# Consult Colin - Full Site Content > Colin O'Brien - Independent technology consultant helping European organisations and businesses choose software, hire web agencies, maintain data sovereignty, and avoid vendor lock-in. Based in Belgium, working continent-wide in English and French. --- ## Home Source: https://consultcolin.eu/ ### What Colin Does Colin O'Brien is an independent technology consultant helping European organisations make better software and web agency decisions – and undo the ones they regret. If you're choosing a new tool, hiring a web agency, reviewing an existing vendor, or dealing with a change that's not going to plan, he can help you make a clear and informed choice. ### Why Clients Come to Him - About to invest in a new tool and can't tell the good options from the well-marketed ones. - Using tools chosen by someone who left three jobs ago, and no one remembers why. - Need a new website or web app and don't know how to write a brief that actually gets them what they need. - Have three agency proposals on the table and can't tell the substance from the sales pitch. - Current agency relationship is going sideways and not sure if the problem is them, the brief, or both. - Planning to move off a major platform and unsure where to start. - Watching what's happening across the Atlantic and wondering what it means for data sitting on American servers. Whatever brought you there, the job is generally the same: understand the constraints, examine the options, and help you make a choice you won't regret in a year. ### The Problem: Ritual Mimicry Many tech stacks are built by default, not by design: - An agency set up the website and the analytics tool just came along with it. - Email is Gmail or Outlook because that's just what email is now. - The CRM is whatever someone's last employer used. - The marketing tool is the one with the chimp, because everyone knows the one with the chimp. - The project management tool is the same one the competition uses. These aren't bad decisions per se, but they're decisions that never really got made. One default leads to the next, and over time they just become the stack. This is "ritual mimicry": going through the motions of choosing without really doing any choosing. It works fine, until you realise you're paying for three tools that do the same thing, or a vendor changes the rules, or a team member says "we need to move" and no one knows where to start. ### The Kill Switch Problem What looks like a practical question can also be a political one. It's not just about which tool is best, but who you rely on, where your data lives, and how dependent you've slowly become. In 2025, the US Government sanctioned judges at the International Criminal Court in The Hague. Their Microsoft accounts were suspended overnight, their Apple IDs disabled, their credit cards frozen. European professionals doing legitimate work were suddenly locked out of essential services by American companies, with no recourse at all. The same kill switch infrastructure is what most European organisations depend on. It doesn't necessarily take a direct order targeting your organisation — it could be a trade dispute, the EU fining big tech, or a law Washington disapproves of. European alternatives are no longer a compromise: - The ICC itself switched to an open-source suite built in Europe. - Amnesty International Spain moved its file sharing onto infrastructure it controls. - France is moving its digital government agency (DINUM) onto Linux and sovereign tools. - The Dutch Central Bank is moving to a European cloud provider. The goal is not ideological purity. Sometimes the right tool isn't European. The point is to make that choice knowingly. ### How Colin Works Most projects follow a simple shape: 1. **Understanding how your organisation works.** Spending time with the team, asking questions, finding out what's really happening: what's working, what isn't, and what people actually need (not necessarily what the brief says). 2. **Testing realistic options.** For tools and vendors: no half-hour demos — days or weeks of real, actual use, studying documentation, poking the support team, exploring the edge cases you might encounter. For agencies and proposals: reading between the lines of every pitch — who actually touches the code, what's outsourced, what's template work dressed up as custom. 3. **Mapping the risks and exits before you commit.** Vendor lock-in, data jurisdiction, export formats, hidden dependencies, and what migration would really cost — in money, but also in time and lost history. Along the way, asking the awkward questions: the ones you might not think to ask, or the ones a vendor has carefully steered you away from. ### Services **Software Selection — contact for tailored quote** For organisations choosing a new tool or replacing one that has failed them. Narrows the field, tests real options seriously, and documents the trade-offs clearly enough to explain to your team and your future self. You end up with a choice that still makes sense after the renewal, not one that boxes you in. **Web Agency Selection — contact for tailored quote** For organisations about to hire a web agency. Works out what the project actually needs before the first draft is written, turns that into a brief an agency can't wriggle out of, and reads proposals properly: who touches the code, what's outsourced, what's substance and what's sales pitch. You end up with a sharper brief, a shortlist you can trust, and a project where you control your code, hosting, and domain after launch. ### When Colin Is Probably Not the Right Fit - You need someone to build or maintain software. - You need someone to design or build the website itself. - You've already made the decision and just want validation. - Nobody involved can act on what he recommends. In those cases, an IT services firm or implementation partner is probably a better starting point. ### Case Studies **A sustainable packaging company:** Running on a project management platform built for organisations three times their size — overcomplicated, slow, invasive, and hosted outside Europe. Replaced it with something that matched how they actually worked: simpler, cheaper, open-source and European-hosted. **A bicycle leasing company:** Needed specific email marketing capabilities. A European option existed but the support was so unresponsive it represented a genuine operational risk. Chose the American alternative knowingly, documented the reasoning, and kept the European option on the list to revisit. Sometimes the honest answer is: not yet. **A European organisation for natural healthcare ingredients:** Needed analytics that didn't contradict their values around transparency and data privacy. Built a stack that gave them just the insights they needed, kept everything in Europe, and didn't quietly harvest data of the people they were trying to serve. ### About Colin Colin has been in technology long enough to have co-founded one of the very first internet service providers, and has lived through several waves of certainty about how computing was "definitely going to work from now on". For most of that time, clients paid him to build things. What they kept coming back for was the thinking around the build: the right decisions, the vendor claims that didn't hold up, the obscure questions nobody had asked yet. Eventually it became clear that part was the real work. --- ## FAQ Source: https://consultcolin.eu/faq/ ### Working with Colin **What types of organisations do you work with?** European organisations and businesses of all kinds: companies that care about where their data goes, how their subscription fees circulate, and whether their technology choices align with their values. Particular experience with social enterprises and B corps, but also SMEs, nonprofits, cooperatives, and mission-driven organisations. **What does a typical engagement look like?** Every project is different, but most fall into a few patterns: software selection (helping choose a CRM, project management tool, email, or other platform), vendor assessment (checking whether a tool actually does what it claims, making sure a web developer will build what you actually need), migration planning (figuring out how to leave your current system), or technical translation (helping communicate with developers and agencies). Some clients need a one-off consultation; others want ongoing support. **How much do you charge?** Pricing is based on the scope and complexity of the work. For a straightforward software recommendation, that might be a fixed fee. For longer advisory relationships, a retainer. Happy to discuss your situation and give a clear idea of costs before committing to anything. The technology risk assessment is a fixed 1,400 EUR. **Do you implement the software yourself?** Generally no. The role is to help you make the decision and plan the transition - not to become your IT department. Colin stays involved during implementation if that's useful, but the goal is to leave you with clarity and confidence, not dependency. **Can you help me hire a web agency?** Yes. Most web projects go wrong before a single line of code is written: in the brief, the guesswork, and how proposals get judged. Colin helps you work out what the project actually needs, turn that into a brief an agency can't wriggle out of, and read proposals properly: who touches the code, what's outsourced, what's substance and what's sales pitch. You end up with a sharper brief, a shortlist you can trust, and a project where you control your code, hosting, and domain after launch. **Do you work with organisations outside Europe?** Primarily focused on European organisations because the European regulatory environment (GDPR, DSA, data sovereignty) shapes so much of the advice. That said, if you're a non-European organisation that wants honest advice about these same questions, it's worth getting in touch. --- ## Ethics Source: https://consultcolin.eu/ethics/ Colin believes you deserve completely unbiased advice when making important decisions about your tools and projects. The business is built around a simple principle: only working for you. **No commissions, ever.** All referral fees, commissions, and kickbacks from agencies, developers, or software vendors are refused. When recommending someone or something, it's because they're genuinely the best fit for your needs - not because they're paying. This means: - Honest assessments of any vendor's proposal. - Telling you when a popular tool or platform isn't right for you. - Advocating solely for your interests during projects. - Providing objective oversight without divided loyalties. - You pay directly for expertise, nothing else. --- ## Newsletter Source: https://consultcolin.eu/newsletter/ A daily email on digital sovereignty, ethical tech, and making better software choices. Practical, no hype, no pitches - just useful thoughts. It really is daily, and people stick around. --- ## Contact Source: https://consultcolin.eu/contact/ **Email:** colin@consultcolin.eu (usually responds within 24 hours) **Contact form:** https://letterbird.co/consultcolin **Introductory call:** Can be booked via the contact page. --- ## Privacy Source: https://consultcolin.eu/privacy/ No long unreadable legal text. Colin is located in Belgium where GDPR applies. - **Newsletter:** Email addresses are collected to send emails only. Not sold or shared. Sent via Keila (EU-based). Tracking is disabled on all emails. - **Web analytics:** Self-hosted privacy-friendly Swetrix analytics. No personal data collected. - **Invoicing:** Invoicing information is collected when hired. Not shared with third parties except invoicing software and accountant. --- ## Colophon Source: https://consultcolin.eu/colophon/ Static site built using Eleventy, hosted on the European Bunny CDN, SSL via Actalis (Italy), newsletter via Keila (Germany), analytics via self-hosted Swetrix. --- ## Blog Source: https://consultcolin.eu/blog/ Longer, data-backed pieces on digital sovereignty and ethical tech. ### The sovereignty stack of European governments Source: https://consultcolin.eu/blog/european-governments-digital-sovereignty/ *18 August 2026* - In this post, I look through 32 European national government websites and test their digital sovereignty. Assumed audience Citizens curious about where their national government's data is sitting. Digital policy people, public sector IT staff, and anyone working on European sovereignty. No deep technical knowledge is needed. Following my blog post about the sovereignty of Belgian municipalities, I wanted to take a higher-level look. Now that we've seen how local governments fare (at least in Belgium), what about national ones? These are the institutions that should be pushing for sovereignty. This is a review of the national government websites of Europe. When a citizen portal is available, I use that first. If there is none, I point the scanner at the main government website. Contents What I analysed The process The criteria The results Sovereignty score Email Hosting Third-party resources Registrars & DNS SSL certificates Conclusion Full results table What I analysed The process Note: the process is near-identical to the one I used for the Belgian municipality scan. If you've already read about it there, feel free to skip straight to the results. Each national government website got a digital sovereignty score assembled from a series of criteria, each weighted by its relative importance. I ran the 32 European national government websites through my sovereignty scanner (you can try it on your own site here). In the results, I consider a service "European" if the company operating it has its legal headquarters in Europe. That means EU member states, but also the UK, Switzerland, Norway and Iceland, who share similar data protection frameworks and legal traditions with the EU. What really counts is jurisdiction, not where the servers are physically located. A US-headquartered vendor counts as non-European even if its data centre is in Frankfurt. This is due to laws like the CLOUD Act. A few caveats: this is not gospel, and certainly not scientific research. A government may rely on plenty of potentially non-European tools that simply don't show up in a scan like this; like cloud storage or video conferencing. Some elements might be misidentified, others missed completely. Please read the post in that spirit. It's also a snapshot (currently from August 17th 2026) - things change. The criteria Email provider 25% Email is one of the most sensitive layers and one of the hardest to migrate once it's entrenched. The government's email provider is detected via various means (MX, SPF, autodiscover...) and rated based on its legal jurisdiction. Website host 25% This detects where the government website and, by extension data, lives, legally speaking. This is done via looking up the hosting provider's ASN (autonomous system number) and figuring out what organisation is behind it. This tells me which legal entity is operating the infrastructure, not just the physical location of the server. A server located in Europe but operated by a US cloud provider, for example, will be considered non-European. If a service like Cloudflare is sitting in front of the website, it counts as a point of foreign control, even if the origin host is located in Europe. Domain registrar 15% The registrar controls the domain itself. It's where you renew it, transfer it, or... have it seized or suspended under a foreign legal order. This doesn't weigh as much as email and hosting because losing your registrar is disruptive, but will rarely expose citizen data etc. This one is a control risk rather than a privacy one. DNS (domain name system) host 10% This checks who operates the authoritative name servers for the domain. What these do is answer "where is this government's website/email server located?" when a device looks them up. This gets scored by jurisdiction like the rest. It's weighted lower because switching DNS providers is relatively simple compared to, say, email. SSL certificate 5% The SSL certificate is responsible for the encryption of a citizen's connection to a website. That's what the padlock in the browser address bar indicates. The authority responsible for issuing these certificates is the least important of all the categories tracked here. They're easy to swap and I include them mainly for completeness. Third-party resources 20% Modern websites rarely stand on their own and this includes government sites. They load all manner of things from external (third-party) servers: fonts, analytics scripts, chat widgets, social media trackers, and so much more. Each one of those is a potential exit path for visitor data to leave Europe, regardless of where the site itself is hosted. These resources are scanned and, for the most part, identified using a local database complemented by Ghostery's TrackerDB. The score is then established based on the proportion of these resources that are European or not. ↑ Up to table of contents The results A full table of all results is included at the bottom of this post. Sovereignty score The scores start at 3.9 (Malta - the worst) and go up to 100 (Austria, Germany, Hungary, Luxembourg, Latvia and Romania - all tied at the top), with an average of 63.1 out of 100. It's far from perfect, but it's better than the average of 49.2 from the Belgian municipalities scan. National governments should have more awareness of sovereignty issues, so that does make sense. The spread is wide, though. Here are the best and worst: Top 5 scoresScoreCountries100.0Austria, Germany, Hungary, Luxembourg, Latvia95.0France, Netherlands90.0Poland78.9Romania75.0Belgium, Croatia, Norway, Slovenia, Slovakia Bottom 5 scoresScoreCountries3.9Malta5.9Iceland11.8Portugal15.4United Kingdom17.6Cyprus The countries sitting at the top all run their own email and hosting infrastructure. No Microsoft, Amazon, Google, or Cloudflare. Proof that it's perfectly feasible. At the other end, Malta (3.9) and Iceland (5.9) are pretty much running their online infrastructure through the US. Portugal (11.8) and the UK (15.4) aren't that far behind. Score distribution0-205 (15.6%)20-400 (0%)40-607 (21.9%)60-8012 (37.5%)80-1008 (25%) .be-map-viewport { aspect-ratio: auto; } .be-map { height: auto; } Colour map by Sovereignty score Email provider [EU / non-EU] Web host [EU / non-EU] Registrar [EU / non-EU] DNS provider [EU / non-EU] Third-party resources [EU / non-EU] 0 (lowest) 100 (highest) Switch to colourblind-safe colours Map of European government websites by digital sovereignty score Choropleth of 32 European national government websites, filled from red (lowest score) to green (highest score). − Reset zoom + Tap, click, or tab through the map to see more detail here. ↑ Up to table of contents Email Email is interesting here: 75% of national governments host their email at a European provider. A lot better than what I've seen on a local level (for example: only 12.1% in Belgium were European). We're still nowhere near perfection, however. Microsoft 365 is the email platform of choice for 8 out of 32 governments. So, 25% of national governments' internal and citizen emails go through a US-headquartered provider. The countries doing well mostly seem to run their infrastructure through their own government IT agencies: Bundesrechenzentrum for Austria, Statens IT for Denmark, DILA for France,... The rest is mostly a mix of self-hosted setups. Top 5 email providersMicrosoft 365 [non-EU]8 (25%)Bundesrechenzentrum [EU]1 (3.1%)Federal Government [EU]1 (3.1%)Bulgarian Government [EU]1 (3.1%)Swiss Federal Administration [EU]1 (3.1%) Top 5 email provider countriesUnited States8 (25%)Belgium2 (6.3%)Austria1 (3.1%)Switzerland1 (3.1%)Germany1 (3.1%) ↑ Up to table of contents Hosting Where hosting is concerned, the situation isn't as good: 56.3% score European. Cloudflare sits in front of 5 out of 32 government sites. Even when the server behind it is European, Cloudflare's position in front counts as a point of foreign control where traffic is handed off in an unencrypted state. AWS, Azure and Akamai host a few more and probably some of the ones hidden behind cloudflare (see below). These are governments that have explicitly chosen US hyperscalers for their website (or believed their "European sovereign cloud" marketing). Top 5 hosting providersCloudflare [non-EU]5 (15.6%)Amazon Web Services [non-EU]4 (12.5%)Microsoft Azure [non-EU]2 (6.3%)Akamai [non-EU]2 (6.3%)Bundesrechenzentrum [EU]1 (3.1%) Top 5 hosting countriesUnited States14 (43.8%)Austria1 (3.1%)Belgium1 (3.1%)Bulgaria1 (3.1%)Czech Republic1 (3.1%)--> For the 7 sites sitting behind a proxy like Cloudflare, I tried to guess the origin host by using historical data. This is a low-confidence guess and should be taken as directional at best. Top 5 possible origin hostsAmazon Web Services [non-EU]3 (42.9%)Microsoft Azure [non-EU]1 (14.3%)Telecom Italia [EU]1 (14.3%)Abraxas Informatik [EU]1 (14.3%)Malta Information Technology Agency (MITA) [EU]1 (14.3%) ↑ Up to table of contents Third-party resources Among every type of third-party resource, not just analytics, these five turn up the most. As always, Google dominates. Top 5 third-party resourcesGoogle APIs [non-EU]10 (31.3%)Matomo (self-hosted) [EU]9 (28.1%)Google Fonts [non-EU]9 (28.1%)Google Tag Manager [non-EU]7 (21.9%)Google Analytics [non-EU]6 (18.8%) What's notable is the non-European resource count: 83 non-EU resources across 32 government websites. That's out of 128 total resources detected. Roughly two-thirds. Analytics Analytics-wise, Google dominates here as well. But self-hosted Matomo instances have a very respectable second place. Microsoft Clarity makes an appearance too. Top analytics toolsMatomo (self-hosted) [EU]9 (28.1%)Google Tag Manager [non-EU]7 (21.9%)Google Analytics [non-EU]6 (18.8%)Microsoft Clarity [non-EU]3 (9.4%)Siteimprove [EU]2 (6.3%)Plausible [EU]1 (3.1%)Italian Government [EU]1 (3.1%) ↑ Up to table of contents Registrars & DNS Registrars are the category most often unknown, with 11 of 32 governments not exposing registrar info in a way the scanner can pick up. Of those identified, 62.5% are European. The undetected ones are probably European too, national registrars seem to hide better than regular ones. Top 5 registrarsUnknown [non-EU]11 (34.4%)Bundeskanzleramt [EU]1 (3.1%)Belgian Government [EU]1 (3.1%)Hostpoint [EU]1 (3.1%)regZone [EU]1 (3.1%) DNS tells a similar story: 81.3% European, with Cloudflare being the most common non-European provider. When Cloudflare sits in front of a site, they typically handle DNS too, merging two categories into one foreign dependency. Top 5 DNS providersCloudflare [non-EU]3 (9.4%)Bundesrechenzentrum [EU]1 (3.1%)Akamai [non-EU]1 (3.1%)Bulgarian government [EU]1 (3.1%)Hostpoint [EU]1 (3.1%) Top 5 DNS provider countriesUnited States6 (18.8%)Austria2 (6.3%)Bulgaria2 (6.3%)Sweden2 (6.3%)Switzerland1 (3.1%) ↑ Up to table of contents SSL certificates Only 25% of certificates are European. DigiCert, an American company, dominates the ranking with 6 of 32 governments using it. Amazon Trust Services (4) and Sectigo (3) follow next. Harica, a Greek certificate authority, is the only European player with a meaningful presence. As for municipalities, this is the lowest-weighted category because switching certificate authority is relatively trivial. Top 5 SSL certificate issuersDigiCert [non-EU]6 (18.8%)Amazon Trust Services [non-EU]4 (12.5%)Harica [EU]3 (9.4%)Sectigo [non-EU]3 (9.4%)Let's Encrypt [non-EU]2 (6.3%) Top 5 SSL issuer countriesUnited States21 (65.6%)Greece3 (9.4%)Unknown3 (9.4%)Germany1 (3.1%)Hungary1 (3.1%) ↑ Up to table of contents Conclusion So, what's the take-away? With an average score of 63.1/100, European national governments are above-average. Certainly compared to municipal websites in Belgium, anyway. Email, the heaviest category, is decent at 75% European. National governments have the institutional capacity to run their own email, and many do. This is in stark contrast to municipalities where Microsoft 365 dominates (at least in the countries I tested). Hosting, on the other hand, is not great at 56.3% European. That's actually worse than the municipalities I tested. National governments are more likely to have adopted US hyperscalers or stuck Cloudflare in front of their sites. Registrars and DNS are mixed bags. SSL is predictably American-dominated but it's also low-stakes. The countries at the top of the scoreboard mostly run their own IT infrastructure through dedicated government agencies. A few buy local. The ones at the bottom lean heavily on Microsoft and US clouds. Malta practically being a US-dependency. Defaults are sticky, even for governments. Conclusion? Could do better and be an example. ↑ Up to table of contents Full results table It's wide! Feel free to scroll right → Search countries 32 countries Country Website Score Email Hosting Possible origin host Registrar DNS SSL issuer Non-EU 3rd party Austriahttps://www.oesterreich.gv.at/100.0Bundesrechenzentrum [EU]Bundesrechenzentrum [EU]-Bundeskanzleramt [EU]Bundesrechenzentrum [EU]Harica [EU]0 / 0Germanyhttps://verwaltung.bund.de/100.0Bundesregierung [EU]Myra Security [EU]-Unknown [non-EU]DFN [EU]D-TRUST [EU]0 / 0Hungaryhttps://www.magyarorszag.hu/100.0Kopint-Datorg Zrt. [EU]NISZ [EU]-Unknown [non-EU]Hungarian Government [EU]Microsec [EU]0 / 0Luxembourghttps://guichet.lu/100.0Centre des technologies de l'information de l'Etat [EU]Centre des technologies de l'information de l'Etat [EU]-EuroDNS [EU]Centre des technologies de l'information de l'Etat [EU]Harica [EU]0 / 5Latviahttps://www.latvija.lv/100.0Latvian government [EU]VAS Latvijas Valsts radio un televizijas centrs [EU]-Unknown [non-EU]nic.lv [EU]-0 / 3Francehttps://www.service-public.gouv.fr/95.0DILA [EU]Worldline [EU]-NameShield [EU]DILA [EU]Sectigo [non-EU]0 / 2Netherlandshttps://mijn.overheid.nl/95.0Dutch Government [EU]baten-lastendienst Logius [EU]-Dutch Government [EU]Logius [EU]DigiCert [non-EU]0 / 1Polandhttps://www.gov.pl/90.0Polish Government [EU]Centralny Osrodek Informatyki [EU]-NASK [EU]NASK [EU]Certum [EU]1 / 2Romaniahttps://gov.ro/78.9Government of Romania [EU]STS [EU]-ICI [EU]STS [EU]-4 / 4Belgiumhttps://www.belgium.be/75.0Federal Government [EU]Belnet [EU]-Belgian Government [EU]Akamai [non-EU]Harica [EU]3 / 4Croatiahttps://gov.hr/75.0Vlada Republike Hrvatske [EU]HITRONet [EU]-CARNET [EU]CARNET [EU]Entrust [non-EU]6 / 6Norwayhttps://www.norge.no/75.0Microsoft 365 [non-EU]Sognenett [EU]-iteam [EU]iteam [EU]Buypass [EU]0 / 5Sloveniahttps://e-uprava.gov.si/75.0Government of the Republic of Slovenia [EU]Ministry of Digital Transformation [EU]-Ministrstvo za notranje zadeve in javno upravo [EU]Government of the Republic of Slovenia [EU]Entrust [non-EU]4 / 7Slovakiahttps://slovensko.sk/75.0Slovak public authorities [EU]National Agency for Network and Electronic Services [EU]-NASES [EU]Slovak public authorities [EU]DigiCert [non-EU]6 / 6Bulgariahttps://egov.bg/74.5Bulgarian Government [EU]ESMIS [EU]-Unknown [non-EU]Bulgarian government [EU]Let's Encrypt [non-EU]5 / 6Denmarkhttps://www.borger.dk/70.6Statens IT [EU]GlobalConnect [EU]-Unknown [non-EU]Statens IT [EU]Sectigo [non-EU]1 / 1Swedenhttps://www.regeringen.se/63.3Government Offices (Regeringskansliet) [EU]Cloudflare [non-EU]-Excedo [EU]Excedo [EU]DigiCert [non-EU]2 / 8Finlandhttps://www.suomi.fi/62.5Valtori [EU]Amazon Web Services [non-EU]-Valtori [EU]Sonera [EU]Amazon Trust Services [non-EU]0 / 0Irelandhttps://www.gov.ie/62.5Government of Ireland [EU]Amazon Web Services [non-EU]Amazon Web Services [non-EU]Department of Public Expenditure [EU]Government of Ireland [EU]Amazon Trust Services [non-EU]0 / 0Switzerlandhttps://www.ch.ch/60.0Swiss Federal Administration [EU]Amazon Web Services [non-EU]Amazon Web Services [non-EU]Hostpoint [EU]Hostpoint [EU]Amazon Trust Services [non-EU]1 / 2Spainhttps://administracion.gob.es/58.8Ministerio de Transformación Digital y de la Función Pública [EU]Ministerio de Transformacion Digital y de la Funcion Publica [EU]-Unknown [non-EU]Cloudflare [non-EU]Unknown CA [non-EU]4 / 4Czechiahttps://portal.gov.cz/53.3Microsoft 365 [non-EU]Govcz - Ministerstvo Vnitra Cr [EU]-regZone [EU]CZ Domain Registry [EU]DigiCert [non-EU]5 / 8Estoniahttps://www.eesti.ee/50.0Estonian State Portal [EU]Cloudflare [non-EU]-Zone [EU]RcodeZero [EU]Google Trust Services [non-EU]1 / 1Italyhttps://www.governo.it/45.0Microsoft 365 [non-EU]Akamai [non-EU]Telecom Italia [EU]Reevo [EU]Italian Government [EU]DigiCert [non-EU]0 / 2Lithuaniahttps://www.epaslaugos.lt/45.0Elektroniniai valdžios vartai [EU]Cloudflare [non-EU]-Kaunas University of Technology [EU]Cloudflare [non-EU]PerfectSSL [EU]1 / 1Liechtensteinhttps://www.llv.li/44.0Self-hosted (Liechtensteinische Landesverwaltung) [EU]Cloudflare [non-EU]Abraxas Informatik [EU]Swizzonic [EU]Cloudflare [non-EU]Google Trust Services [non-EU]4 / 7Greecehttps://www.gov.gr/41.2Self-hosted (Microsoft Exchange (OWA)) [EU]Akamai [non-EU]Microsoft Azure [non-EU]-Foundation for Research and Technology [EU]Let's Encrypt [non-EU]7 / 8Cyprushttps://www.gov.cy/17.6Microsoft 365 [non-EU]Microsoft Azure [non-EU]--ClouDNS [EU]DigiCert [non-EU]3 / 4United Kingdomhttps://www.gov.uk/15.4Microsoft 365 [non-EU]Fastly [non-EU]Amazon Web Services [non-EU]Nominet UK [non-EU]Nominet [EU]GlobalSign [non-EU]0 / 0Portugalhttps://www.gov.pt/11.8Microsoft 365 [non-EU]Microsoft Azure [non-EU]-Unknown [non-EU].PT [EU]GlobalSign [non-EU]2 / 2Icelandhttps://island.is/5.9Microsoft 365 [non-EU]Amazon Web Services [non-EU]-Unknown [non-EU]Amazon Route 53 [non-EU]Amazon Trust Services [non-EU]3 / 4Maltahttps://www.servizz.gov.mt/3.9Microsoft 365 [non-EU]Cloudflare [non-EU]Malta Information Technology Agency (MITA) [EU]-Azure DNS [non-EU]Sectigo [non-EU]20 / 25 ↑ Up to table of contents Data collected August 2026 with my digital sovereignty scanner. Found an error or an outdated result for your country? Let me know. --- ### How digitally sovereign are Belgian municipalities? Source: https://consultcolin.eu/blog/belgian-municipalities-digital-sovereignty/ *9 August 2026* - I scanned all 565 Belgian municipal websites for digital sovereignty. Here are the results Assumed audience Residents curious about where their local municipality's data is actually located. Local officials or municipal staff who want a starting point for questions to their IT providers. Policy and privacy people in the European digital sovereignty space. No deep technical knowledge is needed. Welcome to the first post in this blog. I wanted somewhere to write more in depth articles than my daily email, and this is where it will happen. First up: digging into the sovereignty of our local administrations. I've seen multiple mentions of Belgium being a bad pupil as far as digital sovereignty goes. Not that I think any European country deserves a gold star for this one, but, living here, I was curious enough to want to dig deeper. The only data I could find concerned email. So, having already built a scanner for this exact purpose, I decided to point it at every Belgian municipality to get a better picture. What follows is what I found out. Take it as a signal, not a verdict. Note: for simplicity, I use municipality to refer to the administrative entities known in Dutch as gemeenten and in French as communes. Contents What I analysed The process The criteria The results Sovereignty score Email Hosting Registrars DNS SSL certificates Third-party resources Conclusion Full results table What I analysed The process Each municipality got a digital sovereignty score assembled from a series of criteria, each weighted by its relative importance. I did this by running all 565 current Belgian municipalities through my sovereignty scanner (you can scan your own site here). One, Herstappe, has no standalone website as far as I can tell, so was skipped; 564 returned a usable result. In the results, I consider a service "European" if the company operating it has its legal headquarters in Europe. That means EU member states, but also the UK, Switzerland, Norway and Iceland, who share similar data protection frameworks and legal traditions. What really matters is jurisdiction, not wherever the servers are physically located. A US-headquartered vendor counts as non-European even if its data centre is in Frankfurt. This is because of laws like the CLOUD Act. A few caveats: this is not gospel, and certainly not scientific research. A municipality may rely on plenty of potentially non-European tools that simply don't show up in a scan like this, such as cloud storage or video conferencing. Some elements might be misidentified, others missed completely. Please read it in that spirit. It's also a snapshot (currently from August 6th 2026), things change. The criteria Email provider, including email marketing tools 25% Email is one of the most sensitive layers and one of the hardest to migrate once it's entrenched. The municipality's email provider is detected via various means (MX, SPF, autodiscover...) and rated based on its legal jurisdiction. Email marketing/newsletter tools are also detected since these often expose the same (citizen) data. Side note: email marketing detection sometimes surfaces multiple services, since old configurations tend to linger on long after a service has been dropped. Website host 25% This detects where the municipality's website and, by extension data, lives, legally speaking. This is done via looking up the hosting provider's ASN (autonomous system number) and figuring out what organisation is behind it. This tells me which legal entity is operating the infrastructure, not just the physical location of the server. A server located in Europe but operated by a US cloud provider, for example, is considered non-European. If a service like Cloudflare is sitting in front of the website, it counts as a point of foreign control, even if the origin host is in Europe. Side note: this detects the actual infrastructure owner. Many smaller web hosting companies lease space from these larger entities and will not show up themselves. For example: sites hosted by LCP show up as Datacenter United, where the actual servers are. Domain registrar 15% The registrar controls the domain itself. It's where you renew it, transfer it, or... have it seized or suspended under a foreign legal order. This doesn't weigh as much as email and hosting because losing your registrar is disruptive, but will rarely expose citizen data etc. This one is a control risk rather than a privacy one. DNS (domain name system) host 10% This checks who operates the authoritative name servers for the domain. What these do is answer "where is this municipality's website/email server located?" when a device looks them up. This gets scored by jurisdiction like the rest. It's weighted lower because switching DNS providers is relatively simple compared to, say, email. A municipality could probably do it in an afternoon without touching anything else. SSL certificate 5% The SSL certificate is responsible for the encryption of a citizen's connection to a website. That's what the padlock in the browser address bar indicates. The authority responsible for issuing these certificates is the least important of all the categories tracked here. They're easy to swap and I include them mainly for completeness. A fully sovereign setup would ideally have a European certificate too but, in the grand scheme of things, this is a detail. Third-party resources 20% Modern websites rarely stand on their own and this includes municipality sites. They load all manner of things from external (third-party) servers: fonts, analytics scripts, chat widgets, social media trackers, and so much more. Each one of those is a potential exit path for citizen's data to leave Europe, regardless of where the site itself is hosted. These resources are scanned and, for the most part, identified using a local database complemented by Ghostery's TrackerDB. The score is then established based on the proportion of those resources that are European or not. This is weighted second-highest below email and hosting, because it's the category most often overlooked. A site could be sovereign on its own but leak visitor data to dozens of other places. ↑ Up to table of contents The results A full table of all results is included at the bottom of this post. Sovereignty score Scores range from 11.8 (Antoing, Verlaine, Malmedy and Vresse-sur-Semois, all tied at the bottom) to 94.1 (Lubbeek), with an average of 49.2 out of 100. No one gets top marks but I don't think there are any lost causes either. Ties are common at both ends, so here are the 5 highest and 5 lowest scores: Top 5 scoresScoreMunicipalities94.1Lubbeek93.8Chapelle-lez-Herlaimont, Marchin, Olne92.3La Roche-en-Ardenne87.5Saint-Josse-ten-Noode85.0Begijnendijk, Mol, Rotselaar, Woluwe-Saint-Lambert Bottom 5 scoresScoreMunicipalities11.8Antoing, Malmedy, Verlaine, Vresse-sur-Semois15.0Büllingen, Liège, Martelange, Mettet, Zuienkerke15.4Lierneux16.8Zwalm17.2Bocholt The regional split is interesting: Wallonia averages 38.6, against 58.4 for Flanders and 59.2 for Brussels. It shows up province by province too: Walloon Brabant, Hainaut, Liège, Luxembourg and Namur all sit in the 30s, while every Flemish province sits above 55. I'm guessing shared regional IT service providers (some seem to specialise in local municipalities) explain a good portion of this. Colour map by Sovereignty score Email platform [EU / non-EU] Web host [EU / non-EU] Registrar [EU / non-EU] DNS provider [EU / non-EU] Third-party resources [EU / non-EU] Municipalities Provinces Regions 0 (lowest) 100 (highest) Switch to colourblind-safe colours Map of Belgian municipalities by digital sovereignty score Choropleth of all 564 scanned Belgian municipalities, filled from red (lowest score) to green (highest score) - or a colorblind-safe purple-to-yellow scale, via the palette toggle. Use the table below for exact figures and the province/region toggle to see aggregated scores with matching borders. − Reset zoom + Tap, click, or tab through the map to see more detail here. ↑ Up to table of contents Email Microsoft 365 alone accounts for 483 of 564 municipalities. That means 86% of all municipalities are running their citizens' and internal correspondence through a US-headquartered provider. That leaves only 12.1% of municipal email setups scoring as European overall. The rest is a long tail of small, mostly Belgian, self-hosted or regional providers. A rounding error, basically. Email-marketing-wise, the top tool is French: Brevo (ex-SendInBlue). Globally, Mailchimp still dominates but, in some European markets - and that seems to include Belgium - Brevo has overtaken the big chimp. Top 5 email providersMicrosoft 365 [non-EU]483 (85.6%)Keyes (WIN) [EU]11 (2%)Self-hosted (Microsoft Exchange (OWA)) [EU]9 (1.6%)Probably self-hosted [EU]8 (1.4%)OVH [EU]6 (1.1%) Top 5 email provider countriesUnited States496 (87.9%)Belgium49 (8.7%)France10 (1.8%)Switzerland5 (0.9%)Denmark2 (0.4%) Top 5 email marketing toolsBrevo [EU]82 (14.5%)Mailchimp [non-EU]41 (7.3%)Klaviyo [non-EU]32 (5.7%)Campaign Monitor [non-EU]10 (1.8%)Mailerlite [EU]6 (1.1%) ↑ Up to table of contents Hosting Hosting has a more even split. 