DPE-2026-0009

Third-party resource loading

A resource loaded straight from a third party makes every page view a transfer.

In het NederlandsExterne bron inladenWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Transfer web status active

What it is

A font, script library or image is loaded directly from an external provider instead of being served by the site. Each page view sends the visitor's IP address, and often more, to that provider.

Why it is a separate entry

It needs no consent interaction to establish and no tracking intent to occur. It happens on the first byte, to every visitor, including those who refuse everything.

How it arises

Not to be confused with

This entry is about the mechanism of loading, not about the destination country. Where the data goes is a separate axis; a hotlink within the EEA is still a hotlink.

How to establish it

A subresource request to a host under a different registrable domain, present in the initial document, issued without any interaction.

method network-observedQoD 90

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itWhich hosts does the page contact before any script of yours has run?
In a DPIA, verify this

Verify which external resources the page loads on first byte, rather than reviewing only the tracking section.

As a procurement clause

All fonts, scripts and libraries are served from the controller's own infrastructure.

With a complaint, hand over

A capture of the initial document with every subresource host listed.

Reproduction

Third parties that can confirm it: urlscan.io, webbkoll, webpagetest

Legal framing

Case law

Objections, and the answer

“An IP address is not personal data here.”

The Munich ruling on Google Fonts treats hotlinking a provider resource as a transfer of personal data, precisely because the IP reaches the provider.

“Our hosting is in the Netherlands.”

Storage location and loaded components are different things. The transfer runs through what the page pulls in, not through where it is stored.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0009 (Third-party resource loading)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0009
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0009/index.json
Full
DPE Catalogue. DPE-2026-0009: Third-party resource loading. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0009
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0009, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.