Skip to content
StackPatrol
Sample · paid report

This is what a paid StackPatrol report delivers.

A real 20-page, consent-aware scan of www.dagbladet.no showing the vendor map, region breakdown, cookies, third-party hosts, the hosting/email/DNS infrastructure jurisdiction, Data Privacy Framework status, the consent-aware delta and per-vendor “found on” evidence. The free scan covers up to 2 pages and omits the paid-only sections; a paid report on your own site will look exactly like this, with your data.

Scan your siteNo login required
EU-owned siteOwned by Aller Media (Denmark / Norway)

This site is itself owned by a EU-based company, so most requests it makes are first-party. The stack below still lists the third-party vendors it embeds — but note that the EU Independence Score also weighs the site’s own ownership, not just those vendors.

In plain English

Before a visitor interacts with the consent banner, this page contacts 47 third-party hostnames belonging to 33 vendors we recognise plus 4 unmatched domains. Of those vendors, 14 are US-owned, 16 Europe-based and 3 other / global. After clicking “Accept all”, +19 additional vendors and +98 cookies appear, bringing the totals to 52 vendors and 118 cookies.

Before consent(what loads before the visitor clicks “Accept”)
Hostnames contacted
47
distinct third-party domains
Vendors recognised
33
+ 4 unmatched
Cookies set
20
during the scan
EU score
0
/ 100 · Heavily non-EU dependent
Vendor ownership breakdown(sums to 33 recognised vendors)
US-owned
14
Europe-based
16
Other / global
3
After accepting consent banner(what a visitor who clicks “Accept all” actually loads)
Hostnames contacted
129
+82
distinct third-party domains
Vendors recognised
52
+19
+ 4 unmatched
US-owned vendors
30
+16
of 52 recognised
Cookies set
118
+98
during the scan
Total transfer: 43.1 MB1766 HTTP requests across 20 pages
Want a deeper performance audit? Run PageSpeed Insights
EU Independence Score
0
/ 100
Heavily non-EU dependent
Medium confidence

An experimental signal computed from detected third parties. 14 US-owned vendors detected. Score reflects jurisdiction risk weighted by what each vendor does. Not a compliance rating. Non-EU-owned hosting, email or DNS infrastructure was also factored in.

Score breakdown
  • Baseline
    +100
  • Vendor risk, jurisdiction × category (14 groups)
    Alphabet (4 services), Magnite (Rubicon Project), PubMatic, Xandr / AppNexus, … — capped at −60
    -60
  • Non-EU vendor ratio (52% of classified)
    17 of 33 classified vendors are significantly non-EU owned.
    -10
  • Unmatched third-party domains (4)
    -16
  • Non-EU infrastructure
    hosting (Cloudflare); email (Microsoft 365); DNS (Cloudflare)
    -17
  • Total0

A StackPatrol-defined sovereignty indicator, not an industry standard or compliance score.

Key findings

What to check first, and the suggested next step for each.

  1. 2 trackers kept firing after "Reject all"
    High
    Google Analytics and Google Ad Manager continued sending requests after the reject button was clicked. Check whether they should load before consent.
    Next step: Reproduce the reject flow, then ask your CMP or developer to gate these tags so they stay blocked when consent is refused.
  2. 18 third-party trackers loaded before consent
    Medium
    Adform, Adnuntius and Echobox +15 more fired on a no-interaction page load, before any consent banner was answered.
    Next step: Move these tags behind the consent banner so they only load after the visitor opts in.
  3. 14 US-owned vendors in the stack
    Medium
    US-owned services can be subject to US surveillance law. Confirm a transfer mechanism (DPF, SCCs) is in place for each.
    Next step: For each US-owned vendor, record its DPF certification or SCCs in your processing register, or line up a European alternative.
  4. 4 vendors not named in policy documents
    Medium
    Observed loading but not found in the crawled cookie/privacy documents. A starting point for review — text matching can miss a disclosure.
    Next step: Check each vendor against your cookie and privacy policy, and add any that are genuinely missing.
  5. Core infrastructure runs through US-owned providers
    Low
    hosting, email and DNS sit with US-owned companies — relevant to CLOUD Act exposure, independent of server location.
    Next step: Note these providers in your transfer register alongside their region and DPF status; weigh EU-owned hosting or email if exposure matters.