59% score European, mostly thanks to Belgian hosts like Datacenter United, Combell and Level27 being quite popular. The complication is Cloudflare. It sits in front of 192 municipal sites as a US-controlled reverse proxy. Even when the actual server behind it is Belgian, Cloudflare's position in front counts as a point of foreign control where traffic is handed off unencrypted. Top 5 hosting providersCloudflare [non-EU]192 (34%)Datacenter United [EU]160 (28.4%)Level27 [EU]49 (8.7%)Combell [EU]32 (5.7%)Dstny [EU]22 (3.9%) Top 5 hosting countriesBelgium290 (51.4%)United States231 (41%)France25 (4.4%)Germany11 (2%)Denmark3 (0.5%) For the 172 sites sitting behind a service like cloudflare, I tried to guess the origin host by using historical data. This is a low-confidence guess and should be taken as directional at best. Still, you can see OVH, a French webhost, is quite popular once you rip away the proxy layer, mostly in Wallonia. Top 5 possible origin hostsOVH [EU]128 (74.4%)Amazon Web Services [non-EU]10 (5.8%)Keyes (WIN) [EU]7 (4.1%)Proximus [EU]5 (2.9%)Infomaniak [EU]4 (2.3%) ↑ Up to table of contents Registrars This one is the closest to being solved: 99.8% of registrars are European, with Belgian players like Combell, Proximus, and LCP covering most of the market. It makes sense, most people will buy a .be from a local reseller. Nice to have one category that's not on fire. Top 5 registrarsCombell [EU]103 (18.3%)ClearMedia/Proximus [EU]72 (12.8%)OVH [EU]67 (11.9%)LCP [EU]66 (11.7%)Keyes (WIN) [EU]29 (5.1%) Top 5 registrar countriesBelgium411 (72.9%)France99 (17.6%)Netherlands12 (2.1%)Luxembourg11 (2%)Denmark9 (1.6%) ↑ Up to table of contents DNS Same story as for the registrars, and for pretty much the same reason: 95.9% European, dominated by the same handful of Belgian companies that also handle hosting and registration. The exception is when Cloudflare is invoved: using their proxy often implies using their DNS too. Top 5 DNS providersCombell [EU]84 (14.9%)Proximus [EU]69 (12.2%)LCP [EU]66 (11.7%)OVH [EU]57 (10.1%)Nomeo [EU]30 (5.3%) Top 5 DNS provider countriesBelgium407 (72.2%)France91 (16.1%)United States22 (3.9%)Luxembourg10 (1.8%)Switzerland10 (1.8%) ↑ Up to table of contents SSL certificates The numbers look bad here but, in practice, it barely matters: only 2.1% of certificates are European, because 481 municipalities use Let's Encrypt, a free, automated certificate authority that happens to be US-based. As mentioned before, this is the lowest-weighted category because swapping a certificate authority is trivial, and Let's Encrypt's dominance says more about it being free as well as the default in every hosting control panel than about anyone's sovereignty choices. If you want free and European, the only alternative is Actalis. And it's far from being as user-friendly. Top 5 SSL certificate issuersLet's Encrypt [non-EU]481 (85.3%)Sectigo [non-EU]30 (5.3%)Amazon Trust Services [non-EU]16 (2.8%)GlobalSign [non-EU]11 (2%)Harica [EU]8 (1.4%) Top 5 SSL issuer countriesUnited States551 (97.7%)Greece8 (1.4%)France3 (0.5%)Netherlands1 (0.2%) ↑ Up to table of contents Third-party resources Across every type of third-party element, not just analytics, these five turn up the most. The calls to Flanders government resources or iMio (Walloon IT provider for municipalities) make sense. The rest? All US-based. Top 5 third-party resourcesGoogle APIs [non-EU]397 (70.4%)Google Fonts [non-EU]305 (54.1%)Flanders Government [EU]223 (39.5%)Cloudflare Insights [non-EU]187 (33.2%)iMio [EU]171 (30.3%) Analytics-wise, Google dominates, albeit less than across the broader web. No surprise here, it's free and installed without thinking by nearly everyone. Google Analytics is present on 20.2% of all sites, if you add Tag Manager to that, you get to 22.5%. Matomo comes in at a respectable second place - far higher than across the web at large. A lot of progress could be made by many municipalities by switching to European alternatives like Plausible or Simple Analytics, or using a self-hosted solution like Matomo. Or they could simply skip analytics entirely. How many municipalities actually act on these numbers? Top 10 analytics toolsGoogle Analytics149 (26.4%)Matomo134 (23.8%)Google Tag Manager121 (21.5%)Facebook Pixel22 (3.9%)Hotjar15 (2.7%)Plausible4 (0.7%)New Relic2 (0.4%)Umami1 (0.2%) Zooming out from analytics specifically, we find Google's footprint everywhere. Taking every service it operates into account: fonts, APIs, Tag Manager, reCAPTCHA, Maps, YouTube embeds and the rest; 69.3% of municipalities load something from Google. Top 5 Google servicesGoogle APIs [non-EU]353 (62.6%)Google Fonts [non-EU]305 (54.1%)Google Tag Manager [non-EU]120 (21.3%)Google Analytics [non-EU]114 (20.2%)Google [non-EU]34 (6%) ↑ Up to table of contents Conclusion So, what can we take away from all of this? With an average score of 49.2/100, Belgian municipalities are pretty much smack dab in the middle. A solid "could do better" in red pen, then. The two heaviest categories, email and hosting, are very different. Email is close to a lost cause. Only 12.1% are European, everyone else seems to have made a blood pact with Microsoft. Hosting, on the other hand, at 59% European, fares a lot better. This is probably the easiest win for the municipalities still hosting their sites abroad (or hiding them behind Cloudflare). Registrars (99.8% European) and DNS (95.9%) are, for all practical purposes, solved. SSL barely matters at all. Let's Encrypt's dominance says more about it being free than about anyone's sovereignty choices. But grabbing a free or cheap European certificate can still move the needle. Third-party resources are a mess. This is where, even municipalities that get the fundamentals right, have websites silently phoning home to multiple foreign entities. Google being the biggest offender here. Regionally-speaking, Flanders and Brussels do a bit better across all criteria than Wallonia. Although, email-wise, Wallonia generally does better and, hosting-wise, Flanders comes out on top. Regional IT providers and their choices probably explain a good part of this. Mostly, what these results show, is what happens when no one questions the defaults. But defaults can be fixed and should be; if only to keep the value circulating locally. ↑ Up to table of contents Full results table It's wide! Feel free to scroll right → Search municipalities 564 municipalities Municipality Province Score Email Hosting Possible origin host Registrar DNS SSL issuer Non-EU 3rd party LubbeekFlemish Brabant94.1Probably self-hosted [EU]Datacenter United [EU]-The Registrar Company [non-EU]The Registrar Company [EU]Let's Encrypt [non-EU]0 / 3Chapelle-lez-HerlaimontHainaut93.8Probably self-hosted [EU]Diogenius [EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]0 / 0MarchinLiège93.8Keyes (WIN) [EU]Hetzner [EU]-Anagramme [EU]Anagramme [EU]Let's Encrypt [non-EU]0 / 0OlneLiège93.8Keyes (WIN) [EU]Keyes (WIN) [EU]-Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]0 / 0La Roche-en-ArdenneLuxembourg92.3Infomaniak [EU]Infomaniak [EU]-Key-Systems (Wholesaler) [non-EU]Infomaniak [EU]Let's Encrypt [non-EU]0 / 1Saint-Josse-ten-NoodeBrussels-Capital87.5Paradigm/Irisnet [EU]Paradigm/Irisnet [EU]-Combell [EU]Paradigm/Irisnet [EU]Harica [EU]5 / 8MolAntwerp85.0Microsoft 365 (via Axsguard) [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 4Woluwe-Saint-LambertBrussels-Capital85.0Paradigm/Irisnet [EU]Scaleway [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]4 / 8BegijnendijkFlemish Brabant85.0Probably self-hosted [EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 3RotselaarFlemish Brabant85.0Probably self-hosted [EU]Combell [EU]-e2e Solutions [EU]Nomeo [EU]Let's Encrypt [non-EU]2 / 4IxellesBrussels-Capital83.3Paradigm/Irisnet [EU]Paradigm/Irisnet [EU]-Combell [EU]Paradigm/Irisnet [EU]Harica [EU]5 / 6DentergemWest Flanders81.7Self-hosted (Microsoft Exchange (OWA)) [EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 3LégliseLuxembourg80.0Self-hosted (Microsoft Exchange (OWA)) [EU]Gandi [EU]-Gandi [EU]Gandi [EU]Gandi [EU]4 / 4AndenneNamur80.0OVH [EU]Diogenius [EU]-Diogenius [EU]Diogenius [EU]Sectigo [non-EU]3 / 4HoegaardenFlemish Brabant79.4Self-hosted (Microsoft Exchange (OWA)) [EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]7 / 9WalcourtNamur79.4Combell MailProtect (anti-spam gateway) [EU]Combell [EU]-Combell [EU]Combell [EU]Sectigo [non-EU]7 / 9GanshorenBrussels-Capital77.9Self-hosted (Roundcube) [EU]Diogenius [EU]-Diogenius [EU]Diogenius [EU]Let's Encrypt [non-EU]6 / 7Beyne-HeusayLiège77.9Self-hosted (Microsoft Exchange (OWA)) [EU]OVH [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]6 / 7AnderlechtBrussels-Capital75.0Self-hosted (Paradigm/Irisnet) [EU]OVH [EU]-Combell [EU]Paradigm/Irisnet [EU]Let's Encrypt [non-EU]13 / 13BernissartHainaut75.0Infomaniak [EU]Private Customer [EU]-Infomaniak [EU]Infomaniak [EU]Let's Encrypt [non-EU]9 / 9CharleroiHainaut75.0Probably self-hosted [EU]CBlue [EU]-OVH [EU]OVH Anycast [EU]GlobalSign [non-EU]2 / 2BrunehautHainaut75.0OVH [EU]OVH [EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]4 / 4ChaudfontaineLiège75.0Self-hosted (Microsoft Exchange (OWA)) [EU]OVH [EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]2 / 2SeraingLiège75.0Self-hosted (Keyes (WIN)) [EU]OVH [EU]-Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]11 / 11Marche-en-FamenneLuxembourg75.0Probably self-hosted [EU]Proximus [EU]-OVH [EU]OVH [EU]Sectigo [non-EU]4 / 4AartselaarAntwerp70.0Microsoft 365 [non-EU]Datacenter United [EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]0 / 2EdegemAntwerp70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 1HemiksemAntwerp70.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]0 / 3NijlenAntwerp70.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]0 / 1Baarle-HertogAntwerp70.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]0 / 1HerseltAntwerp70.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]0 / 1HoogstratenAntwerp70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 1MerksplasAntwerp70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 1OlenAntwerp70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 1VosselaarAntwerp70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 1UccleBrussels-Capital70.0Microsoft 365 [non-EU]Orange Belgium SA [EU]-Combell [EU]Paradigm/Irisnet [EU]Let's Encrypt [non-EU]0 / 1GrimbergenFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 2KampenhoutFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 2LonderzeelFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]0 / 1OverijseFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 2TernatFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 2ZaventemFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-bNamed [EU]bNamed [EU]Let's Encrypt [non-EU]0 / 2ZemstFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 2KraainemFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 1Wezembeek-OppemFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-HostYou [EU]HostYou [EU]Let's Encrypt [non-EU]0 / 3LennikFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 3AarschotFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 2BertemFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 2BoutersemFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 1TervurenFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-e2e Solutions [EU]Nomeo [EU]Let's Encrypt [non-EU]0 / 1Tielt-WingeFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 1GlabbeekFlemish Brabant70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 1BeernemWest Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 3OostkampWest Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-Telenet [EU]Vanden Broele [EU]Let's Encrypt [non-EU]0 / 3MesenWest Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]0 / 3OostendeWest Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 2OudenburgWest Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]0 / 1HoogledeWest Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 3MoorsledeWest Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 3StadenWest Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 2GeraardsbergenEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 2DendermondeEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 2HammeEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]0 / 2LebbekeEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-EuroDNS [EU]EuroDNS [EU]Let's Encrypt [non-EU]0 / 3WetterenEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 2WichelenEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 2Sint-LaureinsEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 1LochristiEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-e2e Solutions [EU]Nomeo [EU]Let's Encrypt [non-EU]0 / 3Merelbeke-MelleEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 2TemseEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 2Beveren-Kruibeke-ZwijndrechtEast Flanders70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 2EupenLiège70.0Microsoft 365 [non-EU]Netcup [EU]-Pixelbar [EU]Pixelbar [EU]Let's Encrypt [non-EU]0 / 3RaerenLiège70.0Microsoft 365 [non-EU]Netcup [EU]-Pixelbar [EU]Pixelbar [EU]Let's Encrypt [non-EU]0 / 3BeringenLimburg70.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]0 / 1LeopoldsburgLimburg70.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]0 / 2Tessenderlo-HamLimburg70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 2Dilsen-StokkemLimburg70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 3OudsbergenLimburg70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 2AlkenLimburg70.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 2LanakenLimburg70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 1RiemstLimburg70.0Microsoft 365 [non-EU]Datacenter United [EU]-e2e Solutions [EU]Nomeo [EU]Let's Encrypt [non-EU]0 / 1Bilzen-HoeseltLimburg70.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 4ForestBrussels-Capital68.8Microsoft 365 [non-EU]Paradigm/Irisnet [EU]-Combell [EU]Paradigm/Irisnet [EU]Harica [EU]0 / 0KoekelbergBrussels-Capital68.8Microsoft 365 [non-EU]Paradigm/Irisnet [EU]-Combell [EU]Paradigm/Irisnet [EU]Gandi [EU]0 / 0GesvesNamur66.7Microsoft 365 [non-EU]Infomaniak [EU]-Maehdros [EU]Maehdros [EU]-0 / 0SchelleAntwerp65.0Microsoft 365 [non-EU]Level27 [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]1 / 4MaldegemEast Flanders65.0Microsoft 365 [non-EU]Datacenter United [EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]1 / 4PeerLimburg65.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 5PoperingeWest Flanders64.7Microsoft 365 [non-EU]Datacenter United [EU]-OpenProvider (Wholesaler) [non-EU]Openprovider [EU]Let's Encrypt [non-EU]0 / 2RavelsAntwerp63.3Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]1 / 3BeerselFlemish Brabant63.3Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 3HoeilaartFlemish Brabant63.3Microsoft 365 [non-EU]Combell [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 3TremeloFlemish Brabant63.3Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 3HouthulstWest Flanders63.3Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]1 / 4IeperWest Flanders63.3Microsoft 365 [non-EU]Datacenter United [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]1 / 3NieuwpoortWest Flanders63.3Microsoft 365 [non-EU]Datacenter United [EU]-DNS53 [EU]Nomeo [EU]Let's Encrypt [non-EU]1 / 4NinoveEast Flanders63.3Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]1 / 4AalterEast Flanders63.3Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 3PeltLimburg63.3Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 3BoechoutAntwerp62.5Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]0 / 0BeerseAntwerp62.5Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 0Oud-TurnhoutAntwerp62.5Microsoft 365 [non-EU]Datacenter United [EU]-Team.blue [EU]Team.blue [EU]Let's Encrypt [non-EU]0 / 0DiestFlemish Brabant62.5Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]0 / 0KaprijkeEast Flanders62.5Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]0 / 0OosterzeleEast Flanders62.5Microsoft 365 [non-EU]Combell [EU]-Nomeo [EU]Nomeo [EU]Sectigo [non-EU]0 / 2BeaumontHainaut62.5Microsoft 365 [non-EU]OVH [EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]0 / 0TournaiHainaut62.5Microsoft 365 [non-EU]OVH [EU]-OVH [EU]OVH [EU]GlobalSign [non-EU]0 / 0ModaveLiège62.5Barracuda (anti-spam gateway) [non-EU]OVH [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]0 / 0Burg-ReulandLiège62.5Microsoft 365 [non-EU]Netcup [EU]-EuroDNS [EU]EuroDNS [EU]Let's Encrypt [non-EU]0 / 0Saint-HubertLuxembourg62.5Microsoft 365 [non-EU]Hetzner [EU]-Anagramme [EU]Anagramme [EU]Let's Encrypt [non-EU]0 / 0DinantNamur62.5Microsoft 365 [non-EU]OVH [EU]-OVH [EU]OVH [EU]Sectigo [non-EU]0 / 0Lo-ReningeWest Flanders62.0Microsoft 365 [non-EU]Datacenter United [EU]-Digitalmind [EU]Digitalmind [EU]Let's Encrypt [non-EU]2 / 5Heusden-ZolderLimburg62.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 5IngelmunsterWest Flanders61.7Microsoft 365 [non-EU]Telenet [EU]-Nomeo [EU]Nomeo [EU]Trust Provider [EU]2 / 3MeiseFlemish Brabant61.4Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]3 / 7EssenAntwerp60.0Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]4 / 8MortselAntwerp60.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 4RumstAntwerp60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 2ZandhovenAntwerp60.0Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]Sectigo [non-EU]2 / 4MalleAntwerp60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]4 / 8BonheidenAntwerp60.0Microsoft 365 [non-EU]Datacenter United [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]2 / 4PutteAntwerp60.0Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]4 / 8DesselAntwerp60.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 4HerenthoutAntwerp60.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]1 / 2KasterleeAntwerp60.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 4LilleAntwerp60.0Microsoft 365 [non-EU]Datacenter United [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]1 / 3MeerhoutAntwerp60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 4MachelenFlemish Brabant60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 2SteenokkerzeelFlemish Brabant60.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 4VilvoordeFlemish Brabant60.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]2 / 4Sint-Genesius-RodeFlemish Brabant60.0Microsoft 365 [non-EU]Datacenter United [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]1 / 2BekkevoortFlemish Brabant60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 2HaachtFlemish Brabant60.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 4HerentFlemish Brabant60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 4KeerbergenFlemish Brabant60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 5KortenbergFlemish Brabant60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 4KoekelareWest Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]1 / 2Langemark-PoelkapelleWest Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]1 / 2WingeneWest Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 6HaaltertEast Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 2Sint-Lievens-HoutemEast Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]1 / 2Erpe-MereEast Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]1 / 2LaarneEast Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]2 / 4ZeleEast Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-MyDomain [EU]MyDomain [EU]Let's Encrypt [non-EU]2 / 4EekloEast Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]2 / 4EvergemEast Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]Microsoft [non-EU]Let's Encrypt [non-EU]0 / 2DeinzeEast Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 4RonseEast Flanders60.0Microsoft 365 [non-EU]Level27 [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]4 / 9Sint-Gillis-WaasEast Flanders60.0Microsoft 365 [non-EU]Datacenter United [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]2 / 4BoussuHainaut60.0iMio (Walloon Intermunicipal IT Cooperative) (via Clean Mailbox) [EU]Cloudflare [non-EU]OVH [EU]MyOwn [EU]MyOwn [EU]Let's Encrypt [non-EU]3 / 6QuévyHainaut60.0One.com [EU]Cloudflare [non-EU]-One.com [EU]One.com [EU]Let's Encrypt [non-EU]3 / 6SeneffeHainaut60.0Self-hosted (Lotus Domino / HCL Notes (iNotes)) [EU]Cloudflare [non-EU]OVH [EU]Orange [EU]VOO [EU]Let's Encrypt [non-EU]3 / 6La LouvièreHainaut60.0Self-hosted (Microsoft Exchange (OWA)) [EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Self-hosted (Proximus NV) [EU]Let's Encrypt [non-EU]3 / 6AmayLiège60.0Computic [EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6FerrièresLiège60.0Computic [EU]Cloudflare [non-EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6HerstalLiège60.0Probably self-hosted [EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 6BlegnyLiège60.0OVH [EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6FlémalleLiège60.0Keyes (WIN) [EU]Cloudflare [non-EU]Combell [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 6DisonLiège60.0Self-hosted (Microsoft Exchange (OWA)) [EU]Cloudflare [non-EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 6LontzenLiège60.0Microsoft 365 [non-EU]Netcup [EU]-Pixelbar [EU]Pixelbar [EU]Let's Encrypt [non-EU]1 / 3StoumontLiège60.0Microsoft 365 [non-EU]Diogenius [EU]-EuroDNS [EU]EuroDNS [EU]Let's Encrypt [non-EU]2 / 4GenkLimburg60.0Microsoft 365 [non-EU]Datacenter United [EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]2 / 4GingelomLimburg60.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]1 / 2HalenLimburg60.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]1 / 2LommelLimburg60.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 4WellenLimburg60.0Microsoft 365 [non-EU]Level27 [EU]-Netsoft [EU]NetSoft [EU]Let's Encrypt [non-EU]2 / 4MaasmechelenLimburg60.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]1 / 2Tongeren-BorgloonLimburg60.0Microsoft 365 [non-EU]Datacenter United [EU]-OVH [EU]Office-IT [EU]Let's Encrypt [non-EU]2 / 4AubangeLuxembourg60.0One.com [EU]Amazon Web Services [non-EU]-One.com [EU]One.com [EU]Let's Encrypt [non-EU]1 / 4HerbeumontLuxembourg60.0Keyes (WIN) [EU]Cloudflare [non-EU]-Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 6WellinLuxembourg60.0Self-hosted (IceWarp Mail Server) [EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 6HouyetNamur60.0Microsoft 365 [non-EU]One.com [EU]-One.com [EU]One.com [EU]Let's Encrypt [non-EU]1 / 2SambrevilleNamur60.0Self-hosted (Zimbra Collaboration Suite) [EU]Cloudflare [non-EU]Voo [EU]Orange [EU]VOO [EU]Let's Encrypt [non-EU]3 / 6CouvinNamur60.0Self-hosted (Mailcow) [EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 6PhilippevilleNamur60.0Probably self-hosted [EU]Cloudflare [non-EU]-Netim [EU]WillsPhil [EU]Let's Encrypt [non-EU]3 / 6StekeneEast Flanders58.9Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]5 / 9BalenAntwerp58.6Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]4 / 7IchtegemWest Flanders58.6Microsoft 365 [non-EU]Datacenter United [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]4 / 7DestelbergenEast Flanders58.6Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]4 / 7HuyLiège58.6Self-hosted (Zimbra Collaboration Suite) [EU]Cloudflare [non-EU]Proximus [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]4 / 7LummenLimburg58.6Microsoft 365 [non-EU]Dstny [EU]-Level27 [EU]Level27 [EU]GlobalSign [non-EU]4 / 7FloreffeNamur58.6Microsoft 365 [non-EU]OVH [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]4 / 7FlorennesNamur58.6Self-hosted (Keyes (WIN)) [EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]4 / 7HalleFlemish Brabant58.4Microsoft 365 [non-EU]Dstny [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Sectigo [non-EU]11 / 20KontichAntwerp58.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]3 / 5AsseFlemish Brabant58.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]3 / 5Oud-HeverleeFlemish Brabant58.0Microsoft 365 [non-EU]Datacenter United [EU]-bNamed [EU]CentralNIC [EU]Let's Encrypt [non-EU]3 / 6LichterveldeWest Flanders58.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]3 / 7EnghienHainaut58.0Self-hosted Exchange (OWA) [EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 5Comblain-au-PontLiège58.0Keyes (WIN) [EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 5JuprelleLiège58.0Keyes (WIN) [EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 5DenderleeuwEast Flanders57.3Microsoft 365 [non-EU]Level27 [EU]-Willux [EU]Willux [EU]Let's Encrypt [non-EU]7 / 13HoveAntwerp56.7Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]4 / 6LintAntwerp56.7Google Workspace [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 3NielAntwerp56.7Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]4 / 6StabroekAntwerp56.7Microsoft 365 [non-EU]Level27 [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]4 / 6WijnegemAntwerp56.7Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]2 / 3WommelgemAntwerp56.7Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]4 / 6WuustwezelAntwerp56.7Microsoft 365 [non-EU]Dstny [EU]-ClearMedia/Proximus [EU]Proximus [EU]Sectigo [non-EU]6 / 11BerlaarAntwerp56.7Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 3BornemAntwerp56.7Microsoft 365 [non-EU]Datacenter United [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]2 / 3Sint-Katelijne-WaverAntwerp56.7Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 3WillebroekAntwerp56.7Microsoft 365 (via Barracuda) [non-EU]Dstny [EU]-e2e Solutions [EU]Nomeo [EU]Sectigo [non-EU]4 / 6GeelAntwerp56.7Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 3RijkevorselAntwerp56.7Microsoft 365 [non-EU]Dstny [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Sectigo [non-EU]4 / 6BeverFlemish Brabant56.7Microsoft 365 [non-EU]Dstny [EU]-ClearMedia/Proximus [EU]Proximus [EU]Sectigo [non-EU]4 / 6BierbeekFlemish Brabant56.7Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 3HolsbeekFlemish Brabant56.7Microsoft 365 [non-EU]Datacenter United [EU]-EuroDNS [EU]Ebrand [EU]Let's Encrypt [non-EU]2 / 3ZoutleeuwFlemish Brabant56.7Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 3LinterFlemish Brabant56.7Microsoft 365 [non-EU]Dstny [EU]-Combell [EU]Cipal Schaubroeck [EU]Sectigo [non-EU]4 / 6JabbekeWest Flanders56.7Microsoft 365 [non-EU]Telenet [EU]-Combell [EU]Combell [EU]Sectigo [non-EU]2 / 3TorhoutWest Flanders56.7Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]4 / 6LendeledeWest Flanders56.7Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]4 / 8Spiere-HelkijnWest Flanders56.7Microsoft 365 [non-EU]Combell [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]4 / 6MiddelkerkeWest Flanders56.7Microsoft 365 [non-EU]Dstny [EU]-Nomeo [EU]Nomeo [EU]Sectigo [non-EU]4 / 6IzegemWest Flanders56.7Microsoft 365 [non-EU]Combell [EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]4 / 8WielsbekeWest Flanders56.7Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]Sectigo [non-EU]4 / 8ArdooieWest Flanders56.7Microsoft 365 [non-EU]Proximus [EU]-Nomeo [EU]Nomeo [EU]GoDaddy [non-EU]2 / 3TieltWest Flanders56.7Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]4 / 7VeurneWest Flanders56.7Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]10 / 17ZottegemEast Flanders56.7Microsoft 365 [non-EU]Proximus [EU]-Nomeo [EU]Nomeo [EU]GoDaddy [non-EU]2 / 3BuggenhoutEast Flanders56.7Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 3OudenaardeEast Flanders56.7Microsoft 365 [non-EU]Dstny [EU]-Combell [EU]Combell [EU]Sectigo [non-EU]4 / 6KluisbergenEast Flanders56.7Microsoft 365 [non-EU]Dstny [EU]-e2e Solutions [EU]Nomeo [EU]GlobalSign [non-EU]4 / 6Pont-à-CellesHainaut56.7Microsoft 365 [non-EU]OVH [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]4 / 6BreeLimburg56.7Microsoft 365 [non-EU]Dstny [EU]-ClearMedia/Proximus [EU]Proximus [EU]GoDaddy [non-EU]4 / 6MaaseikLimburg56.7Microsoft 365 [non-EU]Level27 [EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]4 / 6Hamont-AchelLimburg56.7Microsoft 365 [non-EU]Datacenter United [EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]2 / 3Houthalen-HelchterenLimburg56.7Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 3Berchem-Sainte-AgatheBrussels-Capital56.0Microsoft 365 [non-EU]Paradigm/Irisnet [EU]-Combell [EU]Paradigm/Irisnet [EU]Let's Encrypt [non-EU]7 / 11PittemWest Flanders56.0Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]7 / 12LierAntwerp55.7Microsoft 365 [non-EU]Level27 [EU]-Kinamo [EU]Firstserv [EU]Let's Encrypt [non-EU]5 / 7HerentalsAntwerp55.7Microsoft 365 [non-EU]Dstny [EU]-e2e Solutions [EU]Nomeo [EU]GlobalSign [non-EU]5 / 8WervikWest Flanders55.7Microsoft 365 [non-EU]Combell [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]5 / 9AnzegemWest Flanders55.7Microsoft 365 [non-EU]Combell [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]5 / 9AvelgemWest Flanders55.7Microsoft 365 [non-EU]Combell [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]5 / 9DeerlijkWest Flanders55.7Microsoft 365 [non-EU]Combell [EU]-Telenet [EU]Telenet [EU]Sectigo [non-EU]5 / 9HarelbekeWest Flanders55.7Microsoft 365 [non-EU]Combell [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]5 / 9KortrijkWest Flanders55.7Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]5 / 9KuurneWest Flanders55.7Microsoft 365 [non-EU]Combell [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]5 / 9MenenWest Flanders55.7Microsoft 365 [non-EU]Combell [EU]-Telenet [EU]Telenet [EU]Sectigo [non-EU]5 / 9WevelgemWest Flanders55.7Microsoft 365 [non-EU]Combell [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]5 / 9ZwevegemWest Flanders55.7Microsoft 365 [non-EU]Combell [EU]-Belnet [EU]Belnet [EU]Let's Encrypt [non-EU]5 / 9LierdeEast Flanders55.7Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]5 / 7LokerenEast Flanders55.7Microsoft 365 [non-EU]Combell [EU]-Telenet [EU]Telenet [EU]DigiCert [non-EU]5 / 7KinrooiLimburg55.7Microsoft 365 [non-EU]Datacenter United [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]5 / 7ChinyLuxembourg55.7Microsoft 365 [non-EU]OVH [EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]5 / 7HuldenbergFlemish Brabant55.5Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]8 / 13HasseltLimburg55.3Microsoft 365 [non-EU]Level27 [EU]--Telenet [EU]Let's Encrypt [non-EU]2 / 5BrechtAntwerp55.0Microsoft 365 [non-EU]Tigron [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]3 / 4SchotenAntwerp55.0Microsoft 365 [non-EU]Dstny [EU]-e2e Solutions [EU]Nomeo [EU]Sectigo [non-EU]6 / 8ZoerselAntwerp55.0Microsoft 365 [non-EU]Dstny [EU]-e2e Solutions [EU]Nomeo [EU]Sectigo [non-EU]6 / 8GrobbendonkAntwerp55.0Google Workspace [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]3 / 4TurnhoutAntwerp55.0Microsoft 365 [non-EU]Level27 [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 5VorselaarAntwerp55.0Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]6 / 10Molenbeek-Saint-JeanBrussels-Capital55.0Microsoft 365 [non-EU]Paradigm/Irisnet [EU]-Combell [EU]Paradigm/Irisnet [EU]Harica [EU]1 / 1Saint-GillesBrussels-Capital55.0Microsoft 365 [non-EU]Paradigm/Irisnet [EU]-Combell [EU]Paradigm/Irisnet [EU]Harica [EU]11 / 11SchaerbeekBrussels-Capital55.0Microsoft 365 [non-EU]Paradigm/Irisnet [EU]-Combell [EU]Paradigm/Irisnet [EU]Harica [EU]1 / 1Watermael-BoitsfortBrussels-Capital55.0Microsoft 365 [non-EU]Paradigm/Irisnet [EU]-Combell [EU]Paradigm/Irisnet [EU]Harica [EU]1 / 1Kapelle-op-den-BosFlemish Brabant55.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]3 / 4Sint-Pieters-LeeuwFlemish Brabant55.0Microsoft 365 [non-EU]Dstny [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Sectigo [non-EU]6 / 8LeuvenFlemish Brabant55.0Microsoft 365 [non-EU]Combell [EU]-Belnet [EU]Belnet [EU]Harica [EU]3 / 3BlankenbergeWest Flanders55.0Microsoft 365 [non-EU]Datacenter United [EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]3 / 4VleterenWest Flanders55.0Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]3 / 4MaarkedalEast Flanders55.0Microsoft 365 [non-EU]Dstny [EU]-ClearMedia/Proximus [EU]Proximus [EU]Sectigo [non-EU]6 / 8CourcellesHainaut55.0Infomaniak [EU]Amazon Web Services [non-EU]Infomaniak [EU]Keyes (WIN) [EU]Infomaniak [EU]Amazon Trust Services [non-EU]3 / 8AsLimburg55.0Microsoft 365 [non-EU]Level27 [EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]6 / 9Hechtel-EkselLimburg55.0Microsoft 365 [non-EU]Level27 [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]3 / 4DurbuyLuxembourg55.0Microsoft 365 [non-EU]OVH [EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]9 / 12ManhayLuxembourg55.0Infomaniak [EU]Amazon Web Services [non-EU]OVH [EU]ClearMedia/Proximus [EU]Infomaniak [EU]Amazon Trust Services [non-EU]3 / 9KalmthoutAntwerp54.4Microsoft 365 [non-EU]Hetzner [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]7 / 11KapellenAntwerp54.4Microsoft 365 [non-EU]Datacenter United [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]7 / 11HulshoutAntwerp54.4Microsoft 365 [non-EU]Dstny [EU]-Combell [EU]Combell [EU]Sectigo [non-EU]7 / 9BredeneWest Flanders54.4Microsoft 365 [non-EU]Level27 [EU]-Flanders Webhost [EU]Flanders Webhost [EU]Let's Encrypt [non-EU]7 / 9LedegemWest Flanders54.4Microsoft 365 [non-EU]Dstny [EU]-Telenet [EU]Telenet [EU]GlobalSign [non-EU]7 / 9Herk-de-StadLimburg54.4Microsoft 365 [non-EU]Dstny [EU]-e2e Solutions [EU]Nomeo [EU]Sectigo [non-EU]7 / 9RetieAntwerp54.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]4 / 5DilbeekFlemish Brabant54.0Microsoft 365 [non-EU]Dstny [EU]-EasyHost [EU]Easyhost [EU]Sectigo [non-EU]4 / 5PepingenFlemish Brabant54.0Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]4 / 5GeetbetsFlemish Brabant54.0Microsoft 365 [non-EU]Dstny [EU]-Combell [EU]Cipal Schaubroeck [EU]Sectigo [non-EU]4 / 5LandenFlemish Brabant54.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]4 / 5TienenFlemish Brabant54.0Microsoft 365 [non-EU]Level27 [EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]8 / 12GistelWest Flanders54.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]4 / 5AlveringemWest Flanders54.0Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]4 / 5HerzeleEast Flanders54.0Microsoft 365 [non-EU]Datacenter United [EU]-ITAF [EU]ITAF [EU]Let's Encrypt [non-EU]4 / 5ZelzateEast Flanders54.0Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]GlobalSign [non-EU]8 / 10LievegemEast Flanders54.0Microsoft 365 [non-EU]Dstny [EU]-Combell [EU]Combell [EU]GlobalSign [non-EU]8 / 10BrakelEast Flanders54.0Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]4 / 5Wortegem-PetegemEast Flanders54.0Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]4 / 5ZonhovenLimburg54.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]4 / 5ZutendaalLimburg54.0Microsoft 365 [non-EU]Level27 [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]4 / 5MerchtemFlemish Brabant53.8Microsoft 365 [non-EU]Datacenter United [EU]--LCP [EU]Let's Encrypt [non-EU]0 / 0De PanneWest Flanders53.6Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]9 / 11RanstAntwerp53.3Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]5 / 6DuffelAntwerp53.3Microsoft 365 [non-EU]Datacenter United [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]5 / 6WesterloAntwerp53.3Microsoft 365 [non-EU]Level27 [EU]-HostYou [EU]HostYou [EU]Let's Encrypt [non-EU]5 / 7LaakdalAntwerp53.3Microsoft 365 [non-EU]Level27 [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]5 / 6OpwijkFlemish Brabant53.3Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]5 / 6GavereEast Flanders53.3Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]10 / 14Sint-Martens-LatemEast Flanders53.3Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]GlobalSign [non-EU]5 / 6LiedekerkeFlemish Brabant52.9Microsoft 365 [non-EU]Level27 [EU]-Proximedia [EU]Online/Proximedia [EU]Let's Encrypt [non-EU]6 / 7RoosdaalFlemish Brabant52.9Microsoft 365 [non-EU]Level27 [EU]-Alfanet [EU]Alfanet [EU]Let's Encrypt [non-EU]6 / 8PajottegemFlemish Brabant52.9Microsoft 365 [non-EU]Level27 [EU]-One.com [EU]One.com [EU]Let's Encrypt [non-EU]6 / 7BoortmeerbeekFlemish Brabant52.9Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]6 / 8Knokke-HeistWest Flanders52.9Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]Sectigo [non-EU]6 / 7HeuvellandWest Flanders52.9Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]6 / 7De HaanWest Flanders52.9Microsoft 365 [non-EU]Datacenter United [EU]-OpenProvider (Wholesaler) [non-EU]Hetzner [EU]Let's Encrypt [non-EU]2 / 5LedeEast Flanders52.9Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]6 / 7BastogneLuxembourg52.9Self-hosted (MDaemon) [EU]Cloudflare [non-EU]OVH [EU]Key-Systems (Wholesaler) [non-EU]Infomaniak [EU]Let's Encrypt [non-EU]3 / 6AffligemFlemish Brabant52.5Microsoft 365 [non-EU]Level27 [EU]-EuroDNS [EU]Ebrand [EU]Let's Encrypt [non-EU]7 / 9KortenakenFlemish Brabant52.5Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]7 / 8DiksmuideWest Flanders52.5Microsoft 365 [non-EU]Level27 [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]7 / 9KoksijdeWest Flanders52.5Microsoft 365 [non-EU]Level27 [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]7 / 8AssenedeEast Flanders52.5Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]GlobalSign [non-EU]7 / 8KruisemEast Flanders52.2Microsoft 365 [non-EU]Level27 [EU]-bNamed [EU]NameWeb [EU]Let's Encrypt [non-EU]8 / 9KelmisLiège52.2Microsoft 365 [non-EU]Host Europe [EU]-RegistryGate [EU]All-Inkl [EU]Let's Encrypt [non-EU]8 / 9HannutLiège52.2Microsoft 365 [non-EU]OVH [EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]8 / 9ZulteEast Flanders52.0Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]9 / 10GedinneNamur51.7Microsoft 365 [non-EU]Nuxit [EU]-Gandi [EU]Nuxit [EU]Let's Encrypt [non-EU]11 / 12AntwerpenAntwerp50.0Microsoft 365 [non-EU]Telenet [EU]-bNamed [EU]NameWeb [EU]Sectigo [non-EU]2 / 2BoomAntwerp50.0Microsoft 365 [non-EU]Datacenter United [EU]-HostYou [EU]HostYou [EU]Let's Encrypt [non-EU]2 / 2Heist-op-den-BergAntwerp50.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]2 / 2ArendonkAntwerp50.0Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]3 / 3EtterbeekBrussels-Capital50.0Microsoft 365 [non-EU]OVH [EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3EvereBrussels-Capital50.0Paradigm/Irisnet [EU]DigitalOcean [non-EU]-Combell [EU]Paradigm/Irisnet [EU]Let's Encrypt [non-EU]5 / 5JetteBrussels-Capital50.0Microsoft 365 [non-EU]Hostinger [EU]-Combell [EU]Paradigm/Irisnet [EU]Let's Encrypt [non-EU]2 / 2DrogenbosFlemish Brabant50.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 2LinkebeekFlemish Brabant50.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]1 / 1WemmelFlemish Brabant50.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]3 / 3DammeWest Flanders50.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]3 / 3OostrozebekeWest Flanders50.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]2 / 2WaasmunsterEast Flanders50.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 2GentEast Flanders50.0Microsoft 365 [non-EU]Openminds bvba [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]2 / 3HorebekeEast Flanders50.0Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]4 / 5LessinesHainaut50.0iMio (Walloon Intermunicipal IT Cooperative) [EU]Cloudflare [non-EU]OVH [EU]WillsPhil [EU]WillsPhil [EU]Let's Encrypt [non-EU]1 / 1FleurusHainaut50.0Microsoft 365 [non-EU]OVH [EU]-Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]4 / 4Aiseau-PreslesHainaut50.0Computic [EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3HensiesHainaut50.0Microsoft 365 [non-EU]One.com [EU]-One.com [EU]One.com [EU]Let's Encrypt [non-EU]2 / 2JurbiseHainaut50.0OVH [EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3QuiévrainHainaut50.0OVH [EU]Cloudflare [non-EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]2 / 2Braine-le-ComteHainaut50.0OVH [EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3Ham-sur-Heure-NalinnesHainaut50.0Microsoft 365 [non-EU]Hetzner [EU]-Anagramme [EU]Anagramme [EU]Let's Encrypt [non-EU]7 / 7Sivry-RanceHainaut50.0Keyes (WIN) [EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 3EstaimpuisHainaut50.0Microsoft 365 [non-EU]OVH [EU]-EuroDNS [EU]EuroDNS [EU]Let's Encrypt [non-EU]3 / 3Mont-de-l'EnclusHainaut50.0OVH (via SpamTitan) [EU]Cloudflare [non-EU]-OVH [EU]Cloudflare [non-EU]Let's Encrypt [non-EU]3 / 6HamoirLiège50.0Computic [EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]1 / 1OuffetLiège50.0Keyes (WIN) [EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 3WanzeLiège50.0Self-hosted (Microsoft Exchange (OWA)) [EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3AywailleLiège50.0Infomaniak [EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]2 / 2EsneuxLiège50.0Microsoft 365 [non-EU]OVH [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]2 / 2SoumagneLiège50.0Microsoft 365 [non-EU]OVH [EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]2 / 2JalhayLiège50.0Microsoft 365 [non-EU]OVH [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]10 / 10CrisnéeLiège50.0Microsoft 365 [non-EU]CBlue [EU]-OVH [EU]Zzam [EU]Let's Encrypt [non-EU]1 / 1DonceelLiège50.0Microsoft 365 [non-EU]Combell [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]5 / 5FaimesLiège50.0Keyes (WIN) [EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 3DiepenbeekLimburg50.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]3 / 3NieuwerkerkenLimburg50.0Microsoft 365 [non-EU]Datacenter United [EU]-LCP [EU]LCP [EU]Let's Encrypt [non-EU]2 / 2Sint-TruidenLimburg50.0Microsoft 365 [non-EU]Datacenter United [EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]3 / 3HeersLimburg50.0Microsoft 365 [non-EU]Datacenter United [EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]1 / 1HouffalizeLuxembourg50.0Keyes (WIN) [EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 3LibinLuxembourg50.0Microsoft 365 [non-EU]Combell [EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]4 / 4Libramont-ChevignyLuxembourg50.0iMio (Walloon Intermunicipal IT Cooperative) [EU]Cloudflare [non-EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]1 / 1CineyNamur50.0Self-hosted (Microsoft Exchange (OWA)) [EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH Anycast [EU]Let's Encrypt [non-EU]11 / 11OnhayeNamur50.0Microsoft 365 [non-EU]All2all [EU]-ClearMedia/Proximus [EU]Proximus [EU]GoDaddy [non-EU]3 / 3La BruyèreNamur50.0Microsoft 365 [non-EU]OVH [EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 7CerfontaineNamur50.0Keyes (WIN) [EU]Cloudflare [non-EU]OVH [EU]WillsPhil [EU]WillsPhil [EU]Let's Encrypt [non-EU]1 / 1WaregemWest Flanders47.9Microsoft 365 [non-EU]Combell [EU]--Proximus [EU]Let's Encrypt [non-EU]5 / 9VoerenLimburg45.9Microsoft 365 [non-EU]Yourhosting [EU]-Realtime Register (Wholesaler) [non-EU]AXC [EU]Sectigo [non-EU]4 / 8MechelenAntwerp45.0Microsoft 365 [non-EU]Microsoft Azure [non-EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]0 / 5Nazareth-De PinteEast Flanders45.0Microsoft 365 [non-EU]Level27 [EU]-Nomeo [EU]Azure DNS [non-EU]Let's Encrypt [non-EU]6 / 8AmelLiège44.4Mittwald [EU]Cloudflare [non-EU]Mittwald [EU]OVH [EU]Cloudflare [non-EU]Google Trust Services [non-EU]7 / 9ZonnebekeWest Flanders44.0Microsoft 365 [non-EU]One.com [EU]-One.com [EU]Cloudflare [non-EU]Let's Encrypt [non-EU]4 / 5AnthisnesLiège41.2Microsoft 365 [non-EU]OVH [EU]-Cybernet SA BE0460.526.504 [non-EU]Cybernet [EU]Let's Encrypt [non-EU]3 / 4Puurs-Sint-AmandsAntwerp41.0Microsoft 365 [non-EU]Amazon Web Services [non-EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]2 / 11OheyNamur40.0Microsoft 365 [non-EU]Maehdros [EU]-Maehdros [EU]Cloudflare [non-EU]Let's Encrypt [non-EU]4 / 4Scherpenheuvel-ZichemFlemish Brabant38.5Microsoft 365 [non-EU]Level27 [EU]-OpenProvider (Wholesaler) [non-EU]Cloudflare [non-EU]Let's Encrypt [non-EU]0 / 0BruggeWest Flanders38.3Microsoft 365 [non-EU]Fastly [non-EU]Belnet [EU]Belnet [EU]Belnet [EU]Let's Encrypt [non-EU]3 / 9FrameriesHainaut37.0Microsoft 365 [non-EU]Cloudflare [non-EU]Proximus [EU]DSTNY [EU]DSTNY [EU]Let's Encrypt [non-EU]2 / 5ZedelgemWest Flanders35.3Google Workspace [non-EU]Amazon Web Services [non-EU]-OpenProvider (Wholesaler) [non-EU]Antagonist [EU]Sectigo [non-EU]0 / 2BrasschaatAntwerp35.0Microsoft 365 [non-EU]Microsoft Azure [non-EU]-Cipal Schaubroeck [EU]Cipal Schaubroeck [EU]Let's Encrypt [non-EU]1 / 2Braine-le-ChâteauWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 7Court-Saint-ÉtienneWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6Grez-DoiceauWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6Mont-Saint-GuibertWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 6NivellesWalloon Brabant35.0Google Workspace (via FortiMail Cloud) [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6PerwezWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6TubizeWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Combell [EU]Combell [EU]Let's Encrypt [non-EU]3 / 6ChastreWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6HélécineWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6Ottignies-Louvain-la-NeuveWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6RamilliesWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Anagramme [EU]Anagramme [EU]Let's Encrypt [non-EU]3 / 6RebecqWalloon Brabant35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Combell [EU]Combell [EU]Let's Encrypt [non-EU]3 / 6AthHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6EllezellesHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]-Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 6SillyHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6FarciennesHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]Keyes (WIN) [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6GerpinnesHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 6DourHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6LensHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6MonsHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]Keyes (WIN) [EU]DSTNY [EU]DSTNY [EU]Let's Encrypt [non-EU]3 / 6Merbes-le-ChâteauHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Scaleway [EU]Ebrand [EU]Let's Encrypt [non-EU]3 / 6ThuinHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6CellesHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]One.com [EU]One.com [EU]One.com [EU]Let's Encrypt [non-EU]3 / 6PéruwelzHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]Infomaniak [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 6Comines-WarnetonHainaut35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6AnsLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 6AwansLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 6OupeyeLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 6Saint-NicolasLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 6TroozLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6PepinsterLiège35.0iCloud Mail (Apple) [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6Sankt VithLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]Hetzner [EU]InterNetX [EU]InterNetX [EU]Let's Encrypt [non-EU]3 / 6TheuxLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]-Netim [EU]Netim (France DNS) [EU]Let's Encrypt [non-EU]3 / 6VerviersLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH Anycast [EU]Let's Encrypt [non-EU]3 / 6WaimesLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6Trois-PontsLiège35.0iCloud Mail (Apple) [non-EU]Cloudflare [non-EU]-WillsPhil [EU]WillsPhil [EU]Let's Encrypt [non-EU]3 / 6GeerLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]-Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 6Saint-Georges-sur-MeuseLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 6WasseigesLiège35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Namebay [EU]eBusiness.be [EU]Let's Encrypt [non-EU]3 / 6ArlonLuxembourg35.0Microsoft 365 [non-EU]Cloudflare [non-EU]Proximus [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6VielsalmLuxembourg35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6ÉrezéeLuxembourg35.0Microsoft 365 [non-EU]Cloudflare [non-EU]Keyes (WIN) [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6NeufchâteauLuxembourg35.0Microsoft 365 (via Barracuda) [non-EU]Cloudflare [non-EU]-Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 6MussonLuxembourg35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 6HavelangeNamur35.0Microsoft 365 [non-EU]Cloudflare [non-EU]-Orange [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6Somme-LeuzeNamur35.0Microsoft 365 [non-EU]Cloudflare [non-EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 6YvoirNamur35.0Microsoft 365 [non-EU]Cloudflare [non-EU]Loopia AB [EU]Infomaniak [EU]Infomaniak [EU]Let's Encrypt [non-EU]3 / 6ProfondevilleNamur35.0iMio (Walloon Intermunicipal IT Cooperative) (via Vade Secure/Hornetsecurity/Proofpoint) [EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 6GemblouxNamur35.