Federal Ministry of Education — 44 requests, 2 domains, both bildung.gv.at. Zero external requests. The policy describes Siteimprove — the CSP blocks it. A Moodle portal with a strict CSP.
Timeline of the leak
Declared versus actual
Indicators of GDPR non-compliance
- GDPR Art. 13The privacy policy describes Siteimprove Analytics as an active tool — it did not appear in the HAR. The CSP (`default-src 'self'`) blocks external domains. The policy has not been updated and diverges from the actual configuration.
Context
Bundesministerium für Bildung (BMB) is Austria’s federal ministry of education. The bildung.gv.at portal runs on Moodle (eduportal). HAR: 44 requests, 2 domains.
Strict CSP holds the line
CSP: default-src 'self' — one of the strictest profiles in the Austrian series. Only proprietary domains are allowed, plus tube.virtuelle-ph.at for media. Siteimprove (siteimproveanalytics.com) is not on this list — and did not appear in the HAR. Data did not leave.
Policy vs. reality
The privacy policy describes Siteimprove Analytics as an active tool, using cookies on servers in Denmark. This is either outdated information, or Siteimprove operates only on other subdomains of the ministry. Either way, the policy does not reflect the actual configuration of the homepage.
Moodle platform for educators
The site’s structure is Moodle with a custom eduportal theme and plugins (bipidp, eduthek, faq). Integrated with ID Austria via IDP. The portal serves teachers and students — an audience for whom data minimization matters especially.
Conclusion
44 requests, 2 domains, zero external services in the HAR. The CSP does its job. Severity 0 — despite the discrepancy in the policy: no data actually leaves.
702427a9073f4a1c8a86313a2d18bf1faa1707148fa832bd3c900003bef2c58bWhere to file: Datenschutzbehörde (DSB) — file a complaint online →
To: Datenschutzbehörde (DSB) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website bildung.gv.at. 2. Circumstances I visited the website bildung.gv.at and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 26 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) The privacy policy describes Siteimprove Analytics as an active tool — it did not appear in the HAR. The CSP (`default-src 'self'`) blocks external domains. The policy has not been updated and diverges from the actual configuration. Full technical documentation is published at: https://gdpru.eu/en/audits/at-bildung-gv-at/ 3. Provisions violated GDPR Art. 13 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]