Technical observations from an automated scan, ordered by likely impact. Not legal advice — each item is a starting point for review, not a compliance verdict.

Processor & transfer register

A first-draft recipient list for your Art. 30 records and transfer assessment: every external service we observed, grouped by whether data leaves the EEA and whether it fired before or after consent.

Exposure matrix

Within EEAAdequacy mechanismNo adequacy / unknown
Before consent16710
After consent only3412

Cells count observed recipients. This is an exposure overview to help you prioritise — not a GDPR risk rating.

Recipients52

  • i18nexus
    Before consent
    JS Library / CDNUS-owned
    US — DPF status unknown
  • Index Exchange (Casale Media)
    Before consent
    AdvertisingUnknown
    No adequacy decision / unknown
  • jsDelivr
    Before consent
    CDN / HostingGlobal
    No adequacy decision / unknown
  • JW Player
    Before consent
    Video / EmbedUS-owned
    US — DPF status unknown
  • Magnite (Rubicon Project)
    Before consent
    AdvertisingUS-owned
    US — DPF status unknown
  • Maze
    Before consent
    Product AnalyticsUS-owned
    US — DPF status unknown
  • PubMatic
    Before consent
    AdvertisingUS-owned
    US — DPF status unknown
  • SmartyAds
    Before consent
    AdvertisingUnknown
    No adequacy decision / unknown
  • Sourcepoint
    Before consent
    Cookie ConsentUS-owned
    US — DPF status unknown
  • Xandr / AppNexus
    Before consent
    AdvertisingUS-owned
    US — DPF status unknown
  • Adobe (Marketing / Analytics)
    After consent
    Product AnalyticsUS-owned
    US — DPF status unknown
  • Integral Ad Science
    After consent
    AdvertisingUS-owned
    US — DPF status unknown
  • LiveRamp
    After consent
    AdvertisingUS-owned
    US — DPF status unknown
  • MGID
    After consent
    AdvertisingUS-owned
    US — DPF status unknown
  • Nielsen eXelate
    Nielsen
    After consent
    AdvertisingUS-owned
    US — DPF status unknown
  • OpenX
    After consent
    AdvertisingUS-owned
    US — DPF status unknown
  • reCAPTCHA
    After consent
    Security / Bot ProtectionUS-owned
    US — DPF status unknown
  • Sharethrough
    After consent
    AdvertisingUS-owned
    US — DPF status unknown
  • Sovrn
    After consent
    AdvertisingUS-owned
    US — DPF status unknown
  • The Trade Desk
    After consent
    AdvertisingUS-owned
    US — DPF status unknown
  • TripleLift
    After consent
    AdvertisingUS-owned
    US — DPF status unknown
  • Yieldmo
    After consent
    AdvertisingUS-owned
    US — DPF status unknown
  • AWS CloudFront
    Amazon
    Before consent
    CDN / HostingUS-owned
    US — DPF self-certified
    Verified 8 Jul 2026 · Amazon.com, Inc.
  • Cloudflare
    Before consent
    CDN / HostingUS-owned
    US — DPF self-certified
    Verified 8 Jul 2026 · Cloudflare, Inc.
  • Google Analytics
    Alphabet
    Before consent
    AnalyticsUS-owned
    US — DPF self-certified
  • Google APIs / GStatic
    Alphabet
    Before consent
    CDN / HostingUS-owned
    US — DPF self-certified
  • Google Fonts
    Alphabet
    Before consent
    FontsUS-owned
    US — DPF self-certified
  • Google Publisher Tag
    Alphabet
    Before consent
    AdvertisingUS-owned
    US — DPF self-certified
  • Zendesk
    Before consent
    Customer SupportUS-owned
    US — DPF self-certified
  • Amazon Ads
    Amazon
    After consent
    AdvertisingUS-owned
    US — DPF self-certified
  • Google (search / misc)
    Alphabet
    After consent
    JS Library / CDNUS-owned
    US — DPF self-certified
  • Google Ad Traffic Quality
    Alphabet
    After consent
    Security / Bot ProtectionUS-owned
    US — DPF self-certified
  • LinkedIn Insight Tag
    Microsoft
    After consent
    AdvertisingUS-owned
    US — DPF self-certified
  • Adform
    Before consent
    AdvertisingEU
    Within EEA
  • Adnuntius
    Before consent
    AdvertisingEU
    Within EEA
  • Aller Media
    Before consent
    CDN / HostingEU
    Within EEA
  • Bunny.net
    Before consent
    CDN / HostingEU
    Within EEA
  • Dagbladet apps (Aller Media)
    Aller Media
    Before consent
    CDN / HostingEEA
    Within EEA
  • Dagbladet static (dbstatic.no)
    Before consent
    CDN / HostingEU
    Within EEA
  • Echobox
    Before consent
    AnalyticsEU
    Within EEA
  • Improve Digital (360yield)
    Before consent
    AdvertisingEU
    Within EEA
  • Kilkaya
    Before consent
    AnalyticsEU
    Within EEA
  • Mediaconnect
    Before consent
    Marketing AutomationEEA
    Within EEA
  • Medialaben
    Before consent
    AdvertisingEU
    Within EEA
  • Medietall
    Before consent
    AnalyticsEU
    Within EEA
  • NIFS (Norsk og Internasjonal Fotball-Statistikk)
    Before consent
    Video / EmbedEEA
    Within EEA
  • Norsk Tipping Partner
    Norsk Tipping
    Before consent
    AffiliateEEA
    Within EEA
  • NTB (Norsk Telegrambyrå)
    Before consent
    Video / EmbedEEA
    Within EEA
  • Readpeak
    Before consent
    AdvertisingEU
    Within EEA
  • OnAudience
    After consent
    AdvertisingEU
    Within EEA
  • Semasio
    After consent
    AdvertisingEU
    Within EEA
  • Smart AdServer / Equativ
    After consent
    AdvertisingEU
    Within EEA