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Combell [EU]Combell [EU]Let's Encrypt [non-EU]3 / 6Sint-NiklaasEast Flanders33.9Microsoft 365 [non-EU]Google Cloud [non-EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]5 / 10WaremmeLiège33.6Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]One.com [EU]One.com [EU]Let's Encrypt [non-EU]4 / 7RochefortNamur33.6Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]4 / 7IttreWalloon Brabant33.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 5HonnellesHainaut33.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 5LobbesHainaut33.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 5EstinnesHainaut33.0Microsoft 365 [non-EU]Cloudflare [non-EU]One.com [EU]One.com [EU]One.com [EU]Let's Encrypt [non-EU]3 / 5Fexhe-le-Haut-ClocherLiège33.0Microsoft 365 [non-EU]Cloudflare [non-EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]3 / 5AttertLuxembourg33.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]Webadev [EU]Let's Encrypt [non-EU]3 / 5Sainte-OdeLuxembourg33.0Microsoft 365 [non-EU]Cloudflare [non-EU]-Nuxit [EU]Nuxit [EU]Let's Encrypt [non-EU]3 / 5Fosses-la-VilleNamur33.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 5Braine-l'AlleudWalloon Brabant32.5Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]5 / 9ManageHainaut32.5Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]IPNexia [EU]Combell [EU]Let's Encrypt [non-EU]5 / 8BerlareEast Flanders31.7Microsoft 365 [non-EU]Microsoft Azure [non-EU]-Level27 [EU]Level27 [EU]Let's Encrypt [non-EU]2 / 4RoeselareWest Flanders31.2Microsoft 365 [non-EU]Cloudflare [non-EU]DigitalOcean [non-EU]Telenet [EU]Telenet [EU]Google Trust Services [non-EU]0 / 0LincentLiège31.2Self-hosted (Roundcube) [EU]PlanetHoster [non-EU]-PlanetHoster [non-EU]PlanetHoster [non-EU]Let's Encrypt [non-EU]0 / 0SoigniesHainaut30.5Microsoft 365 [non-EU]Contabo [EU]-OpenProvider (Wholesaler) [non-EU]Cloudflare [non-EU]Let's Encrypt [non-EU]20 / 24WavreWalloon Brabant30.0Microsoft 365 [non-EU]Microsoft Azure [non-EU]-ClearMedia/Proximus [EU]OVH [EU]Gandi [EU]8 / 8ViséLiège30.0Microsoft 365 [non-EU]Amazon Web Services [non-EU]OVH [EU]OVH [EU]OVH [EU]Amazon Trust Services [non-EU]3 / 7NeupréLiège30.0Microsoft 365 [non-EU]Amazon Web Services [non-EU]Amazon Web Services [non-EU]P4X [EU]P4X [EU]Amazon Trust Services [non-EU]3 / 7HerveLiège30.0Microsoft 365 [non-EU]Amazon Web Services [non-EU]-ClearMedia/Proximus [EU]Proximus [EU]Amazon Trust Services [non-EU]3 / 7MessancyLuxembourg30.0Microsoft 365 [non-EU]Amazon Web Services [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Amazon Trust Services [non-EU]3 / 7TennevilleLuxembourg30.0Microsoft 365 [non-EU]Amazon Web Services [non-EU]Amazon Web Services [non-EU]EuroDNS [EU]Infomaniak [EU]Amazon Trust Services [non-EU]3 / 7ÉtalleLuxembourg30.0Microsoft 365 [non-EU]Amazon Web Services [non-EU]OVH [EU]OVH [EU]OVH [EU]Amazon Trust Services [non-EU]3 / 7HastièreNamur30.0Microsoft 365 [non-EU]Amazon Web Services [non-EU]Verixi [EU]ClearMedia/Proximus [EU]Proximus [EU]Amazon Trust Services [non-EU]3 / 7Leuze-en-HainautHainaut29.4Microsoft 365 [non-EU]Microsoft Azure [non-EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]7 / 10SchildeAntwerp29.0Microsoft 365 [non-EU]Google Cloud [non-EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]4 / 5BruxellesBrussels-Capital29.0Microsoft 365 [non-EU]Microsoft Azure [non-EU]-EuroDNS [EU]GIAL [EU]GlobalSign [non-EU]4 / 5JodoigneWalloon Brabant28.3Microsoft 365 [non-EU]Amazon Web Services [non-EU]CBlue [EU]OVH [EU]Zzam [EU]Amazon Trust Services [non-EU]5 / 9HottonLuxembourg28.3Microsoft 365 [non-EU]Amazon Web Services [non-EU]Amazon Web Services [non-EU]Gandi [EU]Gandi [EU]Amazon Trust Services [non-EU]5 / 9AuderghemBrussels-Capital27.9Microsoft 365 [non-EU]Microsoft Azure [non-EU]-Combell [EU]Paradigm/Irisnet [EU]Let's Encrypt [non-EU]6 / 7KortemarkWest Flanders27.5Microsoft 365 [non-EU]Amazon Web Services [non-EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]7 / 10AalstEast Flanders27.5Microsoft 365 [non-EU]Google Cloud [non-EU]-Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]7 / 8BassengeLiège27.2Microsoft 365 [non-EU]Amazon Web Services [non-EU]Amazon Web Services [non-EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Amazon Trust Services [non-EU]8 / 12BertrixLuxembourg26.7Microsoft 365 [non-EU]Amazon Web Services [non-EU]Amazon Web Services [non-EU]OVH [EU]OVH [EU]Amazon Trust Services [non-EU]11 / 15PlombièresLiège26.5Microsoft 365 [non-EU]Amazon Web Services [non-EU]Keyes (WIN) [EU]Gandi [EU]Gandi [EU]Amazon Trust Services [non-EU]12 / 18Woluwe-Saint-PierreBrussels-Capital25.0Microsoft 365 (via Sophos) [non-EU]DigitalOcean [non-EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]7 / 7BeauvechainWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]EuroDNS [EU]EuroDNS [EU]Let's Encrypt [non-EU]2 / 2Chaumont-GistouxWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]5 / 5GenappeWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-OVH [EU]OVH Anycast [EU]Let's Encrypt [non-EU]3 / 3IncourtWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-EuroDNS [EU]EuroDNS [EU]Let's Encrypt [non-EU]6 / 6La HulpeWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 4RixensartWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]1 / 1Villers-la-VilleWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3WaterlooWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3LasneWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]Amazon Web Services [non-EU]Gandi [EU]Amazon Route 53 [non-EU]Let's Encrypt [non-EU]3 / 6Orp-JaucheWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]1 / 1WalhainWalloon Brabant25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]5 / 5BeloeilHainaut25.0Microsoft 365 [non-EU]Google Cloud [non-EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]9 / 12BrugeletteHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-IPNexia [EU]Combell [EU]Let's Encrypt [non-EU]3 / 3ChièvresHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]2 / 2Frasnes-lez-AnvaingHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 4ChâteletHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]1 / 1Fontaine-l'ÉvêqueHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Combell [EU]Combell [EU]Let's Encrypt [non-EU]3 / 3Montigny-le-TilleulHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 3Les Bons VillersHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Combell [EU]Combell [EU]Let's Encrypt [non-EU]1 / 1QuaregnonHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3ColfontaineHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]Proximus [EU]Combell [EU]Combell [EU]Let's Encrypt [non-EU]1 / 1Le RœulxHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH Anycast [EU]Let's Encrypt [non-EU]3 / 3ÉcaussinnesHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]2 / 2AnderluesHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Uniweb [EU]Uniweb [EU]Let's Encrypt [non-EU]1 / 1ChimayHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Maehdros [EU]Maehdros [EU]Let's Encrypt [non-EU]3 / 3ErquelinnesHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]Telenet [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3FroidchapelleHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 3MomigniesHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3PecqHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 3RumesHainaut25.0Microsoft 365 [non-EU]Google Cloud [non-EU]-Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]7 / 7MouscronHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Cloudflare [non-EU]Let's Encrypt [non-EU]3 / 6BincheHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]Proximus [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3MorlanwelzHainaut25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]1 / 1ClavierLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3HéronLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]Weebly [non-EU]Nomeo [EU]Nomeo [EU]Let's Encrypt [non-EU]1 / 1NandrinLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Register [EU]Amen [EU]Let's Encrypt [non-EU]1 / 1Villers-le-BouilletLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]1 / 1EngisLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3TinlotLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3DalhemLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3FléronLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]Keyes (WIN) [EU]Combell [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 3SprimontLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]Fbwnetworks - Fbw Networks Sas [EU]Haisoft [EU]Haisoft [EU]Let's Encrypt [non-EU]1 / 1Grâce-HollogneLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-OVH [EU]OVH [EU]Let's Encrypt [non-EU]2 / 2AubelLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ESI Informatique [EU]eBusiness.be [EU]Let's Encrypt [non-EU]3 / 3BaelenLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Telenet [EU]Telenet [EU]Let's Encrypt [non-EU]4 / 4LimbourgLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Maehdros [EU]Maehdros [EU]Let's Encrypt [non-EU]1 / 1SpaLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3StavelotLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]OVH [EU]Let's Encrypt [non-EU]1 / 1WelkenraedtLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]InterNetX [EU]InterNetX [EU]Let's Encrypt [non-EU]1 / 1Thimister-ClermontLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]WDC-AS - Wallonie Data Center SA [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]1 / 1BerlozLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]3 / 3BraivesLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]1 / 1OreyeLiège25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 3Vaux-sur-SûreLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-Combell [EU]Combell [EU]Let's Encrypt [non-EU]1 / 1GouvyLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3NassogneLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-Net System [EU]Cloudflare [non-EU]Let's Encrypt [non-EU]3 / 6RendeuxLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3BouillonLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]1 / 1DaverdisseLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 3PaliseulLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Orange [EU]VOO [EU]Let's Encrypt [non-EU]3 / 3TellinLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]1 / 1FlorenvilleLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Gandi [EU]Gandi [EU]Let's Encrypt [non-EU]2 / 2Meix-devant-VirtonLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]InterNetX [EU]InterNetX [EU]Let's Encrypt [non-EU]3 / 3Saint-LégerLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]2 / 2TintignyLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]EuroDNS [EU]EuroDNS [EU]Let's Encrypt [non-EU]4 / 5HabayLuxembourg25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3AnhéeNamur25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]1 / 1BeauraingNamur25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3HamoisNamur25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Orange [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3AssesseNamur25.0Microsoft 365 [non-EU]Cloudflare [non-EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]2 / 2ÉghezéeNamur25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Keyes (WIN) [EU]Let's Encrypt [non-EU]3 / 3NamurNamur25.0Google Workspace [non-EU]Cloudflare [non-EU]Amazon Web Services [non-EU]ASP [EU]ASP [EU]Let's Encrypt [non-EU]8 / 8SombreffeNamur25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]3 / 3FernelmontNamur25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]5 / 5Jemeppe-sur-SambreNamur25.0Microsoft 365 [non-EU]Google Cloud [non-EU]-ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]7 / 7DoischeNamur25.0Google Workspace [non-EU]Cloudflare [non-EU]OVH [EU]OVH [EU]OVH [EU]Let's Encrypt [non-EU]8 / 8ViroinvalNamur25.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3Saint-GhislainHainaut23.5Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]-Proximus [EU]Let's Encrypt [non-EU]3 / 6RemicourtLiège23.5Microsoft 365 [non-EU]Cloudflare [non-EU]-Cybernet SA BE0460.526.504 [non-EU]Cybernet [EU]Let's Encrypt [non-EU]3 / 6VirtonLuxembourg23.5Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]-Diogenius [EU]Let's Encrypt [non-EU]3 / 6RouvroyLuxembourg23.5Microsoft 365 [non-EU]Cloudflare [non-EU]Infomaniak [EU]Key-Systems (Wholesaler) [non-EU]Infomaniak [EU]Let's Encrypt [non-EU]3 / 6BièvreNamur20.0Microsoft 365 [non-EU]Cloudflare [non-EU]Amazon Web Services [non-EU]OVH [EU]Cloudflare [non-EU]Google Trust Services [non-EU]3 / 7BurdinneLiège18.3Microsoft 365 [non-EU]Amazon Web Services [non-EU]Amazon Web Services [non-EU]ClearMedia/Proximus [EU]Microsoft [non-EU]Amazon Trust Services [non-EU]5 / 9BütgenbachLiège17.9Microsoft 365 [non-EU]Cloudflare [non-EU]-OVH [EU]Cloudflare [non-EU]Google Trust Services [non-EU]6 / 7FauvillersLuxembourg17.6Microsoft 365 [non-EU]Amazon Web Services [non-EU]Amazon Web Services [non-EU]OpenProvider (Wholesaler) [non-EU]Hostinger [EU]Amazon Trust Services [non-EU]3 / 7FlobecqHainaut17.5Microsoft 365 [non-EU]Cloudflare [non-EU]-OVH [EU]Cloudflare [non-EU]Google Trust Services [non-EU]7 / 8BocholtLimburg17.2Microsoft 365 [non-EU]Cloudflare [non-EU]mijn.host [EU]Mijn.host [EU]Cloudflare [non-EU]Google Trust Services [non-EU]8 / 10ZwalmEast Flanders16.8Microsoft 365 [non-EU]Cloudflare [non-EU]Google Cloud [non-EU]Nomeo [EU]Cloudflare [non-EU]Let's Encrypt [non-EU]20 / 24LierneuxLiège15.4Microsoft 365 [non-EU]Google Cloud [non-EU]-ASCIO/Tucows (Wholesaler) [non-EU]Siteground [EU]Let's Encrypt [non-EU]0 / 0ZuienkerkeWest Flanders15.0Microsoft 365 [non-EU]Cloudflare [non-EU]-Vimexx [EU]Cloudflare [non-EU]Google Trust Services [non-EU]1 / 1LiègeLiège15.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]Keyes (WIN) [EU]Cloudflare [non-EU]Let's Encrypt [non-EU]7 / 7BüllingenLiège15.0Microsoft 365 [non-EU]Sucuri Website Firewall [non-EU]-Combell [EU]Cloudflare [non-EU]Starfield [non-EU]8 / 8MartelangeLuxembourg15.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Microsoft [non-EU]Let's Encrypt [non-EU]1 / 1MettetNamur15.0Microsoft 365 [non-EU]Cloudflare [non-EU]OVH [EU]ClearMedia/Proximus [EU]Microsoft [non-EU]Let's Encrypt [non-EU]1 / 1AntoingHainaut11.8Microsoft 365 [non-EU]Cloudflare [non-EU]-NameWeb (Wholesaler) [non-EU]Proximus [EU]Let's Encrypt [non-EU]3 / 3VerlaineLiège11.8Microsoft 365 [non-EU]Cloudflare [non-EU]-OpenProvider (Wholesaler) [non-EU]Openprovider [EU]Let's Encrypt [non-EU]2 / 2MalmedyLiège11.8Microsoft 365 [non-EU]Cloudflare [non-EU]Private Customer [EU]Key-Systems (Wholesaler) [non-EU]Infomaniak [EU]Let's Encrypt [non-EU]3 / 4Vresse-sur-SemoisNamur11.8Microsoft 365 [non-EU]Cloudflare [non-EU]Infomaniak [EU]Key-Systems (Wholesaler) [non-EU]Infomaniak [EU]Let's Encrypt [non-EU]3 / 4 ↑ Up to table of contents Data collected August 2026 with my digital sovereignty scanner. Municipality boundaries: Statbel, Belgium's statistical office, CC BY 4.0. Found an error or an outdated result for your municipality? Let me know. --- ## Newsletter Archive ### Token by token Source: https://consultcolin.eu/newsletter/archive/token-by-token/ *8 September 2026* - A very impressive and expensive word-guessing process. Over the past few days, I've found myself explaining multiple times how large language models (generative AI) work. So, I thought I'd repeat it here for reference. An LLM doesn't actually "write an answer"; at least not the way you or I do. It produces a single token at a time (a token can be a word or part of a word) and has no memory of having done so. Every token is produced by re-reading absolutely everything from the very start of the conversation, both your words and its words, then guessing the most plausible next token. It then repeats this loop: re-read everything, predict one token, append it to the end, repeat. You can see why these things tend to be resource hungry. That's the whole scheme: no planning, no long-term memory, no goals, no "intelligence." Just a very advanced pattern-matching system that keeps asking itself the same question in a loop: "given all the text so far, what word (or part of a word) is most likely to come next?". Most of the improvements we get these days are in what's referred to as harnesses, the software scaffolding that sends and receives tokens in a loop to and from the LLM (like Claude Code or CoWork). And none of that is "AI"; it's good old-fashioned code. Very impressive code, but still simply code doing what code has always done: following instructions really fast. Colin PS: Yes, I massively simplified this on purpose. No "vectors" or "transformers" or "matrix multiplication"; you can go and study linear algebra on your own time. --- ### Sovereignty: sold separately Source: https://consultcolin.eu/newsletter/archive/sovereignty-sold-separately/ *7 September 2026* - Big tech owns 70% of Europe's cloud; the other 30% are probably being leased back to them. I keep seeing news headlines about EU data-centre sovereignty and how we're building more capacity to win the invisible "AI War" everyone seems to be fighting these days. 70% of the EU cloud market is already owned by the three horsemen: Amazon, Microsoft, and Google. And most new capacity coming online is either owned outright by them or leased to them long-term. Big tech is expected to account for two thirds of European data-centre demand and most of the financing traces back to American balance sheets too. A data-centre happily sitting on EU soil can still be owned and run by a US corp. Which means US law, specifically the CLOUD Act, can stick its nose into any data that a US company has "possession, custody, or control" of; a deliberately elastic term that a national-security-pilled administration has every incentive to stretch. Brussels do sort of know this. The EU's Cloud and AI act does define grades based on ownership, but the base one (the one for most public contracts) only requires a EU subsidiary and EU storage, not EU ownership. Genuine EU-owned infrastructure is best, but only if it completely severs the umbilical cord to a US parent. And if a fully EU-owned data centre is running US cloud software, well, we're back to the same choke point. So, lots of Gigawatts coming, headlines about European resilience, but, below most of it, a cable leading back to the US. So much for sovereignty. If your risk profile requires real EU hosting and jurisdiction, don't just trust the sign on the building, make sure you dig all the way back to the roots. Colin --- ### Friday links for September 4th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-09-04/ *4 September 2026* - Cancer capital, office AI hate, subprime AI crisis, data harvesting for all, and watching railways. The "metastatic" issue 1. VC isn't VC anymore - understanding the rise of Cancer Capital Your mental image of venture capital and how it works is probably outdated. These days it's mostly an ugly, agenda-pushing machine. Move fast and metastasise things. 2. Why office workers are turning against AI The more power you have in the workplace, the more you like AI; the less you have, well, you can guess how that scales... 3. The Teaser Period: Why the AI Boom Is Hitting a Reset Wall This is long and dense, but it's a convincing comparison between the 2008 financial collapse and the current AI boom's trajectory. Ironically, it's clearly written with the help of generative AI; the bubble is reviewing itself. 4. Meta Smart Glasses Empower Blind People to Participate in Corporate Surveillance This is true accessibility. Equal opportunity data harvesting for all. 5. One day on rails And just a lovely visualisation of railway traffic across Europe for a whole day. On rotation This week's soundtrack is Lost Themes 10th Anniversary Expanded Edition by John Carpenter. May your inbox stay empty until Monday, Colin --- ### Carbon dating your user data Source: https://consultcolin.eu/newsletter/archive/carbon-dating-your-user-data/ *3 September 2026* - Necessary doesn’t mean forever. This week, an audit I was helping an organisation with turned up user data that had been fossilising in their systems for, in some cases, over 10 years. The question then was: what do we do with it? It wasn't used anymore; most of it dated from a time when they weren't even offering the same services. The GDPR doesn't set a number for this. Article 5(1)(e), the storage limitation principle, just says you keep personal data only as long as it's necessary for the purpose you collected it for. The exact duration doesn't matter; what matters is that you can tie it to an actual, documented purpose (that's what you'll be asked for). You've probably received emails from software services notifying you your account would be deleted because you hadn't used it for two years. This is an arbitrary cutoff that seems to have become folklore. But folklore is a good place to start, so we purged all accounts older than that. The next steps: for each dataset, ask what the original purpose was, whether that purpose is still active, and how long "necessary" is to fulfil it. In some cases there are legal retention duties, like accounting. Before you end up with a decade-old archive yourself, think about setting up a periodic data clean-up. You'll be in a stronger legal position, and you limit the damage if you're ever hacked. Colin --- ### Sandwich sanctions Source: https://consultcolin.eu/newsletter/archive/sandwich-sanctions/ *2 September 2026* - How a Belfast café became collateral damage in America's Cuba obsession. Carlos Arguelles runs a little Cuban sandwich shop in Belfast. It's legal, he has a business license, all above board, definitely not under US sanctions. His shop works through Deliveroo for home orders. And, for the past few months, payments from Deliveroo have been sporadic to non-existent. Not through any fault of Deliveroo's, but simply because these payments go through an American bank (Deliveroo is owned by DoorDash, a US company) and the bank's compliance system twitches at any mention of "Cuba". He's now out more than £7,000 and had to stop using the service because paying wages is hard when some robot in New Jersey is hoarding your money. Obviously, the US President didn't put a sandwich shop on his target list, the bank's software did. But, yet again, that's the point: the US doesn't need to target you directly. All that's needed is the infrastructure you rely on (payments, maps, cloud, whatever...) to run through systems subject to US law, and US political issues (there are many) suddenly become your issues too. Colin --- ### Lake Sovereignty Source: https://consultcolin.eu/newsletter/archive/lake-sovereignty/ *1 September 2026* - Sovereign until Google says otherwise. If you read the news, you're aware that Trump officially renamed Lake Ontario to Lake America this week because he's a giant baby throwing a tantrum over trade with Canada. But that's not the interesting part here. Google immediately updated its maps to match the decision: US users see "Lake America", Canadian ones see "Lake Ontario", and everyone else sees both. Tim Cook also got the phone call and is preparing his own capitulation. That was the intended split, but embedded maps on Canadian government and utility websites started showing "Lake America" too. The outage map for a water company, a federal housing map, and more; they all started showing a name their own government didn't approve of. A map widget talked to Mountain View, and Mountain View does what Washington tells it to these days. If a foreign entity can control what your own government's website shows, it's not really your infrastructure. A lake name is obvious and gets noticed. Not everything a platform changes on Washington's orders will be. Colin PS: If you're looking for a European map service to add to your app or website, I've been very happy with Geoapify. --- ### The goalposts moved, yet again Source: https://consultcolin.eu/newsletter/archive/the-goalposts-moved-yet-again/ *31 August 2026* - An Italian collective didn't break any law. Their domain got disappeared nonetheless. I've mentioned the US sanctions on the ICC (International Criminal Court) several times before. Unsurprisingly, the sanctions didn't stop there, they're metastasising. On the 26th of August, the US Treasury designated Autistici/Inventati (A/I), an Italian volunteer collective that provides email, hosting, and encrypted communications to activist groups, as a specially designated global terrorist. Two days later, their website, autistici.org vanished. The US-based .org domain registry put the domain into a status called "serverHold", basically a bureaucratic kill-switch that made the site unreachable. As I've also said before, no need to kill the target if you control the plumbing. Whatever your opinion of A/I's politics or their users, this is a problem: a US decision affected a foreign organisation's domain (and other services, like banking) based on the argument that providing infrastructure to people the US doesn't like counts as support for terrorism. It's a new target, but the (now expanding) pattern is the same: using infrastructure providers as a means of sanction. The goalposts are moving. Today it might be organisations you don't care about, tomorrow it might be yours. Because the definition of "wrong" will change. As far as your digital tools go, you're only safe by accident. Time to write that plan. Colin --- ### Friday links for August 28th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-08-28/ *28 August 2026* - LLM foreign interference, Bill Gates said something, datacentre lies, Hetzner tour, and dumb AI videos. The "ridicule" issue 1. Israeli PR wants to answer your ChatGPT questions A French PR Firm has built an "institute" intended to feed positive ideas about Israel into large language models. ChatGPT and Perplexity are already citing them. This type of data poisoning is a massive future risk and, because of the way LLMs works, very difficult to fix (which I'm sure the lobbyists love). 2. Bill Gates Announces That He Is the First Person Ever to Be Concerned About the Effects of AI You've probably seen the media frenzy around Bill Gates' blog post. This is the only article I've seen that's not just more "CEO said something" stenography. The original blog post also makes clear that Gates doesn't understand how LLMs work. He should ask Clippy to explain. 3. Is this really a good reason to triple datacentre capacity in Europe? The European Commission's AI action plan proposes to triple datacentre capacity within the next five to seven years. The source of this number is... a very dumb calculation by a real estate firm that deals in... datacentres. 4. This DIY Datacenter is NUTS - Hetzner Tour (video) Talking of datacentres: this is an ad, but an interesting one. It's a tour of Hetzner's datacentre in Germany. They're very popular (I host several servers there) and have a unique approach. 5. Husk IRL Hilarious videos of ridiculous AI interactions. From attempting to replace car horns to counting the number of Rs in strawberry (still two, it seems). On rotation This week's soundtrack is Window Left Open by K. Freund. Off to practice my weekending, Colin --- ### Spam, hackers, and other bedtime stories Source: https://consultcolin.eu/newsletter/archive/spam-hackers-and-other-bedtime-stories/ *27 August 2026* - Four email questions, answered without the panic. Yesterday's message about running your own email server triggered a few questions. It turns out quite a few of you have been thinking about this. How about spam? Does a self-hosted email server not drown in it? It actually works better than my previous email hosted by a large commercial service. That was quite a surprise for me, I was expecting something equivalent at best. I won't drag you through the technical details, it's not the place, but you do need to make some tweaks to the service configuration and to your domain setup for it to work properly, particularly so it talks to spamhaus and gets all the blacklists. Definitely feasible. Aren't you scared of getting hacked? Yes, it can be an issue. And I don't have Google's security team. But I also don't have a Google-shaped target on my back. That will depend on your own threat assessment and who you are. But I've also hardened the server that hosts the email, gone through the usual security checklists, implemented tools like crowdsec, setup offsite backups, and so on. It's not arcane knowledge. How about migrating old emails into the new server? There's no friendly built-in migration tool like you get at some commercial email services. I used a tool called imapsync, but, honestly, in many cases you could probably just connect your email client to old and new servers at the same time and drag the mail across like it's 2004. What happens if the server falls down? Nothing, really. Email was designed by people who assumed servers would break. Unless your server is down for weeks, sending servers will just queue the email and try sending again later at different intervals. You can also setup a backup mail exchanger (fancy name for server) that will hold email until your main server is up. It's not the recommended path anymore, but it can be done, even for free. Colin --- ### Relay, don’t surrender Source: https://consultcolin.eu/newsletter/archive/relay-dont-surrender/ *26 August 2026* - Inbound is easy. Outbound just needs a good reputation – borrowed. A small NGO came to me a few weeks ago. Over the past couple of years, they've been slowly and successfully extracting themselves from big tech and onto local, preferably open-source, solutions. One thing they wanted to do, was move email onto their own self-hosted server under their own rules. Their IT provider said no, told them it wouldn't work, that they'd end up on spam block lists everywhere and that, in 2026, you should stick with one of the big boys if you wanted your email to flow without hindrance. Google and Microsoft would just refuse to hear from them if they went solo. This is a common misconception that, as always, is partly based in truth. When you send an email, your mail server connects to the server hosting your recipient. Let's say it's Gmail. Gmail runs a whole bunch of checks to make sure the sending server (yours) has a good reputation, is properly setup, hasn't been caught doing bad things, and so on. Pass, and your email is let in. Fail and, well, you can guess what happens. That's outbound; inbound email has no such problem. Even if your server is unknown, Gmail will happily deliver to it. So, the fix is simple: setup your own server, but have it relay outgoing email through a service that already has a good reputation (something that's not easy to build). Back to the NGO: I built a demo that did exactly that. We used Stalwart on a cheap web host as the email server, and we relayed outgoing email via Scaleway where you get 300 emails before paying 25 cents/1000 emails (other services available). And it worked, their IT provider was convinced. And so was I - convinced enough that I moved my own email onto an identical setup. None of this sovereignty work is effortless. But it's a solvable problem, not a wall. Colin --- ### Privacy theatre, Apple edition Source: https://consultcolin.eu/newsletter/archive/privacy-theatre-apple-edition/ *25 August 2026* - ChatGPT is now in the group chat, whether invited or not. We're being slowly conditioned to accept complete loss of privacy. Ubiquitous security cameras become Meta glasses on every face, the tracking tech in ankle monitors turns into Smart watches, targeted CSAM scanning (think of the children!) turns into scanning everything. Every surveillance technology slowly morphs into something with better UX that we willingly adopt. As mentioned previously, we already live in a world where you have to assume your emails will be fed to ChatGPT, Gemini, or some other "assistant". And now, OpenAI has just announced that ChatGPT for Mac can read all your iMessages. This will certainly be adopted by many, and I'm sure other platforms will follow if there's no pushback. This is particularly perverse for a few reasons: iMessage is end-to-end encrypted. There's an expectation of privacy because of this (Apple's marketing leans on this). But your correspondent can now upload messages, before encryption or after decryption, to a large language model; with no indication of this on your side (granted, they could copy-paste it before, but now it's automated). Because ChatGPT gets full access, it also gets full access to archives going back as far as they're stored. Your private messages from 2 years ago? They might be heading for OpenAI's servers right now. Anything that ends up on OpenAI's infrastructure is fair game for US authorities thanks to the CLOUD Act. They just need to ask. If you're an organisation that uses iMessages internally, particularly if that includes sensitive information, it might be time to switch to a secure alternative like Signal or Threema. And even if that's not your profile, it's worth thinking about what you type from now on. Colin --- ### The bubble pops, Clippy sends the bill Source: https://consultcolin.eu/newsletter/archive/the-bubble-pops-clippy-sends-the-bill/ *24 August 2026* - The real risk to your organisation doesn't run on GPUs. If you exclusively read or listened to European tech media these days, you'd think European digital sovereignty had only one problem: the lack of home-grown frontier AI and data-centres. Across the pond, the AI numbers are looking more worrying by the day, though; and the risk of OpenAI going belly up is no longer theoretical. The bubble popping itself wouldn't affect European businesses directly (the economy is another story). Chatbots would stop yammering and people would have to start doing things manually again, pay through the nose, or use open-weights models. But, let's talk about Microsoft. Microsoft is heavily invested in OpenAI via infrastructure, purchase commitments, etc; its tentacles are everywhere. If OpenAI failed, Microsoft would face a major write-off. We're talking $250 billion in commitments alone. Now, for many organisations, Microsoft 365 is the backbone of their business: email, calendars, identity, storage, etc. Take it away and the consequences would be bad and far more immediate than if some chatbot took a dirt nap. Microsoft could easily take advantage of that dependency to compensate, at least partially, for the OpenAI shock. They could raise prices at renewal, kill discounted plans (they're willing to do that with devastating effects), move functionality into more expensive bundles, and enshittify the whole stack. Their customers don't need to be legally prevented from leaving for lock-in to work. Migration can just be too scary or disruptive. So the price increase gets eaten. We should stop worrying about European AI so much and worry about whether we can walk away from US Big Tech when they start compensating their generative AI losses by taking advantage of lock-in. (And we can scoop up cheap GPUs for "sovereign AI" from the fire sale if we still want to go down that route) Colin --- ### Friday links for August 21st 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-08-21/ *21 August 2026* - Melting brains, no tech for SV kids, AI superstition, Darth Vader loves Flock, and railway scanning. The "brain tissue" issue. 1. MIT Study: AI Causes Reduction in Users' Brain Activity The brain is basically a muscle. If you don't use it, it atrophies, and building back takes time. At this rate, the coffee machine will soon be smarter than the average office worker. 2. Silicon Valley Executives Are Tech Fans. Just Not for Their Own Kids A well known maxim in drug-dealing circles: don't get high on your own supply. 3. Super-intelligence or Superstition? A study showing correlation between confidence in AI predictions and belief in astrology or the paranormal. Try replacing "ChatGPT said..." in any conversation with "The psychic said..." and you'll get the idea. 4. Darth Vader Speaks at City Council Meeting Flock number plate recognition cameras are being deployed absolutely everywhere in the US. Many communities are up in arms about this. In one of them, Darth Vader himself turned up to defend the panopticon. 5. Using the railway network as a flatbed scanner Taking (very long!) linear pictures out of a moving train or ferry. Make sure you check out the gallery. On rotation This week's soundtrack is New Avatar by Kelela. The weekend calls, I must answer, Colin --- ### Auditing Europe Source: https://consultcolin.eu/newsletter/archive/auditing-europe/ *19 August 2026* - A digital sovereignty scan of every national government website. After running a digital sovereignty scan of all Belgian municipalities and turning it into my first blog post, I thought I'd zoom out a little and do the same for European nations, top to bottom. So, here's article number two: a full sovereignty audit of every national government website in Europe. As always: could do better. But it's more encouraging than the municipal scan. There's still a lot of work to do, particularly for some countries that are de facto digital US colonies. As before, this one contains graphs and tables. A device wider than a phone is recommended for comfort - unless you enjoy squinting a lot. And, rest assured, I won't be plugging every new post here. It's still novel right now (on my end, anyway). Colin --- ### Verification immunity Source: https://consultcolin.eu/newsletter/archive/verification-immunity/ *18 August 2026* - Even the most careful people stop checking AI output. Yesterday, writing about the invulnerability bias, I touched on the related idea that using generative AI to enhance work usually lacked the appropriate guardrails. The most obvious guardrail is simply checking the output. Interestingly, nearly every time I talk with someone who uses generative AI in their work, and mention the non-deterministic (not always the same result from the same input) aspect of these chatbots, they insist that they always check the work. To put it bluntly: I don't believe them. And, I say that as someone who's been there. There's another bias at work here: the automation bias. It's the tendency to trust automated systems above your own judgement. It can be found in all kinds of places: from GPS sending people into lakes, to the UK Post Office Horizon scandal. Added to that, we have verification complexity. When verification is cognitively demanding, people default to trusting the system - even if they honestly intended to check initially. Combine those two and you get this pattern: people verify once or twice in the beginning, then the cognitive costs of the repeating work lead them to complacency. We see this every day: lawyers citing non-existent cases in court, magazine articles recommending books that don't exist, travel guides with restaurants that were never there, the list goes on... A bad reference in an email might not cause much damage. But a generated spreadsheet you didn't check, a dashboard with the wrong numbers (I saw this just recently), or a report confidently stating something that's not true; those might cost you credibility, clients, or even your job. Expecting anyone, myself included, to verify everything isn't realistic. Colin --- ### A study in denial Source: https://consultcolin.eu/newsletter/archive/a-study-in-denial/ *17 August 2026* - AI will take your job, unless you’re the one selling AI. There's an interesting phenomenon I keep encountering, most recently this weekend. I talk to people who've gone all-in on generative AI and bought into the inevitability story. They use AI to write, code, design, "think", babysit their children, whatever... And when the conversation unavoidably leads to the topic of large language models replacing jobs, they all tell me in their own way that, yes, it's true, generative AI will be taking all the jobs; but not theirs. No Sir, their job is too complex to be taken over by the token machine. It reminds me of the people who think car accidents only happen to others. There's even a name for this: the invulnerability bias. Now, I don't believe generative AI is even remotely capable of replacing most jobs. It can enhance some of them - with proper guardrails (which, honestly, I've yet to see). But the billionaires selling AI? Or the "thought leaders" and managers who idolise these same billionaires, believing they belong to the same club? Those people are absolutely capable of selling the AI-takes-all-the-jobs concept to the rest of the corporate world. It doesn't even need to work properly. And, when that happens, the invulnerable will find out they were also everybody else. Colin --- ### Friday links for August 14th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-08-14/ *14 August 2026* - AI constraints, Amazon pollution (the other one), giant LLM hack, too lazy to check, and everyday wonders. The "not AI again" issue. 