PVResponse.be
Contact Steden GBA & AVG JustOnWeb Voorbeeld Procedure FAQ Beveiliging Inloggen Registreren

1. Introduction

A technical analysis of the Belgian government platform https://fines.justonweb.be reveals that the website violates multiple provisions of the General Data Protection Regulation (GDPR) and the Belgian Law of 30 July 2018. The platform's privacy statement does not match the technical reality. This page documents our findings.

2. Privacy statement vs. reality

The privacy statement (dated 12/12/2025, article 13) claims the website uses only session storage and no cookies. Technical inspection via browser developer tools proves this is factually incorrect.

In addition to session storage, the platform actively uses Local Storage — a persistent storage mechanism that persists after closing the browser and which the data controller conceals.

Data found in Local Storage

KeyDescriptionRisk
tokenJWT authentication tokenSession hijacking, unauthorised access
loggedInEideID-based user identificationTraceable to national registry number
eldPvNumberOfficial report numberLink to criminal case file
selectedMyFinesList of fines (base64)Financial personal data, persistent
infractionTypeType of infractionBehavioural data persists beyond session
detailedPageRedirectionNavigation behaviourBehavioural tracking outside session

3. GDPR articles violated

Article 13 — Duty to inform

The data controller must fully and accurately inform the data subject. The privacy statement is factually incorrect. The data subject could not provide informed consent.

Article 5(1)(a) — Transparency principle

The privacy statement provides a false representation of the actual data processing activities.

Article 5(1)(b) — Purpose limitation

JWT tokens and eID identification stored persistently in Local Storage go beyond what is strictly necessary. This suggests a processing purpose that was not disclosed and for which no legal basis was provided.

Article 5(1)(c) — Data minimisation

Persistently storing authentication tokens, national registry numbers and case data beyond the session lifecycle is disproportionate.

Article 32 — Security of processing

JWT tokens in Local Storage are a recognised security risk (OWASP), vulnerable to Cross-Site Scripting (XSS) attacks.

Article 5(2) — Accountability

By publishing a factually incorrect privacy statement while processing personal data via Local Storage, the accountability obligation has been violated.

4. Missing cookie policy (HTTP 404)

The website refers to a cookie policy at https://fines.justonweb.be/Cookie%20policy.pdf. This URL returns an HTTP 404 error — the document does not exist.

5. Contradictions in own terms of use

“FPS Justice does its utmost to ensure the information provided is complete, correct, accurate and up to date.”

— Terms of use justonweb.be, article II

This accuracy commitment applies equally to the privacy statement. Furthermore, Article 82 GDPR is mandatory European law that cannot be excluded by a unilateral liability limitation clause.

6. Structural lack of diligence

The accessibility statement was last reviewed on 19/04/2022, based solely on automated testing. The pattern — an outdated accessibility statement, an inaccurate privacy statement, a non-existent cookie policy — points to systematic negligence.

7. Consequences

Citizens are legally required to use this platform to process financial sanctions, while the platform fails to comply with its own privacy obligations. The data processed:

  • Was not processed in accordance with the GDPR and the Belgian Law of 30 July 2018
  • Was obtained without valid, informed consent
  • May have been exposed to security risks due to unsafe storage methods

Download the full analysis document as an attachment for your contestation:

Note: This analysis is based on technical evidence obtained via the built-in browser developer tools (DevTools > Application > Storage) and on the publicly published privacy statement of fines.justonweb.be dated 12/12/2025. You can verify these findings yourself.
Geen juridisch advies — enkel redactionele bijstand
Over ons Impressum Algemene voorwaarden Privacybeleid Disclaimer Cookiebeleid Beveiliging
© 2026 PVResponse.be