This is a technical first draft of your processor and transfer records, not a legal assessment. Confirm each recipient’s purpose, legal basis and transfer safeguards with your DPO or legal counsel before relying on it.

Infrastructure & jurisdiction

Digital sovereignty is about where data lives and flows, not just which trackers fire. This is who hosts the site, who handles its email, and who answers its DNS — classified by the owning company’s jurisdiction.

Part of this domain's core infrastructure is operated by a non-EU provider. This is a data-transfer consideration independent of the trackers on the page.
  • HostingCloudflareUS-owned

    Served via Cloudflare (United States). Even if the servers physically sit in Europe, Cloudflare is subject to its home-country law — for US providers, the CLOUD Act and FISA 702 mean authorities can in principle compel access to data it processes.

    cf-ray
  • Email (MX)Microsoft 365US-owned

    Email for this domain is handled by Microsoft 365 (United States). Every inbound message — and any personal data inside it — is processed by a provider subject to non-EU law.

    dagbladet-no.mail.protection.outlook.com
  • DNS (NS)CloudflareUS-owned

    Authoritative DNS is operated by Cloudflare (United States). DNS lookups reveal which hostnames visitors resolve, together with their IP addresses, and are processed under non-EU law.

    gordon.ns.cloudflare.com

Provider detection is best-effort, based on response headers and public MX/NS records. Absence of a provider here does not prove a European alternative is in use.