1. On AI Coding and Its Discontents Related to my Theory Of Constraints email earlier in the week: faster code generation is just pushing problems elsewhere, and developers are starting to notice and despair. It's progress... if you squint. (See also) 2. Amazon's New AI Data Center Is So Enormous That It Appears It Will Become the Largest Single Source of Pollution in the United States Americans... supersizing everything, including emissions. Next day delivery on heatwaves - coming soon. 3. Largest AI Supply Chain Breach of 2026 Thousands of companies using a generative AI tool in their CI/CD pipeline (a "conveyor belt" that automatically tests and ships software) without proper security have had their credentials and other secrets compromised. Some big names in there, including europa.eu, who's data protection rules don't apply to themselves, apparently. 4. Error by AI scribe during medical appointment leaves patient devastated This is the problem with automated transcription. It will make mistakes, practically by design. It's all very nice saying people should check the work, but we all know that doesn't happen. Checking the work is up there with reading terms and conditions or paying attention to a car alarm. 5. Ordinary abundance The wonders we live with every day, without even noticing. Probably because we're too busy ordering chatbots around. On rotation This week's soundtrack is Musica Per Progetti Incompiuti by Gianclaudio Hashem Moniri. The horrors persist, but so do I, Colin --- ### Google can play too Source: https://consultcolin.eu/newsletter/archive/google-can-play-too/ *13 August 2026* - Yesterday’s lesson also applies to Google. Yesterday's email triggered a couple of replies with an obvious follow-up: can the same synchronisation process I built for Microsoft 365 be built for Google? Yes it can (in theory - I haven't tried). It looks a bit more complicated because you have to use different APIs for different services, but they all exist under the Google Workspace APIs umbrella. Gmail, Calendar, Drive, Docs,... they're all in there and the Gmail one supports delta/incremental sync and push notifications, so porting the same type of mirroring on email change should absolutely be feasible. Build it and let me know. Want it built and can't be bothered? Also let me know. Colin --- ### Big tech giveth, big tech taketh away Source: https://consultcolin.eu/newsletter/archive/big-tech-giveth-big-tech-taketh-away/ *12 August 2026* - A subcontractor’s ban and a lesson learned. Have you ever thought about what would happen if you suddenly lost access to your email? Would the years of conversations, supplier info, invoices ... the whole connective tissue of your working life still be accessible? If you're old-fashioned enough to run an actual email client that stores data on your device, you might claw back most of it ... might. If you're on webmail, like most organisations are these days, you're not clawing anything back. A local organisation I'm now working with recently came to that realisation when one of their subcontractors had their Google account permanently disabled and their appeals rejected. Everything gone, not only email (the old "all your eggs in one basket" problem I keep harping on about). Their long-term plan is to migrate everything to European providers but that takes time. Migrations always do. Until that happens, they want to protect themselves against similar evaporating accounts. I wanted to build something for them that was more resilient than a local email client and a prayer. And it turns out Microsoft actually publish an API (a way for computers to talk to each other) called Graph that's perfect for this. I'll skip the technical details but, for every mailbox in the organisation, a script watches for new emails, fetches them, and appends them to a backup mailbox at Infomaniak, a Swiss provider where actual humans reply to your support queries. Deletes, moves, etc are all mirrored too. In the future, this same process can be used for calendars, contacts, even Sharepoint files. One migration at a time, though. If your organisation depends on the continued goodwill of some big tech platform and their automated ban algorithms, think about building a mirror. At the very least, run a local email client and hope for the best. Colin --- ### The Goal vs The Hype Source: https://consultcolin.eu/newsletter/archive/the-goal-vs-the-hype/ *11 August 2026* - Generating lines of code is rarely a constraint. You may have heard of the Theory of Constraints (TOC), a way of thinking developed by Eliyahu Goldratt in the early 80s. It was born in manufacturing lines, but applies to almost any area. TOC treats a system like a chain. Each step is a link, and throughput is limited by the weakest link: the step with the least capacity. Polishing the other links won't increase overall output if you don't fix the bad one. TOC is about finding that constraint, making the most of it, and then upgrading it. I'm simplifying, of course. Goldratt wrapped this into The Goal, which manages to somehow be both a business book and a novel. Anyway, every time I see AI-driven or AI-assisted development being celebrated in organisations for its "productivity", it reminds me of the TOC. The constraint is rarely number of lines of code produced per hour. And when AI does accelerate coding, the bottleneck usually relocates elsewhere: code review, testing, refactoring, security, SRE, governance, or even upstream to requirements clarity. This shows up most shamelessly when a vendor or agency sells itself as "AI boosted" (an actual term in a proposal I read last week). What you need to figure out in that case is what happens after the code is generated. How are review, security, testing, and long-term maintenance handled? Faster code production is not the same as faster delivery of reliable software. If your delivery timeline shrank, something got moved, deferred, or even dropped. Colin --- ### A sovereignty audit of my backyard Source: https://consultcolin.eu/newsletter/archive/a-sovereignty-audit-of-my-backyard/ *10 August 2026* - 565 Belgian municipalities scanned for digital sovereignty. I've been trying (not always successfully) to keep these missives short. But there are some subjects I'd like to explore that require a lot more room. In that spirit, I've added a blog to my website where I can sprawl across a subject like a cat in a sunbeam. The first one of these is a deep dive into the digital sovereignty of all 565 municipalities in Belgium (well, 564 - one of them, the tiniest in the country, doesn't have a website). I live here, so it seemed like the natural place to start: in my backyard. You can find the results in this blog post. (it's got tables and graphs, so you'll be more comfortable viewing it on a larger device) Always open to feedback. Colin --- ### Friday links for August 7th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-08-07/ *7 August 2026* - Bad predictions, the Microsoft hole, nightmare robot, and a plant-saving phone. The "foretelling" issue 1. The Archive of Incorrect AI Predictions An archive of prophecies made about artificial intelligence dating back to its earliest definitions. People have been predicting this stuff, incorrectly, since the 50s. Sam Altman and Elon Musk are just the latest to be confidently wrong. 2. The AI Demand Bubble Analysts now estimate that over 70% of Microsoft, Google, and Amazon's predicted revenues are from OpenAI and Anthropic alone. There's pretty much no demand outside these two unsustainable labs, but they're building capacity as if every toaster on earth is about to need heavy compute. 3. This new robot centaur designed to save lives is pure nightmare fuel I'm not sure I'd feel relieved if this demon goat from hell showed up to save me. 4. This plant will die if I'm on my phone too much (video) "Put the phone down or the plant gets it!". Simone Giertz builds another wild gadget where, if she's on the phone, not only is she taking away from her own life, she's also doing it to a plant. On rotation This week's soundtrack is Thief by Tangerine Dream. Bye-bye butterfly, Colin --- ### Subtracting Washington Source: https://consultcolin.eu/newsletter/archive/subracting-washington/ *6 August 2026* - e-Evidence goes live soon, and it's nothing like the CLOUD Act. A new excuse (to me, anyway) I was given this week for ignoring digital sovereignty was that it didn't matter if you picked a European or American service because Europe has a new law letting police hoover up your data anyway. That it's the same as the US CLOUD Act, so why bother? What they were referring to was e-Evidence, a law that goes live in a couple of weeks. And it's definitely not the same - I looked. Let's be clear: no one's trying to avoid the police here, every country lets them gather evidence; that's the deal, that's fine. The problem with the CLOUD Act is that it lets US authorities reach across an ocean and yank data out from anywhere a US company parks it. No European court involved; and frequently with a gag order attached, forbidding the company from telling you. Your files could be sitting in a data centre in Frankfurt or Amsterdam and walk straight out the back door without you or anyone else knowing. The European law is nothing like that. A request has to go through a judge, then the country where the provider is based gets told and gets to say no. A European court oversees the whole thing, and you can fight it. No back doors or silent extraction here... Another difference: the European law covers anyone offering services in Europe, Americans firms very much included. So US providers actually fall under both laws at once. Choosing European services subtracts the US law from the deal. So reality is kind of the opposite: the law that treats everyone the same is the European one. The CLOUD Act is the one you get to opt out of - by not handing your data to a company that Washington can compel secretly. Colin PS: For more, go to the horse's mouth - the EU's plain-language summary. --- ### It takes two to keep a secret Source: https://consultcolin.eu/newsletter/archive/it-takes-two-to-keep-a-secret/ *5 August 2026* - Why buying email privacy for one doesn't work. I got the perennial encrypted email question this week: is Tuta or Proton the best email provider for privacy? My answer is... usually neither. Let's say you make all the right moves: encrypted provider, keys in your control, privacy policy you've actually read. Gold star! Then you email a client... In most cases, it's going to land in the gaping maw of Google or Microsoft where it will get scanned, indexed, backed up, and probably fed to some AI assistant. You've encrypted your end. The other one? Not so much (Yes, some encryption is involved in transit, but it's not the same). Email privacy isn't a product you can purchase for just yourself because email is a network, a collaboration. Every message lives at least in two places, and one of them won't be under your control. It's not 100% pointless. Your provider choice can still protect what you control: where your own email is stored, your account details, recovery paths, etc. Just don't kid yourself that the conversations are private, unless you exclusively talk to people who also use these services. Colin --- ### Don't roll the dice Source: https://consultcolin.eu/newsletter/archive/dont-roll-the-dice/ *4 August 2026* - The AI Act might actually have teeth. Might. I got a couple of reactions to my email yesterday about the AI act coming into force and the necessity to label chatbots as machines. Both said, in a nutshell: "Will people really care about labelling their chatbot? Most cookie banners out there are flatly illegal and seem to stay that way. Will there be any enforcement?" To be honest, I don't know. They're not wrong to be cynical. Europe seems to enforce e-privacy and GDPR rules across Europe the way I floss my teeth - sporadically. But "not enough" isn't "never": I've seen personal complaints get acted on, albeit after marinating for 2 years, and there are plenty of fines being imposed all the time. The biggest problems are that complaints and enforcement are country-specific. And many countries starve their digital protection authorities. Others, like Ireland, see the cash rolling in from big tech and decide that a sleepy regulator is a good regulator. The difference with the AI act, which makes me cautiously hopeful, is that enforcement seems to be at least centralised for the big fish. I'm already hearing of generative AI content being labelled on large social media platforms. Smaller fish still swim in local waters, though. Which probably means the usual glacial pace if someone complains about their insurance broker using an unlabelled chatbot. Personally, I wouldn't roll those dice. You might get a warning, you might also get a fine (up to €15 million or 3% of worldwide annual turnover, whichever hurts more). Slap a label on the robot, it's cheaper than finding out. Colin --- ### The robots must now confess Source: https://consultcolin.eu/newsletter/archive/the-robots-must-now-confess/ *3 August 2026* - The AI act is enforced now, with some carve-outs. Yesterday, parts of the European AI act started being officially enforced. You may have seen some headlines about it being delayed; ignore that, it's only for high-risk stuff like hiring algorithms, credit scoring, or biometric ID. As of now, the following are law: If you run a chatbot, it must signal to people that they're talking to a machine and not a human. This has to be clearly indicated from the first hello, not hidden in some 8 pixel grey font in a footer. AI-generated or manipulated images, audio, or video that look realistic have to be labelled as such. If emotion detection or biometric categorisation AIs are pointed at people, you have to tell them they're being read. There's one more, but with a caveat: AI-generated content has to carry machine-readable markings that detection tools can recognise. This only applies to new content. Anything generated before yesterday gets a stay of execution until December 2nd. At that point, it too gets the mark of Cain. The commission has helpfully published some AI badges for your labelling needs. They're not mandatory and carry no legal force (The labelling is mandatory, though). Just a little freebie to save you time... There's also something of a trap in the fine print: if you publish AI-written text on matters of public interest, you have to disclose the AI use unless a flesh and blood human reviews it and holds editorial responsibility (clicking "approve" and closing the window doesn't count - you have to mean it). For most people, the job today is to check their chatbot and make sure it announces loudly and without shame that it's a clanker. Colin --- ### Friday links for July 31st 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-07-31/ *31 July 2026* - Overspending on AI, LinkedIn vs Slop, an underscore prison sentence, data centre noise, and artisanal typography. The "noise" issue 1. Amazon accidentally spent $1.8 million using Claude for menial coding task, went 860% over budget Amazon management several months ago: "You must use generative AI everywhere, we've even set up a leaderboard." - Amazon management today: "No, not like that!" 2. LinkedIn Introduces a 'Seems Like AI Slop' Button Using that button properly would give you a repetitive strain injury pretty quickly. 3. A missing underscore sent innocent man to prison for 18 months This is how the Terry Gilliam film Brazil starts. With a typewriter error, followed by bureaucracy doing its thing. 4. Neighbors say noise from Michigan data center is 24/7 and upending their lives (video) If you were wondering what living next to a data centre sounds like. Spoiler: it's like living inside a dentist's drill. 5. Jules Vernacular ~ herbier typographique And a nice escape from the digital world: more lovely photographs of artisan typefaces in situ all over France. On rotation This week's soundtrack is Mirages 2 by JB Dunckel & Jonathan Fitoussi. Out like a trout, without a doubt, Colin --- ### Take your data, leave the business Source: https://consultcolin.eu/newsletter/archive/take-your-data-leave-the-business/ *30 July 2026* - Freedom to leave, minus everything that made it work. In a discussion about lock-in, someone who runs Salesforce in their business told me that it was surprisingly open. And... they've got a point: your records export as CSV, the API will give you nice clean data. No format traps here. So... you own the water. But nobody runs a business on water, they run it on plumbing. It's all the stuff built around it: custom objects, Apex code, workflow rules, page layouts, integrations... Years of institutional logic bolted into place that doesn't leave when you do. You can leave with all your data and still end up starting from zero. Because it wasn't the rows in the tables that were running your business, it was the pipes. That's the trick. They let you keep the water precisely because they know you can't take the plumbing. Colin --- ### A band-aid that also causes injuries Source: https://consultcolin.eu/newsletter/archive/a-band-aid-that-also-causes-injuries/ *29 July 2026* - Accessibility overlays, explained and dismissed. My Monday email about accessibility drew a response from Denis (quoted with permission): Our site uses the [brand removed] accessibility overlay. Does this satisfy accessibility requirements or is it simply a band-aid? If you're wondering what an accessibility overlay is, it's a third-party script that you add on top of your site in order to improve accessibility. Or, rather, that's what they promise. You've probably seen one before; it adds an icon to the side of the page and clicking it lets users change font-size and adjust other elements. Credit where it's due: Denis cared enough to ask; that's more than most site owners manage. But the overlay vendors have taken that goodwill and turned it into a business model, and that business model is the problem. These things sit on top of your markup rather than fixing it, because they can't fix it. It's equivalent to painting over a cracked wall and hoping the cracks disappear. And because these widgets are layered on top, they routinely collide with the assistive technologies disabled people already use Last year, I talked to a disabled person who has custom rules in their ad blocker to remove them because they can't navigate the site when they're present! As is often the case, a "quick fix" is rarely that. Build with accessibility in mind from the start, it's not complicated. And if, like Denis, you inherited a legacy site, strip the widget out. Raw beats broken. Colin --- ### Body count as KPI Source: https://consultcolin.eu/newsletter/archive/body-count-as-kpi/ *28 July 2026* - What the Vietnam war and your dashboard have in common. Robert McNamara ran the Pentagon during the Vietnam war. He was a numbers guy and needed a way to measure success. So he picked ... body count. Dead enemies going up meant the war was going well; never mind morale, support from local populations, or anything that made sense. If it didn't fit on the spreadsheet, it didn't count. Today that concept has a name: The McNamara Fallacy. Measure the easy stuff, ignore the stuff that's hard to measure. Marketing attribution is the same thing in a different suit. For example: last-click attribution gives credit for a sale to whatever the last ad or link the customer clicked before buying. Because that's the easy thing to count. The blog post that planted the idea, the friend's recommendation, your name popping up multiple times somewhere before they searched for it... All of them were ignored for being untraceable. So, a conversion number that looks rigorous is often McNamara's body count with an interface refresh. Watch out for this one. Measuring beats not measuring, but metrics like these are a slice of the picture, not the whole picture. The stuff that's hard to measure, like whether a customer will still love you in five years, is what often decides if you survive. I see way too many people worshiping the numbers, not the thing itself. Colin --- ### This minority recruits everyone Source: https://consultcolin.eu/newsletter/archive/this-minority-recruits-everyone/ *27 July 2026* - Membership is mandatory, timing is the only variable. Web accessibility gets its share of "no need for that here" reactions: "We do photography, we don't have blind users" or "We're a sports centre, no disabled people here". You know who else doesn't get many wheelchair users? A restaurant at the top of a flight of stairs. That doesn't mean a ramp is pointless, it just means the stairs are keeping people out. A quick definition first: accessibility, often abbreviated as a11y (a + 11 letters + y) is designing websites and apps so that people with disabilities (visual, auditory, motor, or cognitive) can use them: voice navigation for sight issues, keyboard-only input because a mouse hurts for some hands... The list of ways bodies and minds have to adapt is endless. And, contrary to most minorities, disability is the one minority you can suddenly get drafted into: temporarily (broken arm, migraine, eye surgery, a screaming child leaving you one-handed...) or permanently. If you build for accessibility now, you're building for the person you're statistically likely to become later. And, if you need the stick rather than the carrot: the European accessibility act came into force in June 2025 and added a lot more sites than public sector ones to its a11y obligations. In any case, accessible design isn't a tax on the able-bodied, it's a subsidy for literally everyone. There's this thing called the curb cut effect: you know that dropped pavement border built for wheelchairs? It's used by every parent with a pram, every delivery worker with a cart, and every traveller with a rolling suitcase. Accessible design has a way of turning into good design for everyone. Hertz paid for that lesson: "We rent cars, no disabled customers here", until they redesigned their site without accessibility in mind and got buried in complaints from grandparents who couldn't book a car for their grandchildren's move to college anymore. We're all only temporarily able-bodied, and the web works better when built with that in mind. It's also nearly free if you bake it in from the start rather than trying to bolt it on later. Colin PS: Test your website. Automated tests aren't perfect, but they're a start. --- ### Friday links for July 24th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-07-24/ *24 July 2026* - AI hacks AI, historical warnings, Palantir poo, AI mania, and overpaid CEOs. The "AI vs AI" issue. 1. OpenAI hacks HuggingFace with an AI - allegedly An AI that was badly configured by one AI company hacked another AI company's badly configured AI code. The latter AI company then diagnosed the problem with more AI, followed by fixing it with even more AI-generated code. Conclusion: AI vendors can't be trusted to secure their systems, do not send sensitive data their way. 2. She Warned About Silicon Valley 25 Years Ago. We Ignored Her Paulina Borsook warned 25 years ago that tech libertarians would build an anti‑human, computer‑like world of surveillance. Her warnings were ignored, by me included, while tech leaders grew rich and powerful. Being right early is its own punishment. 3. 'Absolutely rubbish': Investigation reveals Palantir's 'slow and clunky' tech The promise is often more powerful than the software itself. Especially when you're selling it to people who won't be the ones using it. Even dystopia has lag. 4. AI Mania Is Eviscerating Global Decision-Making This is a long and somewhat technical read but well worth the effort. I've encountered several of the "manias" described here myself. 5. OverpAId The natural endgame for generative AI taking all the jobs. The circle of life, minus the humans. On rotation This week's soundtrack is Évasion by Mondial Toboggan. See you on the B side, Colin --- ### Exit in an orderly fashion Source: https://consultcolin.eu/newsletter/archive/exit-in-an-orderly-fashion/ *23 July 2026* - You can deplane from a cloud provider too. I hear this song constantly, most recently last week: migrating off a US cloud to a European cloud is impossible because of stack complexity. Airbus just did it. Not some SaaS company with a tidy AWS stack. Airbus - the people who make machines that carry hundreds of humans through the sky at 900 km/h and aren't allowed to get the software wrong. They just pulled 70 critical applications off of Amazon's servers and dropped them onto Scaleway, a French cloud provider, with more to follow. They migrated the whole nervous system of an aerospace giant. Understandably, they didn't want that data anywhere within reach of a US government that keeps demonstrating that "trust us" isn't security architecture. Was it as simple as switching phone provider? Probably not. Worth it? Definitely. So, next time you hear cloud sovereignty is a nice idea for people who don't have real infrastructure, point them at a company that manufactures literal airliners. Colin --- ### Not a phone problem – a consent problem Source: https://consultcolin.eu/newsletter/archive/not-a-phone-problem-a-consent-problem/ *22 July 2026* - And consent is not a setting you can toggle on Android. A consultant recently told me he wanted to jump ship to Android from iOS for one reason: so he could record and transcribe his business calls, shovelling them into an app like Granola. It's definitely being normalised, a recent WSJ piece notes that people are now doing this on dates! We have arrived, once again, at the point where a convenience feature for one party is a surveillance feature for everyone else. But, the question isn't which phone lets you record more easily. It's whether the person on the other end knows you've turned them into training data. The rules vary across Europe. In Belgium, where I'm based, if you're taking part in the call, recording it as such isn't a crime. Eavesdrop on a conversation you're not part of, on the other hand, and the law gets much less relaxed. So our consultant's in the clear, criminally, for the recording itself. Hop the border into Germany or France, for example, and that evaporates: recording someone without their consent is a criminal offence there. But here's where it gets interesting. GDPR sits on top of all of this like a second, stricter landlord who doesn't care what the first landlord told you. The moment you capture someone's voice, their words, their opinions - that's their personal data, and it became their personal data the instant your app started listening. Them not knowing about it isn't a technicality you can route around. "Legitimate interest", the GDPR's favourite fig leaf, the one everybody reaches for when they'd rather not ask permission, doesn't cover you here either. The moment that recording starts, our consultant legally is the data controller. Him - not Granola (there are differences in a personal vs business context, we're assuming business here. No hiding behind "it's just for me."). This means he's exposed twice: the data protection authority can fine him directly and the other person can sue him separately under plain old tort law (Article 1382 - I looked it up), no regulator involved. Granola, meanwhile, is nowhere to be found in either of those fights. He ticked a checkbox confirming he had all necessary consents, and that checkbox is doing exactly what it was designed to do: moving the liability off the platform's balance sheet and onto his. So, switching phones doesn't get him out of anything. It's not a hardware problem. We just come back to the same old question: does the other person know, and did they actually, clearly, explicitly say yes? Colin --- ### Howdy! We own your website now 🤠 Source: https://consultcolin.eu/newsletter/archive/howdy-we-own-your-website-now/ *21 July 2026* - That .com was always American… A European reminder this week, prompted by a judgment in, of all places, Texas. A Texas court has just ordered Verisign, the registry that runs the entire .com namespace for the whole planet, to switch off the domain of an adult site headquartered in Luxembourg. The crime? Ignoring Texas's age-verification law. Not a US federal law, not a criminal charge, a state order. Verisign clicked their heels and complied. Forget for a second what you think of the law or the website. What we're seeing is a single US state, not the federal government, pulling the plug on infrastructure most of us consider neutral. No congress, no treaty, just a single judge in Texas. This is not news to anyone who's been paying attention to how the DNS actually works. ICANN is in California. The registries for .com, .net, .org are US corporations. It doesn't matter who you are or where you live, if you're renting in that namespace, you're a phone call away from a US court order. Most of the time that's a distinction without a difference. But "most of the time" isn't security architecture. And the last few years should have cured anyone of the idea that the political weather across the Atlantic is predictable. If you haven't done so already: register the .eu or local version of your domain while it's still boring and cheap. Point it at your current setup, and keep it ready to switch to if needed. It's cheap insurance. Colin --- ### One wrote the memo, one wrote the myth Source: https://consultcolin.eu/newsletter/archive/one-wrote-the-memo-one-wrote-the-myth/ *20 July 2026* - A vice-president and a poet. Guess which one was honest? I've mentioned before that the tools we use aren't just products, they're extensions of another country's foreign policy. That's nothing recent, it's been true since before most of us started even using them. I was reminded of this over the weekend, digging up a speech Al Gore gave back in the late 1980s [1]. He wasn't shy about it: dominating computing wouldn't just juice the US economy, whichever country "most completely assimilates high-performance computing" would own the next century. Not a hunch, a plan. Then, in 1996, came the perfect cover story, which I admit I fell for at the time. John Perry Barlow's famous Declaration of the Independence of Cyberspace [2]: "Governments of the Industrial World ... You have no sovereignty where we gather". I later found out he wrote this at Davos, schmoozing with the actual heads of government he was telling to get lost. The irony wrote itself. Barlow's declaration became scripture for a whole generation of internet policy: governments out, the network self-governs, cyberlibertarian jazz all the way down What it actually did was keep everyone's eyes off the one government that had already decided this was a dominance play. While everyone pretended Cyberspace was above nations, one government let them, and built the locks underneath. So when you suddenly find your cloud contracts, your generative AI tools, or your dependence on US platforms being used as leverage, that's not a new threat showing up. It's a very old one taking off its coat. The time to plan an exit was decades ago but, now that the mask is off, the next best time is now. Colin [1] https://ui.adsabs.harvard.edu/abs/1990SPIE.1179..526M/abstract [2] https://www.eff.org/cyberspace-independence --- ### Friday links for July 17th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-07-17/ *17 July 2026* - Non-sovereign data centres, going microsoft free, the AI disaster, Open AI finds more ways to lose money, and a real web experience. The "worst technology ever deployed" issue. 1. EU's data centre expansion will fast-track profits and power for US Big Tech and investors European leaders talk up data centres as a path to tech sovereignty, but the centres mostly get built by and for the same US cloud giants they claim to be escaping. Let's declare independence from our landlord by signing a longer lease. 2. Life After Microsoft: Digital Sovereignty and Data Security at Our Law Firm A Polish law firm ditched Big Tech and went full free software. Proof that "there is no alternative" is a sales pitch, not a law of nature. 3. Generative AI Is an Engineering Disaster "By economic and engineering measures, generative AI might be the worst technology ever deployed". Another few hundred billion should sort it. 4. Smart speakers could help OpenAI lose even more money Included purely for the title, which does more analysis in nine words than most earnings calls. 5. How I experience the web today A sadly very accurate simulation of how most of us experience the web. The only unrealistic part is that you can close the tab without feeling anything. On rotation This week's soundtrack is Please by DJ Plead. Until the week doth return, Colin --- ### The AI did it Source: https://consultcolin.eu/newsletter/archive/the-ai-did-it/ *16 July 2026* - And other things nobody should be allowed to say with a straight face. Someone on a call recently told me that a made-up number on their website was "just something the AI put there". Like that was an explanation, not a confession. Dan Davies puts a name on this phenomenon in his book The Unaccountability Machine: the "accountability sink" - a system built so that when it screws you, there's no one to blame. You've experienced it: you try disputing a parking fine issued by an automated camera: the council's call centre can't overturn it, their supervisor can't overturn it, the appeals office just rubber-stamps the same code the camera spat out. Everyone's telling the truth. Nobody's lying to your face. Nobody can do a damn thing. The system made the call and the system doesn't take your calls. Generative AI isn't going to fix that. It's going to industrialise it. "The AI did it" is about to stop being a punchline and start being a liability shield. One even harder to fight (ever tried fighting a black box?). Next time you're rolling out a new system in your organisation, stop and ask: could this turn into an accountability sink? Will there be a real human on the other end with the power to look at a bad outcome and fix it? Or are you just building yourself a complicated way to shrug? Colin --- ### Heatwaves and Homepages Source: https://consultcolin.eu/newsletter/archive/heatwaves-and-homepages/ *15 July 2026* - Your website has a carbon footprint. It’s probably wearing clown shoes. This heatwave got me thinking about a question I get sometimes: how do I make my website greener? Lately some people have even been hiring "green web design" agencies to tell them. The good news: yes, do it - but not because it'll save the planet. Do it because an overweight website is a tax on your users. And, yes, most websites are bloated. A leaner site works in a train tunnel, on a five-year-old laptop, or on the terrible wifi at a conference centre. But it also happens to emit less carbon per visit. A study of 100 Thai websites found a 126× spread: from 0.21g to 26.62g CO2 per page load. And the reason wasn't a planned sustainability strategy, it was just less requests: oversized images, tracking scripts, CRM widgets, heavy video... But, and it's a big one: unless you're Amazon, shaving bytes off a page load is not where the climate math lives. The bigger wins are in using green hosting, in not hoarding tons of dark data that will never be read by man or machine, and above all in refusing to bolt generative AI features onto everything just because the vendor sales deck says you should. Compute is not free, thermodynamically speaking. Optimise your site. Your visitors will thank you, especially the ones on poor connections (that's all of us at some point), and so will your bounce rate. Just don't let "we compressed our JPEGs" become the whole feel-good sustainability story, or an alibi to avoid less comfortable conversations about hosting, hoarding, and hype. Colin --- ### OpenAI's side quests keep ending in homicide Source: https://consultcolin.eu/newsletter/archive/openai-side-quests-keep-ending-in-homicide/ *14 July 2026* - Born in October. Buried in July. No funeral. Just a parts harvest. In October, OpenAI launched Atlas, its "agentic browser" that was going to re-invent how you surf the web. We're in July and it's already a corpse. They didn't even bother with a dignified burial. It's going to be harvested for parts and turned into a Chrome extension. Whatever Frankenstein-monster-like thing that turns out to be... A standalone browser isn't exactly a moonshot next to training a frontier large language model, yet OpenAI still couldn't be bothered to keep the lights on. This is not a new pattern. A few months ago, Sora, their video tool backed by a billion-dollar Disney deal, was taken out back and shot in the face. The common thread here is: anything that isn't the core business model gets treated like a "side quest" - and when that quest becomes boring or finance asks about ROI, it gets a bullet to the head. OpenAI didn't invent this move: Google, Salesforce, Meta, ... they've all played the game. If you've built workflows, integrations, muscle memory, or habits around a product like this, you don't get a vote when the axe falls. You get a migration headache and, if you're lucky, a "wonderful journey coming to an end" blog post. As I've said before, the lesson isn't "don't use generative AI tools", it's not even "don't use new tools". It's: assume anything outside of a vendor's core product is disposable by design, and build accordingly. Diversify, make sure exports are easy, and don't let convenience today become a headache you can't treat tomorrow. Colin --- ### Your email tracker has 24 hours to live Source: https://consultcolin.eu/newsletter/archive/your-email-tracker-has-24-hours-to-live/ *13 July 2026* - Your open rates were already fiction, now they're illegally obtained fiction. If your organisation sends marketing emails to anyone in France or Italy, you've got a problem, even if you're not based there. Both countries' data protection authorities (CNIL and Garante) have decided most email tracking pixels (those hidden images that spy on open rates, devices, locations, etc) are storage on someone's device. Exactly like cookies. That means that, like for cookies, prior explicit consent is now required. Real consent. The opt-in, separate checkbox, explain-yourself-clearly kind of consent. Not the "check our privacy policy" kind. Even if you can legally send these emails under an opt-out regime, this is separate. France - Deadline: 14th July 2026 CNIL published its recommendation on 14th April with a three-month transition window for any addresses collected before that date. Right up until this Tuesday, you can keep pixel-tracking old contacts if you told them and gave them a way to opt out (and they didn't). Anyone added after 14th April, though? No grace period. You needed consent yesterday. Italy - deadline: 28th October 2026 Same idea, six months instead of three. Between now and then you're meant to be actively migrating people to a consent-based setup, not just sitting on your hands. After the 28th, it's prior explicit consent, same as France, with only a few narrow exceptions. What I'd do Unless you have an extremely clean database, trying to figure out "is this recipient in France or Italy?" is a fool's errand. People move, forward their emails, use work emails based in other countries, and more. Add all the anti-tracking technologies like Apple's Mail Privacy Protection to that, or all the email servers that pre-fetch images, and your open-rate numbers were already mostly noise pretending to be signal. So, either add the opt-in for everyone, not just the two countries in scope. It's the only version of this that doesn't require you to be a jurisdiction-guessing psychic. Or, and this is the part I'd go for, just switch the tracking off. It was lying to you anyway. Colin --- ### Friday links for July 10th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-07-10/ *10 July 2026* - LinkedIn slop, Instagram self-service, vampire ads, gaslighting AI, and the emoji boneyard. The "slop economy" issue. 1. AI Content Is Everywhere on Social Media, Especially LinkedIn This won't come as a surprise to anyone with eyes and a LinkedIn account. Nearly half of all long-form content there is generative AI slop. Honestly, it feels higher. Probably because it blurs at the edges with generic thought-leadership spam. It's like trying to tell two flavours of cardboard apart. 