Blog
Articles on GDPR compliance, European cloud alternatives, third-party risk, and practical guidance for reducing your website's dependency on US-owned services.
- Digital sovereignty
Europe wants tech sovereignty. Most companies don't even know what their websites load.
Digital sovereignty is usually discussed in terms of cloud, AI and chips. But dependency is also visible much closer to the surface — in the connections a website makes when someone visits it. A look at the four kinds of dependency, and one real scan of a large European software company.
- Audit
What loads on 10 Norwegian telecom and fibre sites, before and after consent
A before-and-after consent audit of ten well-known Norwegian mobile, broadband and fibre providers. The most surprising finding: a B2B infrastructure company with a heavy programmatic ad stack running before the user clicked anything.
- Audit
What loads on 10 Norwegian municipality sites, before and after consent
A before-and-after consent audit of ten large Norwegian municipalities. The range was enormous: from a perfect EU score with 6 third-party domains to a public site running Meta Pixel with no visible consent choice in the test.
- Audit
What loads on 10 Norwegian news sites, before and after consent
A before-and-after consent audit of ten major Norwegian news publishers. On the most extreme sites, the post-consent sample ended with 91 to 140 cookies and 41 to 53 vendors after a single click.
- Methodology
Why StackPatrol does not show Stripe, Resend or your other backend services
If you scan your own site and notice that obvious tools like Stripe, Resend, SendGrid or Postmark are missing from the report, that is expected behaviour. Here is why, and what to do about it.
- GDPR
Your website probably has more US data processors than you realize
Most European websites unknowingly contact US-owned services on every page load. Here is how to find them and what GDPR requires you to do about it.