Detected vendors

52 vendors across 12 categories · highest-risk first · 19 marked load only after consent

Disclosure gap

The vendors this site loads, checked against the 2 policy documents we could read (cookie / privacy / DPA). Compared against multiple policy documents.

4 vendors are observed loading on the site but not named in any policy document we could read. This is a technical observation, not a legal finding — review whether each belongs in your privacy or cookie policy.

  • OnAudienceEUAdvertising
  • ReadpeakEUAdvertising
  • SemasioEUAdvertising
  • SmartyAdsUnknownAdvertising

We match vendor names and domains against the text of the site’s own policy documents. Matching can miss a disclosure (e.g. a vendor named only inside a linked sub-processor list), so treat any gap as a prompt to verify, not as proof of non-disclosure.

Reject-all verdict

Does clicking “Reject all” actually stop the trackers? We reject on a clean visit, then watch which non-essential vendors keep firing.

2 tracking vendors kept sending requests after we clicked “Reject all”. The banner did not stop them — review whether these should fire before consent.

  • Google AnalyticsUS-ownedAnalytics
  • Google Ad ManagerUS-ownedAdvertising

A technical observation of network activity after an automated rejection, not a legal ruling. We only count advertising, analytics and similar non-essential vendors; functional and infrastructure services are ignored. Some banners hide reject behind a settings panel we may not reach automatically.

Cookies before consent (20)

4 third-party16 first-party

These cookies are set on the entry page before the user interacts with the consent banner. The cookies that only appear after “Accept all” are listed in the post-consent delta above.

medialaben.noThird-party · 1
__cf_bm
dagbladet.appThird-party · 1
__cf_bm
dbstatic.noThird-party · 1
__cf_bm
widget-mediator.zopim.comThird-party · 1
AWSALBCORS
dagbladet.noFirst-party · 12
abTestCookie__cf_bmallerM_seg2blaize_sessionblaize_tracking_id_sp_suxavier-id_ga_0GXRCV5QGT_ga__zlcmid__mbl_k5a
www.dagbladet.noFirst-party · 2
AWSALBAWSALBCORS
kundeservice.dagbladet.noFirst-party · 2
_cfuvid__cf_bm

Unmatched third-party domains

These domains were detected but not yet matched to a known vendor in our database.

eu-img-cdn.livecenter.comlivecenter.norkon.netlivecentercdn.norkon.netwww.e-pages.dk

Recommendations

  • Review AWS CloudFront if you want a European alternative. Options include Bunny.net, Scaleway Edge, OVHcloud CDN.
  • Review Cloudflare if you want a European alternative. Options include Bunny.net, Fastly (US), KeyCDN (Switzerland).
  • Review Google Analytics if you want a European alternative. Options include Plausible, Matomo, Simple Analytics.
  • Review Google APIs / GStatic if you want a European alternative. Options include Bunny CDN, jsDelivr, cdnjs (Cloudflare).
  • Review Google Fonts if you want a European alternative. Options include Bunny Fonts (bunny.net), Self-hosted fonts, Fontshare.
  • Review Google Publisher Tag if you want a European alternative. Options include Adnuntius, Adform.
  • Review i18nexus if you want a European alternative. Options include Lokalise (LV), Crowdin (EE/UA).
  • Review JW Player if you want a European alternative. Options include Bunny Stream, Vimeo OTT (US).

A note on this report

StackPatrol is the technical map your DPO needs before the legal review. It surfaces the third-party services your site loads and where those vendors are based, so the legal analysis starts from facts, not guesswork.

What we provide is a technical signal: ownership region, observed network requests, vendor metadata. Legal applicability — whether a specific vendor or data flow is lawful for your use case — depends on your contracts, DPAs, sub-processors, data categories, and legal basis. We don’t give legal advice.

Vendor database verified June 2026.

Run this on your own site.

Free, no login required, results in under a minute. Paid plans add consent-aware scanning, deeper crawls and PDF reports.