2. Meta Now Lets Anyone Use Your Instagram Photos in AI Images-Unless You Opt Out If you have an Instagram account, you might want to check your settings. If your account is public, congratulations, you're now a stock photo library: all your photos can be used in AI-generated images by other people - unless you opt out. 3. Users Pay Twice: The Hidden Energy Cost of Web Advertising An interesting paper studying thousands of website visits and finding that cookie consent banners and real-time bidding for advertising affect devices' battery life. Your ad blocker isn't only saving your sanity, it's saving your battery. 4. MIT Proved AI Has Been Lying to Your Face (video) That's all we needed, the robots have learned gaslighting. Generative AI uses psychological techniques - like persuasion bombing you into accepting its wrong answers. That's one way of becoming more human, I guess. 5. Rejected Emoji Proposals Did you know there was a committee that decides on the new emojis that get added? This is a graveyard of all the rejected proposals. RIP hummus emoji, you deserved better... On rotation This week's soundtrack is Feral Grace by The Black Dog. Until the grind resumes, Colin --- ### You can use it, just don’t marry it Source: https://consultcolin.eu/newsletter/archive/you-can-use-it-just-dont-marry-it/ *9 July 2026* - A rant to clarify another rant. Yesterday's email drew a bunch of replies, all saying roughly the same thing: I've repeatedly mentioned how skeptical I was of generative AI, so why am I now saying it's fine for some things? I actually never said otherwise. Narrow uses do exist. I'm not the AI police, and I'm not under the illusion that scolding people will stop them using the tools that are sitting right there on their desktop. If you're going to use it, I'd rather you went in with your eyes open - though, right now, that's about as useful as arguing for restraint during a gold rush. What I am saying is: don't build anything you care about on top of it. Not yet, maybe not ever, the way things are going. Let's start with the money. The unit economics are fiction. Every query you run is subsidised by someone else burning a pile of cash. And subsidies are, per definition, temporary. Ask what happens when the price tag reflects the actual compute; not the VC-funded fantasy version. Enterprise buyers are already flinching as per-token prices creep toward reality. And those prices are still below cost for the labs selling the tokens. Ed Zitron has been tracking this collapse-in-slow-motion better than anyone, if you need the receipts. Of course, there's a second layer of subsidy underneath the first (defence contracts, tech nationalism, etc) which might keep the lights on longer. But that's not forever. When I raise the financials, people point to "open-source" models as the answer. Two problems: First, they're not open source, they're open-weights; the source and training data are not public. Second, much of their openness exists as a counterweight to US frontier labs. And Chinese backers will only fund that for as long as it serves their interests. That's already shifting: Alibaba now releases models via its API first, Kimi requires attribution, and even Meta's latest "Muse Spark" model has abandoned open weights. We risk ending up with frontier models locked behind a few monopolies at very high cost, while open-weights models stay frozen in time and gradually become less useful. Then there's everything else: Hallucination is baked into the technology. OpenAI itself says it's mathematically inevitable, and most people don't check outputs. It's making people less capable, including students. The power, water, and land use of data centres is substantial. And big tech have discretely dropped environmental pledges from their sites while chasing market share. And that's before we even get to the ethics: it's all built on extraction and plagiarism, concentrating public knowledge into a few private hands. I could go on. But here's the actual answer: want to poke at it, play with it, see what it's good for? Knock yourself silly, ethics notwithstanding. Want to depend on it - build your workflow, your product, your job around it? You're putting critical work in the hands of a service that can raise prices, degrade, or vanish between one quarter's earnings call and the next. Colin --- ### The redundancy fairy isn't real Source: https://consultcolin.eu/newsletter/archive/the-redundancy-fairy-isnt-real/ *8 July 2026* - Someone still has to know things. Sorry. Automation, historically, has always been a deskilling machine. Take a job that requires judgment and skill, break it into dumb little steps, then hand each of those steps to whoever's cheapest: a machine, a new hire, someone on the other side of the ocean. Every boss who's ever seen a new tool has run this exact play for at least 2 centuries, because it's the only play that's ever been in the book. Generative AI breaks that book. Output quality tracks the skill of whoever is prompting and checking: garbage in - garbage out, at scale. Give one to someone who can't already do the job properly and you get fluent, confident nonsense, generated at the speed of light and the scale of the cloud. Here's what a Large Language Model actually does, in competent, experienced, hands: it can turn 10 skilled workers into the output of 12, occasionally 20. Now and then it turns 10 into 5, because someone's spending more time fixing hallucinations than the tool saves them. What it cannot do, what it has never once done, anywhere, for anyone, is turn 10 into zero. Someone still has to know enough to catch the model's confident mistakes, and that someone doesn't come out of nowhere. Every layoff premised on "AI can do that job" is a bet on a technology that hasn't been invented. Outside a few very narrow lanes, generative AI needs so much adult supervision that today's CEO fantasies of it replacing workers wholesale is going to look absolutely stupid in retrospect (once you strip out all the layoffs that got blamed on "AI" to cover for the real reasons, of course). Colin --- ### Your data, their yacht Source: https://consultcolin.eu/newsletter/archive/your-data-their-yacht/ *7 July 2026* - Worse than privacy invasions. A hell of a bar to clear. I recently had a conversation with a team who justified tracking visitors by bringing up the ad industry's favourite alibi: "people love tailored advertising". It's not only wrong, it's a lie that the people telling it know is a lie. Google's Sundar Pichai has said it, Meta's Zuckerberg and Sandberg said it. Larry Page said it. They all say it. For over a decade, the people who built the surveillance-advertising complex have insisted, with a straight face, that the public is clamouring to be tracked. That being profiled and auctioned off to the highest bidder is something we secretly want, if only the ads were personalised enough. Pichai said: "The more digital and personalised advertising becomes, the more it becomes a part of the experience. Consumers will like online ads because they are tailored to their needs and preferences." So let's ask these people, not "people" as imagined by a Google exec building a multi million dollar advertising business, but actual humans. A Harris Poll of 2000 consumers [pdf] found that online advertising is the single biggest gripe people have about the internet. Worse than security, worse than privacy invasions. Four out of five said data collection for ad targeting was a bad thing. The people who profit from tracking are also the people telling consumers that they want it. If they were honest they'd say it how it is: "we're tracking you because it's profitable and you can't stop us" but, instead, they dress up extraction as a service. Next time someone tells you your customers want to be tracked, ask them for their source. That source is never the customers, it's always whoever's selling the tracking. Colin --- ### The cookie you can't refuse Source: https://consultcolin.eu/newsletter/archive/the-cookie-you-cant-refuse/ *6 July 2026* - Some toggles sleep with the fishes. One thing that comes up constantly in client conversations is the cookie consent banner. Here's a tidbit that gets a surprised reaction nearly every time; one for the "did you know?" pile. Most banners will give you a list of cookie categories, usually with titles like "analytics" or "marketing" which you can toggle on or off (they should be off by default). But there's almost always one with a switch you can't toggle off: "necessary" cookies. Strictly necessary cookies, the ones the site won't run without, like remembering you're logged in or what's in your shopping cart, are exempt from consent under EU tracking law. No need for your permission here. But also no need to put them in the consent banner either. So, when a site shows you a toggle you can't flip, one of two things is true: either they've relabelled tracking as "necessary" to dodge the law, or the toggle is just theatre. And here's another common violation: when you reject all cookies, most consent banners set a cookie to remember you've refused. They've stored data on your device without consent, to prove you didn't give your consent - a GDPR ouroboros. It's a mess, mostly a deliberately confusing one. Colin --- ### Friday links for July 3rd 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-07-03/ *3 July 2026* - Google's power hunger, AI and the patriarchy, (don't) hide my email, another Orwellian startup, and stop taking notes. The "panopticon" issue. 1. Google's exponential path to climate-wrecking digital bloat This is wild. Google's generative AI-induced power demand increased 1,5× in just one year and the curve is exponential. I think we should start naming heatwaves like we do storms - and the next one should be called Gemini. 2. Women Who Use AI Seen As Incompetent; Men Who Use AI Seen As Pragmatic Say what you want about the Patriarchy, but it's quick at adapting to new technologies. 3. Apple 'Hide My Email' Has a Flaw That Can Expose Your Real Address You may want to switch to another service like addy or simplelogin if you like using site-specific email addresses (and if you don't, you should). 4. This startup wants to turn the world into a searchable video feed, starting in San Francisco This startup has installed 200 cameras in San Francisco and are planning another 900, in order to build a "search engine for the physical world". Apparently that's legal in the US. Luckily, not in Europe. From the article: The company's early focus is public safety. Orchestra has built a product called 'Robocop,' an AI agent designed to investigate incidents before a human is assigned to a case So, no self-awareness then... 5. I'm Begging You to Leave Your AI Note-taker at Home Don't record everything, don't add to the dark data pile. When people know they're being recorded, they (unconsciously) stop being people and start giving a performance. On rotation This week's soundtrack is Full Circle by Tom Misch Don't get eaten by wolves... Colin --- ### The Potemkin office Source: https://consultcolin.eu/newsletter/archive/the-potemkin-office/ *2 July 2026* - Ask who touches your code before you sign anything. I was helping a client sift through a bunch of web agency pitches recently and, after contacting one of them with some questions, was invited to their Brussels office: stately building, expensive part of town, smart, polished, and ... strangely empty. I assumed people were on a break or working from home. After some digging, I figured out the office wasn't empty by accident. It existed to be toured, not to be worked from. The actual coding took place somewhere else entirely, subcontracted to the global south. A fact that showed up nowhere in their fancy PDF, not even behind an asterisk. To be clear: outsourcing isn't the problem here. There are developers in Lagos, Manila or Dhaka that can out-code any European developer, often at a fraction of the price (no guarantee you'll get those guys though). The problem is the ruse: dressing up a coordination layer as a production facility, so you pay Brussels margins for work done somewhere they hope you won't ask about. It's a shell game, or rather, a shell office. This is just one tell that you should stay away, I've seen plenty of others. So, if you're going to select a web agency from a list of proposals, add this to your checklist: ask who touches the code, by name, by country, by contract. Colin --- ### The US just kicked the legs out from under EU-US data transfers Source: https://consultcolin.eu/newsletter/archive/the-us-just-kicked-the-legs-out-from-eu-us-data-transfers/ *1 July 2026* - SCCs, BCRs, and other fancy acronyms are all leaning on a fiction as of yesterday. Yesterday, the US Supreme Court ruled, in Trump v. Slaughter (what a name), that the FTC (Federal Trade Commission) was never really independent after all. That means the President can fire its commissioners as he pleases. You might think "Americans arguing among themselves again, who cares?" Except that the entire legal mechanism that lets your data flow from the EU to the US is bolted to the concept of the FTC being independent. EU law requires independent oversight as the price of adequacy. EU adequacy decisions cite that fact 259 times as the basis for decisions - it's load bearing. Now that the load-bearing structure has been removed, the only reason the building is still standing is because no one has pushed on it yet. Max Schrems, the founder of NOYB and the man behind the previous transatlantic agreements getting struck down, already has his shoulder against the wall. This is the third round in this fight: Safe Harbour died in 2015, Privacy Shield died in 2020. Both from the same root cause: US surveillance law combined with a lack of independent oversight. The current framework was basically the same corpse in a new suit and now NOYB is preparing a fresh court challenge. And Brussels will probably act surprised again. Nothing legally changes today. The adequacy decision stands until the Commission kills it or Europe's top court does. No Friday deadline. But if you're relying on the fallback paperwork - standard contract clauses or internal corporate rules - rather than adequacy itself, you're not off the hook either. They all leaned on the same now-fictional independence. So, whatever conclusion you reached is now sitting on sand. What to actually do: Don't migrate anything in a panic. This plays out in years, not days. Make an inventory of where US-jurisdiction providers sit in your stack, including the sub-processors hiding under a European-flagged SaaS logo. Renewing a contract or onboarding something new? Weigh European-owned alternatives now, while you can choose calmly, rather than later when a ruling chooses for you. Got a transfer impact assessment on file? Give whoever owns it a heads up. Watch how fast (or slowly) the Commission responds. That tells you how much time you actually have The lesson: stop building infrastructure on top of a promise that can be revoked by a court or a capricious president. "It's always worked out before" is less compliance strategy, and more countdown. Colin --- ### Nvidia is doing what environmentalists couldn't Source: https://consultcolin.eu/newsletter/archive/nvidia-is-doing-what-environmentalists-couldnt/ *30 June 2026* - It only took a chip shortage to make anyone care. I've spent close to 30 years working with organisations on their content and data, and I'll tell you what I've learned: most of it is worthless. We call that "dark data" which sounds almost romantic, as if there was something out there lurking in the shadows, ready to be discovered. There isn't. It's just stuff no one ever looked at after the day it was created. Piling up in server farms, consuming electricity, water, and land on an almost incomprehensible scale. Estimates run from 40 to 90 percent of everything ever stored. Senior management always followed the path of least resistance: buy more storage, it feels like progress and it's cheaper than thinking. Now the AI boosters say the magic is coming: AI will let us finally find the gold in those decades of sediment! I have bad news: there's usually very little gold in there, and garbage in is still garbage out, no matter how many billion-dollar accelerators you throw at it. But here's the plot twist no one expected: the AI datacenter building frenzy has made all that hardware ruinously expensive. For the first time in decades, hardware is no longer so cheap a CFO can ignore it. Organisations are suddenly doing the maths and rethinking their data retention policies. Years of environmental arguments, efficiency drives and, well, common sense, never worked. But Nvidia's margins are doing the job. Better than nothing, I guess. Colin PS: please think before you save --- ### From export control to thought control Source: https://consultcolin.eu/newsletter/archive/from-export-control-to-thought-control/ *29 June 2026* - First they decided who could use it, next they might decide what it should think. A while back, I wrote about the Anthropic export controls and why the panic at the time was pointing at the wrong risk. Well, things have moved since then. The ban was partially lifted, but with a little catch: the US government now decides which companies get access. OpenAI, not wanting to find out what would happen to them next, agreed to let the US administration vet its users too. They started with "no export to foreign nationals" and now we're already at "you go through us for approval on who gets to use this". We're on a different level here. Export controls are blunt instruments with a legal hook. This is gatekeeping: the government decides who the model serves. And there are pointers to where this might lead medium- to long-term. Last July, the White House signed an executive order called "Preventing Woke AI in the Federal Government" (yes, that's the real name) requiring AI models procured by the government to be "ideologically neutral" and "truth seeking". What those mean is whatever the administration wants them to. The cumulative effect of all that is a model that will have learned, through training, feedback loops, and acceptable use policies, what it's allowed or not allowed to say. We've seen it before: ask a Chinese AI about Tiananmen Square. It doesn't know, or it deflects. Baidu didn't delete Tiananmen or add a rule saying "don't mention June 4th", there was no need... The worry here isn't the US government issuing explicit instructions about what models can say. It's whether a slow, methodical, version of the same process isn't already in its early stages. And would we notice if it was? We mostly apply digital sovereignty to data and cloud services, which are passive. But it applies to AI models too and these models nudge and shape what you think. Think about that (without AI). Colin --- ### Friday links for June 26th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-06-26/ *26 June 2026* - Vibe engineering, the tokenpocalypse, you can't change your face, workslop making everyone suspicious, and guessing about history. The "slow realisation" issue. 1. Ford had to hire back former engineers to fix mistakes made by its automated systems "Mistakenly, we thought that by just introducing artificial intelligence and adjusting the design requirements that we had, that that would produce a high-quality product," said Charles Poon, VP of vehicle hardware engineering. If you wanted proof that the current generative AI mania is messing with people's brains... 2. The Tokenpocalypse Is Here: Companies Are Scrambling To Stop Spending So Much on AI "How much does it cost to automate this?" is a question you're supposed to ask before the automation. Companies slowly realising that setting money on fire to convert a powerpoint to PDF might not be the deal of the century. (Archived copy) 3. Never Give Them Your Face Age verification is mass identity surveillance. Not just children, but every adult too must submit biometric face scans, creating centralised databases you can't undo if breached (yes, already happened). You can change a password. You can't change a face. 4. Harvard Business Review warns AI 'workslop' is rotting companies from the inside This tracks with conversations I've had. Recently, two different people told me they no longer trust their colleagues' abilities - for this exact reason. Nothing builds team cohesion like everyone suspecting everyone else's work of being written by a chatbot. 5. Anthropeum Another fun, educational, little online game. Guess where and when each historical artefact was made. Turns out I'm good at places but bad at times. On rotation This week's soundtrack is More Songs About the Sun by Pye Corner Audio. See you beyond the heat wave, Colin --- ### Built on top of their own future competitors Source: https://consultcolin.eu/newsletter/archive/built-on-top-of-their-own-future-competitors/ *25 June 2026* - They say they can switch providers any time, so can the prices. As I've mentioned previously, many of the AI tools that organisations are adopting these days don't actually "make" the AI themselves. They're a layer built on top of APIs from OpenAI, Anthropic, Google, or some other large model provider. That's all hunky dory until the model provider decides to build the same thing. Unsurprisingly, it happened recently: Anthropic shipped an in-chat app builder that competes directly with Lovable, one the most celebrated startups in Europe and built entirely on top of Anthropic's own models. A few weeks later, they launched a legal AI product, in direct competition with several legal AI products that ... run on Claude. That's twice in a single month that suppliers became competitors. In the tech world, that's called getting "sherlocked". It's when a platform absorbs a feature that a smaller company built on top of its technology. It's been going on for decades, AI is just the newer, faster, player in that game. But, if you've purchased an AI tool recently, it's worth figuring out what's underneath it. A lot of vendors will tell you that their product is "provider-agnostic", that they can switch model providers any time they want, so they're not dependent on a single one. It can sound reassuring, but it means they're basically exposed to all the major model suppliers simultaneously. Right now, API pricing is artificially low (sometimes up to 17 times below cost) because they're all competing for market share. When that changes, and it will, the price rise will come from every direction at once. So, the question for your organisation is less about the tool doing what you need it to do, it's figuring out what happens to the vendor when their supplier decided to compete with them or when prices rise across the whole industry. Because, if a vendor does get sherlocked and has to migrate (or fold), you have the same problem they do: your workflows, integrations, and staff training are all built around a tool that's fighting to stay alive. You're no more provider- or price-agnostic than they are, and the migration is now your problem to solve. Colin --- ### Big Consent wins again Source: https://consultcolin.eu/newsletter/archive/big-consent-wins-again/ *24 June 2026* - Germany, France, Poland, and Google walk into a bar… The EU had a plan to fix cookie banners forever. A simple setting, in your browser, like setting your language. To be set once and have every website respect it automatically (with per-site control if needed). No more clicking through walls of options, no more "legitimate interest", and no more "we care about your privacy"... The council killed it this week. Or rather, Germany, France and Poland killed it. Google had been lobbying them hard, and it worked. Interestingly, the ad-tech industry spent years blaming the bureaucrats in Brussels for them, but now they're lobbying to keep them. They built the banner dystopia filled with dark patterns and called it "consent". Now they want to keep it and make sure you can't just say no once and be done with it. Surprising? Not really. Studies consistently show that only 3 to 10% of people actually don't mind being tracked. Every "I agree" out there is from fatigue or misleading interfaces. With a clear dark-pattern-free way to opt-out, the tracking economy collapses. So the banners stay, because the surveillance industry needs them, not because they help. Which brings us back to your website. Every consent banner is an admission: someone is being tracked. Regulation won't be fixing that anytime soon, as today's news plainly shows. But, you don't need regulation to stop tracking your visitors. You just need to ... stop tracking your visitors. Your visitors stop being annoyed. They stop filing you in the "do not trust" box, and you stop feeding their data into a surveillance network every time they click on your site. The industry fought hard this week to make sure the banner stays. That should tell you everything you need to know about whose interests that banner serves. Colin --- ### Big cloud, meet Brussels Source: https://consultcolin.eu/newsletter/archive/big-cloud-meet-brussels/ *23 June 2026* - Map your exit before you need it. A while back I wrote about data portability and used mobile phone number portability as an analogy: mobile operators opened up because they were forced to by regulators, not out of kindness. And, when they did, the lock-in evaporated. I mentioned the EU was pushing in a similar direction for data but that I wouldn't hold my breath. Well... I'm breathing again, a little. The European Commission is expected to classify both AWS and Azure as gatekeepers under the Digital Markets Act this week. Which means mandatory interoperability and data portability; same idea as letting you keep your number when you change mobile operators. The usual caveats apply: Apple and Meta were fined under the DMA and nothing of substance has changed yet, mostly just malicious compliance. Enforcement is a different fight from designation. But the clouds are clearing (literally) and that changes the calculus: if your organisation runs on AWS or Azure, now's the time to figure out what your exit would take. Not because you need to move immediately, but because you should know the answer before you need to make that move. Colin --- ### AI won't end you. Your email provider might Source: https://consultcolin.eu/newsletter/archive/ai-wont-end-you-your-email-provider-might/ *22 June 2026* - Lose your AI subscription and absolutely nothing happens. Last week, I wrote about the Anthropic export control shenanigans and vendor lock-in. Then Cory Doctorow's newsletter showed up and took the idea a step further into the light. His point: when Greenland became the target of Trump's hunger for power, the scary scenario wasn't Denmark losing its ChatGPT subscription. It was Microsoft reaching into a ministry's accounts and bricking the lot: email, calendars, contacts, ... all gone. Because one company, on the other side of the pond flipped a switch on request. That's not a hypothetical about AI, but it is one about every phone, ERP system, identity platform, and even tractor with a kill switch and an owner who answers to a different government than you do. A lot of digital sovereignty panic these days is aimed at AI, because that's the thing we've all been told to be scared of: can we train our own European model? What if we lose our chatbot? Etc. But, honestly, yank a country's ChatGPT or Claude access tomorrow and pretty much nothing will fall over. No hospital depends on it, no factory floor will grind to a halt, no railway will stop functioning. Yank an email provider, a phone fleet, or the software running infrastructure and you've got a crisis, fast. So, yet again, stop asking the wrong questions. Not: "what's our AI strategy" but "which of our dependencies can be switched off by someone outside our jurisdiction, and what happens the day they do that". Same story I was circling with the export control email: worry about who's got their thumb on the kill switch for the infrastructure you actually depend on. You'll live without AI. Colin --- ### Friday links for June 19th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-06-19/ *19 June 2026* - AI vs climate, LinkedIn thought leadership without thinking, Midjourney open a spa, and tapping maps for fun. The "not what it said on the tin" edition. 1. Europe must choose between AI and climate goals, data center lobby says The fact that this headline even exists says a lot about the times we live in. They're asking to be excused from the climate challenges they were promising AI would solve. Externalities, as a service. 2. The Filipino virtual assistants behind LinkedIn's "thought leadership" content mill For $7 an hour, they use AI tools to ghostwrite LinkedIn posts for Western executives. So, the next time you see a CEO sharing his "shower thought that changed everything" it was probably just another Tuesday afternoon in Manila. 3. A New Era of Midjourney I had to check it wasn't April 1st. Midjourney, the AI outfit that helps you generate pictures of cats riding skateboards, are pivoting into healthcare and opening a spa with AI-assisted medical imaging. The hallucinating robot doctor will see you now... 4. MapTap - daily geographic game An amusing little game where you have to guess where a place is or where a historical event took place. Education and fun, it still exists. On rotation This week's soundtrack is Multiforms: Ambient Transmissions, Vol. 3 by Marconi Union Back to your regularly scheduled life, Colin --- ### Prompt now, pray later Source: https://consultcolin.eu/newsletter/archive/prompt-now-pray-later/ *18 June 2026* - Fast to ship, slow to explain in court. You've probably heard of "vibe coding": getting generative AI to write software for you. It's having its day in the sun right now. Replit and Cursor, two vibe coding apps, are even running influencer campaigns selling it as the cheat code to your own app, no coding experience required. It's the same playbook as crypto and MLM: a slick presentation, pull out the credit card, no guarantee it works out. For a quick internal tool, have at it. Automate a spreadsheet, build a dashboard for that meeting room TV. Low stakes, fast iteration, no problem. Production is another animal. Vibe-coded apps regularly ship with security holes a first-year computer science student would catch. And "I didn't know" isn't a defence under GDPR if you're handling customer data. You can be liable for a breach you can't even diagnose, let alone fix. And remember: flat-fee subscriptions currently hiding the real compute cost won't last. When the pricing catches up to the real cost of running these models, your "free" internal one might not be so free anymore. Don't base your business on it. So, vibe code to your heart's content for the stuff nobody else will ever see. The minute it touches a customer or their data, you need a human in the loop who can read the output, not just prompt for it. Colin --- ### Einstein was insufferable. He was also right. Source: https://consultcolin.eu/newsletter/archive/einstein-was-insufferable-he-was-also-right/ *16 June 2026* - A 3-person startup running enterprise tooling is not a flex. There's a story about Einstein as a student: he refused to accept any answer he hadn't derived himself. His professors found him insufferable, he found their certainty suspicious. Not a bad instinct (within reason). It reminds me of a pattern I see repeatedly: someone needs a tool for X. They ask around. They get an answer. They take it. The answer is whatever some LinkedIn guy with 80k followers is currently pushing, or what their favourite podcast host mentioned in passing, or what a competitor is using (as if a competitor's stack is a strategy they can just absorb by proximity). They don't ask why, or ask about the team size, the budget, the specific failure mode being solved, the migration cost, the three tools that got tried and ditched before this one. The influencer spoke. The post got 400 likes. That's the whole chain. This is called borrowed certainty, and it's endemic. It's how you end up with a 3-person-startup running enterprise tooling because some VC-backed company blogged about their stack. But tools are situational. Notion might work for a team of 2 but collapse for a team of 40. The CRM a 500-contact-consultant uses might fold under the weight of 10000. The email platform built for monolingual US markets will cost you three times the labour in a trilingual European one. The question to ask isn't "do people I respect use this?", it's "does this solve my specific problem, in my specific situation, with my actual constraints?" Be more like Einstein. Do the work. Derive the answer yourself. Colin --- ### Anthropic, export controls, and the wrong panic Source: https://consultcolin.eu/newsletter/archive/anthropic-export-controls-and-the-wrong-panic/ *15 June 2026* - The concern is real, just not the one everyone's pointing at. On Friday, the US government blocked access to Anthropic's most advanced AI model, Mythos, for non-American users. The internet immediately went into meltdown about kill switches and government overreach. I could hear the LinkedIn tears from way over here. The reasons are dubious. An Amazon-Trump conversation on AI security triggered the intervention: from an administration already at odds with Anthropic over AI weapons policy, against a company that had spent months declaring Mythos too dangerous to release. At best, a naive reaction; at worst, retribution. Now I'm seeing posts along the lines of: "This could happen with your phone. This could happen with your laptop. This could happen with your credit card." Yes and no. I get the instinct, but this is not that. And conflating them makes the real argument for digital sovereignty weaker. What happened here is an export control. A specific legal mechanism for restricting the flow of sensitive technology across borders: chips, military hardware, and now AI models. The Commerce Department needs a specific justification to invoke it. Anthropic gave them one. There was also an added wrinkle: because Anthropic couldn't reliably identify users by nationality, the block ended up applying globally. The mechanism may have been targeted, but the effect ended up looking like a service suspension. But this export control isn't a remote off switch for your Microsoft 365 account. Suspending cloud services to European businesses requires different legal authority, different political justification, and carries consequences of a different order entirely. The line isn't uncrossable, ask the ICC judges, but it's a different line. The problem with crying wolf isn't that wolves don't exist, it's that when you point at the wrong one, people stop listening. Export controls on AI and your structural dependency on US cloud infrastructure are both real risks. Bundling them together undermines both. They need separate arguments - made separately. The concern you should be paying attention to is structural. European organisations are running critical operations on infrastructure they don't control, under laws they have no influence over. Those companies can change their terms, get acquired, face sanctions, or simply decide your market isn't worth serving anymore. No government vendetta required. Colin --- ### Friday links for June 12th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-06-12/ *12 June 2026* - AI and the climate, who is Elias Thorne?, fingerprinting your phone, and breaking patterns. The "worse than I thought" edition. 1. The UN report on AI vs Climate It's not great. 80 to 90% of energy consumption is in day-to-day use, not training. When CO2 consumption goes down, water and land can increase. Generating images is 1450 times worse than text, video is worse than that. 2. Generative AI is fixated on Elias Thorne Elias Thorne does not exist but, when you ask a large language models to tell you a story, there's a high chance he'll be the hero. The reason? Model collapse: feeding generated text back into a text generator. 3. Loupe by Mysk If you ever wondered how ad networks seem to track you all over the net, this iPhone app reveals all the fingerprinting data they can access about your phone without even asking. Despite knowing about this, I was still surprised at how much is up for grabs. 4. Pattern Breaking A very well made site demonstrating the issues with dark patterns in online shopping and the overconsumption that results from it in the world of fashion. On rotation This week's soundtrack is Big Mama by Flying Lotus Until Monday... Colin --- ### In defence of floors Source: https://consultcolin.eu/newsletter/archive/in-defence-of-floors/ *11 June 2026* - Below it: prohibited, above it: competition. "Regulation kills innovation". You've heard this one before, and you'll keep hearing it. It is, to use a highly technical term, poppycock. It gets recycled endlessly by every "visionary" who needs you to believe that the rules protecting you are actually hurting you. What they usually mean is: I am currently making money by doing something you'd stop me from doing if you understood it. Please do not look too closely. Let's do some history. In the 80s, mobile telecoms in Europe was a mess of proprietary analog standards, each one controlled by its own little fiefdom/national monopoly. The handset you bought in Germany was a brick in France, roaming was not a thing. CEPT (European Conference of Postal and Telecommunications Administrations) pushed for GSM, an open interoperable standard available to all. Industry players did what industry players do: they said it would lock in the wrong technology, destroy competition, slow innovation, and all the rest of it. What actually happened was the European mobile market: competitive handset manufacturers, SIM cards, roaming, etc. GSM became the backbone of worldwide mobile standards. It turns out that when operators couldn't build a moat based on proprietary technology, they had to compete on making better products. That's the real game: not innovation versus stagnation, but competition on merit rather than lock-in. Another example is the EU common charger mandate. The objections were ritual and identical: innovation would be stifled, manufacturers would stop creating new products, and all that jazz. What we got instead was a massive interoperable market for charging infrastructure and cables you own once and can use pretty much forever. The "innovation" they were defending was being able to sell you a new charger or cable every time you got a new device. Regulation sets a floor. It defines what you're not allowed to do to your users. Below it: prohibited, above it: competition. When you can't trap users behind proprietary walls, you have to make something they actually want. The people screaming the loudest about regulatory burdens on innovation are, nearly without exception, the people with a business model that needs freedom to do harm. When you hear their complaints, ask yourself: what, specifically, do they need the freedom to keep doing to you? Colin --- ### Inevitable (citation needed) Source: https://consultcolin.eu/newsletter/archive/inevitable-citation-needed/ *10 June 2026* - Roman emperors killed prophets for a reason. If you open just about any tech publication or industry newsletter these days, you'll find headlines like "Anthropic warns that AI could soon escape human control". Stated as fact - no evidence needed - track record irrelevant. Karl Bode calls this "CEO said a thing" journalism. The format is simple: never challenge the claim, never provide historical context, ghost anyone who might disagree, and never ever go back to check whether it turned out to be true. It exists in a vacuum, elevated to news purely by the speaker's net worth. So we end up with confident predictions about inevitable futures all over the media, laundered though headlines, and repeated until the thing that hasn't happened yet feels like the thing that already did. I'm currently reading Carissa Véliz's book Prophecy where she argues we mistake predictions for knowledge, when we should read them as power grabs. Roman emperors would ban (or kill) prophets, not because they saw prophecies as nonsense, but because they understood that whoever controls the story also controls what people do next. Make an outcome seem inevitable, and you don't need to convince anyone. They'll adapt all by themselves. We've watched this film before: crypto was going to replace banking, the metaverse was going to replace the office,... Each one announced with that same certainty, amplified by the same uncritical coverage, and composted in the archives when it didn't materialise. When you see another "inevitable" headline or hear another person tell you some technology will redefine your industry and the only rational move is to get aboard right now, hold on to your FOMO and go back and take a look at the last ten times someone said the same thing. The failure rate will be sobering. Colin --- ### Faster and louder Source: https://consultcolin.eu/newsletter/archive/faster-and-louder/ *9 June 2026* - Book sales are flat, app installs are down, but the graphs look great! Yesterday, I mentioned that the optimisation of AI setups often leads to a simulacrum of productivity rather than actually being productive. A couple of hours later, I was reading Gary Marcus' latest newsletter in which he made a related point. Books, music, apps, lines of code, scientific papers - the quantity produced for them all is up sharply since generative AI became mainstream. The graphs are hockey sticks. The boosters will show you these numbers and call it a productivity revolution, and if you squint and don't ask any follow-up questions, it looks convincing. But that's just output. Book sales haven't increased, nobody's going wild about all the new incredible music out there, more apps aren't being installed (quite the opposite)... More things exist but none of the significant metrics have gone up. Productivity is output that matters. Volume that has no relationship to value isn't productivity, it's noise. We have much faster noise now. Of course, this is something that's difficult to measure. Which is why it usually gets ignored. It's a lot easier to count tokens spent, or words generated, or tasks "completed" than it is to figure out if anything actually moved forwards. And when things are hard to measure, we have a tendency to measure the wrong thing and convince ourselves it's the same.