Skip to content
Back to Blog
6 min readdata-breachprivacytrackingavg

Belastingdienst Adobe Analytics breach: when your own tracking becomes the data leak

A data breach does not need a hacker. In early June 2026 the Belastingdienst reported one after Adobe Analytics quietly sent visitor behaviour to the US, with no consent, on tax payment pages and a benefits-recovery site. The data walked out through code the organisation installed itself.

TL;DR

The Belastingdienst (the Dutch Tax Administration) reported a data breach to the Autoriteit Persoonsgegevens after a researcher found Adobe Analytics quietly sending visitor behaviour to Adobe in the United States. The tracking ran on tax payment pages and on the childcare-benefits recovery site, capturing search terms, chatbot input, and page titles without a legal basis or consent. The tracker has since been switched off.

Incident Response PlaybookExpand
  1. Inventory every third-party script and tracker on your web properties, starting with payment and login flows.
  2. Identify what each one sends, to whom, and to which country.
  3. Check for persistent identifiers, how long they live, and whether they qualify as personal data.
  4. Confirm a legal basis under the AVG (the Dutch GDPR) and valid consent under the Telecommunicatiewet before any non-essential tag fires.
  5. Disable trackers that lack a basis or consent now. Do not wait for the investigation to finish.
  6. Preserve evidence of the configuration first: requests, tag setups, consent logs.
  7. Determine scope. Which pages, which users, over what period, and how sensitive the context was.
  8. Notify legal counsel and assess whether the threshold for a reportable breach is met.
  9. Where personal data was disclosed without a basis, notify the Autoriteit Persoonsgegevens within 72 hours.
  10. Fix the root cause with a consent platform that blocks non-essential tags until consent is given.
  11. Review who approved the tag and why it went unnoticed. This is almost always a process gap.
  12. Re-audit on a schedule. Tags reappear during marketing and site changes.

When your own tracking becomes the leak

The Belastingdienst Adobe Analytics breach is a reminder that a data leak does not require a hacker. In early June 2026 the Dutch Tax Administration reported a data breach to the Autoriteit Persoonsgegevens after an independent researcher showed that its own websites were sending visitor behaviour to Adobe in the United States. There was no intrusion and no ransom. The data left through tracking software the organisation had installed itself, on pages where people pay tax and where victims of the childcare-benefits scandal seek help. That is what makes this case worth reading even if you will never run Adobe Analytics.

What happened

The issue surfaced through a report by researcher Mick Beer, published in early June, describing how the recovery site for the childcare-benefits affair and the tax payment environment passed behavioural data to Adobe Inc. According to Security.NL, the data included specific details such as the open assessment a person was viewing, alongside search queries and chatbot input. Reporting on the article prompted questions in the Tweede Kamer.

The Belastingdienst first disabled Adobe Analytics on its sites, then confirmed it had filed a data breach notification with the Autoriteit Persoonsgegevens. State Secretary Eerenberg of Finance set this out in a letter to parliament and thanked the researcher for flagging the issue. The matter is now with the regulator, and parliament has been told it will be informed about next steps.

How the leak worked

This was not an attack but an unlawful data flow built into the sites. The tracking set a persistent identifier described as a 38-digit value with a two-year lifespan, which under the European Court of Justice's Breyer ruling qualifies as personal data. As the researcher's analysis noted, there was no consent management platform in place, and tracking began before any interaction, meaning data flowed before a visitor could agree to anything.

Two separate rules apply here. The AVG requires a legal basis under Article 6 for processing personal data, and the Telecommunicatiewet requires prior consent for placing and reading trackers. Neither was satisfied. The transfer to Adobe in the United States is largely covered by the EU-US Data Privacy Framework, under which Adobe has been certified since July 2023, but that framework does not remove the separate consent and legal-basis obligations. The Autoriteit Persoonsgegevens has fined similar tracking before, including a case involving the retailer Kruidvat.

Who is affected

Anyone who used the affected pages is potentially in scope, and the sensitivity varies sharply by context. A visitor checking a tax assessment is one thing. A victim of the childcare-benefits affair searching a recovery site, where a page title can reveal someone's status, is another. The combination of a persistent identifier and the content of what people searched for or typed into a chatbot is what turns a routine analytics setup into a reportable breach.

Beyond the direct individuals, this lands on every organisation that runs marketing tags on sensitive web properties without checking what those tags actually send. The pattern here is common: a tag added for legitimate analytics, never reviewed, quietly transmitting more than anyone intended.

What this means for your organisation

A few practical takeaways.

You are responsible for what your own code sends. Most breach planning focuses on attackers getting in. This case is about data getting out through software you chose to install. If you do not know exactly which third-party scripts run on your login and payment pages, you do not know what you are leaking.

Consent is not a banner, it is a gate. A consent platform that fires tags before the visitor agrees provides no protection. The test is simple: does anything non-essential load before consent. If it does, you have the same problem.

Sensitive context raises the stakes. The same tracker is a minor issue on a marketing blog and a serious one on a benefits recovery site. Match your scrutiny to how sensitive the page is, not to how the tag was originally justified.

Knowing what your web estate exposes, including third-party data flows, is exactly what SecDesk's Threat Exposure Management is built to surface. If you want a clear picture of what your own sites are sending and to whom, you can reach SecDesk at secdesk.com.

This is a sensitive topic for the people whose data was involved, particularly those connected to the childcare-benefits affair. Affected individuals can find guidance through the Autoriteit Persoonsgegevens.

Talk to a senior responder about Belastingdienst Adobe Analytics breach: when your own tracking becomes the data leak.

Schedule a response call
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now