Technical audit · 2026-05-26

fwf.ac.at

Austrian Science Fund

Austrian Science Fund — 86 requests, 8 domains. The Usercentrics CMP with an autoblocker holds trackers back. Friendly Captcha for forms. No analytics, no advertising in the HAR. Gap: Usercentrics and frcapi are not declared in the policy.

Timeline of the leak

+998 ms · Usercentrics autoblocker
privacy-proxy.usercentrics.eu/latest/uc-block.bundle.js — the tracker blocker loads first among external services.
+1000 ms · Usercentrics loader
app.usercentrics.eu/browser-ui/latest/loader.js — the CMP initializes.
+1910 ms · Friendly Captcha
global.frcapi.com — an anti-bot system for forms. GDPR-compliant, data stays within the EU.
+2539–3802 ms · Usercentrics banner
Full CMP initialization: settings, translations, UI components. Banner displayed.
Session total
86 requests. No analytics trackers appear in the HAR — the consent gate holds. 33 requests to Usercentrics infrastructure.

Declared versus actual

+ Usercentrics CMP — not mentioned in the policy — не заявлен
+ Friendly Captcha (global.frcapi.com) — not mentioned in the policy — не заявлен

Transfer timings

+998 ms privacy-proxy.usercentrics.eu

Autoblocker — blocks all trackers until consent.

+1910 ms global.frcapi.com

Friendly Captcha. Servers in the EU.

Indicators of GDPR non-compliance

Context

FWF (Fonds zur Förderung der wissenschaftlichen Forschung) is Austria’s principal fund for financing fundamental scientific research. HAR: 86 requests, 8 domains.

Usercentrics holds the line

The Usercentrics CMP is set up with an autoblocker (uc-block.bundle.js) — it loads first among the external services and blocks all trackers until the user makes a choice. There is no Google Analytics, no Matomo, no analytics pings of any kind in the HAR. 33 requests to Usercentrics infrastructure — the CMP system itself. The architecture is correct.

Friendly Captcha instead of reCAPTCHA

Forms use global.frcapi.com — Friendly Captcha, a European alternative to Google reCAPTCHA. Data is processed on servers within the EU, with nothing sent to Google. A good choice for a science fund.

A gap in the policy

The privacy policy (in English) describes the newsletter, grant applications, and personal data in detail — but does not mention Usercentrics as a consent data processor or Friendly Captcha. Both load on every visit and transmit data to external servers.

Conclusion

86 requests, 8 domains, zero analytics trackers. The science fund chose the right tools and configured them correctly. The only gap is the failure to declare the CMP itself and the Captcha in the policy.

Evidence
Original (audit)
HAR file: at/fwf-ac-at-2026-05-26.har
SHA-256: 8977b22a140a3b3c8bb2024a194977b3a64533ac8d6b263c8ff3cf1a9d2d52f7
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Datenschutzbehörde (DSB)file a complaint online →

To: Datenschutzbehörde (DSB)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website fwf.ac.at.

2. Circumstances
I visited the website fwf.ac.at and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 26 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) The Usercentrics CMP (app.usercentrics.eu, api.usercentrics.eu, privacy-proxy.usercentrics.eu) and Friendly Captcha (global.frcapi.com) load before consent and are not mentioned in the privacy policy. Both services transmit data to external servers on every visit.

Full technical documentation is published at: https://gdpru.eu/en/audits/at-fwf-ac-at/

3. Provisions violated
GDPR Art. 13

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]