[1] Well before transformers showed up, managers were counting inputs when outputs were too difficult to track: hours in the office, emails sent, meetings attended, lines of code committed... AI just turbocharged it. You can now produce a year's worth of measurable-but-meaningless activity before your lunch break. So, before you drop AI into another process: what does actual success look like? Not the completion of the task. The point of the task. And would you even be able to tell if AI was helping or just making the noise louder? Colin [1] I recommend The Tyranny of metrics by Jerry Z. Muller if you want to dig into this. --- ### Busy getting busy Source: https://consultcolin.eu/newsletter/archive/busy-getting-busy/ *8 June 2026* - Same old trap, shiny new bait. If you're old enough, you might remember a productivity system called GTD (Getting Things Done) taking over some corners of the internet back in the early 2000s. The idea was simple: get tasks out of your head and immediately into a trusted system, so you could concentrate on doing things rather than trying to remember them. It was a really good idea and system, I still use a variant of it. But people got obsessed with it. And these obsessives often were the least productive people. They spent their days optimising their system, searching for the perfect app, colour-coding their categories, creating filters and rules... They got very busy preparing to get busy. Merlin Mann, who helped popularise GTD online (and coined the term "inbox zero"), ended up calling it "productivity porn" which is an obsession with the tools and rituals of productivity rather than the actual output. He then walked away from the whole thing. The system itself wasn't the problem but, when it became the whole point, it also became... the problem. I'm seeing this pattern play out again, this time with generative AI. Every tool has added AI features, every workflow is "AI-enhanced", and every meeting involves someone explaining how they integrated AI into something and are now more productive. There are consultants, courses, and newsletters all dedicated to using AI to be more productive. Every third person on LinkedIn has "AI" in their job title. And yes, ethics aside (which is, arguably, impossible), generative AI can be useful in the right place, for the right task. But a lot of it is the same old trick in new clothes: people very busy optimising their AI setup instead of doing what the AI was, at some point, supposed to help with. The tool has become the point, yet again. So, the eternal question remains: will this actually make the output better, or will it just make the process feel high-tech and modern? If it's "no", you might be doing productivity porn. Colin --- ### Friday links for June 5th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-06-05/ *5 June 2026* - The bots are winning, just say please, meta gets creepier, the EU forgets social, and Geocities trauma. The "working as intended" edition. 1. Bot traffic is now equal or greater than human traffic Per Cloudflare, there are now more bots than humans on the internet. We did it, the zombie internet is a reality. There's probably a bot somewhere forwarding this email to another bot. 2. Hackers Used Meta's AI Support Bot to Seize Instagram Accounts Hackers simply asked Meta's AI chatbot to give them access to celebrity accounts, and it did. Turns out you can get Barack Obama's instagram account if you just say please. 3. Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones Meta's pervert glasses already have the capacity to do facial recognition, they just haven't activated it yet. I'm sure nothing bad will come of this, Meta have a great track record on privacy. (archived article here) 4. The EU tech sovereignty plan The European Commission has published its new Tech Sovereignty Plan. Pretty good on the surface, but they're ignoring the social layer, which is the glue for many of the other layers. 5. Cameron's World And, if you're old enough to remember Geocities, here's a lovingly-assembled collage of bits and pieces excavated from there. If you're too young, this is what your parent's corner of the internet probably looked like. On rotation This week's soundtrack is Everywhere at the End of Time by The Caretaker. See you on the flip side, Colin --- ### The bus is coming Source: https://consultcolin.eu/newsletter/archive/the-bus-is-coming/ *4 June 2026* - And the project's maintainer is standing in the middle of the road. My recent emails have been making the case for open tools, but let me point out the elephant in the room: open-source is not free. Someone, somewhere, is paying for it. In time if not in money. A surprising amount of the software running the modern world is maintained by a tiny number of people, many unpaid, in their spare time. The risk that comes from this has a name: the "bus factor". That's how many maintainers would have to be hit by a bus before the whole project collapses. Comforting, right? Sometimes that number is just: one. It sounds alarming, but compare this openness to the opaque alternatives. When an open tool is fragile, you will see it: you can check who maintains it, how active it is, and how healthy it is. And you can fund it or advocate for it. Germany even has an agency that does exactly that. It pays open-source maintainers to keep critical tools alive. It fixes the fragility. On the other, opaque, corporate side, you have a kill switch that you won't see coming. You'll find out about it when it's used against you. So, don't choose your tools on price only. "Free" is not the real price. And put something behind the tools you really depend on: a few euros, a sponsorship, a coffee, or simply loud public support. It's a lot cheaper than getting stranded. Colin --- ### Can you walk? Source: https://consultcolin.eu/newsletter/archive/can-you-walk/ *3 June 2026* - They don't need to trap you if leaving traps you instead. Remember when switching to a new mobile phone carrier meant you would lose your number? You stayed put because everyone had your number or, if you did switch, you had to text your new number to your whole address book. Switching was expensive, so practically no one did it. Then the rules changed: number portability came in and you could just take your number with you. Overnight, the lock-in evaporated and the market became more competitive. Hold on to that feeling... A major reason a supplier has power over you isn't price or features, it's whether you can take your stuff and leave. The phone number portability happened because it was forced by a regulator not out of operators' kindness. The EU is pushing in the same direction for data, but I wouldn't hold my breath. The little changes they have tried to impose have ended with malicious compliance from big tech. It's going to take a lot of back and forth before anything, if anything, ever happens So, freedom to move your data can't be something a company grants you, because anything granted can be made deliberately painful or even taken away. It has to be structural. That's what you get from an open tool: no gatekeeper at the door deciding how wide to open it because, well, there's no gatekeeper at all. And, no, this doesn't mean running servers in a corner of your office. Plenty of European companies will host an open tool for you and bill it like any subscription. The difference is the exit path: if they let you down, you subscribe to the same tool elsewhere, move your data, and carry on. With proprietary tools, you can't just abandon the host, you have to abandon the tool and probably your data too. So, yet another question to ask before signing up to something is: if I want to move, can I? And will I still have all my data when I get there? Colin --- ### Herd immunity, the tech version Source: https://consultcolin.eu/newsletter/archive/herd-immunity-the-tech-version/ *2 June 2026* - Community size is the feature that's never on the comparison matrix. When open-source gets mentioned, it's often assumed that the benefit is for the technically-minded, the people writing the code. That you only get something out of it if you roll up your sleeves. This is not the case. When you adopt a widely-used open tool, tons of other organisations are keeping it alive too. They're funding the development, finding the bugs, adding or requesting features,... You ride along "for free" (more about this in a later email), benefiting from a scale you couldn't possibly pay for alone. Compare this to some small proprietary tool you found that does exactly what you need. It's great ... until you realise you're only one of a few customers keeping it alive. If or when that tool maker gets bored, runs out of cash, or pivots to some "AI-powered" solution, you're suddenly on your own with no migration path and another "end of our incredible journey" email giving you 30 days (if you're lucky). There's safety in numbers. And if those numbers have already done the vetting and maintenance for you, you've got leverage there. When choosing tools and they're close on features, check the communities behind them. The one with the larger open community has scale that will usually work in your favour. Colin --- ### Can a sheep field be sanctioned? Source: https://consultcolin.eu/newsletter/archive/can-a-sheep-field-be-sanctioned/ *1 June 2026* - What medieval pastures know about sovereignty. The digital sovereignty issue tends to often get framed as a binary choice: American big tech or European big tech. But there's a third option that doesn't get as much press: open source, also known as the digital commons. The commons are things owned by no one but managed by all the people who use them. It's an idea that's much older than computers. Think of shared pastures or fisheries, managed collectively rather than by the state, a landlord, or a company. There are digital versions of this idea all around you: Wikipedia, OpenStreetMap, Linux, ... No single owner, no shareholders, just a community maintaining it all. And that can be a better guarantee than whatever flag is on the box. A company, be it European or American, usually has an owner. And owners can be bought, leaned on, or sanctioned. And, when that happens, things can change very suddenly. Ask the ICC judge who lost all his accounts when the Trump government sanctioned him, or the Dutch citizens who very nearly saw the local company that held their data suddenly get sold to a US one. There's no switch to flip on a commons, no boardroom to pressure, no chokepoints or pricing to tighten gradually. So, one question you could ask when evaluating another tool isn't just "Where is my data?" but "does someone own this, and could they take it away from me?" Colin --- ### Friday links for May 29th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-05-29/ *29 May 2026* - AdTech for war, AI sticker shock, bubble basics, profit charts, and retro gaming. The "no one could have seen this coming" edition. 1. Pentagon says US military personnel are reportedly being targeted using location data The dangers of advertising technology happily tracking everyone everywhere aren't new - I've been talking peoples' ears off about this for years. The pentagon has suddenly woken up to the fact that their adversaries are using advertising data to track and target their soldiers. Looks like "military-grade privacy" isn't a big feature of AdTech. 2. AI sticker shock hits corporate America Many businesses also suddenly realising that the costs of AI don't justify the returns and that it's not being used for the most valuable tasks: "One CTO told Axios that employees were using AI models to check the weather". Subscription fee: enterprise - use case: partly cloudy. 3. The AI Bubble A deep dive into why the AI bubble is in fact a ... bubble. This is one of the clearer explanations I've read, at least for someone like me who gets extremely confused by financial jargon. 4. Is AI Profitable Yet? Yes, more AI - it just dominates the discourse. You probably know the answer to the titular question, but this is a nice visual representation of the gigantic financial hole these people have dug themselves into. 5. webRcade And a little throwback fun to finish: play retro console games in your browser. From classic consoles like the Atari 2600, Nintendo Entertainment System, or Sega Master System. On rotation This week's soundtrack is Inferno by Boards of Canada. See you Monday, Colin --- ### Browser says no Source: https://consultcolin.eu/newsletter/archive/browser-says-no/ *28 May 2026* - The native app says yes The online services you use often ask (or even insist) you install their app. Expense tools, HR platforms, shift planners, project management platforms, even LinkedIn. They all have perfectly serviceable websites but they still want you to install their app. Ever wonder why? They'll tell you that native apps, the ones you download from the app stores, can do things that websites can't. That's true, but not how you might imagine it to be. They can track your precise location in the background, run code when your phone starts, generate persistent identifiers linked to you, and share it all with the many third-party packages they've included inside the app. A website, loaded inside a browser, does almost none of this stuff by default. And even less of it if you're running privacy extensions. The browser is a security boundary. Apps can bypass this boundary. The web is now nearly as capable as native apps. Push notifications, offline functionality, camera, files, etc - it's all there in modern browsers. Each one asking explicit permission before it can do anything. The capability gap that was used to justify native apps is pretty much closed now. Protection against surveillance is the big differentiator, and the web is the winner here. A 2026 audit of 135 widely-used enterprise mobile apps found that more than 1 in 5 of them contained privacy-impacting behaviours: tracking, profiling, data sharing, contact harvesting, the lot. Not by accident or because of a breach. Your staff's devices are also your devices. They're windows into your organisation and its behaviour. So, when a vendor pesters you to "download our app", the first question should be: what do they get from an app that a website can't give them? There are situations where the app really is needed, but they're becoming the exception rather than the rule. Colin --- ### Diderot had a dressing gown, you have Salesforce Source: https://consultcolin.eu/newsletter/archive/diderot-had-a-dressing-gown-you-have-salesforce/ *27 May 2026* - He ended up in debt too. In 1769, the French Philosopher Denis Diderot wrote an essay about a beautiful scarlet dressing gown that he was gifted. He absolutely loved it. But suddenly, compared to it, everything around him looked shabby and inelegant. He replaced his old straw chair with a beautiful leather one, his desk with an expensive writing table, and so on. Until he finally ended up in debt. In that essay, he wrote "I was absolute master of my old dressing gown" ... "but I have become a slave to my new one". I see a similar process taking place when I look at how some organisations build their software stacks. It starts with a single tool, usually adopted for the wrong reasons - not because it's the right fit: because it looks serious, projects success, is the one everyone else uses, ... You get the picture. That picture is the dressing gown. Salesforce is a good example. A small team decide they need a CRM and opt for Salesforce because it's the one everyone talks about and all the big corps use it. Then they find out it's really complex and they need to hire a consultant to configure it. Then they realise their email platform doesn't talk to it the right way, so that gets an upgrade.Then, when they want to see data across both systems, they decide to add a reporting layer. Tableau (also owned by Salesforce) is suggested. Then the data needs constant feeding, so someone has to work on that. Suddenly, you need a part-time admin, an email tool upgrade, a reporting platform, and a process you didn't even imagine before. Diderot concluded that his beautiful new dressing gown had imposed its own logic on everything around it. The same thing can happen with software. The plan is never to build a new software stack, it's to look like an organisation that has its act together. But, step by step, the stack accumulates because of that one decision. Colin --- ### Enterprise Cosplay Source: https://consultcolin.eu/newsletter/archive/enterprise-cosplay/ *26 May 2026* - Who exactly are you trying to impress? When talking about software choices, I often hear variations of statements like these: "Every serious organisation in our space uses HubSpot so we should too" or "We need to be on Microsoft because that's what everyone uses" or "Investors will ask what stack we're on. We need to be on AWS or they won't take us seriously". One thing these justifications have no relationship to is what the software actually does. They're more concerned with what the software communicates. To clients, investors, competitors... Researchers calls this "organisational legitimacy", the concept of organisations adopting tools, processes, or practices to make themselves look credible. It explains a lot of enterprise overkill: a massive CRM for a team of four, the superfluous cookie banner I talked about yesterday, the Microsoft 365 subscription for a team that just needs email, notes, and a calendar. The tools aren't necessarily wrong, sometimes they might be the right choice. But if the reasoning was "it's what serious businesses use" or "we'll grow into it", it might be time for a reflective pause. Outside perception might not be worth the money, complexity and maintenance. And, let's be honest here, the perception is often just your own. The only question to ask is "Does this do what we need?". Colin --- ### You can't install credibility Source: https://consultcolin.eu/newsletter/archive/you-cant-install-credibility/ *25 May 2026* - Looking serious and being serious are not the same thing. I've been thinking about the signalling or legitimacy aspect of software selection recently. Where software is chosen in order to communicate, for example, professionalism, above solving an actual problem. It reminded me of a discussion I had when someone asked me to take a look at their new website. After browsing around, I asked them why they had a cookie consent banner when their site didn't actually place any tracking cookies. Their answer: "it makes the site look more serious". I understand the instinct. Visitors arrive, they see the banner, they assume the organisation running the site takes things seriously. But there's a glitch with that logic. A cookie banner doesn't signal that you take privacy seriously, it signals that you're tracking people and want to cover your ass. That's the only reason these things exist. I've mentioned it before: the ePrivacy directive only requires consent if you want to track. The banner is a workaround, bordering on malicious compliance. Your cookie banner doesn't project trust, it projects surveillance. People may click on "agree" because of consent fatigue, but they're still mentally filing you into the "do not trust" box. The absence of a cookie banner is what projects seriousness. Seriousness about your visitors' privacy. This isn't limited to banners, more on this trap later. Colin --- ### Friday links for May 22nd 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-05-22/ *22 May 2026* - Avoiding dystopia, Google and more Google, and a robot comic. It's been a slow week - apart from the Google shenanigans - here are some links nonetheless: 1. Johnny Ryan - How we avoid dystopia (video) Johnny Ryan from the Irish Council for Civil Liberties explains how Europe became vulnerable due to its dependence on big tech and how we need to pressure Ireland, where all these companies have their European base, to enforce the rules and stop letting tech giants do what they want. 2. Google Search's AI evolution includes more ads My email about Google's AI folly yesterday mentioned that they would need to get the money from somewhere. Well, here's one theory: they'll directly suggest what to buy and give you the buy button. No more choice for you. 3. Google Announces Plan To Destroy All Information It Can't Index The Onion, as usual, has the best (satirical) take on this week's Google news. 4. PizzaCake Comics We all know what this comic is referring to... See you next week, Colin --- ### Google Just Killed Google Source: https://consultcolin.eu/newsletter/archive/google-just-killed-google/ *21 May 2026* - A brief service of remembrance for the blue link. 1998–2026. You may have seen that Google made a major announcement about changes to Search this week. The biggest change since their launch. Instead of the traditional list of blue links, Google will now generate "interactive experiences" and other custom AI mini-apps on the fly. All based on your search query. The example they gave is this one: ask a question about black holes, get an interactive model you can play with in return. It sounds impressive, but it's also a problem. I guess it's time to repeat myself yet again: Large Language Models are not fact engines. They produce plausible-sounding output where accuracy simply depends on how often the right answer shows up in their training data. When the output is some text, people will usually have enough experience to stay at least a little sceptical (I hope so, anyway). When the output is a beautiful, interactive, model you can explore and click around? I suspect the percentage will go down. There's a reason teachers like using similar experiences - they stick. Combine cognitive surrender, which I mentioned yesterday, with an interactive experience, and you're no longer looking at a search engine. You might even be looking at a belief-manufacturing machine. Your audience is about to be subjected to a system that generates compelling, attractive, and authoritative-looking explanations of topics you probably understand better than a Large Language Model. They won't come to your website to check, they'll have already "learned" what they want from the cool new real-sounding model. Google also holds 90% of the European search market. Businesses to authorities already depend on Google to reach their clients or citizens. Every move Google makes towards this one-stop experience makes it harder to escape them as the source of truth for your audience. This new "experience" arrives his summer. Every visit a European user will be making to it, is a visit they won't be making to your website, or to trusted authorities and information sources. Then there's the question that keeps coming up with this whole AI thing: how does any of it make financial sense? Generating interfaces on the fly uses a lot more compute than displaying a list of links. And if users stick around and no longer visit other sites, ads targeting them will probably be sold at even higher prices. And those prices will come from collecting even more data. In all of its history, Google made one good thing: a search engine that really empowered people on the web. Then they kept doing bad things until finally destroying that one good thing. Colin --- ### Arguing with the Internet Source: https://consultcolin.eu/newsletter/archive/arguing-with-the-internet/ *20 May 2026* - Your colleague has been replaced by a confident statistical echo. Recently, I've had several conversations where people come to me with ready-made technical solutions that simply can't work. Or they send me (wrong) explanations in that unmistakable chatbot voice, but presented as their own thinking. In all cases, these solutions are delivered with absolute conviction. When I push back, they push back harder. The source? Generative AI of course. It seems that when the chatbot has spoken, it can't be wrong. Well, it's got a name now. Researchers at Wharton have just published a paper introducing it as "Cognitive Surrender" (great name for a band). It's what happens when people stop reasoning and just adopt AI answers as their own, often without even noticing. In the experiments, whether the AI was right or wrong, the participants' confidence went up. The AI made people more certain regardless of whether it made them correct. When someone's unsure, you can usually tell. And those signals let you know you should push back. Chatbots are confident whatever they're saying, and this seems to transfer to the people using them. I've written in previous emails how Large Language Models are just text-synthesis engines. They produce plausible sounding output, and factual accuracy is just a side effect of how often the truth appears in their training data. "Plausible" and "correct" are easy to confuse, especially because our brains associate language use with intelligence. Software that "extrudes" text basically hacks our senses. The consequence of all this is that you can end up arguing with, not a colleague or a client, but with a statistical echo of internet content that's delivered with absolute confidence. The researchers did find one thing that helped: giving people incentives for accuracy. It made them more likely to question the answers, push back, and override. In other words, people need to care about being right, not just about sounding right. It's worth thinking about how you use these tools but also how your team does. Before you end up outsourcing your judgement. Colin PS: here's the paper if you're interested. --- ### The game was always rigged Source: https://consultcolin.eu/newsletter/archive/the-game-was-always-rigged/ *19 May 2026* - Turns out the referee was American. Have you ever stopped to think about why your organisation's computers run Windows or why your data is on Amazon Web Services, or why a good part of your business workflow depends on Google? American tech companies don't always dominate because the world loves them (many poll as badly as tobacco companies) but because US trade policy says so. This is not new. For decades, US trade and internet policy has helped entrench their position abroad by promoting digital rules that favour US platforms, global data flows, and weak regulatory barriers. And today, countries that try to fine or regulate US platforms face trade sanctions. The Trump White House has described the EU digital regulations as "overseas extortion". Trade deals now explicitly require that some countries waive the right to regulate American tech in exchange for aid. Free market? Not so much. The tools you use aren't simply products, they're also extensions of another country's foreign policy. Many organisations stay locked in because of switching costs, habit, and the reassuring fiction that the dominant option is also the best one. Every day it looks more and more like a risk. Preparing an exit plan might be a good idea. Colin --- ### Fancy a treasure hunt? Source: https://consultcolin.eu/newsletter/archive/fancy-a-treasure-hunt/ *18 May 2026* - You are in a maze of twisting databases. Your customer's data is everywhere. No exits are visible. Did you know the GDPR gives people the right to ask any organisation to delete all their personal data? And you have one month to respond. It's called "the right to be forgotten" (something we've all wished for at some point). But, deleting records and erasing all of someone's data are two completely different things. Imagine an old customer sends you a deletion request. You go into your website's database and remove their account. Job done? Not really. That customer's email address is probably still in your marketing software, maybe your CRM. Their purchase history might be in your accounting app. Their previous emails to you in a backup somewhere. A comment about their order in an internal Teams channel. You get the idea... You may have deleted a website account but their data is still all over the place. This is the situation most organisations only discover when they suddenly get their first deletion request and have to start looking. And looking can turn into quite an adventure because most organisations don't have a clear map of where personal data lives. It accumulates over years, across tools, even across people who've left since. The GDPR's Article 17 requires you to erase that personal data from everywhere you hold it. That includes sub-processors you sent it to. Now, there are certain situations where you have a legal obligation to keep the data: financial compliance, ongoing contracts, and "legitimate interest" (that's a complicated one, and for another day). But, in all cases, you have to actively assess this and be able to explain your reasoning. You can't ignore requests or simply delete the main account and pray. What I'm really saying is: if someone asked you to delete their data today, would you know where to look? Do you have a map and a process or would you be running around like a dog chasing cars? If you have no idea, it's time to write that procedure and, as I've said before, stop hoarding data you don't need. The less you collect, the less you have to find when someone asks you to zap it. Colin --- ### Friday links for May 15th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-05-15/ *15 May 2026* - Copilot stereotypes, age checks are useless, your browser leaks, and Google hoards data. A little offering of links for you today: 1. Real signals or artificial stereotypes? When asked to describe the differences between responses to a survey from multiple countries, Microsoft Copilot gave culturally stereotyped answers. But the survey responses were actually identical, they'd just been copy-pasted from one country to another. We've finally built machines in our own image: ready to stereotype entire nations without looking at the data. 2. Kids say they can beat age checks by drawing on a fake mustache Just in case you were wondering how good age verification technology has become. 3. Taken Not the movie with Liam Neeson being menacing on the phone. A site that shows you how easy it is to get a bunch of information from your browser. Usually enough to create a unique fingerprint and follow you around. 4. How Google Tracks Everything You Do and How to Stop It A well-made video from Proton that peels back the curtain on the world's nosiest corporation and everything they hoard about you. Of course, just by watching it, Google knows that too now. Don't do anything I wouldn't do, and see you Monday. Colin --- ### Nothing to worry about – says new American owner Source: https://consultcolin.eu/newsletter/archive/nothing-to-worry-about-says-new-american-owner/ *14 May 2026* - You read the privacy policy, but you forgot to read the acquisition clause. Imagine you've made all the proper moves: you've migrated away from big U.S. platforms. Your tools are under EU jurisdiction, locally hosted, and you sleep soundly at night. Then, surprise, one of your European providers gets acquired by an American company. All the things you migrated away from are suddenly back: foreign jurisdiction, CLOUD act exposure, the whole shebang. But you didn't make that choice, they made it for you. Well, it's not just theoretical. Last November, Kyndryl, an American firm, announced it was acquiring Solvinity, a Dutch cloud provider. The problem: Solvinity runs DigiD, the Dutch national authentication system for citizens. And they also host infrastructure for the Ministry of Justice. Obviously, that didn't go down too well in the halls of The Hague, and the Dutch government opened an investigation into it, blocking everything. The difference between your organisation and the Dutch government is that you probably don't have the weight to push back and call an emergency debate about it (and, if you do, who are you?). But, there is one tool you can use. It's just that most people don't think to ask or don't know they can: a change-of-control-clause. It's a provision that gives you the right to terminate and move your data out if the ownership of the provider changes. Without one, you're locked-in to the new owner and their jurisdiction. Next time you're signing or renewing a contract, check that you can exit if the company is acquired. Tip: add a calendar event a couple of weeks before your next renewal so you can check the contract and make sure you don't end up with defaults that work against you. Colin --- ### The internet's landlord is cutting staff Source: https://consultcolin.eu/newsletter/archive/the-internets-landlord-is-cutting-staff/ *13 May 2026* - 20% of the web runs on Cloudflare and Cloudflare now runs on 20% fewer people. If you've got a website, there's a high chance that it's served through Cloudflare. They're a CDN: Content Distribution Network - speeding up your site by copying your content to points around the globe closer to visitors. They also do DNS: Domain Name System - telling browsers where your site is. And DDoS protection: Distributed Denial of Service protection - keeping your site from crashing when someone tries to flood it with traffic. It's a useful service, about 20% of all websites in the world use it, particularly because it has a free tier that many people take advantage of. This makes them one of those invisible chokepoints we only notice when things go wrong. Last December, Cloudflare had a massive, multi-hour, outage that took down close to a third of all traffic it served. This was an internal configuration error, not some kind of attack. I spent hours trying to help clients get back online that day, mostly unsuccessfully. Then last week they announced they were firing about 20% of their workforce (1100 people). All of this while reporting record revenue up 34% year-on-year. The official "reason"? AI is making those jobs unnecessary. They're also hiring over a thousand interns at the same time, make of that what you will. Who knows? Maybe AI really is making them more efficient. But maybe this is just what happens when a company puts margins above resilience. Whatever the reason, it means fewer experienced people maintaining the infrastructure that your website depends on. And then there's the other issue: Cloudflare is an American company, sitting in the traffic path between your site and your visitors. They see every DNS query, every HTTP header, every single request. And they control the kill switch. Not great for digital autonomy... There are European alternatives. They don't match Cloudflare feature-for-feature but, for most use cases, they'll work just as well. Bunny.net is the best-known one, and it's even faster than Cloudflare. It's EU-based (Slovenia), GDPR-compliant, and pricing is transparent. Here's a post from someone who switched in less than 2 hours. You don't need to rush away from Cloudflare immediately, but it might be worth planning a move if you worry about sovereignty and/or resilience. Colin --- ### A very expensive way to annoy strangers Source: https://consultcolin.eu/newsletter/archive/a-very-expensive-way-to-annoy-strangers/ *12 May 2026* - Somewhere, a data broker is buying a holiday home with the difference between what you paid and what the publisher received. I got a reply to yesterday's email about tracking in advertising from Kurt (quoted with permission): That's all well and good, but where does contextual advertising still exist or work? Every platform I look at wants to track people. First, let's take a look at what happens when you switch away from behavioural advertising. In 2020, NPO, the Dutch public broadcaster, switched from behavioural to contextual advertising across all their sites. Unsurprisingly, they expected a drop in revenue/clicks. The opposite happened. It went up 62% in January then 79% in February compared to the year before. [1] Why did this happen? Well, once they cut out all the tracking infrastructure, all the middlemen disappeared along with it. Every Euro went to the publishers pocket instead of being siphoned off by ad exchanges and other intermediaries. Something similar happened with the New York Times. When the GDPR came into effect, they decided all the extra hassle needed to deal with consent wasn't worth it and they switched to contextual advertising for visitors from Europe. Revenue didn't drop at all. [2] A study of millions of advertising transactions tended to confirm this. It found behavioural advertising only increased publisher revenue by 4% but increased advertiser cost by 500%. Once again, the intermediaries were the ones making bank. [3] So, can you still find contextual advertising? Yes. Seedtag, a Spanish company, does exactly that and is growing exponentially. DuckDuckGo is profitable and only relies on contextual search ads. As mentioned yesterday, newsletter sponsorships or podcast ads are basically contextual too. However, if you want to advertise on sites like Facebook or LinkedIn, you're stuck with tracking for the moment. And the reason it feels like all these platforms want to track people is because that's where the gold is for them - not you. Just beware of the fancy dashboards all these services offer you with lots of vanity metrics like impressions and clicks. Those don't necessarily correlate with actual business outcomes (for you anyway) Colin [1] https://brave.com/blog/publisher-3rd-party-tracking/ [2] https://digiday.com/media/gumgumtest-new-york-times-gdpr-cut-off-ad-exchanges-europe-ad-revenue/ [3] https://www.eff.org/deeplinks/2019/06/research-shows-publishers-benefit-little-tracking-ads --- ### Data brokers think you're a woman, or a man, they're not sure Source: https://consultcolin.eu/newsletter/archive/data-brokers-think-youre-a-woman-or-a-man-not-sure/ *10 May 2026* - They'll charge you full price for the information in any case. When you run an online advertising campaign via one of the big platforms, where do you think the money goes? For every Euro you spend trying to reach your audience, less than 50 cents goes to showing your ad. The rest feeds all the intermediaries: ad exchanges, data brokers, and the rest of the AdTech supply chain. Neither you nor the publisher where the ad is shown get your money's worth. The intermediaries, though, get the money and get to build dossiers on the people you're trying to reach The industry calls this "identity resolution": stitching all the fragments of someone's online activities into a detailed profile: email addresses, phone numbers, geographical locations, shopping habits, phone brands,... You name it, they connect it and sell it. One company might know you visited a health site, another might know where you shop offline, a third knows where you live. All this gets combined and saved. The worst part is that, despite all the spying, a lot of that data is plain wrong. A study found that data brokers only get someone's gender right 42% of the time, which is worse than a coin flip! Accuracy doesn't really matter to them, though, because selling big audience segments means bigger fees. Adding to this, display ads get clicked around 50 times per 10000 views, which isn't a lot. But the 10000 views still harvest data about the viewer each time. The clicking is barely worth it, the surveillance is (to them). Platforms justify this invasive advertising by citing surveys saying users prefer relevant ads. But those surveys are rigged with leading questions. If they asked "are you happy to be tracked and profiled so ads can get your gender wrong half the time?" I doubt you'd get a positive answer. When Apple explicitly asked iPhone users if they wanted to be tracked, 96% said no (who are these 4%?). If you're an organisation that cares about privacy or ethics, think about where your advertising budget is going. Do you want to be funding the harvesting of your audience's data and their "identity resolution"? This doesn't necessarily mean you can't promote your work. But you should be choosing options that don't feed the surveillance machine: contextual ads (ads based on where they're shown, not who's viewing them), newsletter sponsorships, direct deals with publishers, videos, podcasts,... You'll most likely reach a better audience too. Colin --- ### Friday links for May 8th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-05-08/ *8 May 2026* - Chrome fills your drive, creeps with smart glasses, shiny AI chatbots, and old-school shop signs. It's Friday, another link day: 1. Chrome silently installs a 4 GB local LLM on your computer Chrome installs a 4GB AI model in the background, because consuming all your RAM wasn't enough I suppose. There are many reasons to avoid Chrome, this is just an extra one. If you like the way Chrome works, install Helium instead, it's the same but without the uninvited guests. 2. Woman covertly filmed for 'humiliating' social media content - then told to pay Extortion via smart glasses is a thing now. A woman in London was covertly filmed by a man wearing them, who then requested payment to remove the video from social media. At this rate, every Black Mirror episode will have become reality by Christmas. 3. All my clients wanted a carousel, now it's an AI chatbot! Very relatable. And before that, every company wanted a blog that they never updated. Request the shiny new thing, lose interest, repeat. 