Technical audit · 2026-05-26

bildung.gv.at

Austrian Federal Ministry of Education

Federal Ministry of Education — 44 requests, 2 domains, both bildung.gv.at. Zero external requests. The policy describes Siteimprove — the CSP blocks it. A Moodle portal with a strict CSP.

Timeline of the leak

+0 ms · load
All requests to [www.bildung.gv.at](https://www.bildung.gv.at) and bildung.gv.at (apex, IDP images). Zero external.
Session total
44 requests, 2 domains. Siteimprove blocked by the CSP — data did not leave.

Declared versus actual

Siteimprove Analytics — declared in the policy, blocked by the CSP, absent from the HAR — declared

Indicators of GDPR non-compliance

Context

Bundesministerium für Bildung (BMB) is Austria’s federal ministry of education. The bildung.gv.at portal runs on Moodle (eduportal). HAR: 44 requests, 2 domains.

Strict CSP holds the line

CSP: default-src 'self' — one of the strictest profiles in the Austrian series. Only proprietary domains are allowed, plus tube.virtuelle-ph.at for media. Siteimprove (siteimproveanalytics.com) is not on this list — and did not appear in the HAR. Data did not leave.

Policy vs. reality

The privacy policy describes Siteimprove Analytics as an active tool, using cookies on servers in Denmark. This is either outdated information, or Siteimprove operates only on other subdomains of the ministry. Either way, the policy does not reflect the actual configuration of the homepage.

Moodle platform for educators

The site’s structure is Moodle with a custom eduportal theme and plugins (bipidp, eduthek, faq). Integrated with ID Austria via IDP. The portal serves teachers and students — an audience for whom data minimization matters especially.

Conclusion

44 requests, 2 domains, zero external services in the HAR. The CSP does its job. Severity 0 — despite the discrepancy in the policy: no data actually leaves.

Evidence
Original (audit)
HAR file: at/bildung-gv-at-2026-05-26.har
SHA-256: 702427a9073f4a1c8a86313a2d18bf1faa1707148fa832bd3c900003bef2c58b
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Datenschutzbehörde (DSB)file a complaint online →

To: Datenschutzbehörde (DSB)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website bildung.gv.at.

2. Circumstances
I visited the website bildung.gv.at and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 26 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) The privacy policy describes Siteimprove Analytics as an active tool — it did not appear in the HAR. The CSP (`default-src 'self'`) blocks external domains. The policy has not been updated and diverges from the actual configuration.

Full technical documentation is published at: https://gdpru.eu/en/audits/at-bildung-gv-at/

3. Provisions violated
GDPR Art. 13

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]