A citizen who opens the website of their town hall did not choose to be exposed to anyone else. They came for a form, an opening time, a council minutes PDF. Yet the moment that homepage loads, their browser may quietly contact a handful of other companies, each of which receives their IP address and, depending on one header, the exact page they are reading.
That header is the Referrer Policy. We measured whether French public websites declare one, and how many third parties their homepage calls. Here is what 600 domains gave us.
What we measured, and on what
We took a systematic sample of 600 domains belonging to French public bodies, mostly town halls and local authorities, and issued one GET request per domain on 1 September 2026, with a user agent that names itself and links to the method. 466 answered over HTTPS. The 134 that did not respond are counted separately and excluded from every rate below, because a silent domain is not a compliant domain and it is not a failing one either.
For each responding homepage we recorded three facts:
- the
Referrer-Policyresponse header, and its value, - the number of distinct third-party domains the HTML asks the browser to fetch,
- whether a cookie was set on that first request.
The four reserves, stated before the numbers
- This is the homepage, not the site. An internal form page may behave very differently.
- A third party is not a tracker. A font, a map or a video player is a third party. The count measures exposure, not intent.
- The count is a floor, never a total. We only see what the served HTML declares. Third parties injected later by JavaScript are invisible to this method.
- No conclusion about lawfulness can be drawn from this file. It describes what a page asks a browser to do, not what a controller has declared.
The result: 81% declare no Referrer Policy
Of the 466 responding sites, 88 declare a Referrer Policy and 378 do not. That is 19% against 81%.
| What we found | Count | Share of responding sites |
|---|---|---|
Declares a Referrer-Policy | 88 | 19% |
| Declares none | 378 | 81% |
| Calls no third party at all | 108 | 23% |
| Sets a cookie on the homepage | 122 | 26% |
| Median number of third parties | 2 |
Among the 88 that do declare one, the distribution is reassuring: 49 use strict-origin-when-cross-origin, which is the modern sensible default, 16 use the older no-referrer-when-downgrade, and 13 use same-origin. Only four use unsafe-url, which sends the full URL to every third party including over plain HTTP.
The honest reading is that the absence of a header is not, on its own, a leak: current browsers already default to strict-origin-when-cross-origin. What the absence means is that the protection depends entirely on the visitor's browser rather than on a choice made by the public body. For a service that citizens cannot opt out of using, that difference is not cosmetic.
Third parties: a median of two, and a long tail

The photograph shows a modern administrative facade in grey concrete, lit from the side, with a single small surveillance camera fixed to the wall between two window bays. Nothing in the image is hidden, and nothing in it announces itself either.
108 sites (23%) call no third party at all from their homepage. That is the encouraging half of this dataset: a public homepage that depends on nobody is not a theoretical ideal, roughly one in four already does it.
The median is 2 third parties. The distribution then thins out quickly: 44 sites call 5, sixteen call 6, and four sites call 10 or 11.
The most frequently contacted operators across the sample:
| Third party | Present on | Share of responding sites |
|---|---|---|
googleapis.com | 196 | 42% |
gstatic.com | 100 | 21% |
googletagmanager.com | 72 | 15% |
google.com | 72 | 15% |
cloudflare.com | 67 | 14% |
hcaptcha.com | 34 | 7% |
googleapis.com at 42% is almost entirely web fonts. It is the single most effective thing to change on this list, because a font can be self hosted in an afternoon and the visitor's IP then stops travelling. googletagmanager.com at 15% is a different matter, since a tag manager exists to load other things.
The two outliers, described carefully
The two highest counts in the sample, at 11 third parties each, are status pages on esante.gouv.fr subdomains, and they call doubleclick.net, ads-twitter.com and facebook.net. Two things must be said in the same breath. These are service status pages, not the health services themselves, and they appear to run on a third-party status platform whose own page template brings those tags along. That is an accurate description of what we measured and it is as far as the measurement lets us go.
What a visitor can actually do about it
Nothing on this list is under the visitor's control. You cannot make a town hall self host its fonts, and you did not choose to load the page that calls them. What you can change is what those third parties learn about you when the call happens: a VPN replaces the IP address that every one of those operators would otherwise record, on every site, including the ones that behave well.
That is a narrow benefit and worth stating narrowly. It does not stop the request, it does not remove the tag, and it does nothing about cookies you accept afterwards. It changes one field, the one that identifies your connection.
Hide the IP that every third party recordsA single homepage can hand your address to six separate operators. A VPN changes what they receive, on every site you visit, not just the ones you chose.The data, open and repeatable
Both the dataset and the collection script are published so that anyone can rerun the measurement, extend the sample, or contradict the result. The script performs one request per domain, identifies itself, and writes one row per domain along with a summary file.
A single run is a snapshot, not a state. These figures describe 1 September 2026. If a public body self hosts its fonts next month, its row changes, and that is exactly what a repeatable method is for.
Frequently asked questions
What is a Referrer Policy, in one sentence? It is an HTTP response header telling the browser how much of the current URL to disclose when requesting something from another server.
Does a third-party domain mean a tracker? No. A font, a map and a video player are all third parties. The count measures exposure, not intent.
Are these sites breaking the law? We do not say that, and the data cannot support it. Lawfulness depends on purpose and on what the controller declared, which a single HTTP request cannot reveal.
Measured on 1 September 2026 by one GET request per domain, on the homepage only. 600 domains sampled, 466 responded. All rates are computed on responding domains. Commercial links carry rel="sponsored nofollow"; an affiliate commission may apply at no extra cost to you.
Fix the leak - encrypt everything with NordVPN
Secure DNS · kill switch · Threat Protection · 30-day money-back
