leuven with a technical exposition. The findings were recorded on 22 August 2026 on www.leuven.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Content-Security-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.

Stad Hasselt Analysis available

Data controller: Stad Hasselt (KBO 0207.476.069) — Groenplein 1, 3500 Hasselt — Website: www.hasselt.be.

This annex is intended to supplement the contestation of a sanction or retribution by Stad Hasselt with a technical exposition. The findings were recorded on 22 August 2026 on www.hasselt.be and indicate shortcomings in GDPR, ePrivacy and security of processing.

1. Identified shortcomings

FindingLegal basisRisk
No Strict-Transport-Security response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
Only partial Content-Security-Policy (only frame-ancestors, report-uri)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
No Referrer-Policy response headerArt. 32 AVG / RGPD / DSGVO / GDPRBreach
No Permissions-Policy header (sensors/geolocation not restricted)Art. 32 AVG / RGPD / DSGVO / GDPRInformational
Google Fonts (fonts.googleapis.com) — undisclosed US transferHfd. V AVG / Ch. V RGPD / Kap. V DSGVO / Ch. V GDPRBreach
Uses Piwik PRO (EU-hosted analytics) instead of Google AnalyticsArt. 5(1)(c) AVG / GDPR / DSGVO✓ Compliant

2. Legal qualification

Article 5(1)(a) GDPR — transparency

Data subjects must be informed transparently and fairly about the processing; missing or inaccurate technical security undermines this duty.

Article 6 GDPR — legal basis

General municipal competences cannot, after DPA decision 56/2026 (Dilbeek), serve as a legal basis for data transfers or ANPR use without a specific legal basis and a DPIA.

Chapter V GDPR — transfers

Using US processors (GA, GTM, Google Fonts, Facebook, LinkedIn, ...) implies a US transfer which, without an appropriate safeguard (Ch. V GDPR), is unlawful.

Article 32 GDPR — security

The absence of appropriate technical measures (HSTS, CSP, Referrer-Policy) is not compatible with article 32 GDPR for a public platform processing personal data.

Article 129 ECA — ePrivacy

Non-essential cookies, social embeds and other trackers require prior, informed, specific and granular consent; a reference to browser settings is insufficient.

3. Recommended defence arguments

  • the contested sanction be set aside or reformed for unlawful processing of personal data;
  • the identified technical shortcomings be placed on record;
  • in the alternative, that a fresh review be conducted on the basis of lawfully obtained data;
  • the data subject's right to lodge a complaint with the Belgian Data Protection Authority be preserved;
  • the reservation of the right to compensation under article 82 GDPR be acknowledged.
Note: Audit on 22 August 2026 of the public landing page. The contested measure is a parking retribution or municipal administrative (GAS) fine that falls fully under the GDPR. You can verify the findings yourself via your browser's DevTools.
Geen juridisch advies — enkel redactionele bijstand
Over ons Impressum Algemene voorwaarden Privacybeleid Disclaimer Cookiebeleid Beveiliging
© 2026 PVResponse.be