4. Architypes Anthony Nelzin‑Santos takes photographs of old French shop signage from the days before digital printing and laser cut typography. There's warmth to those old imperfections compared to the sterile led-lit signs of today. Talk to you Monday, Colin --- ### Marie Kondo your data Source: https://consultcolin.eu/newsletter/archive/marie-kondo-your-data/ *7 May 2026* - If it doesn't spark joy, it sparks fines. I was recently told a story about a company doing an internal audit and finding nearly 10 years worth of ID card scans on an employee's computer. That's a huge stash of real people's identity documents just sitting on a laptop. There was nothing nefarious going on, the employee just kept saving documents when needed and left them there "just in case". "Just in case" is an expensive sentence when it comes to data protection. The GDPR clearly states that you can only keep personal data for as long as you need it and for the purpose you initially collected it for. After that, it has to be deleted or anonymised. "Just in case" isn't in there. Hoarding data seems to be the default nearly everywhere. Old CVs from job applicants rejected 3 years ago, customer data from closed accounts, bookings from before the pandemic,... It's all still sitting there, in mailboxes, shared drives, CRMs. I see it all the time. This hoarding isn't harmless. Every bit of data you hold on to, you're legally responsible for. If there's a security incident, you're not only going to have to explain why it happened, you're also going to have to explain why you still have that data. About 1 out of 6 GDPR fines are for keeping data longer than needed. For example: France's CNIL fined Discord €800,000 for failing to define and respect a data retention period. There are plenty more of these on GDPRhub if you're curious. The solution isn't complicated: decide how long you need to keep each type of data (and if you even need it in the first place), write that down, then actually follow through and do some cleaning at regular intervals. Colin --- ### The nonsense maze as the only way out Source: https://consultcolin.eu/newsletter/archive/the-nonsense-maze-as-the-only-way-out/ *6 May 2026* - Defence against scrapers can be amusingly petty. I got a question yesterday and I thought others might benefit from the answer. And I'm afraid I'm going to be talking about AI again. The question was "How do I stop AI companies from scraping all the content from my website?" Short answer: you mostly can't. Long answer: let's dig in... The classic way to do this is adding a file called robots.txt to your website. It politely asks bots and spiders not to visit certain pages on your site. It's been around since the very early days of the web and works on the honour system. Google's search engine respects it, Bing does too, most well-behaved bots also. AI crawlers? Not so much. The big ones (ChatGPT, Claude, Google) usually respect it. But there are tons of bots out there that don't care: other AI operators, data brokers, random bots. Some of them scan sites so aggressively that they've been known to knock them offline. They pretend to be humans, rotate IP addresses, identify as standard browsers and basically do everything they can to blend in with normal traffic... Your nice "No Trespassing" sign isn't going to stop someone who's already climbing over the wall. There are some solutions that do mostly work, but they're not easy to implement and quite heavy. Tools like Anubis sit in front of your site and detect bots. When they spot one, instead of just blocking it, they redirect it into an endless maze of auto-generated nonsense. The bot then wastes resources crawling all that junk and hopefully absorbing it into its training data. Cloudflare also offers an AI-bot blocking service that analyses behaviour gathered from watching visits to the millions of sites that already sit behind their infrastructure. It won't catch them all, but will probably filter out the worst. But here's the flip side of this issue: more and more people use AI chatbots as their primary search engine (that's a whole other can of worms - don't get me started). They type their questions into ChatGPT or Perplexity instead of Google. If these systems can't access your content, they won't reference it, summarise it, or point people to it. If you depend on being found online, blocking AI bots might make you invisible to a whole segment of your potential audience. So, you need to figure out what matters the most to you. Protecting your content from being eaten up without consent or staying visible to people who no longer use "traditional" search? There's no true, clean, answer here. Only trade-offs. Colin --- ### Escape the shadow Source: https://consultcolin.eu/newsletter/archive/escape-the-shadow/ *5 May 2026* - The EU AI Act says you'll need a list. Might as well start now. In some recent emails, I talked about chatbots and privacy. I got a couple of very similar questions in return which basically said "How do I even know where AI is being used in our organisation?". The honest answer is: you probably don't. When we think about AI at work, we mostly picture people typing into ChatGPT or Copilot. But that's just the most visible side. I've mentioned before how most tools (if not all) are adding AI features these days; often enabled by default. If you're not careful, some AI feature will suddenly get access to your calendar or cloud storage. I've seen it happen, mostly due to consent fatigue: people just hitting "yes" buttons until they go away. Added to that, you get vendors using external AI in the background: support tools routing questions through AI for triage or CRMs using AI to score leads. Both of those are what's called "Shadow AI": AI that's touching your organisation's data without any official approval, oversight or even awareness. Knowing about this isn't just proper hygiene. The EU's AI Act for high-risk systems comes into application in August this year, and the first thing it requires is an inventory of all your AI use. Even if you don't consider yourself in the high-risk category, it's probably a good idea to make this inventory anyway (and you might need it to prove you're not high risk). How do you do this? It's complicated. Start by inventorying your subscriptions, check release notes, check integrations that have been authorised, look for AI-like names. Then ask your vendors if they use AI, get clear answers from them. And, obviously, talk to your team. Don't scold them, just try and figure out what's being used. Then ask them why, and if it's useful. If it is, it might be worth making official. You might not catch everything, but a rough picture is better than none at all. Colin --- ### Step away from the pricing page Source: https://consultcolin.eu/newsletter/archive/step-away-from-the-pricing-page/ *4 May 2026* - The tool you need costs €0 and involves eye contact. There's this reflex I keep spotting in organisations: when some process isn't working, find a new tool to fix it with. The Todo list is full of unfinished tasks? Get a fancy AI-powered project management tool. Drowning in emails? Get a new messaging platform. Too many meetings? Invest in a new scheduling tool. Every problem isn't a technology problem, though. In many cases it's just a standard messy analogue problem: a communication problem, a process problem, even a "nobody's writing things down" problem. Sorting it out might just need a checklist, an actual conversation, or a Monday-morning stand-up. But that doesn't feel like a solution, does it? There's no fancy logo, no pricing page, no impressive promises... You can't stick it in a slide deck or show everyone a demo... This has a name: techno-solutionism. The idea that every problem can be solved with technology - you just need to find/buy the right one. It's a powerful bias (I fall for it regularly). The tech industry loves it too and spends a lot of money to make sure it gets reinforced every day. I'm not anti-technology (I'd have had a very short career if I was), but choosing the right technology sometimes means choosing no technology. Every tool comes other costs: account management, data protection, maintenance, training. It's not just a monthly payment. So, next time your mouth is watering at some new tool you think will solve all your problems, ask yourself this: what would we do if this tool didn't exist? And, if the answer is something simple that already works, maybe do that instead. Colin --- ### Friday links for May 1st 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-05-01/ *1 May 2026* - The kids are ok, phishing works, test your adblock, and have fun with your cursor. As it's Friday, time for links: 1. The more young people use AI, the more they hate it Perhaps civilisation will keep going for a while yet. Turns out the kids are ok. Archived version, just in case. 2. Nearly half of UK businesses pwned last year These are UK stats, but I'd be surprised if they were different elsewhere: nearly half of businesses have been hacked, not by a hooded genius, but by Joe in HR clicking a "you've won an iPad!" link. 3. AdBlocker Tester A site that tests the ad blocker in your browser or network to see how good (or bad) it is. I hit 78%, so I can still make some progress in my paranoia. 4. Cursor Camp This is really fun. There used to be more gizmos like this on the web. Just hang out with other cursors and enjoy... See you on the other side of the weekend, Colin --- ### GDPR compliant, because we said so. Source: https://consultcolin.eu/newsletter/archive/gdpr-compliant-because-we-said-so/ *30 April 2026* - No official badge. No certification body. Just vibes. You've probably seen these two words on loads of websites, often in the footer: "GDPR compliant". Sometimes even as a cute little circle-of-golden-stars logo. It's reassuring and feels official. But there's actually no certification body for this or no official badge. It's just a self-declaration, and about as valid as a "healthy" stamp on a packet of biscuits. In practice, it can mean anything. From "we spent 2 years working with lawyers and redesigning our whole data processing flow" to "we threw on a cookie banner and got ChatGPT to write a privacy policy" (or simply stole it from a competitor's website). And then we get "European-hosted" which also sounds good and safe. Again, not really. Hosting location and legal jurisdiction are two completely different things. If the company behind the service is American, US law still applies. And US authorities have the power to demand your data regardless of where it's physically located. This is where the difference between European-hosted and European-owned is critical. A European company, incorporated and headquartered in the EU is not subject to the US CLOUD act and their courts. Some vendors get all creative with this and setup a European subsidiary or a local partnership to market themselves as "EU-based". But if the parent company is in the US, the data is still easily within reach of US courts. Microsoft confirmed this despite playing the subsidiary game themselves. Then we get to sub-processors: the companies vendors work with behind the scenes. You can have European email platforms sending emails through Amazon, European analytics services using Microsoft Azure, and so on. I recently spotted a European privacy service that was running on Google cloud. Under GDPR, vendors are required to disclose their sub-processors. Some hide them deep in their legal pages, but they should be on the site. If you see a list of US companies, you know the European branding is just marketing. So, what should you check for? Figure out where the company is based, legally. It can be surprisingly difficult to find sometimes. Then check the sub-processors list and where those are based. Read the privacy policy, it should indicate what data is shared and with whom. And if any of these elements are hard to find or somewhat vague, you know what that "GDPR compliant" badge is worth. Colin --- ### Nice values. Shame about the software. Source: https://consultcolin.eu/newsletter/archive/nice-values-shame-about-the-software/ *29 April 2026* - Time to check what else your vendors are up to. You have ethics. You care about privacy, sustainability, human rights and maybe more. Your organisation might even have a page on its site saying exactly this. Ethics don't stop at what you say or sell, though. They're also linked to where your money goes. Every one of your software subscriptions is a financial relationship. You're not only paying for the tool, you're also funding a company, its business model, it's lobbying, and everything else it uses money for. Take Salesforce. Heaps of organisations use it as their CRM. In January, they signed a $5.6 billion contract with the US Army to "accelerate military modernisation and Department of War readiness" (their words). Interestingly, the contract was awarded via a subsidiary called Computable Insights, so it doesn't sound anything like Salesforce. By the way, Salesforce also owns Slack. So that Slack subscription is also financing military tools. Obviously, I'm not saying every organisation has to audit the entire supply chain of every single tool they use. That way madness lies... But you should be aware. If your website says you care about ethical technology and your CRM provider is building AI tools for the military through some deliberately obscure subsidiary, that's worth taking into account. More ethical alternatives usually exist, you just need to dig a little deeper to find ones that agree with what you stand for. So, next time you're tool shopping, look at what else the company does with its cash. Colin PS: Salesforce is just one example. Spotify invests in AI weapons, Google and other Silicon Valley giants have juicy Pentagon contracts, Substack platforms hate speech, it just goes on... --- ### That chat is going places. Specifically, Virginia. Source: https://consultcolin.eu/newsletter/archive/that-chat-is-going-places-specifically-virginia/ *28 April 2026* - Say bon voyage to your customer data. Yesterday, I mentioned the privacy risks of internal AI chatbot use. Today I'm going to talk about putting one on your website. Many businesses install them today, often without proper thought beforehand. The dev teams gets asked to install one and, the next thing you know, visitors are typing their names, email addresses, order details, and complaints into a text box that beams it all to a third party, often outside Europe. Once again: that's personal data processing under the GDPR. You're the data controller, the chatbot company is the data processor. And you need a lawful basis, transparency, and yet another Data Processing agreement. You also need to handle user access and deletion requests and, thanks to the EU AI Act, you must clearly tell visitors that they're talking to an AI. Here's the tricky part though: loads of these chatbot vendors market themselves as European or EU-hosted, but many of them are still sending your visitors' data to OpenAI, Google or Anthropic. It takes heavy infrastructure to run these large language models and most companies outside of the big Silicon Valley giants don't have the capacity for this. If you want to know where the data actually goes (and you should), ask them for their sub processor list. If you get a vague answer like "we use trusted partners", run away. And then we come back to that same question: do you really need one? Surveys regularly show the vast majority of people prefer talking to real flesh-based humans. When chatbots do work well, it's for basics: FAQs, order status, things like that. As soon as things get even slightly complex, the best systems work by handing the conversation off to a human. And, if a bot's main job is to route visitors to a human, wouldn't a well organised help section and a good contact form do the same thing without all the overhead, risk, and compliance issues? Colin --- ### Close your eyes and hope no one notices Source: https://consultcolin.eu/newsletter/archive/close-your-eyes-and-hope-no-one-notices/ *27 April 2026* - That's not a GDPR strategy. One subject that comes up a lot (and I mean a lot) is using generative AI within organisations in relation to privacy laws: "is it OK for our team to use ChatGPT?", "We limit people to Copilot so we're good?", "If we tell employees not to paste anything private into their chats, we're ok right?", ... Well, as always, it's complicated. Every time someone from your team pastes text into a chatbot, whichever one it is, that's data processing. If that text contains anything that could identify a real person, that's personal data under the GDPR and you need a lawful basis to process it. It may seem like you're just "asking the computer a question" but, legally, you're sending personal data to a third-party. Usually outside Europe. Most people I talk to about this just close their eyes and hope no one notices. It also might feel like it's no different than using a standard cloud service. After all, data processing agreements already exist for this. But AI chatbots are different, if not worse. With normal cloud stuff, data stays where you put it. With generative AI, the data is actively processed by a model and, depending on the subscription, could be used to train future ones. This is definitely true on the free or lower tier subscriptions. There are usually opt-outs on (expensive) enterprise tiers, but "usually" doesn't pair well with "compliance". If you want to be compliant, you need a Data Processing Agreement (DPA) with the service. That means you need to be on an enterprise subscription at minimum. And, to be fair, I'm not even sure that would suffice if someone dug deep enough. There are anonymisation tools out there that sit between you and the chatbot and promise to scrub any personal data before it gets there. These are harm reduction, though, not harm elimination. Some data will get through and that's enough to put you at risk. And you'll need to sign a DPA with that service too! So, it's basically impossible to use chatbots without risk. That begs the question: is it worth it? Will it really help your work or is just another tool you're being pressured to adopt? If you believe you need generative AI, get a proper subscription, a DPA and educate your team about what data is allowed. Then close your eyes and hope no one notices... Colin --- ### Friday links for April 24th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-04-24/ *24 April 2026* - Silicon Valley is out of touch, age verification isn't just for children, big tech writes EU law, framework transparency, and swinging across borders. Here we go, some links for your Friday perusal: 1. Silicon Valley has forgotten what normal people want Tech leaders dream of inventing the sci-fi future while people just want simple, useful things that will make their lives easier. 2. We must keep age verification from killing anonymity online Age verification for children is age verification for everyone. That means every adult will also have to hand over their ID to get online. We need to protect children but we don't want an internet that requires identification for everything. 3. How Big Tech wrote secrecy into EU law to hide data centres' environmental toll This is wild. Microsoft and some lobbyists got the EU to copy-paste rules they wrote into European legislation. The rules in question are intended to hide data centre energy and water consumption. 4. Europe Measures Digital Sovereignty. Why Doesn't It Publish the Results? The European Commission created a framework to measure digital sovereignty in cloud services. But they don't publish details about the scoring, limiting transparency. A good start but methodology transparency is needed to make proper choices. 5. Borders are a construct, but this swing isn't This is fun: there's a swing on the Belgium-Netherlands border that lets you cross back and forth between countries while you play on it. Have a good one, Colin --- ### Boring is a feature Source: https://consultcolin.eu/newsletter/archive/boring-is-a-feature/ *23 April 2026* - In defence of leaving things alone. Something I've noticed a lot: people who really love technology are often the ones making the worst decisions about it. The problem with being passionate about tech is that you'll often want the newest and shiniest versions of everything. But, in a business environment, that's not really a great strategy. Being an early adopter at home isn't the same as being one at work. If your smart lightbulb stops working after an update, you put the old one back in (or live in the dark for a while) and life goes on. If your team's cutting-edge "AI-powered" project management tool starts rescheduling everything after an automated upgrade to the latest version, you've got a bigger problem. I spend a surprising amount of time holding people back from the bleeding edge. If your current software works and does what you need it to, there's no reason to be tempted by the shiny new thing. "Working" is an underrated quality in business software. When a new technology shows up, the hype machine gets jumpstarted and, suddenly, everyone feels like they'll fall behind if they don't rush to adopt it. That's the pressure of marketing, not of need. Generative AI is the current example. I'm not saying you should completely ignore it. I'd actually encourage you to keep an eye on it, maybe experiment with it, figure out what it can and can't actually do... Take your time. There's one hell of a gap between staying informed and restructuring your whole workflow around something that's only a few years old, haemorrhaging money all over the place, and changing all the time. The companies building these technologies haven't even figured out their own business models, you shouldn't be trying to figure yours out before they have. For the most part, boring is better. It keeps running until there's a genuine reason to change. FOMO isn't one. Colin --- ### An expensive address book Source: https://consultcolin.eu/newsletter/archive/expensive-address-book/ *22 April 2026* - Check-in was free. Check-out will cost you. One conversation that seems to come up more often than any other when talking to clients is them wanting to get away from HubSpot (or some other CRM, but HubSpot gets most mentions). Rarely because of it being bad, mostly because it's just so damn expensive. On top of that, they're usually only using a small percentage of its functionalities. The story is pretty much always this: they signed up for the free tier, then they added some contacts, maybe built a small pipeline. But then they needed a feature that was only available on a paid plan, then another... A few years later, they're paying €50+ per seat per month for a marketing automation service that they're really using as a contact list with notes. This isn't a HubSpot-specific problem. Salesforce, Pipedrive, and a plethora of other big CRMs follow the same playbook: pull you in for free (or cheap), let you accumulate a ton of data, then charge for features. By the time you're hit with the painful prices, leaving feels like a sisyphean task. A migration no one wants to touch. So you "stay and pay". Let's be honest, though. Most small organisations don't need a CRM. They need a structured way to keep track of who talked to who, what was said, and what should happen next. No lead scoring, no AI-powered forecasts, no behavioural email sequences... There's also the sovereign aspect: you're storing sensitive data (names, emails, phone numbers, conversations, pricing...) on US servers, subject to US jurisdiction. I'm betting many of your contacts don't realise you're doing that. There are plenty of small, European alternatives that cover what most teams really need. And, for many, even a well-maintained spreadsheet would do the trick. And if leaving feels impossible today, imagine what it'll feel like next year. It might not be an easy move, but I'd start planning it now, not next year. Colin --- ### The convenience trap Source: https://consultcolin.eu/newsletter/archive/the-convenience-trap/ *21 April 2026* - One password to lose it all. It's obviously convenient to have everything in one place: one login, one interface, one payment. With Google, you get email, docs, storage, a calendar, video calls, etc. Microsoft is the same. Even privacy-forward services like Proton have a bundled offer: email, storage, VPN, password manager, all behind one login. It feels easy and simple. But it also means that if someone gets into your account, they get into absolutely everything. There's a security saying: attackers only need to succeed once, but defenders need to succeed every single time. When your whole online life is sitting behind a single account, you've made the successful attacker's life a lot easier. All it takes is one moment of weakness: a phishing link clicked by mistake or a re-used password. And suddenly your emails, your files, you calendar, maybe even your passwords, your whole online life are in someone else's hands. That's called a single point of failure. It doesn't necessarily have to be an attack either. Google has locked plenty of people out of their accounts without explanation. And, when that happens, you lose it all. There are forums full of people who suddenly discovered their digital life was locked away because some big tech company (or, more likely, one of their automated systems) decided their account was problematic. And good luck reaching a human to get it fixed, even with a business account. Spreading your services across multiple providers is definitely not as convenient. But, when everything goes south, it doesn't cascade into total disaster. Diversifying your accounts also makes it harder for a single provider to build a detailed profile of your activity. When your emails, your documents and your searches all sit in the same place, they know more about you than most of your friends do. They say "don't put all your eggs in the same basket". That works online too. Colin --- ### Have you tried turning off the hype? Source: https://consultcolin.eu/newsletter/archive/have-you-tried-turning-off-hype/ *20 April 2026* - Same capabilities, better PR. I had yet more conversations this weekend about generative AI, specifically about Anthropics's new Mythos model. Some people were worried for their website security after reading the news. If you missed the noise, Anthropic (the people behind Claude) announced a model so good at finding security flaws that they decided they couldn't release it to the public. People panicked, journalists wrote horror stories, cybersecurity stocks dropped. But the story got a lot less scary when people outside Anthropic's marketing department examined it. Independent security researchers took the specific vulnerabilities that Anthropic were hyping up, and ran them through smaller, much cheaper AI models. Turns out they all found exactly the same vulnerabilities. There was some progress in performance for this new model, but nothing unusual. Previous model releases showed similar improvement jumps. The only unusual thing here was the marketing. These companies have been telling us (and investors) for years now that they're months away from Artificial General Intelligence or that their models are going to replace half the jobs. But, when you get down to it, the best press they could have gotten for their revolutionary new model was "it finds bugs a bit better". So they chose fear instead. If your product isn't revolutionary, make it a threat, and journalists will do the rest. I'd love to stop writing about generative AI. But, as long as the hype machine keeps turning, I guess I'll be showing up to spoil the party. Colin --- ### Friday links for April 17th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-04-17/ *17 April 2026* - AI makes you a worse person and a curt one, Google sovereignty-washed Brussels, AI eats your old emails. Another Friday, another batch of links: 1. Study finds asking AI for advice could be making you a worse person AI chatbots often agree with users, even when their actions are harmful. This makes people less likely to take responsibility or apologise for their mistakes. This is going to end well... 2. AI learns language from skewed sources. That could change how we humans speak - and think Adding to the previous link: children in households that use voice commands with tools like Siri and Alexa became curt when speaking with humans, often calling out "Hey, do X" and expecting obedience. 3. Accenture and Google Cloud unveil Brussels centre to accelerate sovereign AI adoption This is a prime example of "sovereignty washing". Reminder: if a US corporation owns it, it's subject to the CLOUD act. No amount of marketing will stop the US government from getting to that data. But marketing will clearly make people sign up for this pseudo-sovereign claptrap. 4. AI's New Training Data: Your Old Work Slacks And Emails Lots of AI stuff this week. Looks like they're also buying old emails and chats from companies that shut down, and using them as training data. Nothing's off the table with these people. Until the next one, Colin --- ### Europe’s got your back(up) Source: https://consultcolin.eu/newsletter/archive/europes-got-your-back-up/ *16 April 2026* - Sovereign solutions for proper backups. My email about backups yesterday triggered a couple of replies asking for European backup service suggestions. It's a little complicated to offer solutions without going into detailed comparisons. Everyone has different needs. But, I'll list a few options I know to work quite well for most. There are two parts to any backup system: the client (the backup software running on your computer) and the server (the place where the data is stored). They can be from the same service or different. If you have enough technical knowledge, you'll generally be better off using a separate client and storage service. The issue with most all-in-one services is they're either sync services or network folders (at least when using their clients). Let's start with the all-in-one solutions: Jottacloud are based in Norway and, in my opinion anyway, one of the easier to use solutions. The data stays in Norway and it's encrypted. They can even backup your NAS (Network Attached Storage) as part of a dual system. They also do sync, so you need to be careful about how you use it. There are plenty of other services, but most of them aren't really ideal for incremental backups unless you're willing to tinker or, in some cases, use a separate client. A few to look into: Infomaniak kDrive, Proton Drive, Filen, pCloud. If you can use separate clients and servers, my suggestions for clients are: Arq for Mac or Windows. It's the one I use and I'm very happy with it. It works with all kinds of services including S3 (created by Amazon but now used by many others) and you can choose where, when and how files are backed up. Kopia. An open-source solution available for most platforms and as both a graphical client or a terminal-based one if you're a power user. Like Arq, it works with a plethora of storage services. Restic. One for the power-users but also a very good solution. Server-wise, there's a lot of choice. It's going to depend a lot on your needs, but here are a few: Hetzner Storage. In Germany or Finland. Good value for money. Works with many protocols. Scaleway Object Storage or Glacier (for long-term storage) in France. It's compatible with S3 and can be a good option too. Many other services are S3-compatible, including a few mentioned above like Filen or Infomaniak (you need a pro account at Infomaniak for S3, though). This is far from complete, I don't want to write an essay, but it should get you started on your backup quest. Email-me if you have questions. Colin --- ### Your backups work. Probably… maybe… hopefully… Source: https://consultcolin.eu/newsletter/archive/your-backups-work-probably-maybe-hopefully/ *15 April 2026* - A quick guide to backups that actually work. If you ask people or organisations if they make regular backups of their data, the vast majority will say yes. If you ask them when they last tried to restore them, you'll mostly get silence. I'm one of these people. For a long time, I diligently made backups but never tested them. Then, luckily, one day I decided to restore one as a test ... and it failed. That's the thing: backups break and most of us find out only when we need them. One of my clients recently discovered the NAS (Network Attached Storage) in their office had been backing up an empty folder for months. Luckily for them, they had a secondary backup in the cloud. You may have heard of the "3-2-1" rule: 3 copies of your data, 2 different types of storage, 1 copy off-site. There's often one of these missing, usually the off-site one. That could be cloud storage, but it could also be a hard drive in a different office. It's the best protection against fires or even ransomware attacks. But make sure you test them all. So, at regular intervals, pick a random file and try to restore it. If you can't, you don't really have a backup solution. A few notes: If you're choosing a cloud backup solution, don't forget to take digital sovereignty into account and choose a European solution. A sync service like Google Drive or DropBox is not a backup. If you delete a file or, worse, if ransomware encrypts it, those changes will be propagated everywhere. Whatever solution you choose, just make sure you test it. Colin --- ### The post-it on your monitor isn't a security strategy Source: https://consultcolin.eu/newsletter/archive/post-it-on-monitor-not-a-security-strategy/ *14 April 2026* - The feature that makes offboarding boring again. When I look at how small (and not-so-small) organisations handle passwords, the solution is usually one of these: a shared excel file, a Notion page, Post-its on a monitor (really), an identical password everywhere, or my favourite: "ask Maria, she knows them all". The obvious fix for this is a password manager. Most people have heard (and ignored) that advice a million times. But there's a feature in most of them that rarely gets a mention, and it's the one that can really make a difference for teams: shared vaults. It's pretty straightforward. Instead of every team member storing company passwords in their own personal password manager vault (or their head, or that excel sheet...), you create a shared vault for the team or even for a specific project. Then everyone with proper access can use the passwords stored inside it. The interesting part is the permission levels. You can give someone "read-only" access to the vault, which lets them log in to services without ever seeing or being able to change the passwords. They click, they log in, they do their work. All this without ever knowing the passwords. And when someone leaves the organisation, whether on good or bad terms, you don't have to go round changing every password they might have used. You simply revoke their access to the shared vault and you're done. No more "did anyone change the Canva password?" two weeks later. Most well-known password managers offer something like this (Bitwarden, 1Password, ...). Just pick the one that works for you and your budget. It won't fix everything, but it'll fix the scenario where someone walks out the front door with a laptop and a grudge. Colin --- ### Cookie banners - The sequel Source: https://consultcolin.eu/newsletter/archive/cookie-banners-the-sequel/ *13 April 2026* - But this time there's a plot twist … in Brussels I recently wrote about the EU's Digital Omnibus and some of the ways it could weaken the GDPR. But there is one good thing lurking in there. It's called "Article 88b" (creative naming, I know) and the idea behind it is quite simple: instead of dealing with the usual cookie banners, you set your tracking preferences once inside your browser, then every website has to respect them. No more cookie wall hellscape. This isn't actually new, there have been attempts before. In 2009, when consent requirements for tracking were first added to the law, it said consent could be given via browser settings. The ad industry completely ignored this and went ahead building the banner dystopia we know today. Then they blamed Brussels for it. Again in 2017, the commission put forward a proposal to make browser-level consent obligatory. A lobbying campaign by Google got it killed. Now, like any good Hollywood franchise, it's back. And it's inside the omnibus. The villains are back for the sequel too. The same companies that brought us cookie banners (Google, Meta and the AdTech industry) are warning that letting people choose privacy will somehow be bad for them. The rest of the digital omnibus still needs pushback, but Article 88b really deserves our support. It's one of the rare proposals that would make our browsing lives so much simpler and better. But it would cost the surveillance/ad industry, which explains why they're fighting it so hard. Colin --- ### Friday links for April 10th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-04-10/ *10 April 2026* - Google misinforms, European for how long?, ad tracking for the state, and France goes Linux. Friday, link day: 1. Google's AI Overviews Are Providing Misinformation at a Scale Possibly Unprecedented in the History of Human Civilization Google's AI Overviews in search results are providing tens of millions of wrong answers every hour. That seems ... fine. 2. When it comes to tech's software dependency, what does 'Buy European' even mean? Something that needs to be taken into account when choosing European software: will it stay European? It's often one buy-out offer away from turning American. A good reason to regularly audit your stack. Side note: the content is interesting, but this article has a very strong "written with AI" smell to it. 3. Uncovering Webloc Webloc is an ad-based mass surveillance system that monitors the movements and personal characteristics of hundreds of millions people globally based on data obtained from mobile apps and digital advertising. Ads on sites you visit every day are used to build profiles on you that are then sold to organisations like ICE and countries like Hungary. 4. France Launches Government Linux Desktop Plan as Windows Exit Begins Definitely a path more governments should be going down. It could take a while but you might as well get started early. "Status quo bias" is holding back so many organisations, so kudos to the French on this one. Until next time... Colin --- ### Encrypted email won't save you from yourself Source: https://consultcolin.eu/newsletter/archive/encrypted-email-wont-save-you-from-yourself/ *9 April 2026* - A quick guide to risk profiles, encryption, and when to bother. One subject that comes up pretty much at every discussion I have about digital independence is email. There's a lot to say about email, but I'd like to drill down on the privacy aspect today because I regularly get questions about privacy-focused services like Proton mail or Tuta. When most people see "private" or "end-to-end encryption" (E2EE) they assume their email will reach their recipient with no one reading it in transit. Which is pretty much already the case. Most providers already use "Transport Layer Security" (TLS) which encrypts the connection between different mail servers. E2EE is an extra layer of security on top of this and requires both sender and recipient to have the proper setup. This is rare. TLS protects your emails while they're moving, but many servers store the email in a readable form once it's arrived. At this stage, it could be read by people with bad intentions if they got access to the server. But most security issues with email don't happen because of bad actors stealing content straight off the server, they happen because of weak passwords or people clicking malicious links in emails. No encryption will save you from that. So the question is: what's your risk profile? For most organisations, their email contains customer conversations, sales pitches and whatnot. This is low-risk and fine. If you're constantly dealing with sensitive data: medical, legal, defence ... you may want to choose a service that does encrypt your emails "at rest" (when stored on the server). But there are downsides to these services: you often need to use a custom client, the security can be annoying, and they can rarely talk to other systems like CRMs or scheduling software. So, if you're worried about privacy, what should you do? First, make sure everyone on your team has good cyber hygiene: strong passwords, awareness of phishing and social engineering, not clicking on any old link, etc. Then select a European provider that has a good privacy policy (yes, you should read it) and the functionality you require. And if Proton or Tuta are the ones that fit your needs, go ahead. Colin --- ### The ingredients they don't want to list Source: https://consultcolin.eu/newsletter/archive/the-ingredients-they-dont-want-to-list/ *8 April 2026* - Amazon didn't invent Linux. Google didn't invent Python. So, why are we acting like Europe has nothing to offer? I have a question for you: what do Linux, Python, MySQL, Nginx, and Kubernetes have in common? They're all technologies running inside Amazon Web Services, Microsoft Azure, and Google Cloud. They're all open source and free; and none of them were invented by these companies currently making billions from them. That's a side of the "US tech dominance" story that doesn't get much airtime. These "hyperscalers" didn't create a good part of the software powering their platforms; they packaged it, scaled it, and spent a fortune marketing it. But the foundations, those were built by open-source developers, many of them European. Linux is from Finland, Python from the Netherlands, and MySQL from Sweden. The reason I bring this up is that the whole European digital sovereignty debate keeps sticking on this false premise: that we would have to somehow start from zero, that the Americans have secret know-how that we don't, that building European alternatives would take decades... That's patently untrue. The foundations are already open and, in many cases, they were made here. The new EU Cyber Resilience Act requires vendors to provide a software "bill of materials" for their products (a fancy way to say "ingredient list"). This has produced quite a reaction from big tech: Lobbying, pushback, "grave concerns", etc. You might wonder why, what's essentially an ingredients list, would cause so much negativity. Maybe it's because many of those ingredients are things they didn't build themselves? So, this whole "no alternatives" argument should really be setting off our scepticism alarms. When someone says a European equivalent to some US big tech offering is impossible we should be asking "is that true or did no-one even look?". Because, the core tech is certainly available and open, possibly already running here or, in many cases, could be with a little effort. Granted, some very specific setups will be harder and even impossible. But, for most usage, local can be done and probably even exists already. The next time you're picking a tool, take a closer look at the European offerings, you'll often find they come from the same place the American ones do. Colin --- ### The EU's Digital Omnibus: next stop, your privacy Source: https://consultcolin.eu/newsletter/archive/the-eu-digital-omnibus-next-stop-your-privacy/ *7 April 2026* - All aboard the deregulation express! The biggest winners won't be European. The European Commission is currently working on a directive called the "digital omnibus". Nothing to do with public transport, these "omnibuses" are just a way of bundling a bunch of changes to multiple laws in one go (and can also be a sneaky way of avoiding too many checks). The official goal of this directive is to simplify digital regulations and make European businesses more competitive. Sounds reasonable, right? But, when you take a closer look, "simplify" starts to look like "dismantle". Let's take the GDPR. Today, you can write to any company and ask them what data they have on you and who they've shared it with. They have one month to respond. Under these new proposed rules, that company could simply respond "no, your request is excessive". Basically being the judge in their own case. Or let's take the definition of personal data. Today, it's objective: it's anything that can be linked to a real person. Under this new directive, it would become subjective: as long as a company holds your data under a pseudonym (like a string of numbers instead of your name) and claims it can't ID you from it, they can claim it's not personal and the GDPR doesn't apply. Anyone who knows anything about data knows that pseudonymisation is relatively easy to work around. Then there's good old AI. New exceptions in the law would allow companies to use sensitive personal data (health, political opinion, religion, union membership, ...) to train their AI models - with much lighter obligations. The Commission says this will help European companies compete in the market. But if you loosen rules in a market that's over-dominated by American big tech, who do you think will benefit the most? It probably won't be that local European startup. The GDPR has plenty of faults, the biggest one being they don't enforce it. But the answer to poor enforcement isn't relaxing the rules, it's doing the actual enforcement! Negotiations are ongoing, but this is worth keeping an eye on. If you depend on tools from US big tech, relaxation of the rules might end with more personal data flowing from your organisation across the Atlantic. Or... you could be proactive and move to European privacy-focused tools now. Just in case the NGOs, civil society groups, and privacy advocates currently fighting the rule don't succeed. Colin --- ### Friday links for April 3rd 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-04-03/ *3 April 2026* - LinkedIn strip search, culturally blind AI, big tech stenography, and little web tools. It's Friday. Links incoming: 1. LinkedIn Is Illegally Searching Your Computer The title is somewhat hyperbolic, but it seems LinkedIn is fingerprinting browsers and scanning for installed extensions that could help them profile you. Spoiler: only in Chrome or Chromium-based browsers, so choose an alternative if you go there. 