On April 18, 2026, Booking.com's privacy policy page was detected as changed, but the visible content captured is an AWS WAF security challenge page rather than the actual privacy statement text. The detected change appears to involve an internal timestamp or nonce value update in the security challenge script, not a substantive change to privacy policy terms. This means no meaningful change to consumer data rights or protections can be confirmed from the available content.