A tag manager loads measurement or advertising tags at runtime. The identifiers of those tags are not in the delivered HTML, so reading the source suggests they are gone while the traffic shows otherwise.
Why it is a separate entry
Mostly a methodological trap rather than a harm in itself, and that is why it is catalogued. A researcher who checks only the source concludes that tracking stopped when it did not. It also means the operator can change what runs without any change to the site.
How it arises
tags migrated from hardcoded to container-managed
marketing team with dashboard access and no deployment
Not to be confused with
Not every container is this entry. It applies when a tag observed in traffic cannot be found in the delivered source.
How to establish it
A property or measurement identifier present in network traffic and absent from the fetched HTML document. A set comparison, not an observation.
method differentialQoD 97
Requirements on the measurement
fetch and retain the HTML document in the same capture
search for the full identifier and for split forms; dynamic assembly would otherwise be missed
What would refute it
automatedThe identifier is present in the source but assembled dynamically.finding falls
automatedThe initiator is another script rather than the container.reclassify
Where this plugs into existing processes
The one question that surfaces itWhich tags does your container load that are not in the source, and who can change them?
In a DPIA, verify this
Verify what fires at runtime rather than reading the page source, and require the container version history.
As a procurement clause
The supplier delivers the tag container version history alongside the site, so what ran when is auditable.
With a complaint, hand over
A capture showing an identifier in traffic that is absent from the fetched HTML.
Reproduction
METHOD.md · by hand · no dedicated reproduction exists yet; follow the general method and the indicator above
repro/web/check.mjs · script · the run reports DPE-2026-0011 as present, with the detail behind it
Third parties that can confirm it: urlscan.io
Legal framing
eu-gdpr-6-1-a
Objections, and the answer
“We removed the tracking; it is not in our code.”
Absence from the source is not absence from the traffic. The container is the reliable indicator, and its version history shows what ran when.
What this does not establish
harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
unlawfulness; that is for a supervisory authority or a court
intent; a fault is usually a build decision, not a plan
absence: not finding it in one capture is not evidence that it is not there
DPE Catalogue. DPE-2026-0011: Tag loaded outside the source. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0011
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0011, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.