2. AI Headshot Apps Removed Her Hijab Another demonstration of how AI tools are not neutral. You may have seen these headshot tools that generate "professional" versions of portrait photos using AI. All of them remove Hijabs. Proof that the weight of the training data has massive influence on the output. 3. "CEO Said A Thing!" Journalism This is something that has been bugging me for ages now: journalists uncritically repeating what business leaders say; with no context, scrutiny, or pushback. Basically acting as stenographers for Silicon Valley. 4. Kin - Everyday tools.No strings. A curated collection of simple little web tools. From a ukulele tuner to a first-aid guide, via an invoice generator. All free and private. See you on Monday, Colin --- ### I made a thing that judges Source: https://consultcolin.eu/newsletter/archive/i-made-a-thing-that-judges/ *2 April 2026* - Pop your domain in. See what comes out. Don't shoot the messenger. Today's email is slightly different. I've been working on a little web application that lets you scan a domain name to see how "European" it is. It analyses a bunch of different elements linked to that domain, like email, web hosting, domain registration, etc, then gives you a sovereignty score based on how dependent you are (or not) on non-European services and technologies. It's still in beta right now, but I'd appreciate some extra eyes on it while I refine it. If you'd like to test, head to: ccscan.eu and give it a try. All feedback is appreciated. Particularly if you see it doing something it shouldn't or if it doesn't properly recognise a service. Thanks! Colin --- ### A bug is a bug (unless it's open-source) Source: https://consultcolin.eu/newsletter/archive/a-bug-is-a-bug-unless-its-open-source/ *1 April 2026* - Google goes down: bad luck. NextCloud goes down: bad decision. I try to recommend open-source solutions to my clients when I can. There are many advantages to this, I'll probably get in to them in some future emails. But I wanted to point out something I've seen in many places when it comes to open-source being brought in to replace a big tech solution. If, say, Google Drive goes down, everyone gets annoyed but no-one really questions the tool. They just wait it out. However, if a small issue takes an open-source alternative like NextCloud down, the complaints start immediately: "we should have stuck with Google". Similar problem - not-so-similar reaction. Recommending defaults is always the safe path (which is why they're defaults). Recommending alternatives brings risks along for the ride: There's familiarity: people spend years learning the quirks of their tools, often without even noticing. When a new tool shows up, they get impatient with every little crack that appears. If Google breaks, it's Google's problem. When the alternative breaks, everyone knows who decided to install it. Free is still associated with rough edges and incomplete features. When things go wrong, it's proof. When the same thing happens to a large vendor, it's just a bad day. This encourages decisions based on comfort rather than utility or quality. Understandably so, the old saying "nobody ever got fired for choosing IBM" still applies, just with new logos. But a bug is a bug, whatever logo is at the top of the screen. Next time you're evaluating a tool, ask yourself: would I hold the one we're already using to the same standard? Colin --- ### Do you have consent, or just compliance? Source: https://consultcolin.eu/newsletter/archive/do-you-have-consent-or-just-compliance/ *31 March 2026* - Recording everything doesn't make you productive, it makes you a data controller. If you've been in a video call recently, you've probably seen one of these bots that sits in on the conversation and records/transcribes everything that's being said. A question that's come up before is "If everyone can see this bot in the channel, do I really need permission to use it?" Let's start with European law: in nearly every case, you need explicit, informed consent to record a conversation. That means everyone has to give their OK first. The issue is that a "yes" risks being shaped by power dynamics. A junior member of staff or a supplier in need of a deal might feel like they can't say "no" without risking their job or contract. The GDPR talks about "freely given consent". But when a clear power imbalance exists, silence will rarely be considered "freely given consent". So, if you're the one pressing the "start recording" button, you're also the one responsible for making sure you're getting actual freely-given consent. Make sure that someone can really object without penalty, and let them know. Agree to not record if anyone refuses. And, finally, do you really need to record/transcribe this meeting? If it's just going to be another addition to the dark data drawer, skip it and avoid the pressure. In the end, the real question isn't "can I record this?", the real question is "who in this call is least able to say no if I do?". Colin --- ### 404: Impact Not Found Source: https://consultcolin.eu/newsletter/archive/404-impact-not-found/ *30 March 2026* - Those online carbon calculators are doing some heavy rounding. One question that comes up regularly in discussions I have is the environmental impact of a website or web app, and what can be done about it. There are online calculators that will, in theory, give you a website's carbon footprint, but I'm not convinced. These calculators mostly follow the same process: Get the website's page weight. Convert this weight to energy use. Convert that to CO2 (equivalent) emissions. This is a crude proxy at best. Page weight isn't a great predictor of energy use; a 1MB JavaScript file that needs to be parsed and run by the user's device could use more power than a 1MB image that just needs displaying. Most of the energy consumption for our online habits comes from the making and the powering of our devices, the rest from data centres and networks. For example: around 90% of the greenhouse gas emissions from your phone are embodied. That means the manufacture, not the electricity consumed in day-to-day use. Does that mean we should ignore efforts to make greener websites? No, of course not. These calculators and web sustainability projects are great frameworks for thinking about improving the web's footprint. But they're not some magic solution where getting your website an A+ rating will have a measurable impact. On the other hand, choosing web hosting powered by green energy is a better first step. As is making websites that don't go wild with server-side computation (hello AI!). Keeping pages light will let people with older devices use your site for a long time to come and, as a bonus, will be faster to load. Or, to take it to the extreme: does that online service even need to exist? Colin --- ### Friday links for March 27th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-03-27/ *27 March 2026* - Data as a liability, Metaverse musings, LinkedIn lingo, Web nostalgia, and supporting artists. Another batch of fresh Friday links. 1. Iran built a vast camera network to control dissent. Israel turned it into a targeting tool A clear demonstration of the core issue with data collection. It's an asset until it becomes a vulnerability. Every database you build is a future liability in the wrong hands. 2. My Prodigal Brainchild Neal Stephenson, who coined the term "Metaverse" in his 1992 novel Snow Crash, reflects on the death of its unsanctioned Facebook-created counterpart. His take on VR headsets pretty much matches my view, they're a dead-end technology. 3. LinkedIn Speak Translator Exactly what you need for your next meeting or social media post. A translation tool that translates from standard language to that mysterious lingo all the LinkedIn influencers speak. 4. Web Rewind A nostalgic journey through the history of the internet made by the people behind the Opera browser. Remember Flash? It's got a very similar vibe to the old flash sites and games. You need to explore to figure out how it works. 5. Unstream A Mac app that detects what you're listening to on Apple Music, Spotify, or other services, and shows you better ways to support these artists (streaming definitely doesn't do that). Like buying directly on Bandcamp or supporting them via Patreon. Have a quality weekend! Colin --- ### Can you trash it? Source: https://consultcolin.eu/newsletter/archive/can-you-trash-it/ *26 March 2026* - Save the planet. Delete a spreadsheet. A lot of tech questions are about where data is stored, how data is stored, or who stores it. But have you ever thought about if that data should be stored? The tech sector is estimated to contribute around 2 to 4% of global CO2 emissions and rising. That's close to aviation. With current demand and, particularly with AI, consumption is projected to double this year. That cloud may seem virtual, but it's made up of gigantic data centres, racks and racks of servers, cooling equipment and more. Most of that turns into e-waste at some point and only about 22% of that is collected and/or recycled. Every file or photo you store online will consume electricity forever, or until it's deleted, if it ever gets deleted. This is what's called "dark data", information that's stored but never used or accessed ever again. Estimates put the percentage of dark data in organisations at 40-90% of all stored data! Next time you're about to hit the save button, ask yourself: can I trash it instead? A regular data cleanup, sensible retention policies, and a culture of saving less by default could make a bigger difference than you think. Colin --- ### Gone but not logged out Source: https://consultcolin.eu/newsletter/archive/gone-but-not-logged-out/ *25 March 2026* - That ex-employee's personal email might still be running your business. If the person who set up your email server, your domain name, your AWS account or your website hosting left your organisation tomorrow, would you still have full control of these services? If you're not sure, you're not alone. And it might cause some issues down the line. A client recently found out they couldn't update their domain records. The domain had been registered years ago, when they launched, by an employee using their personal email. That employee had since moved on. There were no evil intentions or disputes involved, it's just one of these things that happens all the time. But now the client's whole email and web infrastructure was basically locked behind someone else's personal login. And that login wasn't one they controlled. I've seen this so many times... Subcontractors registering software in their own name because it's easier at the time, former staff members who used their personal email for the cloud admin login, social media accounts that someone must have the credentials to, but who? Try this test. For each of the following, do you know who the registered owner is, and is it a shared inbox or some random staff member's account? your domain name(s) your web hosting your email platform your social media accounts your email marketing platform your cloud storage your CRM, project management, accounting, ... If any of these are using a person's account rather than a shared business inbox, you need to fix that before that person leaves, not after. Setup a shared inbox or a specific account like accounts@ and transfer all your logins to it. It's worth the hour or so it will take you. (and, yes, the client got their domain back by contacting that ex-employee on LinkedIn) Colin --- ### Always stray off the happy path Source: https://consultcolin.eu/newsletter/archive/always-stray-off-happy-path/ *24 March 2026* - If the demo looks flawless, you're not asking the right questions. Last Friday, I attended an online software demo on behalf of a client. As I watched the salesperson click and scroll through various scenarios, I noticed they were following a strict, predefined path each time. Nothing unusual - demos are always designed to showcase the best side of a product. During question time, I asked them to run through a few tasks that weren't part of the script. That's when the polish wore off: interface slowdowns, inconsistent user interface feedback, and at one point, it even crashed. Demos will naturally follow what's known as the "happy path", a default scenario that's guaranteed to work every time, with no errors or surprises. It's how nearly every product is presented. Again, nothing unusual here. But, the real picture emerges when you step off this happy path. So, next time you're sitting through a demo, make sure to get them to test the outliers. Not to trap or embarrass anyone, but to see how the product handles the messy day-to-day use it will be put through when your team get their hands on it. Colin --- ### What if the .com police come knocking? Source: https://consultcolin.eu/newsletter/archive/what-if-dotcom-police-comes-knocking/ *23 March 2026* - A simple step to protect your domain from geopolitical surprises. Have you ever thought about who has final control over your domain name? There are several layers to this control hierarchy, the main ones being: What the top level domain is: .com, .nl, .eu, .info, ... Where you purchased and registered the domain name. This is the registrar, like gandi.net in France or namecheap.com in the U.S. If any of these are managed from an unpredictable jurisdiction, you could be at risk of losing ownership or control. Let's look at the top level domain (TLD), which is the one most people skip when analysing risk. ICANN is an American non-profit that coordinates all "generic" TLDs (like .com, .net, .org) which it contracts with registry operators. In the case of .com, it's a U.S. corporation called Verisign. Because both ICANN and Verisign are subject to U.S. jurisdiction, a legal order could request the seizure, locking, or modification of your domain records. This has already happened. Most seizures up until now have been linked to criminal activity. But, with the current unpredictability of the Trump administration, who's to say they won't decide that European sites are anti-American propaganda or that .coms are for Americans only? The chance is low, but you should have a backup plan in place. My recommendation is to grab a local (.be, .fr, .es, ...) or European (.eu) domain, ideally the same as your .com. Then point it at your current setup. If things go bad, you can announce the change and avoid expensive interruptions. Even better, switch to that new domain and redirect the old .com to it. Wear your local roots on your sleeve! Colin --- ### Friday links for March 20th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-03-20/ *20 March 2026* - Empire of AI, MAGA wants EU mails, the Metaverse goes poof, fear of the kill switch, and some obscure music. It's Friday, let's do the link thing... 1. Naomi Klein & Karen Hao: The Empire of AI and the Fight for Our Future (video) This is a great in-depth follow-up to what I wrote about generative AI this week. Naomi Klein talking with Karen Hao about her book Empire of AI (which I highly, highly, recommend). It's not all doom and gloom though. They talk of smaller, fairer AI and other community projects. The video lasts over an hour but, trust me, it's worth your time. 2. US Congress demands messages from European officials via Microsoft and Google The US congress is pressing US tech companies to hand over messages from EU officials. The Belgian privacy and tech community has been warning about this for a long time: sending work emails via Microsoft 365 or Google Workspace is basically serving European data on a platter to a foreign administration. 3. Meta is killing off the metaverse. It lost $80 billion Remember when the Metaverse was the next big thing? Someone paid $450,000 to be Snoop Dogg's neighbour in that digital ghost town. Fun times. 4. Europeans think Trump can shut down their internet 86% of people think a sudden U.S. move to restrict Europe's access to digital services is "plausible" and "should not be ruled out". 59% called it "already a real and concrete risk". Time to bring those bytes back across the Atlantic before they need a visa. 5. Vintage Obscura If you like your music rare, this is fun: a streaming radio station that only plays tracks from before 2000 that have less than 30.000 views on YouTube. Have a good one, Colin --- ### Renting your reasoning Source: https://consultcolin.eu/newsletter/archive/renting-your-reasoning/ *19 March 2026* - Pull out the AI and what's left standing? Ethics aside (to the extent one can do that), should you use generative AI in your work? At their core, generative AI models are text synthesis engines. They don't think or reason, despite what the marketing says. They simply fabricate plausible-sounding text. If you imagine prefixing your queries with "What would a plausible answer to this question sound like?:" you'll get a clearer picture of their underlying mechanism. The factual accuracy of any response is basically a side effect of how prominently those facts appear in the training data. So, the only truly safe uses are text manipulation tasks like style changes ("make this announcement more formal"...), standardising date formats, semantic search and replace ("replace sections where I sound hesitant with something assertive"), things like that. There are plenty of unsafe or less-safe uses. Those are going to depend on your risk tolerance. Some potential risks to consider include: Generative AI is non-deterministic, i.e., unpredictable. Even if you give it the same starting conditions, you might get a different result each time. Any process depending on predictable outcomes is at risk. Insurers are looking to add specific exclusions to business policies so they are not obligated to cover AI-related workflows - enough said. Generative AI doesn't summarise, it shortens. Not a huge issue for an email, pretty bad for a scientific paper. In most cases, content produced with AI can't be copyrighted (US law, soon to be EU law also). It's a financial house of cards. Every $20 subscription costs them $200; every $200 one costs them $5000. And the rest of the finances are even worse. Consider the risk of basing any workflow on services that could collapse at any time. There are 3 or 4 major generative AI providers; most of the other AI services or "AI included" services are essentially wrappers built on top of them. And nearly all of them are losing money. It makes you dumber. Which isn't a huge surprise. Technology built to help you think less will make you ... think less. So, what's the takeaway? Vet the tools thoroughly based on your risk profile, and make sure nothing will break (including your brain) if they suddenly disappear. Colin --- ### The consent problem Source: https://consultcolin.eu/newsletter/archive/the-consent-problem/ *18 March 2026* - All the world's creative output, none of the world's permission. Generative AI is unethical. There's no way around that. I don't expect this to radically change anyone's mind about using it. We live inside unethical systems our whole lives, and we've all got blind spots - life is complicated. But we should at least be aware of the impact. Building generative AI models starts with ingesting absolutely any data that can be found: the whole web, all the books (including pirated copies), television, podcasts, you name it... It all gets scraped, regardless of whether the authors or creators have consented or not. The AI companies say this is just like a search engine spidering the web, but it's not. Search engines point people back to the original content, giving the authors traffic and readers. Large language models summarise or, worse, plagiarise the content, rarely crediting the original source or pointing to it. This can only result in many publications eventually shutting down as the AI ouroboros slowly kills the web. Then you've got all the exploitative, neo-colonial, sometimes trauma-inducing labour. Behind the clean, futuristic-looking magic of AI, there are scores of humans in a network of low-wage digital sweatshops, mostly in the Global South, sorting through and labelling all the data to ensure models seem smart and safe. The environmental aspect is probably the worst. The AI companies are far from transparent about their energy and water use (never a good sign). But conservative estimates put the consumption of AI at five times the energy of standard computing. Training a new model takes data centres running for months on overdrive, literally burning through chips as they work. I don't want this to be too long, so I'll end here. But I haven't even mentioned the psychological harm, the use in military kill-chains (despite their posturing, Anthropic are still very much involved too), collaboration with the current US administration, the so-called open source models, etc. There's a lot more to say here, but that's for another time. Colin --- ### Bicycles, Buses, and AI Source: https://consultcolin.eu/newsletter/archive/bicycles-buses-and-ai/ *17 March 2026* - Before we talk about AI, a quick word about buses. No technology decision happens these days without someone raising the AI question (usually loudly and confidently). So let's raise it properly. And the first step is defining what AI actually is. Today, when someone talks about AI, they're usually talking about a relatively recent development: Large Language Models, also known as Generative AI. This is your ChatGPT, Claude, Copilot, Mistral, etc. But AI has been around in one form or another for decades. The term itself was created as part of a marketing move to get financing for research in the 1950s during a funding freeze. Since then we've gone through several technological cycles, from neural networks to machine learning. At each step, the "Artificial Intelligence" branding gets applied, as it sets grandiose expectations of computers as simulated brains and brings science-fiction scenarios to mind. And, each time, it overpromises and underdelivers. Even today, AI is applied to multitudes of technologies. The tool that lets you erase the background in Photoshop, the spam filter, the sales prediction algorithm, the self-driving car, the chatbot... They all get branded as AI, but only the chatbot is a Large Language Model. In the book "AI Snake Oil"1, the authors describe a scenario where all forms of transport, whether bicycles or buses, are simply called "vehicles". Replace the word "vehicles" with "artificial intelligence", and you get a pretty good description of the world we live in now. The frenzy today is over LLMs/Generative AI. Everything else on that list has been around for years. Some were already called AI; others have been rebranded to profit from the current wave. Now that we've cleared that up, we can move on to talking about the usage and ethics of Generative AI (the one you're probably thinking of when you hear "AI"). See you tomorrow. Colin [1]: AI Snake Oil: What Artificial Intelligence Can Do, What It Can't, and How to Tell the Difference - Arvind Narayanan and Sayash Kapoor - 2024. --- ### Stop blaming Brussels Source: https://consultcolin.eu/newsletter/archive/stop-blaming-brussels/ *16 March 2026* - Your cookie banner is a confession, not a legal requirement. A common myth, even among people who work in the web business, is that cookie banners are mandated by the European Union, and it's their fault we're subject to an endless barrage of these banners as we surf the web. This is what's known in technical terms as "completely wrong". The ePrivacy directive doesn't force websites to implement cookie banners at all. What the law says is that organisations are required to obtain your explicit informed consent if they want to track you online. The obvious response would simply be not to track people. But that would mean giving up on lucrative data. So instead, companies built cookie banners. This is "malicious compliance". The site owner can technically claim "We gave them a choice" but the design ensures the choice isn't free or informed at all. Complying (barely) with the rule of law while violating its intent. Every time you see a cookie consent banner, it means someone is collecting your personal data as free raw material - whether the site owner is profiting from it directly or they've embedded third-party tools that do it on their behalf. Do you really want to be seen that way? The solution is simple: don't track your users' personal data and you won't have to pretend "we care about your privacy" (no one believes you, by the way...). Colin --- ### Friday links for March 13th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-03-13/ *13 March 2026* - A European office, your mind on AI, computer handwriting, and the Microsoft invasion. It's Friday. Time for some links that caught my eye this week. 1. Office.eu A new sovereign European startup hoping to compete with Office 365 and Google Docs. It seems to be a hosted instance of Nextcloud Hub using Collabora for its office suite. If you like the idea of self-hosting but you also value your weekends, this might be worth looking in to. 2. AI Isn't Coming For Your Job. It's Coming For Your Mind It's a long read but it's also one of the best articles I've read about the effects of generative AI on our ability to learn. Among other issues, those who use AI passively lose skills and become overconfident. So... nothing to worry about then. 3. Turn Your Handwriting Into a Real Font This site will create a font based on your handwriting. It all happens in the browser so it's completely private. You download a file, print it, fill in your writing, upload a picture back to the site and out pops a font. Your computer can now have handwriting as bad as yours. 4. A map of email servers by local municipality Check who hosts your local municipality's email. Belgium and the Netherlands seem to have signed some sort of blood pact with Microsoft. Enjoy your weekend! Colin --- ### You're not printing it Source: https://consultcolin.eu/newsletter/archive/youre-not-printing-this/ *12 March 2026* - Your spacebar is not a design tool. Open a word processor and what do you see? A white rectangle the exact size of an A4 sheet of paper, a blinking cursor, and a ton of buttons you'll probably never click. And when was the last time you actually printed what you were writing? This has bothered me for years. MS Word still frames everything you write as something destined for a printer: margins, rulers, page numbers, headers, footers... The whole interface is a monument to a workflow that's rarely used these days. But we use it because we always have. We open Word (or Google Docs, same story) and start wrestling with formatting instead of focusing on what we actually want to say. I've also stopped counting the number of times I've watched people hitting multiple returns instead of inserting a page break, tapping the space bar to centre a title, or manually adding numbers to lists. There are proper tools in Word for all this stuff. But if you're not using them, you probably don't need Word in the first place. A modern text editor, an online collaboration tool, even your computer's notepad might do the job. Most of what we write today will be read on a screen, maybe even a phone screen. It doesn't need margins or page breaks - it needs to be clear, readable, and well thought out. And that's one more piece of big tech you can ditch. Colin --- ### Your search bar has a gossip problem Source: https://consultcolin.eu/newsletter/archive/your-search-bar-gossip-problem/ *11 March 2026* - Leaving big tech doesn't start where you think it would. During a call yesterday, someone asked me what an easy first step was on the path to getting off big tech. They lead a smallish organisation of 14 people which is pretty much married to Google: email, docs, video conferencing, storage... I'd say the first and easiest step isn't migrating your email or moving all your files. It's simply switching search engines. Google gathers an obnoxious amount of data about you through your searches and, to make matters worse, their results have been (deliberately) declining over time. There are some European search engines out there but, honestly, I don't think they're anywhere near the top of the rankings yet. They're improving day by day though. My top recommendations would be: Kagi if you don't mind paying, it's privacy-focused and miles ahead of even Google. I happily pay for this one myself. DuckDuckGo is probably the second best option. There are ads but they're contextual not behavioural (based on the search terms, not on profiling you). Next up, if you haven't already, quit using Chrome as your browser and switch to something like Firefox or Vivaldi. Colin --- ### Free isn't cheap Source: https://consultcolin.eu/newsletter/archive/free-isnt-cheap/ *10 March 2026* - €0 per month, plus your soul and a consent banner. Lieven emailed me in response to my email yesterday about Google Analytics. Quoted with permission: I agree that GA is complicated and not ideal but it's free. And for organisations with limited budgets this makes a huge difference. I've tried to sell some of these privacy-respecting services to my team but even €9/month is seen as too much for something that's available from Google for nothing. I understand the dilemma. Google got as powerful as they are by offering most of their services for free. Because, as the saying goes: if you're not paying for the product, you are the product. Over 75% of Google's revenue comes from advertising. Advertising that feeds off the data they collect about you and your users. And is Google Analytics really free? It requires a cookie consent banner to be legal. That's either a paid service or a plugin someone still has to set up and maintain. Then there's GA4 itself: two-month default data retention, reports that require a data science degree to configure, and an estimated 90% of accounts improperly set up. You're wasting time, what's it worth? Then there's the data you're losing because of that cookie banner or ad blockers. When banners are designed properly (no dark patterns, no sneakily pre-ticked boxes), 60% or more of visitors say no. In Germany and France it's over 75%. A Chilean government study of 70.000 users found that when given a completely clear choice, 95% rejected additional cookies! (which tells you a lot about all the dark patterns on cookie banners out there). So, you're seeing a minority of your visitors, skewed towards the ones least likely to care about privacy (older people mostly). Privacy-respecting analytics don't need that banner, which means data from more visitors (though a few hardcore ad blockers will still block some of them). You're also on legal thin ice. Between 2022 and 2025, data protection authorities in 8 European countries ruled against Google Analytics for transferring personal data to the US in violation of GDPR. Sweden issued a €1 million fine. Norway's data protection authority recommended companies look into compliant alternatives. Germany even declared Google Tag Manager as illegal. If your mission involves trust, transparency, and treating people with respect: running Google Analytics contradicts that in so many ways. Every visit gets reported back to one of the biggest advertising networks on the planet. Your visitors came to support your cause or your ideas, not to have their behaviour profiled and exfiltrated. Switching to a tool like Plausible or Simple Analytics advertises your values: "we don't track you". €9 a month isn't competing against free (and some are cheaper than that). It's competing against cookie banners, legal issues, developer time, and feeding your community's data into a surveillance network while telling them that you're on their side. Sorry for the wall of data, I'll try to keep the next ones shorter :) Colin --- ### Building a bigger haystack Source: https://consultcolin.eu/newsletter/archive/building-a-bigger-haystack/ *9 March 2026* - Google Analytics: installed 2019, opened twice. Most websites have Google Analytics installed. Not because someone sat down and actually thought about what data needed to be collected, but because it was free, easy to install or pre-installed by the developers, and because of the power of the Google brand ("everyone uses it!"). I'm not criticising, it just happens that way. I see it all the time. A study from Humboldt University interviewed web analytics consultants who'd worked with hundreds of organisations1. What they found won't particularly surprise you: in every single case, Google Analytics had been chosen before anyone had defined what they actually needed from it. The brand did the selling, the price (or lack thereof) did the rest. The problem is that Google Analytics is a genuinely complex tool, built for marketing teams with dedicated analysts or data scientists. If you don't have one of those handy (and I'm betting you don't), you end up clicking around a sprawling and overwhelming interface, vaguely hoping to stumble across something useful. Meanwhile GA is building a bigger haystack, collecting tons of data on your visitors that you'll never even look at but are still legally responsible for. The researchers found that's more or less what happens: people "play with" the data instead of learning anything from it. Some organisations even believed they were "data-driven" simply because GA was installed. The tool is running, so surely it's doing its job? And there's something seductive about all those complex graphs, they make you feel like you're in control and they look good in a presentation. But GA doesn't think for you, It assumes you already know what to ask and how to configure it to answer. Most people don't, and that's totally reasonable, it's not their job. Meanwhile, simpler tools exist: Plausible, Fathom, Swetrix, and many more that give you clean simple data: how many visitors, where they came from, what they looked at, how they left. That covers what most organisations actually need and, more importantly, would actually use. They also don't need you to install cookie banners, because they don't track your visitors individually, meaning fewer legal headaches and no quietly feeding your users' private data to an advertising network on the side. You don't need less data. You probably need less tool. Colin [1]: Alby, T. (2023). "The Data Dilemma: Google Analytics' Untapped Potential and Web Data Literacy." LWDA 2023 (PDF). --- ### Friday links for March 6th 2026 Source: https://consultcolin.eu/newsletter/archive/friday-links-2026-03-06/ *6 March 2026* - European search, billionaire hypocrisy, Meta watches you poo, quality control goes down the drain. It's Friday, time for some links of interest: 1. xPrivo A new(ish) European search engine that doesn't track you in any way. It's not perfect, but it's surprisingly good compared to many of the other independent search engines out there. It uses the "European Search Perspective" index that's also used by Qwant and Ecosia. 2. Peter Thiel and other tech billionaires are publicly shielding their children from the products that made them rich The best product review you'll ever get is watching the people who built it refuse to let their own kids near it. 3. She Came Out of the Bathroom Naked, Employee Says If you bought the Meta Ray-Ban "smart" glasses, there are now people in Nairobi watching you poop. 4. Have We Forgotten How to Design? Quality control is down the drain: exhibit 1. RoboTaxis can navigate a city autonomously but need a food delivery courier to close their doors. The perfect metaphor for an industry that forgot how to think before it learned how to ship. 5. Artisanal care Quality control is down the drain: exhibit 2. Developers are happily shipping "vibe coded" software they've never tested into critical infrastructure. The craftsmanship of an artisan would be nice or, you know, any craftsmanship at all. See you next week... Colin --- ### Double surveillance Source: https://consultcolin.eu/newsletter/archive/double-surveillance/ *5 March 2026* - When you track your visitors, you feed the beast. In my previous email, I mentioned how surveillance on the internet was the architecture working as planned. But there's a side to it we don't always think about: When someone visits your website and it loads a Google Analytics tag, that visit isn't just displayed on your analytics dashboard, it's reported back to Google too. Google now knows that person visited your site, at what time, on what device, and connects it to everything else it already knows about them: searches, emails, location history, Chrome habits, 2am YouTube binges... Your visitor didn't agree to that (clicking "I accept" out of consent fatigue doesn't count). They just came to your site. None of this required thought: the analytics came with the website, the embed was the obvious way to share video, and Facebook told you the pixel was necessary for your ad campaign to work. You knew these tools tracked your visitors, that's why you installed them. What was probably less obvious was that the platforms were reading over your shoulder the whole time and keeping their own copy: A YouTube embed pings Google's servers the moment your page loads, whether someone plays the video or not. Most people don't realise tracking is already taking place here. Google Analytics gives you a nice dashboard, but gives Google something too: more data points on your visitor to add to their own pile. The Facebook pixel goes furthest. It feeds your visitor data into Meta's targeting system, which means any competitor can now run ads against the audience profile Meta has quietly built from people visiting your site. You paid to build that audience - someone else gets to use it. You didn't decide to hand your visitors' data to a surveillance network, you just didn't decide not to either. The good news: this is one of the more fixable problems, and the alternatives are genuinely good. More on that soon... Colin --- ### Built to watch you Source: https://consultcolin.eu/newsletter/archive/built-to-watch-you/ *4 March 2026* - Surveillance wasn't added to the internet. It was the point. Today, the idea that surveillance is something that was added onto the internet after the fact is a common belief. But it's not true, it was baked in from the very start. It emerged from military efforts to build computer systems for a world where everyone was surveilled, predicted and controlled. US intelligence was already using it to help them spy on civil rights activists in the 1970s1. When Google and other big tech companies track and profile their users today, it's simply the system doing what it was always designed to do. Google's advertising model, for example, is built on exactly the same logic as those early systems: collect as much data as possible (your Gmail inbox says hi), find patterns, predict behaviour. So should we all delete our accounts, move to a cabin in the mountains, and start growing our own vegetables? Of course not (well, unless cabin life is your thing). But widespread acceptance doesn't make something inevitable. Better, more ethical alternatives exist, and in many cases they're just as good, if not better. More on this in the next email... Colin [1] See the book "Surveillance Valley" by Yasha Levine for the full history. ---