1. Introduction
A technical analysis of the Belgian government platform https://fines.justonweb.be reveals that the website violates multiple provisions of the General Data Protection Regulation (GDPR) and the Belgian Law of 30 July 2018. The platform's privacy statement does not match the technical reality. This page documents our findings.
2. Privacy statement vs. reality
The privacy statement (dated 12/12/2025, article 13) claims the website uses only session storage and no cookies. Technical inspection via browser developer tools proves this is factually incorrect.
In addition to session storage, the platform actively uses Local Storage — a persistent storage mechanism that persists after closing the browser and which the data controller conceals.
Data found in Local Storage
| Key | Description | Risk |
|---|---|---|
token | JWT authentication token | Session hijacking, unauthorised access |
loggedInEid | eID-based user identification | Traceable to national registry number |
eldPvNumber | Official report number | Link to criminal case file |
selectedMyFines | List of fines (base64) | Financial personal data, persistent |
infractionType | Type of infraction | Behavioural data persists beyond session |
detailedPageRedirection | Navigation behaviour | Behavioural tracking outside session |
3. GDPR articles violated
Article 13 — Duty to inform
The data controller must fully and accurately inform the data subject. The privacy statement is factually incorrect. The data subject could not provide informed consent.
Article 5(1)(a) — Transparency principle
The privacy statement provides a false representation of the actual data processing activities.
Article 5(1)(b) — Purpose limitation
JWT tokens and eID identification stored persistently in Local Storage go beyond what is strictly necessary. This suggests a processing purpose that was not disclosed and for which no legal basis was provided.
Article 5(1)(c) — Data minimisation
Persistently storing authentication tokens, national registry numbers and case data beyond the session lifecycle is disproportionate.
Article 32 — Security of processing
JWT tokens in Local Storage are a recognised security risk (OWASP), vulnerable to Cross-Site Scripting (XSS) attacks.
Article 5(2) — Accountability
By publishing a factually incorrect privacy statement while processing personal data via Local Storage, the accountability obligation has been violated.
4. Missing cookie policy (HTTP 404)
The website refers to a cookie policy at https://fines.justonweb.be/Cookie%20policy.pdf. This URL returns an HTTP 404 error — the document does not exist.
5. Contradictions in own terms of use
“FPS Justice does its utmost to ensure the information provided is complete, correct, accurate and up to date.”
This accuracy commitment applies equally to the privacy statement. Furthermore, Article 82 GDPR is mandatory European law that cannot be excluded by a unilateral liability limitation clause.
6. Structural lack of diligence
The accessibility statement was last reviewed on 19/04/2022, based solely on automated testing. The pattern — an outdated accessibility statement, an inaccurate privacy statement, a non-existent cookie policy — points to systematic negligence.
7. Consequences
Citizens are legally required to use this platform to process financial sanctions, while the platform fails to comply with its own privacy obligations. The data processed:
- Was not processed in accordance with the GDPR and the Belgian Law of 30 July 2018
- Was obtained without valid, informed consent
- May have been exposed to security risks due to unsafe storage methods
Download the full analysis document as an attachment for your contestation: