# Tuesday, teenage competition
Cathy needed the insurance attestation for her son’s school trip. She opened doccle.be and waited for it to load.
In those few seconds, before her thumb had moved, the page quietly said hello to twelve companies she had never heard of. Most of them sit in the United States, and have to abide by US laws.
A grey box slid up from the bottom. We value your privacy. Two buttons. Cathy clicked Accept all, because it was Tuesday and the she was already late.
At the kitchen table her son Mica, sixteen, decided to race his mom to it. He watched the same box appear on his phone and tapped the small grey Reject. It had become an automatism.
Both of them got the document, Mica beat his mom to it in a matter of seconds. What happened around the document though, was not the same. This article is about that difference.
# Cookies are the small part
Almost everyone has clicked a cookie banner. Almost no one is sure what a cookie is.
A cookie is a small note a website leaves in your browser so it can recognise you later. There are two kinds, and the difference matters more than the banner lets on.
- A first-party cookie belongs to the site you are actually visiting. It remembers that you are logged in, or what language you read. This is usually the useful kind.
- A third-party cookie belongs to some other company whose code is running quietly on the page. It can read a tag that follows you from site to site and stitch your visits together into a profile.
Here is the part the banner never mentions: blocking cookies no longer stops tracking on its own. The industry moved past cookies years ago. Cookies are the doorway. The interesting things happen further inside.
# The watchers already in the shop
Picture a website as a shop.
When you walk in, the shop has quietly invited several advertising agencies to stand inside and watch. They see you arrive before you touch anything: which door you came through, what you are wearing, where you go first. They notice how you linger around that yellow sweater and walk straight through the sports section. On Doccle, that crowd was about a dozen companies, gathered before Cathy had done a single thing.
Some of those watchers are easy to spot. Others are dressed in the shop’s own uniform. The address launch.doccle.be looks like Doccle, so you assume it works for Doccle. It does not. It is Amazon equipment in the United States. You cannot tell from the name on the door.
And some watchers do not even need to be seen. The shop can write down your details itself, smile, and post a copy to a company abroad after you have left. From where you are standing, nothing looked like it was being sent.
The direction of travel is always the same: make the watching harder to notice, including for people who believe they refused it.
# What the tools actually collect
Not every tracker does the same thing. They sit on a scale.
Let’s begin with the cookies. Cookies come in flavors. Some only live on your computer for as long as you’re on a site. That’s what we call ‘session cookies’. A session cookie is typically used to remind the website that you’re already logged in. Sometimes, a website asks to ‘remember you’. At this point, the cookie will survive your visit to a site, and stay on your computer for a period that is set by the cookie - this can be anything between 15 minutes and 2 years. For some things (like the example given), that makes perfect sense. But if a cookie remembers your ID for an advertising company, it will recognize you, even if you hadn’t visited that site for over a year. And the cookie obviously gets reset and the timer restarts.
Next are the javascript trackers that run things in your browser - and immediately send the results to their server. At the light end for example, there’s a consent tool, the thing that shows you the banner and writes down your answer. On Doccle this was Cookiebot, run by a German company. It does one thing, and if it’s done, it goes dormant, doing nothing more than just repeating your preference. Low harm. But even that company gets the tiniest bit of information about you as a visitor. They promise not to share. As a European company odds are that they abide with that rule as there aren’t any conflicting laws.
In the middle is analytics. Google Analytics and Matomo count your visit, tie it to an identifier, and build up a picture of who comes to the site and what they do. It sees every page you load, every form you submit, every term you search. These analytics are interesting because they can tell what pages need improvement, what the most popular pages are and where the visitors come from. Depending on the settings, this can be more or less invasive. Centralized platforms like Google Analytics internally aggregate the insights from different platforms and create an in depth profile of your interests. This will result in serving you the most tempting ads. Profiler discovered that you’re most impulsive when you’re surfing at 2AM? That’s when you’ll get served those yummy trash ads. Have been talking about marital problems? Maybe you could be served ads for marital councelling? You wish! The algorithm considers dating sites much more profitable. Matomo on the other hand, is a local platform. The server gets the same insights, but it’s only there to serve the website administrator. No centralized platform that sucks it all in.
And if you think those analytics tools are nasty, you haven’t heard about the next thing: the heavy end is session replay. Doccle runs Microsoft Clarity: a tool that records your session to a server somewhere. Mouse movements, scrolling, clicks, what you typed into a form. Analytics counts what you did. It sees you linger, follows what you type (even if you don’t press that “submit” button).
# What your behaviour gives away
So why should we care? Privacy is long dead already, isn’t it? And it can come in handy if that ad makes my shopping experience easier. Thing is: We rarely know exactly what a company keeps. What we do know is that a session-replay tool watches behaviour, and behaviour describes you even when your name is nowhere attached.
A replay sees more than which buttons you pressed. It sees timing. Think about how you enter a password:
- If the box fills in one instant, you almost certainly pasted it from a password manager. If it gets filled the moment the pages gets loaded, it even reveals that it gets submitted automatically. That hints you are careful about security.
- If it fills slowly, character by character, you are typing from memory. That hints you reuse passwords simple enough to recall. It typically won’t store your password, but might get to grab the length of your password.
You never chose to share either fact. A pause before you click, or the rhythm of your typing, is a small piece of information about you, gathered without a single field being filled in. This is why “they only record what I clicked” misses the point. The how is data too.
# The nagging is the point
Some sites behave well when you refuse, and then ask again. And again. The banner returns a few pages later: “Are you really really sure you don’t want our cookies?”, and a few pages after that, until refusing feels like more effort than giving in.
This is designed friction. Saying no is made tiring on purpose, in the hope that one day you are in a hurry and click the easy button. As we will see, European rules say refusing is supposed to be as easy as accepting. The nagging is what happens when a site obeys the letter of that rule and works around its spirit.
# Accept versus Reject, in real numbers
This is where Cathy’s tired tap and Mica’s reflex Reject stop being a story and become measurements. BeLibre ran the Leak Detector against Doccle twice on the same evening: one visit refusing tracking, one visit accepting all of it. Same site, same tool, minutes apart.
| Mica (Reject) | Cathy (Accept all) | |
|---|---|---|
| Overall score | 49 / 100 | 0 / 100 |
| Privacy sub-score | 3 / 10 | 0 / 10 |
| Outside companies contacted | 12 | 17 |
| Trackers receiving personal data | 5 | 6 |
| Advertising profilers added | none beyond the baseline | Meta (Facebook) Pixel, plus Xandr/AppNexus |
| Persistent third-party cookies | 1 (Google reCAPTCHA) | advertising cookies from Google DoubleClick (about 13 months) and Xandr (about 90 days) |
| Session replay (Microsoft Clarity) | active | active |
Read across the bottom rows. Accepting did not just switch on a little more analytics. It pulled in cross-site advertising networks (Meta and Microsoft’s Xandr) that had been completely silent a moment earlier, and it let them drop cookies that sit in the browser for months, following the visitor far beyond Doccle.
Here’s the catch: Refusing helped a great deal. It did not make Doccle clean. Even on Mica’s Reject visit, session replay was still recording, a persistent Google cookie was still set, and the site’s own infrastructure still ran on American hosting (Amazon) with email handled by Microsoft. Refusing tracking lowers your exposure. It does not switch it off.
# What the law actually asks
A common belief is that GDPR is “about the cookies.” It is not that narrow.
GDPR governs the handling of personal data of every kind, and personal data includes things most people would not guess, such as your IP address and the identifiers in those tracking cookies. The banner itself comes from a separate rule, the ePrivacy Directive, which says non-essential tracking needs your consent before it starts, that the consent must be freely given, and that refusing must be as easy as accepting. That is the rule the nagging is bending.
Two more duties are worth knowing as a visitor:
- You have rights over your data, including the right to see what is held and to ask for it to be deleted.
- Sending personal data outside the European Union, which is exactly what those US trackers and US hosting do, triggers extra legal obligations (the area shaped by the Schrems II judgment).
One sentence is enough to keep: if a site sets tracking cookies before you have agreed, that is very likely already a breach.
# Tuesday again
The following week the grey box was back. We value your privacy. Cathy sighed wanted to click Accept all, because there was always something.
Mica reached over and showed her the small grey Reject, and the browser extension that blocks most of the watchers before they arrive. It took ten seconds. She would have to do it on her phone too, and on her father’s tablet, where the box is even pushier.
None of this makes a person invisible. Mica was being filmed as well, and his documents still travelled through American hardware. But the gap between his visit and his mother’s was significant, and it was the size of an advertising industry.
A few habits close most of that gap:
- Treat Reject as the default, and Accept all as handing out a copy of your visit.
- Use a browser or extension that blocks trackers, so most of them never get in.
- Remember that the banner is the doorway, and that the choice behind it is worth the ten seconds.
# Want to try it for yourself?
Doccle is just an example. By far not the best pupil in the class, but not terrible either. Some blog sites can infest you with hundreds of trackers. There are techniques to analyze this, but with BeLibre we developed a tool to test sites you’re hesitant about. Read our article on the Leak Detector on our blog.